Building a Security-Positive Culture: Why Technology Alone Won't Work
Controls only work when people want them to. Why visible leadership, role-specific awareness and low-friction secure defaults matter more than the next tool, and how to tell whether your culture is actually shifting.
The Most Expensive Security Tool Nobody Buys
I spent $2 million on endpoint detection and response last year. Every device is monitored. Every suspicious process is flagged. We have visibility into attacks in real-time.
And yet, someone still plugged an unknown USB drive into a critical network because they thought it might contain a password they'd forgotten.
That's not a detection problem. That's a culture problem.
I've learned something in two decades of security leadership: you cannot technologically enforce behavior you haven't culturally established. The fanciest firewall in the world can't stop an insider threat. The best SIEM can't prevent phishing if your team doesn't think twice before clicking. Encryption is useless if people share passwords in Slack.
Security culture—the shared beliefs, behaviors, and values around information protection—is the foundation everything else rests on. Ignore it, and your controls are just friction people will find ways around. Build it intentionally, and your entire security program becomes more effective, faster, and cheaper.
This isn't mystical. It's measurable. And it's learnable.
What Is Security Culture, Really?
Culture is the set of unwritten rules about how things are actually done in your organization. It's what people do when nobody's watching.
Security culture is when protecting information becomes part of how your organization thinks and acts—not because of a policy mandate, but because it's genuinely valued.
The difference shows up everywhere:
- Weak culture: A developer sees a database password in a log file, thinks "that's bad practice," and... does nothing because "that's IT's job."
- Strong culture: A developer sees the same password, immediately reports it through the incident channel, and the team takes it seriously.
- Weak culture: An employee gets a suspicious email and deletes it, thinking "probably spam."
- Strong culture: An employee gets the same email, immediately forwards it to security, and the team learns from it.
- Weak culture: A manager bypasses a security control because they're in a rush, reasoning "just this once."
- Strong culture: A manager is in a rush, but doesn't even consider bypassing controls because they understand why they exist and respect them.
One organization has policy. The other has culture. Only one is truly secure.
The Tone-at-the-Top Effect
Here's what research and my experience both show: visible leadership behavior is the single strongest influence on security culture.
When executives visibly follow policies, when they ask security questions in strategy meetings, when they acknowledge (not minimize) security concerns, when they fund security initiatives because it matters—not because they were forced to—everyone notices. And behavior changes.
When executives do the opposite—bypass controls, deprioritize security when it's inconvenient, talk about security as a cost center holding back innovation—everyone notices that too. And culture gets worse, no matter how many awareness posters you put up.
I've seen this play out dozens of times:
A CISO I know was struggling with password reuse. People were using simple passwords across multiple systems. No amount of enforcement worked. Then the CTO made a point of using a password manager visibly, mentioning it in conversations, asking other executives about theirs. Within three months, adoption of password managers across the organization jumped 40%. Not from a mandate. From visibility.
Another organization had an incident where a senior leader left access credentials in a public GitHub repository. Instead of quietly fixing it, the leadership team announced what happened, explained what they learned, and documented the process improvement that came from it. It was humble, transparent, and taught the entire organization something. That moment communicated far more about the importance of security than a thousand mandatory training sessions.
The inverse matters too. When I've seen CISOs struggle to build culture, it's often because executive leadership is silently working around security controls—and everyone knows it. You can't build a culture of "security matters" while the people running the company are proving they don't think it does.
The Three Pillars of Security Culture
Building security culture isn't accidental. It requires three overlapping changes:
1. Visible Leadership Commitment
This is the foundation. Without it, nothing else sticks.
Visible leadership commitment means:
- The board and executive team understand security's role in business strategy, not just risk management. They see security as an enabler, not just a safeguard.
- Security has a seat at major decisions. When you're making decisions about mergers, new products, process changes, or technology investments—security is in the room early, not brought in after.
- Leaders live the culture they ask others to follow. They use security tools, they don't tailgate through doors, they report suspicious emails, they ask for security sign-off. Their behavior models what they're asking for.
- Resources follow commitment. If security truly matters, it shows in budget, in hiring, in time allocation. When security always loses the resource conversation, people notice.
- Leaders talk about security in positive terms. Not "security is a cost we have to bear," but "security enables us to move faster because our customers trust us" or "security helps us compete."
2. Awareness and Training Tailored to the Audience
One generic security awareness program fits nobody well.
Effective security awareness is:
- Role-specific. Developers need to know about secure coding. Executives need to know about governance and risk. Finance needs to know about vendor security. The same training for everyone is ineffective noise.
- Behavioral, not informational. The goal isn't to check a box ("8 hours of annual training"). It's to change behavior. You can do this through simulations, scenarios, micro-learning, and measurement—not just lectures.
- Continuous and accessible. One hour of training per year doesn't stick. Integrated, ongoing reminders and learning (security tips in team meetings, lunch-and-learn sessions, monthly updates) work better.
- Practical and relevant. Employees care about security threats that affect their work. A developer cares about injection attacks. A data analyst cares about data classification. A support agent cares about social engineering. Meet them where they are.
- Tied to consequences and culture. When someone violates security, the response should reinforce culture—education, usually, not punishment—unless it's willful negligence. When someone does security right, acknowledge it.
3. Making Secure Behavior the Easy Path
Here's the uncomfortable truth: if being insecure is easier than being secure, people will be insecure. Even if they know better.
Making secure behavior easy means:
- Security tools don't get in the way. Password managers make complex passwords easy. MFA should be smooth and fast (not a 5-minute ordeal). Encryption shouldn't require special steps. VPNs should connect reliably. If you're asking people to be secure, don't make it painful.
- Processes reflect security. Approving access shouldn't take two weeks. Getting security review on code shouldn't be a bottleneck. Reporting an incident shouldn't require six approval steps. Build security into workflows, not on top of them.
- Security is built into how work gets done. Instead of "encryption is optional," it's built into the platform. Instead of "classify this data," classification happens automatically. Shift left—make secure the default, not the option.
- Removing friction removes excuses. When someone says "I didn't follow the security process because it was too complicated," listen. That's a sign you've designed for friction, not behavior change.
The Culture-Technology Balance
Here's where it gets strategic: culture and technology work together, but culture wins when they conflict.
A strong detection and response system (technology) catches the person plugging in the USB drive. A strong security culture prevents them from wanting to do it in the first place.
A strong access control system (technology) prevents unauthorized access to files. A strong security culture means people don't try to access data they don't need.
A sophisticated DLP system (technology) can catch data exfiltration. A strong security culture means people understand why that data is protected and respect it.
Technology gives you compliance and detection. Culture gives you prevention and alignment.
The organizations I've seen get security right aren't the ones with the most tools. They're the ones where:
- The board takes security seriously
- Executives visibly practice what they preach
- People understand why security matters (not just what to do)
- Tools are built to make secure behavior easy, not hard
- Mistakes are learning opportunities, not just punishment
They invest in both, but they prioritize culture. Because culture is what makes the tools work.
How to Know If Your Culture Is Shifting
Culture change is gradual, but it's measurable. Here are signs you're moving in the right direction:
People report security concerns without fear. When someone notices something wrong—a policy gap, a process that's vulnerable, a suspicious email—they report it. Not eventually, after checking with their manager three times. Immediately. And when they do, nothing bad happens to them.
Senior leaders are asked about security decisions, and they have thoughtful answers. Not "security said we have to," but "here's why that matters for our business" or "here's the risk trade-off we're making."
New employees learn the culture quickly. You can tell an organization has strong culture when new hires pick up behavioral norms within weeks—they see how people do things and follow suit. When nobody has to explicitly teach the culture, it's working.
Security issues are discussed in retrospectives and strategic planning, not just incident response. Security isn't a sidebar. It's part of how you evaluate success.
People push back on shortcuts respectfully. When someone suggests bypassing a control to move faster, other team members will push back—not because they're rule-followers, but because they understand why the control exists and genuinely think the shortcut is a bad idea.
Metrics shift. Phishing click rates go down. Time to remediate findings shortens. Security findings in peer review go up. These are lagging indicators—they show that behavior is actually changing.
The Long Game
Building security culture is not a three-month project. It's a multi-year transformation, because you're fundamentally changing how an organization thinks.
But here's the payoff: once you have it, you have something far more valuable than any tool.
You have an organization where security doesn't slow you down—it enables you. Where people think about security because they genuinely understand why it matters. Where a security problem is everyone's problem, not the CISO's problem.
You've moved from security-as-compliance to security-as-business-value.
And that's when your security program stops being expensive friction and starts being competitive advantage.
Reflection Questions
Before you go, ask yourself:
- Visible leadership: Can you name three specific behaviors your CEO or board has done recently that signal security matters to them? If not, is security really part of their strategy?
- Awareness alignment: When was the last time you had a security conversation tailored to a specific role (developers, finance, executives)? Or is your awareness program one-size-fits-all?
- Ease of secure behavior: If an employee wanted to do everything security recommends, would it make their job harder or easier? Could you cut the friction by 50%?
- Psychological safety: If someone reported a security mistake tomorrow—not out of malice, just human error—would they be thanked for catching it, or disciplined?
- Cultural indicators: In the last month, has someone reported a security concern without being asked? That's the sign that culture is real.
If you're weak on more than two of these, your security culture needs work. And that's where to start, before worrying about your next tool purchase.