Security Culture: Why It’s Easy to Design and Hard to Achieve
All security leaders want to build a strong security culture to serve as a foundation for their organizations. What that means is pretty straightforward. How you get there is anything but.
The Essence of a Strong Security Culture
An organization’s security culture is the extent to which security goals are incorporated into the attitudes, decisions, and actions of its employees. At a basic level, a thriving security culture exists when the following has been accomplished:
- Employees feel safe and secure (real and perceived).
- Employees protect each other.
- Employees actively provide information to protect themselves, their coworkers, and the business.
- Leaders and employees trust security.
The Science and Art of Security Management
Developing a comprehensive security program requires implementing a range of specialized, process-driven features tailored to specific industry, business, and location risks. These core elements constitute the science—or process—of security:
- Governance and validation: Policies and procedures, asset assessment, and compliance auditing
- Technical systems: Integrated security technology, including video surveillance, access control, intrusion detection, and artificial intelligence
- Human defense and mobility: Executive protection, travel risk management, and specialized staffing operations
- Threat mitigation and response: Intelligence gathering, formal investigations, workplace violence prevention and response, and enterprise crisis management
- Internal risk and resilience: Dedicated insider threat programs, training and awareness initiatives, supply chain security, and the enforcement of intellectual property rights
All these specialties are complex and challenging, and they require significant time, knowledge, and experience to implement and manage. Experience is one of the keys, because it helps leaders develop wisdom; learning through mistakes and accomplishments puts leaders in a better position to handle the challenges that lay ahead. The corporate scars security leaders wear—and the successes they have earned—are significant achievements to be celebrated. However, for most security leaders, success in the science of security management is the easier side of the equation.
The art of security management is about human connections, which is the foundational skill needed to create and maintain a strong security culture. Human brains must continuously interpret new experiences and stresses in the context of changing emotions and fluctuating moods. In a real sense, everyone is a slightly different person every single day. Making human connections, then, is frankly complicated and often difficult. A security professional can perfectly engineer the science side of security, and yet, this perfectly engineered system—not to mention the reputation and credibility of the security department—remains vulnerable if the department fails in the art of security. The art of security is finding ways to make connections built upon civility, respect, and dignity in the workplace. It is an essential part of organizational culture if security programs and processes are to be successful.
While making these connections can lead to the most rewarding experiences security professionals will have in their careers, they can be incredibly difficult. And the biggest challenge of all? Making human connections that can influence an organization’s executives and leaders.
The Challenge Executives Present
The hardest part of building an impactful security culture isn't designing the model—it's getting high-status leaders to genuinely care for people. That may sound harsh, but there is a psychological basis that describes the challenge. Neuroscientists have identified status as a core social domain we all have. Status is one’s relative importance to others, and we desire status because it signifies that others value us. Research from Dr. David Rock and the NeuroLeadership Institute shows that gaining even a small amount of power fundamentally changes how the brain processes information. Power shifts cognitive focus from the concrete (the individual human experience) to the abstract (systemic goals).
The C-suite at most organizations is composed of highly educated, intelligent, and experienced high-status individuals who focus on where the company is going and how it will win. These leaders tend to see the people in an organization less as individuals and more as a collective force working toward shared goals. The very best leaders are able to overcome this attitude and emphatically see people as a collection of individuals.
For the security leader attempting to build and maintain a positive security culture, executives and other leaders with status are a primary target. They must not only endorse the program, but they also need to model it and reinforce it. To do this, they must be able to see the workforce as individuals, not an abstract collective. To influence security culture, you must establish with leaders that the individuals in an organization will decide for themselves how engaged they are with their jobs and their colleagues each day. Executives must also understand that how much discretionary effort, care, production, teamwork, and innovation employees give depends on how they and their colleagues are treated and their sense of fairness.
If making executives see and understand those concepts sounds like a daunting task, it is! But let’s break it down into some actionable chunks that security professionals can use as building blocks.
The art of security management is about human connections, which is the foundational skill needed to create and maintain a strong security culture.
Connecting with Executives
Security professionals who think they can build an unassailable case demonstrating the value of security and thereby gain the trust and support of business leaders are likely to be disappointed. The reality is that business leaders need to know and like you first. Only then do you begin the positive journey of earning their respect, proving your value, and, ultimately, gaining their trust. They are the ones who decide if trust has been established, not you. And that process takes time—built one interaction after another.
Fortunately, the opportunities to connect on a humanistic level are all around you. Every formal and informal in-person or virtual contact, every written or verbal communication—these are all golden opportunities to show your personality, empathy, and, importantly, your eagerness to know the business leader and to protect their interests and the interests of their colleagues.
It can help to place high-status executives and leaders in one of three categories: Some will be supportive, even strong advocates for security. These people have embraced the security culture you’re trying to establish. Others may have had both positive and negative interactions with security, or perhaps they don’t think about security beyond key cards and who to call in an emergency, so while they are not actively supporting the security culture, neither are they antagonistic. Then there’s the third group, those who are skeptical of security. They may have had a negative interaction at some point or it may just be a competition for resources, and they see security as a drain on the organization’s resources without providing value. For each of these categories, security leaders need to develop a strategy to make meaningful connections.
How do you achieve that? First remember these relationships last as long as your career at your company lasts. While you shouldn’t take the advocates and middle category for granted, the naysayers or skeptics should be the priority group for several reasons. First, they can help, hurt, or put your credibility, your work, and the security department’s reputation at risk simply by making subtle or direct negative comments to their peer leadership groups or to their direct reports.
When I’ve started new security leadership positions, I actively sought to determine who those leaders are, and I figuratively ran towards them. That means asking for in-person meetings where I, with pen and pad in hand, ask them to share the experiences and opinions they have about the security function. This is where your empathic listening shines. You must ensure you understand and document all their concerns without being defensive or debating their positions, then you ask them for the chance to review all they have shared.
Next you must review and work on all their concerns and get back with them as soon as you can with an action plan on what can be corrected or improved to their satisfaction. Every interaction is an opportunity for them to get to know you better, ideally begin to like you, and then gradually trust you.
Tips, Tactics, and Techniques to Try
Time is precious. The simple underlying principle of any business is maximum profit and minimal expense. While many leaders will understand and support all (or most) of their area’s security program costs, it’s the security professional’s job to explain all the quantitative and qualitative benefits of the program in a precise and concise way. One simple yet major point to consider: Every single one of those leaders believes that time is precious.
The time the workforce performs work and produces goods or services is tangible and under constant management. When security offers to provide security training, business leaders may first see it is “time not working.” The best security practitioners understand this challenge and are successful in designing impactful initial (compliance-focused) training and ongoing (security culture-focused) training programs that reinforce the workforce’s feeling of security, show that the company cares for them, and respects the value of the time it takes to do the training. For business leaders, it’s important they believe that the time invested in security training pays off in higher employee engagement and business success.
Be likeable. I previously said that executives must know and like you prior to trusting you, but what does that mean exactly? Being likeable is, of course, subjective. A place to start is to think of the qualities you try to bring to interactions with others. Personal connections are made when you approach those interactions with empathy, sincerity, humility, and vulnerability.
Be mindful of your personality traits and character attributes. Think of personality traits as your psychological hardware. They are how you process the world and react to stimuli. For example, you fall somewhere on a continuum between serious and aloof, or introverted or extroverted. Personality will evolve somewhat over time, but you can’t actively change your position on the continuum—you can guide yourself to act more one way or the other, but the underlying trait remains. Your career success hinges on self-awareness and being vulnerable to learning what things you can potentially change to better connect and interact with people. Seeking feedback from leaders and department colleagues has multiple benefits: You can improve yourself, and it will show those leaders and colleagues that you respect and value their insights and that you are trying to make a positive impact.
Character attributes are different. Think of them as your operational software. These are the moral and ethical boundaries forged by your system of beliefs, habits, and deliberate choices over time. With work, you can actively adjust your character attributes. It helps to think about this in an intentional way: What character attributes will enable you to make human connections?
For me personally, these eight character attributes have been foundational in my career: fairness, innovation, tenacity, respect, credibility, vulnerability, being perceptive, and being engaging.
Combine this with self-care for your physical, mental, emotional, and spiritual health, and you will better navigate the natural rhythm and dynamics of successful human connections.
Beware your biases. Be aware of your similarity bias—an inclination to gravitate toward people who are part of your tribe. That might mean listening more readily to people from similar backgrounds, such as past service in the same branch of military service or the same former government agency. Or it could mean dismissing input from people from different industries or geographic locations, thinking their experiences could not apply to your situation. Similarity bias is a shortcut, and the human brain loves taking shortcuts. You must do the work and find a seasoned practitioner who is different than you but has accomplished things you’d like to accomplish. You may need to be creative, but their experiences are likely to contain lessons for you.
Address shortcomings. Trust is based on saying what you will do and then doing what you said. If you do anything that a leader can interpret as failing to do what you said you’d do, you need to sense that and address it as soon as possible. The business leader will appreciate your vulnerability and feel respected.
Beyond the C-Suite
The focus of this article has been on how to influence high-status leaders in an organization. There is good reason for that. It is the single hardest thing for security professionals to accomplish, and it is critical for successful security culture outcomes. However, high-status executives cannot simply proclaim a security culture any more than the security team can.
A culture, by definition, is the shared practices, experiences, and values that govern how a collection of people act, and it’s important to remember that each individual in that collection makes their own choices. Ultimately, in an organization with a strong security culture, individuals will choose to act in ways that enhance the safety and security of themselves and those around them. They will feel empowered to take actions and share information as needed to ensure safety and security is maintained.
While high-status executives have outsized influence, the truth is that security culture permeates throughout the entire organization. Each physical site or department has a senior leader, and she or he embodies a culture that manifests through their daily actions, decisions, and interactions. How they treat people under stress, how they handle fairness, and whether they show civility and respect define the culture that the employees experience, judge, and emulate.
Fortunately, the same techniques used to understand and influence high-status individuals can be used to make human connections with others. Ideally, everyone in the security department should have that same innate desire for human connection. Security leaders should make hiring decisions accordingly and invest in training their teams, not just in security knowledge but in how to make better human connections.
Influencing a company’s security culture is the most important achievement a security professional can accomplish. It’s a journey with no beginning, middle, or end, and it can take years to advance, but ultimately, an organization’s security culture will determine the success of the entire security program.
John Rodriguez is the founder of Empathic Security Cultures, LLC, based in Austin, Texas, with more than 44 years of pure corporate security experience working for major corporations including General Motors, Kimberly-Clark, Levi Strauss & Co., and Cardinal Health. He previously was the CSO for Temple-Inland in Austin, Texas. Rodriguez is a globally recognized security culture expert and works with global security departments and leadership teams to enhance their security programs for improved employee engagement and talent retention.
© John P. Rodriguez, 2026









