Motivating your teams to work securely
Watch the TSC webinar on motivating people to work securely, covering the COM-B behaviour change model, social norms, leadership modelling, feedback loops and how to build a lasting security culture.
How to motivate employees to work securely
Motivating employees to work securely is one of the hardest parts of building a strong security culture. This TSC webinar explains why knowledge and annual security awareness training are only the starting point, and why lasting behaviour change depends on capability, opportunity and motivation working together.
Using the COM-B behaviour change model, the session explores what really drives secure behaviour: clear expectations, supportive systems, leadership modelling, social norms, feedback, autonomy, competence and a sense of belonging. It shows why people often want to do the right thing but are blocked by unclear processes, poor reporting routes, information overload, weak manager engagement or leaders who do not model the behaviours they expect.
The webinar also explains why training needs to happen in the flow of work, not just once a year. Through practical examples, conformity research, self-determination theory and real client insight, it shows how security leaders, CISOs and managers can motivate teams to build secure habits that last.
Essential viewing for anyone responsible for security awareness training, cyber security behaviour change, employee motivation, COM-B security culture or moving from tick-box compliance to secure everyday behaviour.
In this webinar, you'll discover:
Turn motivation into lasting security behaviour change
This webinar explains how motivation, capability and opportunity shape secure behaviour at work. TSC's security awareness training and eLearning modules help your people build practical habits, reduce everyday risk and strengthen security culture across teams.
View the full webinar transcript
Introduction
This is part two of a series of webinars that we're going to deliver about the model that we use at TSC which is about COM-B, and I'm going to explain a little bit about what COM-B is during the webinar. I'm aware that some people will have been on the first webinar that I delivered and I do need to revisit some of the slides from that in order to get us to the point where we can focus on the topic of today, which is about motivating people to work securely.
Just a little bit about myself for those of you that haven't been on a webinar that I facilitated before. I'm head of communications at the security company and I've worked at TSC for eight years now, which has been an incredible journey. Every day is different. The challenges that we face and the threat landscape that we work in change all the time, so it just makes it continually interesting. But before I joined TSC, I was in training and development for more than 30 years. So what I like to do whenever I'm delivering webinars is combine my knowledge and experience of information and cyber security with my decades of experience of training and development, to help people understand the risks and threats and how to apply that individually and in the workplace.
What we like is feedback from you. I'll be going through the slides, but I'll make sure we've got at least 15 minutes before 3 o'clock to cover your questions. So as we go through, use the chat and Q&A functions to post any questions as they occur to you, and we'll cover them at the end so you get the best out of this hour.
Today's agenda
There are three things I'm going to look at. The first is the tactics you can deploy to improve security behaviours across your workforce. People asked for this topic because it is the most challenging thing to achieve: actually motivating people. So I want to give you some tactics and strategies to assist you on that journey.
We'll also acknowledge some of the key blockers that prevent people from being motivated and changing their behaviour, and for each one I'll say what you need to do to remove it. And we're doing all of this in the context of creating a more secure culture. Everybody's journey to a secure culture is different, but there is always room for improvement, and I'll focus on why enabling people to be motivated is one of the critical keys that unlocks it.
What we mean by motivation and security culture
I always like to start by clarifying terms. Motivation is basically what is impacting on people's behaviour: the forces acting on a person to behave a certain way, and what is internally driving them. So we're looking at those external and internal motivational factors. And the definition we use at TSC is that a security culture is about the values, the beliefs and the behaviours that people have and deploy that determine how securely they work.
There's a third thing to cover before we get into COM-B. As humans, there are some fundamental things that are part of our makeup. In general terms, we are social beings. We like to form groups and we thrive on social bonds. I won't go into detail on Maslow's hierarchy of needs, but Maslow theorised about what motivates us, and this need for social bonds and a sense of belonging is fundamental. His theory has stood the test of time since the 50s. We have internal drivers, all different for everybody, but we also respond to external stimulus, and all of these things impact on how motivated people are.
The COM-B model
At the security company we use a model to support organisations to create a more secure working culture. It's called COM-B, which stands for Capability, Opportunity and Motivation that informs Behaviour. It's almost like an onion, with different layers: the infrastructure within your organisation, the processes and systems that support people to behave securely, and then the three central elements of motivation, capability and opportunity.
Capability: when you want people to behave securely, they need to be capable. Have they got the right skills, the right knowledge, the ability to do what you're asking? And do they have the cognitive capacity, meaning they're not too overwhelmed with everything else going on to focus on what you need them to do?
Opportunity: this is much more about the infrastructure, systems and processes. Do people have the resources they need to behave securely? Are the systems and processes right? Does their working environment enable them? And do they have people around them to help and support them to be that strong line of defence?
Motivation: this is where we go deeper. Do people want to do this, that internal desire and drive? Do they believe that they should, which links to their belief patterns? And have they got the right habits, the skills deployed day in, day out, to be a strong line of defence?
You can lead a horse to water
As a trainer, I can take people down a route, provide knowledge and skills, and get to the point where they need to apply it. That's taking the horse to the water; getting them to drink is the challenge. As a trainer or manager, we might model what we want people to do, but the horse can still look bemused: "Where is the rest of my group? You're not part of my group, so I don't have to do what you're doing." The motivation isn't there.
Being in a training function is quite similar to being in an information security team: we support teams delivering the service the business offers, but we're not an inherent part of their team, which creates a fundamental problem to address. Where we need to get to is people being in their group, in their safe environment, all doing the same thing, creating a norm for that group. It's all about social groups and social norms.
Why training individuals isn't enough
Training underpins motivation and willingness, but we tend to train individuals. You'll have an annual programme, which is great and provides the foundation of knowledge. But if you take one person out of their team, teach them something, and expect them to apply it back among 15 colleagues, that's difficult, especially if they aren't a manager. The norms of the group re-establish, so it's hard for that person to apply what they learned.
So the tactic is: yes, people need the annual training, but they then need training in the flow of work, happening as they do their job, in their context, with the people they work with, where they get continual feedback and reinforcement. Bite-size learning, short videos, animations and facilitated team activities that managers run regularly all help, because behaviour change happens in context with the whole group, establishing new norms. That means devolving some of the training responsibility to teams.
People want to do well, but blockers get in the way
One thing to hold onto: people have an inherent drive to do things well. Nobody comes to work wanting to fail. You have a captive audience who are motivated to be there and want to do well, but there are common blockers that prevent them from working securely.
Many of our clients run surveys to establish where they are on security culture and where they want to get to. At the end we ask: what would you recommend we do to improve our security culture? Between 30 and 60% of people take the time to respond, and that's gold dust, because they're telling you the blockers they'd like removed. Some common themes come through.
Knowledge: people say they want more training and development, but in detail they ask for things like a short video from a senior leader, or someone telling a story about something they experienced, or the chance to revisit learning more frequently. Storytelling matters.
Processes: people pick up on processes that frustrate them. One client introducing multi-factor authentication saw real anxiety in the responses. Reporting security incidents is another: people often say it's too complicated and ask us to streamline it. We like to do things the quickest, easiest way, like cutting across the grass rather than following the path. One company's reporting process was six steps: find the incident, go to the intranet, find the IT security page, find the form, decide the incident type, enter all the information, submit. If it's that convoluted, people put it off, forget, and don't report. If people tell you a process is a barrier, it's our responsibility to listen and streamline.
What people see others doing: one survey asked whether people were confident about when to wear their ID badge, and whether they'd challenge someone not wearing one. People said they knew why they should, but if their managers and senior leaders don't wear them, why should they, and how do they challenge someone more senior? People observe the norms and what their leaders do. If leaders aren't doing what you ask, people won't be motivated to either, so consider a programme of support and clarity for senior leaders and managers.
Conformity and social influence
Ultimately people want to conform, and two things influence this. The first is informational social influence: in a new or uncertain situation, people look at how everyone else is behaving, replicate it, and then internalise it, which is exactly why you need leaders and managers visibly working securely.
There's a well-known social experiment (I trained as a psychologist before training and development) that shows this. A woman new to a room joins others who all stand up every time a beep sounds. Within two beeps she joins in, with no idea why. Remove everyone else, and she still stands at the beep, she's internalised it. Then a newcomer arrives, asks why she's doing it, and she says "I don't know, everybody was doing it." He starts doing it too. It shows how social norms and the need to conform play out.
The second is normative social influence: people look at what's expected. Researchers (Schultz) helped a hotel chain reduce towel and bedding washing by placing one message in each room: "75% of guests reuse their towels." That single message about what most people do reduced towel usage by 25%. So people want to know what's expected and what the norm is, and you need to make that information available.
The cycle of change
What drives us internally is captured by Prochaska and DiClemente's cycle of change. People move from not knowing they need to change, to understanding they need to, to taking action, and then maintaining the behaviour, usually around six months, until it becomes internalised and subconscious. That's where you want to get to: a secure behaviour that's an automatic habit. And if you can shift a desired behaviour from something people need to do to something they want to do, you've got that internal driver.
A quick personal example. I dislocated my ankle, and the physiotherapist told me I was dehydrated and needed to hydrate more. I wanted my ankle to heal, so I decided I wanted to do it, but it required three large glasses of water a day on top of everything else. For the first couple of days I managed it, then I slipped. I needed reinforcement, reminders and conversation. My partner became critical, asking "have you had your second glass yet?" Over time it became automatic. So with motivation and behaviour change, you move people to understanding something needs to change, get them to decide they want to, then support them to maintain it.
Self-determination theory
Self-determination theory has three elements, all of which need to be in place for people to be self-motivated.
Autonomy: people need a level of autonomy and to understand why. Long, strong passwords are a good example: explain why they need to be long and strong, give the rule (three unconnected words with a couple of characters swapped), but let people choose their own words. An unexplained mandate won't motivate.
Competence: people need to believe they're effective and that it's working, through feedback, and to feel safe learning from mistakes. If someone clicks a phishing email, it's okay, as long as they then report it. But if you don't give people the tools and resources to act, motivation suffers.
Belonging and impact: people need to see that what they do makes a difference. A frequent survey comment is "I report incidents and never hear anything, so I don't know if it's making a difference," and if they don't know, they stop. Equally, failing to listen to feedback, or being defensive about it, erodes motivation.
Strategies that work
Start by being absolutely clear which behaviours you want to change; don't bombard people. Pick the ones with the biggest impact on a secure culture and focus there, then deploy your team strategies.
Be crystal clear with the information and guidance you provide. Lead from the front: whatever behaviours you want, your senior leaders need to display them now, from wearing an ID badge to long strong passwords to not using USB sticks. And it's not just senior leaders, every team leader needs to be seen doing it, because their team looks to them and replicates and internalises it. Get your managers to engage with the agenda, understand why it matters, support their teams and explain why, and keep the chatter and stories going.
Give feedback. If people are doing the right thing, praise and acknowledge it, we too often only give feedback when things go wrong. And if behaviour is required and people aren't doing it, think about consequences. Ask, listen and respond: find out the barriers in your workplace, and if you ask, you must listen and respond, staying open to feedback. Chatter, informal conversations in teams initiated by managers, is half the battle. And incorporate learning in the flow of work, in context, underpinned by great awareness and training materials.
Questions and answers
Would it be unethical to make up statistics to influence people to do the right thing?
Wherever you search, you can find a statistic that gets your message across, so you can find evidence that points people the right way. The hotel chain simply said "70% of our guests do this" and it changed behaviour. The key is to make sure that, if challenged, you'd feel confident explaining where the information came from.
Have you helped companies build COM-B theory into their documented cyber culture strategies?
Yes, absolutely. It's a model we use across the full range of our work. Some clients focus on one aspect, others want the holistic view across all the dynamics. We've aligned the COM-B requirements with SABRE so we can build it into the surveys, helping people see their strengths and areas for improvement against the model. One thing we don't do is compare where one organisation sits against another; the NCSC has also stopped using evaluation tools that way, because every organisation is so unique. But COM-B provides a brilliant framework to help you move forward.
How do you ensure bite-sized training and initiatives don't just become white noise?
It comes down to your team managers. They need to deploy a full range of resources, animations, team activities and so on, but crucially have the conversation about it and relate it back to the work, coming back to it regularly so it stays relevant. This is why training in the flow of work is so important: people are in context, thinking about their day-to-day work and what they can realistically do to be more secure. It's far more effective devolved to team level.
Giving people enough information to ask the right questions seems to conflict with giving clear, simple instruction. How do they fit together?
The two go side by side. We want people to be autonomous and think for themselves, but to get them there you need to be clear, offer guidance and be quite directive, depending on where they are on their journey. You provide the clear instruction to make them aware, and once they've decided to behave differently, that's when they start to think, ask questions and consider how to apply it. So it all interlinks.
Does a tick-box mentality towards training affect how important employees think it is?
Yes. If the only training people receive is ten mandatory courses once a year, with information and cyber security among them, they'll see it as not that important, just something to get done, and you won't get behaviour change. Compliance has its place and your organisation probably won't change that element. But it's about layering: engage your team managers, get them having conversations with their teams, and give them a toolkit of resources to use month by month on topics relevant to their context. That's how you get the change.
Security behaviour change FAQ
How do you motivate employees to work securely?
Employees are more likely to work securely when they understand why it matters, have clear guidance, see leaders modelling the right behaviours and receive feedback when they act securely. Motivation also depends on making secure behaviour easy, relevant and part of normal team routines.
What is the COM-B model in security awareness?
The COM-B model explains that behaviour depends on capability, opportunity and motivation. In security awareness, this means employees need the knowledge and skills to act securely, the systems and environment that make secure behaviour possible, and the motivation to apply those behaviours every day.
Why does annual security training fail to change behaviour?
Annual training can build knowledge, but it rarely changes behaviour on its own. Secure habits need regular reinforcement, manager-led conversations, feedback loops, practical resources, social norms and training in the flow of work so people can apply what they learn in real situations.