The ASIS Foundation recently published its latest research report: Security Culture: A Strategic Capability That Builds Resilience in a Volatile World. The report (free for ASIS members) is a rigorously researched examination of what security culture is in organizations, why it matters, and how security professionals can build a strong security culture in their organizations.
Rachel Briggs, the author of the report, will be leading a webinar on the findings on 28 July: Effective Security Rests on a Positive Security Culture. She will be joined by security experts Alexei Hnatiw, creative director at Solvd Together, and Joe Olivarez, Jr., executive vice president, Health, Safety, Security, Environment & Enterprise Quality (HSSE&EQ) and chief security officer at Jacobs.
We asked ASIS Foundation Chair Richard Brooks, CPP, PCI, PSP, associate director for security EMEA for Collins Aerospace, about how the report came together and his top-level impressions of it.
Why was security culture an important topic for the foundation to study?
Security culture has long been a term used across organizations, yet its definition and practical application remain ambiguous. Many organizations strive to “improve security culture" and seek measurable evidence to demonstrate progress, but often without a clear framework or structured approach to achieve it. This lack of clarity has made it challenging to address security culture comprehensively. The report seeks to define what security culture truly is, and establish metrics to measure it effectively, and it provides a practical framework for organizations to adopt. This groundbreaking research holds the potential to bridge the gap between theory and practice, offering valuable insights for both academics and practitioners. Ultimately, it aspires to set a new global standard for security teams to enhance their organizational resilience and effectiveness.
What is the process of selecting and working with a researcher like?
The process of selecting and collaborating with a researcher is both rigorous and highly rewarding. During my first year as chair of the ASIS Foundation Research Committee, I experienced a significant learning curve as I transitioned into the role, following in the footsteps of the highly experienced Dave Brooks. Fortunately, my previous years of involvement on the committee and familiarity with the selection process made the transition smoother.
The process begins with the creation of a comprehensive Request for Proposal (RFP) document, meticulously prepared and finalized with the invaluable support of our dedicated project manager, Polly Karpowicz. This RFP is then distributed to our extensive global network of researchers, ensuring a wide range of potential collaborators. Once the proposals are submitted, they are compiled into a working document for thorough review. Each committee member carefully evaluates the proposals, considering both quantitative and qualitative factors.
Following individual reviews, the committee convenes to discuss the leading proposals in detail and make a collective decision. After selecting the research team, we hold a series of meetings to ensure that the project brief and vision are clearly understood. This collaborative approach ensures alignment before the team embarks on developing the first draft of their work.
Overall, the selection process is transparent, methodical, and deeply engaging. It’s a privilege to participate in such a thoughtful and collaborative effort, which not only ensures the selection of the most suitable researcher but also sets the stage for a successful partnership that aligns with the goals of the committee and foundation.
Now that the report is complete and published, what are your impressions?
The completed report is truly impressive, both in its content and its presentation. The design team has done an exceptional job of bringing the report to life, ensuring it is visually engaging, readable, and accessible to a wide audience. The layout is thoughtfully structured, allowing the information to flow seamlessly through the various sections and culminating in strong, impactful conclusions that I believe will deeply resonate with the audience.
Rachel and the team at The Clarity Factory have gone above and beyond to make the report highly practitioner-focused, ensuring that the insights are not only valuable but also actionable. Their hard work and attention to detail are evident throughout, and I’m confident that readers will appreciate the effort and expertise that has gone into creating such a polished and practical resource.
You’ll be part of a GSX session that discusses the report’s findings, why should people attend that session?
This session is a must-attend for anyone navigating the evolving and increasingly complex challenges of organizational security. Today, security programs are under more scrutiny than ever, driven by heightened demands from executive leadership, constrained budgets, and a rapidly shifting geopolitical landscape. With the rise of diverse and sophisticated threat actors, coupled with a growing range of focus areas, many organizations are finding that the demand for security support far exceeds the available resources.
In this context, fostering a strong security culture has become one of the most critical priorities for organizations. During this session, we’ll dive into the findings from the report, offering actionable insights and practical strategies that attendees can implement quickly and effectively within their own teams and departments. Additionally, we’ll address and dispel some common misconceptions about security culture, providing clarity and guidance on how to approach this vital topic.
If you’re looking to stay ahead in today’s challenging security environment and enhance your organization’s resilience, this session will provide you with the tools and knowledge to make a tangible impact. Don’t miss this opportunity to gain valuable takeaways and join the conversation on one of the most pressing issues in security today!
What is the one, most important takeaway you got from the report that you think could be beneficial for you or your organization?
There are numerous valuable insights in the report, but the standout takeaway for me is the culture framework, which is built around six key elements (no spoilers here!). This framework is not only comprehensive but also practical, enabling organizations to quickly assess their current security culture baseline and identify clear, actionable steps for both short-term improvements and long-term growth. It’s a straightforward yet powerful tool that can drive meaningful change.
In addition to the framework, the ‘Tips’ sections scattered throughout the report are another highlight. These sections capture insights and real-world examples shared by senior security leaders interviewed during the project, offering readers practical advice and proven strategies they can apply within their own organizations.