Skip to content

Introduction to Security Culture

  • Knowledge Level: Introductory
  • Protection Stage: Plan & Build
  • Time to read:

If you’re new to the topic, get started here with an overview of security culture and why it’s important

Last Updated: 19 June 2025
Share this article:

What is Security Culture?

Security culture is often referred to as “the way things are done around here” or the values and attitudes towards security that are shared by everyone in an organisation. We find that most of these definitions can be a bit intangible and impenetrable; it’s not clear from these definitions how you can change your security culture.

In NPSA, we like to take it back to BASICS and use the common metaphor of an iceberg to think about the fundamental blocks that shape and influence security culture.1

Security Culture iceberg. Above water - Security Behaviours. Below water - Personal Attitudes and Skills, Organisation Influences and Cultural Style

Security Behaviours
At the surface, you have your Security Behaviours – these are the visible behaviours across your organisation.

  • For example, does your workforce wear their passes? Do they lock away their documents at the end of the day. These behaviours could also manifest through security breaches, incidents, or near misses.

Personal Attitudes and Skills
This layer relates to the attitudes and skills held by your workforce in relation to security, alongside the extent to which staff have the skills required to comply with security processes and procedures.

  • What is your workforce’s attitude towards security? Do they understand the threat and understand what they should be doing? Are they motivated to act in a secure way?

Organisational Influences and Levers
Personal attitudes and skills are shaped by your organisational influences; the resources and levers available within an organisation to bring about an effective security culture. Resources and levers include factors such as organisational incentives, technical systems, security policies, and management commitment.

  • Are you shaping the workplace environment to encourage and enable your workforce to behave securely? Are you incentivising your workforce to act in a secure way through reward and recognition?
  • Are you making it easy for them to do so? How committed are your management to good security – do they role model good behaviours or encourage the workforce to cut corners?

Cultural Style
Wider organisational values and goals shape the type of security culture that is effective for individual organisations. Setting the vision about the type of desired security culture, in the context of organisational goals, is the bedrock that drives decision making about the resources needed to bring about desired change.

  • What do you value as an organisation? What are your key drivers? Is it innovation? Accuracy? These values and your cultural style will underpin the rest  of the iceberg.

Footnote:
1. The concept of the 'cultural iceberg' was conceived of in 1976 by anthropologist Edward T. Hall. For further information see: Hall, E. T. (1976). Beyond culture. New York: Anchor Press/Double day. 

Why Should I Care About Security Culture?

An effective security culture is increasingly recognised as an essential part of protective security, both across Industry and Government. Investing in your security culture helps establish a workforce that are engaged with, and take responsibility for, security issues. This is vital in a rapidly changing world where threats and vulnerabilities are ever-changing. Having a workforce that is resilient to these changes and can spot and report potential vulnerabilities is crucial to your organisational health.

Security Culture: Myth-Busting

We have compiled a list of some of the more common misconceptions about security culture:

  • Organisations have different assets, values, priorities and necessary ways of working, which inform the type of security culture that will work best for that organisation. The right security culture will enhance an organisation’s ability to operate and improve overall business performance because it aligns with that organisation’s personal drivers and values.
  • In this way, you cannot ‘copy’ another organisation's security culture; you need to invest time and resources in understanding both your current and desired cultures, and how to get there.
  • 'Security’ is often considered to be the responsibility of just the ‘security team’, and ‘security culture’ is often just one part of one person’s role. However, embedding a cultural change requires commitment from your entire workforce. This starts from the very top with your senior  decision makers, whose support is crucial. Without their vision for what they want the organisation’s security culture to look like, their commitment of the time and resources required to push through the changes required, their endorsement of the strategy and their role-modelling of the values and behaviours you expect to see, the chances of success are slim.
  • Beneath the senior leadership, NPSA recommend setting up a ‘cross-functional team’ that incorporates members from different sections of the business that have the time, resources and expertise required to help instil a new or evolve a current culture e.g. a representative from the I.T department to ensure that there are no technical barriers to staff  behaving in a secure way, and Comms and Training Teams to ensure staff are kept informed and have access to the appropriate training materials.
  • Depending on organisational hierarchy, you will almost certainly also want middle management, such as line managers, to take ownership of this work too, as they will be critical in implementing and embedding change with their teams and role-modelling expectations. In this way, everyone has a role to play in fostering a strong security culture.
  • Security culture can be measured and quantified, allowing an organisation to map its progress and improve over time. Utilising or embedding metrics like security incidents or HR casework can help to make security culture a tangible driver of organisational outcomes.
  • NPSA’s Security Culture Tool can be used to measure and quantify security culture through a combination of tailored workforce surveys.
  • When exploring their security culture, an organisation may find that they have sub-cultures; different sections of the organisation might have their own security culture or behavioural expectations. For example, these may exist between different departments (e.g. commercial teams vs security teams) or different locations (where an organisation works across multiple sites or even countries).
  • Whilst some culture change programmes may seek to wipe out sub-cultures, they are not inherently undesirable – legitimate sub-cultures can enhance the ability of particular business areas to fulfil their specific organisational objectives.
  • It is important to explore these and determine whether they are justifiable and serve a genuine business purpose, or whether they have evolved organically over time and could instead be having a negative impact on an organisation’s ability to instil good security behaviours.
  • Justifiable differences should be recognised and communicated to the organisation so that the workforce are clear on what is expected of them and understand why differences in practices are accepted. Not only will this help improve compliance with these expectations, but it also helps to prevent dissatisfaction and de-motivation amongst staff.
  • Organisations are complex and dynamic ecosystems. Your security culture is enacted through everyday actions and decisions made by your workforce both within and physically outside of the office (including, for example, your wider supply chain). To ensure an appropriate security culture endures, you need to put in place resources and measures to continually reinforce it and keep it front and centre.
  • A great way to do this is to find examples of individuals and teams demonstrating proactive security behaviours and recognise them publicly. Whatever you reward you will tend to get more of, so be clear to your workforce  about what 'good' looks like.
  • Often, senior leaders within an organisation assume that their individual intentions lead directly to a strong security culture; there is an assumption that their good intentions will be observed and understood by everyone.
  • The truth is that a strong security culture will only begin to manifest once an organisation's senior leadership are intentional about defining and role modelling it and have put the right resources behind making it happen. Central to this is communication - let your workforce know what you expect, both existing employees and the people you're hiring.
Did you find this page useful?
helpfulness rating