Skip to content
All posts

How to move from security compliance to lasting behavioural change

 

Changing behaviour

Winning board support is only the beginning ... discover how to move beyond tick-box compliance to drive lasting behavioural change and embed a true culture of security.

Compliance frameworks can provide structure, accountability and assurance. They can also help organisations demonstrate that recognised controls and governance processes are in place.

But compliance alone does not guarantee that people will behave securely.

An organisation may complete audits, deliver mandatory training and record policy acceptance while employees continue to make risky decisions in practice. Lasting improvement depends on turning formal requirements into secure everyday behaviour.

That requires more than achieving compliance. It requires leadership, communication, measurement and a security culture that employees understand and support.

Why security compliance matters

Standards and frameworks such as ISO 27001, PCI DSS, COBIT and NIST provide organisations with a structured approach to managing information security risk.

They can help organisations:

  • Assess existing controls
  • Identify security gaps
  • Define responsibilities
  • Improve governance
  • Demonstrate assurance to customers and partners
  • Meet contractual and procurement requirements
  • Support regulatory obligations
  • Create a basis for continual improvement

Certification or alignment with a recognised framework can also provide valuable external assurance. It shows that the organisation has taken a systematic approach to protecting information and managing security risk.

For boards, this makes compliance easier to understand, approve and monitor. It creates clear objectives, defined requirements and visible evidence of progress.

However, the existence of policies and controls does not mean employees will always follow them.

Why compliance does not guarantee behavioural change

Compliance frameworks describe what an organisation should have in place. They cannot fully determine how people will behave when they are busy, distracted, under pressure or faced with an unfamiliar situation.

Employees may complete required training without remembering or applying it. They may accept policies without understanding how those policies affect their work. They may also find ways around controls they see as confusing, inconvenient or unnecessary.

This creates a gap between formal compliance and operational reality.

An organisation may be able to demonstrate that:

  • Training was delivered
  • Policies were published
  • Controls were implemented
  • Assessments were completed
  • Employees acknowledged requirements

But these measures do not automatically show that employees:

  • Recognise suspicious activity
  • Report potential threats
  • Protect sensitive information
  • Follow secure processes consistently
  • Avoid repeating risky behaviour
  • Understand their role in managing security risk

Compliance provides the structure. Behaviour determines whether that structure works in practice.

The risks of a tick-box approach

When security is presented mainly as a set of mandatory tasks, employees may focus on completing the requirement rather than understanding its purpose.

Training becomes something to finish. Policies become documents to accept. Security controls become obstacles to work around.

This can lead to superficial compliance without meaningful engagement.

Repeated campaigns, policy updates and mandatory exercises can also create fatigue. Employees may stop paying attention when every message is presented with the same urgency or delivered without clear relevance to their role.

A tick-box approach can therefore create several risks:

  • Low engagement with security communications
  • Poor retention of training content
  • Increased use of insecure workarounds
  • Reduced confidence in reporting concerns
  • Limited understanding of why controls matter
  • Little evidence of lasting behavioural improvement

The solution is not to reduce the importance of compliance. It is to connect compliance requirements to the decisions employees make every day.

Use culture to sustain secure behaviour

Security culture influences what people do when no one is checking.

It is shaped by leadership, shared expectations, working practices and the way the organisation responds to mistakes and concerns.

A strong security culture helps employees understand:

  • Why information security matters
  • What secure behaviour looks like
  • How security relates to their role
  • Where to find guidance
  • How to report a concern
  • That secure behaviour is supported by leadership

This requires more than policies and annual training. Employees need regular communication, realistic guidance and practical support.

Security messages should explain the purpose behind a requirement, not simply state the rule. For example, rather than telling employees not to share data through an unapproved service, explain the risk, provide an approved alternative and make the secure option easy to use.

When employees understand both the reason for a control and the action expected of them, they are more likely to apply it consistently.

How to win board support for behavioural change

Boards are more likely to support behavioural change when it is presented as a business risk issue rather than a standalone awareness activity.

The case should connect human behaviour to outcomes that matter to the organisation.

Link behaviour to business risk

Show where employee decisions affect:

  • Operational disruption
  • Financial loss
  • Regulatory exposure
  • Customer trust
  • Data protection
  • Incident response
  • Organisational resilience

Use relevant examples from incidents, reporting data, simulations and internal assessments to demonstrate where behaviour creates or reduces risk.

Show where compliance depends on people

Many controls rely on employees making the correct decision.

Access controls depend on people protecting credentials. Data classification depends on information being labelled and handled correctly. Incident response depends on employees recognising and reporting concerns promptly.

Make these dependencies visible to the board.

Define measurable outcomes

Avoid presenting success only through completion rates.

Training completion can confirm that an activity took place, but it does not prove that behaviour changed.

Include measures such as:

  • Phishing reporting rates
  • Repeated risky actions
  • Time taken to report incidents
  • Employee confidence
  • Policy understanding
  • Use of approved tools and processes
  • Changes in simulation performance
  • Behavioural trends by role or risk group

Explain the value of leadership participation

Employees take cues from senior leaders.

When executives follow security processes, participate in training and communicate the importance of secure behaviour, they show that security requirements apply across the organisation.

Leadership should therefore be part of the programme, not simply its sponsor.

Report progress clearly

Boards need concise evidence of whether risk is increasing or decreasing.

Reporting should explain:

  • The most important human risks
  • Which groups or behaviours need attention
  • What action is being taken
  • Whether previous interventions worked
  • What support or investment is required

This makes behavioural change easier to govern and connects it directly to wider security objectives.

Measure outcomes, not just activity

A security programme should distinguish between activity and impact.

Activity measures include:

  • Number of training modules delivered
  • Percentage of employees completing training
  • Number of communications sent
  • Number of simulations conducted
  • Number of policies acknowledged

Impact measures show whether behaviour changed.

These may include:

  • More employees reporting suspicious messages
  • Fewer repeated simulation failures
  • Faster escalation of security concerns
  • Better handling of sensitive data
  • Greater confidence in recognising threats
  • Reduced use of unapproved processes
  • Improved security behaviours in higher-risk teams

Both types of measurement are useful, but they answer different questions.

Activity shows what the organisation delivered. Impact shows whether it made a difference.

Building compliance into a stronger security culture

Compliance and behavioural change should not be treated as competing objectives.

Compliance provides structure, governance and accountability. Behavioural change helps ensure those requirements are understood and applied consistently.

To bring the two together:

  • Explain why controls matter
  • Make secure actions practical
  • Tailor guidance to different roles
  • Reinforce messages regularly
  • Encourage employees to report concerns
  • Respond constructively to mistakes
  • Involve senior leaders visibly
  • Measure behaviour as well as completion
  • Use findings to improve the programme

Board approval is an important starting point, but it is not the end of the process.

For compliance to reduce risk over time, leaders must support the communication, systems and cultural change needed to turn formal requirements into secure everyday behaviour.

The strongest organisations do not simply demonstrate that controls exist. They build a culture in which people understand those controls, trust them and apply them consistently.


Move beyond compliance to lasting behavioural change

TSC helps organisations turn security requirements into practical, measurable behaviours that reduce human risk and strengthen security culture.

Explore our Human Risk Platform


Related pages

Human Risk Platform
Products & Services