Skip to content
All posts

Security Culture: Where do you start

Watch the TSC webinar on building a security culture and learn how to move from tick-box training to lasting behaviour change, using the COM-B model, social norms and leadership.

Building a security culture starts with behaviour

Security culture is not built through training alone. It is shaped by the values, beliefs and everyday behaviours that determine how securely people work, from reporting incidents and recognising phishing attempts to asking questions, challenging unusual requests and following secure processes.

This webinar explains why organisations should start by defining the behaviours they want to see, then work backwards to build the capability, opportunity and motivation people need to act securely. Using the COM-B model, the session shows how security awareness, leadership, systems, feedback, habits and social norms all influence behaviour change.

Drawing on practical examples, including why phishing still works, how habits form and why compliance-only training often fails, the webinar sets out a clear approach to improving cyber security culture. It covers common blockers such as information overload, lack of measurement, weak leadership modelling and unclear goals, before outlining practical strategies that help secure behaviours become part of everyday work.

Essential viewing for security awareness leaders, CISOs, HR teams, managers and anyone responsible for moving from tick-box training to measurable cyber security behaviour change.

In this free webinar, you'll discover:

What security culture really means and why it starts with behaviour, not technology
Why you should define the behaviours you want before anything else
How the COM-B model links capability, opportunity and motivation to behaviour
Why phishing still works and what to realistically expect from your people
Why training alone never changes behaviour - lessons from real-world culture failures
How habits form over time and how to support them until they stick
Proven strategies clients use, from leadership modelling to feedback and competition
Blockers to avoid: information overload, no measurement and compliance-only thinking

Turn security culture insight into practical behaviour change

This webinar explains why secure behaviour depends on capability, opportunity and motivation — not training alone. TSC's security awareness training and eLearning modules help your people build everyday habits that reduce risk and strengthen security culture.

Book an eLearning demo


View full webinar transcript

Introduction

We've been at TSC for nearly 30 years, with a wealth of specialism in training, development and raising awareness across workforces. More recently we've been helping organisations take a much broader view of their security culture, because training plays a part, but the picture is much bigger. In this session I'll explain what we mean by security culture and the ways we help clients develop it. My background is more than 30 years in training and development, so what I like to do is combine that with our information and cyber security expertise to help people learn and apply it.

Start at the end

There's a song that says "start at the very beginning, it's a very good place to start." When it comes to security culture, I completely disagree. You need to start at the end: where are you aiming, what are you trying to achieve, and how do you want your people to behave? Start with that vision of where you want everyone to be, then enable people to get there in a progressive way.

What we mean by culture

Three things make up culture in an organisation: the values, the beliefs and the behaviours of everyone who works there. Together they determine how people interact and do their jobs. So when we talk about security culture, we mean the values, beliefs and behaviours people demonstrate that determine how securely they work day to day. The focus of this session is very much the people, not the technical solutions, what people do day in, day out.

Defining the behaviours you want

You need to be able to describe what you want to see, and set a timeframe: in two or three years, this is what I want to see across our workforce. Unless you define it, you can't measure it, and measurement is key. The right behaviours depend on your organisation: do you want people to be curious and ask questions, to be alert to visitors and strangers, to report incidents and near-misses, or to recognise phishing across email, SMS, social media and mobile? Pin down what you actually want people to do.

The COM-B model

We use a model called COM-B, which stands for Capability, Opportunity and Motivation that informs Behaviour. We like it because it's holistic, pulling together around 14 theoretical frameworks, from Bandura's social learning theory to Maslow's hierarchy of needs, into one picture. The outer layers are your infrastructure: the policies, procedures, guidelines and regulations that shape what people do. The centre is about people: their capability, their opportunity and their motivation. All three need to be working for people to behave securely.

Why training alone doesn't change culture

I have over 30 years in training and development and I fundamentally believe in it, but on its own it does not change behaviour. Take a non-security example that's in most people's consciousness. After Stephen Lawrence's death, the Macpherson report identified institutional racism in the Metropolitan Police, and a great deal of training followed. Yet 30 years later, the review after Sarah Everard's murder again found institutional racism, misogyny and homophobia. The lesson: when you look at culture you must look at many things, not just training, because training provides a foundation but doesn't on its own shift behaviour.

Capability

Capability is about whether people have the skills and knowledge, the physical ability, and the cognitive capacity to do what you're asking, in other words, that they're not so overwhelmed by other messaging that they can't focus on the key things you need them to do.

Why phishing still works

Here's a striking point on capability. The first phishing attack was in 1995, when a tool called AOHell let hackers pose as AOL staff to harvest credentials. Nearly 30 years on, companies still tell us phishing is their biggest risk. Microsoft now stops around 3.4 billion suspicious emails every day, and some still get through. Why does phishing still work? Cambridge research shows the human mind doesn't read every letter, it reads words as whole shapes, as long as the first and last letters are right. So when people work at pace, the small changes that signal a phishing email, like an altered URL, slip past. The Verizon 2022 Data Breach Investigations Report found 2.9% of phishing emails are still clicked. In an organisation of 5,000 people, that's around 140 people. So the realistic behaviour to aim for may not be "spot every phishing email" but "report it when you do click," because then you can act.

Opportunity

People don't come to work wanting to fail; they want to do a good job. But specific things can prevent them applying their knowledge. Opportunity asks: do people have the resources they need, the right systems and processes, and a working environment that enables secure behaviour? And do they have people around them to help and support them? If people are working at pace in an environment that makes phishing hard to spot, you have a double whammy: how the brain works plus an environment that makes it harder.

Motivation and habits

Motivation is about whether people want to behave securely, whether they believe they should, and whether they have the right habits. When you first ask people to adopt a new behaviour, like creating long, strong passwords using three random words, it takes conscious effort. But supported over time, around six months, it becomes subconscious and ingrained, a habit. If you can support people to build secure habits, you're onto a winner, but it takes time, persistence and constant reinforcement.

The common blockers

As well as the above, several things block behaviour change. Not knowing your starting point: acknowledge what's already working so you don't keep re-treading habits people have already formed. Information overload: if there's too much going on, people go blind to your key messages. Lack of measurement: if you're not measuring, you don't know what's working. And over-emphasis on compliance: if the only training is the annual refresher because it's a compliance requirement, you'll improve knowledge but not change behaviour. We help organisations with SABRE (Security Awareness Behaviour Research) to determine where they're starting from, where they want to be, and to measure it.

Strategies that work

First, have a solid foundation of training and awareness so people's knowledge and skills are high. Then layer on what actually shifts behaviour. Ask, listen and respond: surveys often show 30 to 60% of people will tell you the blockers they'd like removed, but if you ask, you must act on it. Lead from the front: one client's CEO, asked at a town hall what the biggest threat was, answered without pause, "the cyber risks," and that message, repeated, has huge impact. Make sure managers are "doing the do," visibly modelling secure behaviour, because teams replicate their leaders. Run manager masterclasses and feed back which teams are performing best, a little competitiveness works well. Give people feedback when they do the right thing, and apply consequences when behaviour is required and not met. Create chatter, informal conversations about security in teams. And integrate the behaviours you want into appraisal and performance-development conversations, which drives remarkable results.

Finally, identify your priorities. Using the Pareto principle, focus your energy on the 20% of things that deliver 80% of the change, rather than spreading yourself thin.

Questions and answers

What if managers aren't exhibiting the behaviours we expect, and the security role feels tokenistic?

See it as an opportunity rather than a barrier. Managers are people of influence, and as humans we follow our leaders. So focus your time and energy on getting managers to behave securely, and you'll see the difference flow through their teams.

How do you support people to build the right habits?

Define and model the behaviours you want, then give feedback, encouragement and reinforcement as people start to use them, until, over time, they become automatic. Motivation is a huge topic in its own right. Think of how people gave up smoking: for everyone the trigger was slightly different, a health scare, cost, the public-spaces ban. We can help you identify what will motivate people in your organisation.

How do you stop bite-sized training and initiatives becoming white noise?

It comes down to your team managers deploying a range of resources, animations, activities, conversations, and constantly relating them back to the work so it stays relevant. Training in the flow of work, in context, is far more effective than something running in the background.

People say they want more guidance but not more training, and our resources go unused. What do we do?

People absorb information differently, some need to hear it, some to see it, some to read it, some to experience it, so offer the same message in multiple formats: a short refresher conversation, a video, a team Q&A. If relying on people seeking out a SharePoint page isn't working, take the message to them in the format they'll engage with.

In an always-on, 24/7 world, how do you balance fast service with a secure culture that asks people to slow down?

Acknowledge that you can't always slow people down, so don't set a behaviour that requires it. If the business needs real-time responses, accept that people may click phishing links, and make reporting as easy as possible so they can flag it instantly.

If an organisation hasn't defined goals, how do you assess its security culture maturity?

There are maturity models, but all of them require you to define what you're trying to achieve, and I'd recommend defining behaviours, because behaviour is what shifts culture. Interestingly, the NCSC stopped supporting its IAMM maturity model, acknowledging that every organisation is so unique you can't meaningfully compare one against another. So look at where you are, and use COM-B as the framework to move forward.

Security culture FAQ

What is security culture?

Security culture is the values, beliefs and behaviours that shape how people work securely every day. It goes beyond cyber security training and focuses on the real actions employees take, such as reporting incidents, challenging unusual requests, spotting phishing attempts and following secure processes.

Why doesn't training alone change security behaviour?

Training builds knowledge, but behaviour change also needs capability, opportunity and motivation. Employees need clear expectations, supportive systems, visible leadership, regular reinforcement, feedback and easy ways to act securely. Without these, security awareness can become a compliance exercise rather than a lasting culture shift.

How can organisations improve security culture?

Organisations can improve security culture by defining the behaviours they want to see, measuring their starting point, removing blockers, supporting managers to model secure behaviour, creating regular security conversations and reinforcing good habits over time. A behaviour-led approach helps turn awareness into everyday action.


Related pages

Human Risk Platform
Products & Services