5 Factors to Help Build a Case for Security Culture
Security teams, governance, controls, and technologies are a necessity as business environments grow ever more complex and volatile, but they cannot on their own deliver secure outcomes at scale. Security teams must work to embed security culture as a normal, supported, and effective part of everyday work, thereby strengthening organizational resilience, security performance, and crisis capability.
I researched and wrote Security Culture: A Strategic Capability That Builds Resilience in a Volatile World for the ASIS Foundation. (The report is sponsored by Amazon WWOS, Axis Communications, and Thermal Radar.) This article is adapted from the report and presents five key areas that security leaders can explore to make a business case for security culture in their organizations. But let’s start by understanding the underlying concept.
Why Security Culture?
Organizations face a range of threats, including everything from crime, terrorism, espionage, and cyberattacks to activism, workplace violence, and supply chain disruptions.
Security teams play a critical role in preventing, mitigating, and responding to these threats, but they are only part of the story. No matter how well-designed security governance structures, controls, and technologies may be, they cannot on their own deliver secure outcomes at scale.
Security is ultimately enacted through the everyday actions, decisions, and behaviors of employees, contractors, and partners. When people feel pressured, confused, disengaged, or fearful of consequences, even the strongest security frameworks can be undermined.
No matter how well-designed security governance structures, controls, and technologies may be, they cannot on their own deliver secure outcomes at scale.
What Is Security Culture?
Security culture—the security-related norms, values, attitudes, and assumptions of employees—sets the tone for the organization. It influences whether staff understand that they have a role to play in security, take that responsibility seriously, pay attention to security campaigns, assume colleagues are doing likewise, and feel comfortable speaking up if they see something that might negatively impact safety or security.
Understanding of security culture has evolved significantly in recent years. Where it was once treated as little more than an issue of training or awareness, it is now increasingly recognized as a multifaceted program reinforced by leadership and governance.
The foundation report establishes a framework for security culture encompassing six factors that should be reflected in a security team’s security culture and awareness program:
Attitudes: Do employees care about security?
Knowledge: Do employees know what is expected?
Behavior: Do employees do what is expected? What do they see others doing?
Communication: Do executives and security leaders communicate security in a relatable and understandable way?
Compliance: Are policies sensible and easy to follow?d
Empowerment: Do employees feel able to play their part?
Security Culture Watchlist
There are many pitfalls that can erode or outright undermine the security culture that security teams try to establish. Security leaders should be mindful of the following:
- Controls do not guarantee compliance.
- Employees balance secure behaviors against competing priorities: commercial urgency, pressure from managers, staffing constraints, or pressure to find workarounds when security systems are not user friendly.
- Employees may also lapse in their practice of secure behaviors if they are distracted or fatigued in fast-paced or stressful work environments.
- Employees don’t generally “think security.” They need security teams to make it easy for them to play their part through sensible policies and clear communication.
- Incentives are more important than penalties in influencing behavior.
- Employees need to feel positively towards security and be confident of the difference they can make.
- People influence people—especially leaders, managers, and workplace influencers.
- Knowing the right thing to do is a prerequisite, but knowledge alone does not change behavior. Employees must also understand the threat is real, be reminded to play their part, feel that others are doing likewise, and be subject to user-friendly policies that are easy to understand.
Making the Business Case for Security Culture
There is not an abundance of scholarship specifically on security culture. However, there is plenty on organizational theory and organizational culture. Applying the lessons from these areas to security culture can help security leaders make a strong case to executives and other business leaders that security culture is a strategic capability rather than a supporting activity. Here are five factors to consider.
Increased vulnerabilities at the physical–cyber security interface. The holistic nature of risk and the expanding interface between physical and cybersecurity systems strengthen the case for investing in security culture.
Physical security systems, including access control, surveillance, mass notification, travel risk platforms, and security operations centers, are now deeply integrated with digital networks and data flows. As a result, behavioral failures in one domain can rapidly cascade into the other, and employees do not distinguish between physical security and cybersecurity in their daily decisions. Joint cyber and physical security culture programs can be force multipliers across the business.
Regulatory, legal, and governance expectations. Regulatory and governance frameworks reinforce the importance of security culture. Regulators increasingly expect organizations to demonstrate oversight of security risks, integration of controls into enterprise risk management structures, and ongoing education and awareness.
Following major security incidents, regulatory and legal scrutiny often focuses on cultural questions: whether known risks were ignored, whether policies were routinely bypassed, whether leaders failed to act on warning signs, or whether employees felt able to report concerns. Organizations that can demonstrate a proactive, learning‑oriented security culture are better positioned to withstand post‑incident scrutiny.
Accelerated adoption of artificial intelligence (AI) and emerging technologies. The rapid adoption of artificial intelligence and other emerging technologies increases the importance of security culture as a frontline defense. AI tools are changing how employees work, share information, and make decisions—often at a pace that outstrips formal policy and technical updates. Employees are sharing sensitive work information with AI tools, frequently without formal authorization, with policy struggling to keep up.
For security teams, the implications are significant. Information shared with AI tools can include executive travel itineraries, facility floorplans, or guarding patterns, all of which can materially increase physical risk if misused. In this environment, secure outcomes increasingly depend on employee judgment, awareness, and shared norms, making security culture an increasingly critical control layer.
Improved crisis response and resilience. A healthy security culture can help to improve crisis readiness and response. Organizations with shared expectations, trusted reporting channels, and practiced escalation behaviors coordinate more effectively under stress, reducing confusion and delays during critical incidents.
A mature security culture can also enhance long‑term resilience by embedding vigilance, learning, and adaptation into everyday operations, enabling organizations to adjust behavior as threats evolve, technologies change, and operating environments become more complex, without relying solely on reactive controls or post‑incident fixes. When employees act appropriately without continuous oversight, it can allow security teams to focus on high-value activities rather than routine checking.
Reduced likelihood and cost of security incidents. A strong security culture can reduce both the frequency and the severity of security incidents by addressing the human behaviors that controls alone cannot mitigate. Security events—such as unauthorized access, theft, insider compromise, workplace violence precursors, travel incidents, or third‑party security breaches—are frequently preceded by weak signals that go unnoticed or unreported.
Research from high‑reliability organizations shows that cultures that encourage speaking up and shared responsibility surface risks earlier and prevent escalation into major incidents. Data from IBM’s Cost of a Data Breach shows that employee training is one of the top 10 net contributors to reducing the cost of a data breach. The report calculates that investment in employee training reduces the cost of an average data breach by $192,266. By reducing preventable lapses, such as propped doors, unchallenged access, ignored insider warning signs, or failure to follow travel protocols, security culture improves the return on investment across physical controls, guarding, and technology.
Within a global operating environment characterized by heightened security risks, increased volatility, increased regulator and investor pressure, and the opportunities and challenges of AI, security culture can enable security teams to scale their efforts and embed security culture as a normal, supported and effective part of everyday work, thereby strengthening organizational resilience, security performance, and crisis capability.
Rachel Briggs, OBE, is the founder of The Clarity Factory, a research and consulting firm serving physical and cybersecurity teams in multinational corporations. Briggs is a leading researcher, consultant, speaker, educator, and author in the security field. She researched and wrote the ASIS Foundation report Security Culture: A Strategic Capability That Builds Resilience in a Volatile World.









