Published: 08 August 2024
Summary
Security has long focused on making users aware of cyber risks and mitigating actions to take, which has not stopped dangerous behaviors. Security and risk management leaders should use communication directed at culture to address risk behaviors.
Included in Full Research
Overview
Key Findings
Users are often insulated from the consequences of cyber-risk breaches, so there’s a need to find ways other than direct punishment to make cyber risk feel real enough for them to act to avoid it, and leverage cultural levers like peer pressure to enforce it.
In the absence of a proper framework, the lack of personal consequences or negative feedback from poor security choices enables employees to respond to motivations and feedback that do not prioritize security.
Recommendations
To motivate employees to prioritize security in their decisions and actions, security and risk management (SRM) leaders should:
Clients can log in to view the entire
document.