How to Build a Security Culture That Actually Sticks
Summary
- Security culture fails when executive goals for risk mitigation clash with employees' need for daily efficiency.
- Introduce security changes incrementally, like slowly turning up the heat on a boiling frog, to reduce resistance and normalize new behaviors.
- Employees who are most resistant to security changes can become your greatest advocates if you involve them in the testing and feedback process.
- True security is achieved when a company moves beyond simple compliance and builds a culture of commitment, where everyone feels responsible for protecting the organization.
Executive leaders know cybersecurity is a top priority, but there’s often a frustrating disconnect. You invest in security tools and expect the organization to be secure, yet your teams see new protocols as roadblocks that slow them down. This friction is the number one killer of any security initiative. The solution isn’t another tool; it’s building a genuine security culture.
A strong security culture transforms your team from a potential liability into your greatest defense asset. It shifts the mindset from begrudging compliance to a shared commitment to protecting the organization. This is achieved not through sudden, drastic mandates, but through incremental change, clear communication, and empowering everyone to become security advocates.
Key Takeaways
- Bridge the Executive-Employee Gap: Security fails when leadership’s goals (risk mitigation) clash with employees’ daily reality (efficiency). A strong culture aligns these perspectives.
- Embrace the “Boiled Frog” Approach: Introduce security changes gradually and strategically. Small, consistent steps are more effective and create less resistance than sudden, disruptive overhauls.
- Turn Resisters into Advocates: The employees most vocal about security friction are often your best resource. Involve them in the testing and feedback process to create buy-in and improve rollouts.
- Focus on Commitment, Not Just Compliance: Compliance checks a box, but commitment drives proactive behavior. True security culture is built when employees understand the “why” and feel a sense of ownership.
Table of Contents
- Why Leaders and Employees See Security Differently
- The Myth That Security Is Just an IT Problem
- The “Boiled Frog” Approach: Building Security Incrementally
- How to Empower Non-Technical Leaders as Security Advocates
- From Compliance to Commitment: Making Security Part of Your DNA
The Disconnect: Why Leaders and Employees See Security Differently
From the C-suite, the directive is clear: keep the organization operational and secure. Cybersecurity is a fundamental business risk that needs to be managed. But for an employee on the front lines, a new security measure like multi-factor authentication (MFA) can feel like just another hurdle.
“Your end users are usually the ones that will face most of that resistance,” explains Nate, CIT’s Director of Cybersecurity. “They say, ‘I don’t want multi-factor, it slows me down.’ There’s a disconnect between the business owners’ expectations and the employees’ experience.”
This gap exists because the urgency felt at the leadership level doesn’t always trickle down. While executives understand the catastrophic cost of a breach, employees experience the daily friction of security controls. Without a strong culture to provide context, security feels like a punishment, not a protection.
The Myth That Security Is Just an IT Problem
One of the most pervasive misconceptions sabotaging security culture is the belief that “someone else is taking care of it.”
“The comment comes up, ‘I don’t really care. That’s what I have a cybersecurity person for,'” says Todd, CIT’s COO and CISO. “This idea that ‘my team’s taking care of me, I don’t need to worry about it’ perpetuates through organizations.”
This mindset is dangerous. While your IT and security teams deploy firewalls, antivirus software, and other protections, they can’t stop an employee from clicking on a sophisticated phishing email or using a weak, reused password. Security is a shared responsibility. Every team member, from accounting to sales, is a guardian of the company’s data.
Another common myth is that security’s only purpose is to make work more complicated. In reality, modern security strategies can actually reduce complexity.
“With things like single sign-on (SSO) and passwordless authentication, we are increasing security’s effectiveness while also reducing the complexity for the end user,” Nate notes. Imagine an employee logging into their computer and all their applications in under 10 seconds using just their fingerprint. “That’s a huge win. It’s more secure and easier than managing a dozen different passwords.”
The “Boiled Frog” Approach: Building Security Incrementally
How did CIT build its own internal security culture? Not overnight. It was a gradual process of turning up the heat.
“I’ll use the ‘boiled frog’ approach,” says Nate. “If you slowly turn it up, it starts to become the norm. If you do it slow enough and strategic enough, people don’t really ever notice the big changes.”
This started with simple things. Years ago, CIT, like many companies, only required MFA for external logins. The first step was to introduce it internally. To ease the transition, the team implemented passwordless options, like a simple push notification, instead of requiring a password and a code.
From there, the security team made small, incremental adjustments on the back end:
- Challenging the frequency of MFA prompts based on risk.
- Evaluating the security posture of the device being used.
- Moving toward a Zero Trust model of continuous evaluation.
Each quarter, a control might get slightly tightened. This slow, steady progression allowed the changes to become normalized behavior rather than a series of jarring disruptions. The same principle applies to phishing simulations. Todd recalls moving from annual tests, to quarterly, to monthly, and eventually to weekly to build the desired behavior. Once the culture was established, the frequency could be relaxed.
How to Empower Non-Technical Leaders as Security Advocates
Building a security culture cannot be a top-down mandate from the IT department alone. It requires buy-in and advocacy from leaders across the entire organization. But how can a non-technical manager in finance or marketing become a security champion?
1. Listen and Provide Feedback: Security leaders want to know when a control is creating too much friction. “If we’ve made a security control that is overly complicated, we do want to hear about it,” Todd emphasizes. “There are almost always ways we can find compensating controls that aren’t quite so in-your-face.” Encourage your team to provide constructive feedback, creating a safe environment for communication.
2. Turn Resisters into Testers: Nate shares a powerful story about an employee who was initially “vehemently opposed” to new security measures because they slowed him down. Every time a change impacted his workflow, he would voice his concerns. Instead of shutting him down, Nate started a dialogue.
“Eventually, I started calling him my ‘bug bounty finder,'” Nate recalls. The relationship transformed. The employee went from being the last to adopt a change to the first to test it. “He loved that he was engaged in the process.” By involving your most critical users early, you not only improve the solution but also create powerful advocates.
3. Reinforce Good Behavior: As a leader, you have the power to reinforce the culture you want to see. When an employee identifies a potential risk or goes the extra mile to follow a security protocol, recognize it.
“Public recognition is a big one,” says Nate. “In your next team meeting, just say, ‘I wanted to give kudos to Alex in accounting because they identified something that was a risk to the business and brought it to our attention.'” Whether it’s a shout-out, a $20 gift card, or another incentive, reinforcing the desired behavior is one of the fastest ways to drive cultural change.
From Compliance to Commitment: Making Security Part of Your DNA
Many organizations approach security from a place of compliance: they do the bare minimum required by an insurance policy or industry regulation. This is a fragile state.
A committed organization, on the other hand, embeds security into its core values. The transition from compliance to commitment is a multi-year journey driven by leadership. It happens when “why we need to be secure” is communicated relentlessly.
“We use the terminology ‘seven times, seven ways’ when it comes to communication at CIT,” says Todd. “And we communicate that much more frequently than that.”
The message must be consistent, come from different voices, and be framed in the context of the business’s mission. When an employee in a non-technical role says, “I have to create a ticket to track that for our SOC 2 compliance,” you know you’re winning. They understand the assignment and their role in the bigger picture.
For employees, the key is to have grace and patience. “When things are being pushed down, mistakes may happen,” Nate advises. “Most people are not trying to make your job harder. We’re just trying to align with what the business needs are.”
Ultimately, a strong security culture is built on communication, collaboration, and a shared understanding that protecting the organization is everyone’s job.
Glossary of Terms
- Multi-Factor Authentication (MFA): A security process that requires users to provide two or more verification factors to gain access to a resource, such as a password and a code from a mobile app.
- Single Sign-On (SSO): An authentication scheme that allows a user to log in with a single set of credentials to multiple independent software systems.
- Passwordless Authentication: A method of verifying a user’s identity without using a password, instead relying on factors like biometrics (fingerprint, face ID), a physical security key (like a YubiKey), or a push notification.
- Phishing Simulation: A security training exercise where fake, malicious-looking emails are sent to employees to test their ability to recognize and report phishing attempts.
- Zero Trust: A security model based on the principle of “never trust, always verify.” It requires strict identity verification for every person and device trying to access resources on a private network, regardless of whether they are sitting inside or outside of the network perimeter.
- SOC 2 Compliance: A voluntary compliance standard for service organizations, developed by the American Institute of CPAs (AICPA), which specifies how organizations should manage customer data based on five “trust service principles”—security, availability, processing integrity, confidentiality, and privacy.
Frequently Asked Questions
How long does it take to build a strong security culture?
Building a genuine security culture is a long-term process, not a one-time project. Expect it to be a multi-year journey. You may start to feel the initial shifts in organizational mindset and behavior within the first 6 to 12 months of consistent effort.
What is the first step a non-technical leader can take to support security?
Start with communication. Create an open and safe environment for your team to discuss security controls and provide feedback. Act as a bridge between your team and the IT/security department, ensuring their operational concerns are heard and addressed constructively.
Can we build a good security culture if our IT is outsourced?
Absolutely. The principles remain the same. An outsourced partner like CIT can drive the recommendations and manage the tools, but building the culture is still an internal effort led by the organization’s leaders. A good partner can act as a guide and even be the “bad guy” to help you enforce necessary changes, making it easier to get internal buy-in.
How do we get executive buy-in if leadership is resistant to security spending?
Translate technical needs into business risks. Instead of asking for a specific tool, present the business case. Explain how a security investment mitigates the risk of downtime, financial loss, or reputational damage. Frame it in terms of business continuity and protecting the bottom line.
Listen to the Full Episode
Hear directly from CIT’s cybersecurity leaders on the nuances of building a resilient security culture.