Technology stops a great deal of cyber attack activity, but the decisions people make every day still determine whether an organisation is breached. A single click on a convincing email, a reused password, or an unreported anomaly can undo millions of dollars of controls. That is why a security-aware culture is one of the highest-return investments any organisation can make, and also one of the most frequently mishandled.
The mistake most organisations make is equating culture with training. They roll out an annual module, record completion rates, and report a healthy percentage to the board. Meanwhile, behaviour barely changes. Real culture is not what people are told once a year; it is what they do when no one is watching.
Why annual training fails
Knowledge fades quickly. Studies of learning retention consistently show that information delivered in a single session decays within weeks unless it is reinforced. A once-a-year course also signals, however unintentionally, that security is a compliance exercise to be endured rather than a genuine part of the job.
Worse, generic training rarely connects to the specific decisions people actually face. Telling an accounts payable officer that they should “be vigilant” does nothing; showing them a realistic example of a fake invoice or a spoofed supplier email change, and giving them a simple verification step, changes behaviour. Culture is built through frequent, relevant, role-specific reinforcement, not annual broadcasts.
The three foundations of security culture
A genuine security-aware culture rests on three things that work together. Remove any one and the other two struggle.
- Make the secure choice the easy choice. If the secure way to do something is slow or awkward, people will route around it, and you cannot train your way out of bad design. Single sign-on, a well-run password manager, simple reporting buttons and sensible default settings remove friction so that doing the right thing requires no special effort.
- Reinforce continuously. Short, frequent touchpoints beat long, rare ones. Monthly phishing simulations, brief tip-of-the-week communications, contextual prompts at the moment of risk, and discussion in team meetings keep security present without becoming background noise.
- Lead visibly. Culture is set by what leaders do, not what they say. When executives complete the same training, follow the same access controls and openly discuss security in business decisions, staff take it seriously. When leaders demand exceptions, the message is that the rules are for other people.
Build a just culture so people report
The single most valuable behaviour you can cultivate is fast, honest reporting. The earlier the security team learns that something looks wrong, the cheaper and smaller the incident. Yet in many organisations, fear of blame means staff stay silent, and a phishing click that could have been contained in minutes becomes a breach discovered weeks later.
A just culture solves this. It draws a clear line between honest mistakes, which are treated as learning opportunities, and reckless or malicious behaviour, which is not. Someone who clicks a sophisticated phishing link and immediately reports it should be thanked, not punished. The moment people are penalised for honest errors, reporting stops and your visibility collapses.
Practical steps include a no-blame reporting policy, a one-click report button in email, public recognition for people who catch and report threats, and ensuring the first response to any report is supportive rather than accusatory. The aim is an environment where raising a concern is always the safe choice.
Measure behaviour, not completion
If you measure training completion, you will optimise for training completion, which tells you nothing about risk. Measure behaviour instead.
- Phishing click and report rates over time. A falling click rate paired with a rising report rate is strong evidence of cultural change.
- Reporting speed and volume. How quickly and how often do staff report suspicious activity? More reports usually mean a healthier culture, not a worse one.
- Process adherence. How often are secure processes followed versus bypassed for convenience? High bypass rates point to friction you need to design out.
- Repeat-clicker trends. A small group of repeat clickers needs targeted coaching, not organisation-wide blame.
These behavioural indicators belong in your broader security reporting. Our guide to the Essential Eight covers the technical controls that reduce the impact when someone does make a mistake, and a strong culture and strong controls reinforce each other.
Tailor the approach to your sector
Culture work is not one-size-fits-all. A large enterprise with shift workers, a council with frontline customer service staff, and a financial services firm under regulatory scrutiny each face different pressures.
Australian councils, for example, often combine long-serving staff, contractors and elected members across many sites, which makes consistent reinforcement harder; our guidance on cybersecurity for Australian councils addresses these realities. Financial services firms must align awareness efforts with their obligations under APRA CPS 234, which expects staff to understand their information security responsibilities. Government agencies operating under state frameworks have their own training and assurance expectations to meet.
Embed security into onboarding and everyday processes
Culture is shaped most powerfully at the moments when people form habits, and the strongest of these is when someone joins the organisation. New starters arrive ready to learn how things are done. If security is presented in their first week as a normal, valued part of the job, alongside meaningful, role-specific guidance rather than a generic compliance video, it sets an expectation that lasts. If it is buried in a stack of forms or omitted entirely, the message is that security is an afterthought.
Beyond onboarding, the goal is to weave security into existing workflows rather than bolting it on as a separate activity. Build verification steps into the procurement and payment processes that fraudsters target. Add a brief security consideration to project kick-offs and change approvals. Make secure behaviour part of how teams already work, so it does not feel like extra effort imposed from outside. Culture that lives inside everyday processes is far more durable than culture that depends on people remembering a training session.
Address the human factors behind risky behaviour
People rarely make insecure choices out of carelessness alone. More often there is a reason: they are under time pressure, the secure path is confusing, they do not understand the risk, or they have learned that asking for help is slow or unwelcome. A blame-first response treats the symptom; a culture-first response asks why the behaviour made sense to the person at the time.
This matters because the same root causes recur. If staff repeatedly bypass a control, the control is probably badly designed, and no amount of reminding will fix a workflow that punishes the secure choice. If a particular team clicks phishing simulations more than others, they may face email-heavy roles that warrant tailored support rather than censure. Treating risky behaviour as information about your environment, rather than as evidence of bad employees, is what separates organisations that genuinely improve from those that run the same training every year and wonder why nothing changes.
Sustaining culture over time
Culture is not a project with an end date. The threats change, staff turn over, and complacency creeps back. Treat culture as an ongoing program with an owner, a calendar of activity and metrics that are reviewed regularly. Refresh phishing themes so they stay realistic, update scenarios as new attack techniques emerge, and revisit your reporting and recognition practices to keep them genuine rather than tokenistic.
Above all, keep leadership engaged. The fastest way to erode a security culture is for executives to stop modelling it. The fastest way to build one is for them to keep showing, in their own behaviour, that security is simply part of how the organisation does its work.
CISO Advisory helps Australian organisations move from box-ticking awareness training to measurable behaviour change, integrated with their wider virtual CISO and governance program. To discuss building a security-aware culture in your organisation, contact us or call 07 2112 8502.
Frequently asked questions
Why is security awareness training alone not enough?
One-off annual training delivers a burst of knowledge that fades within weeks and rarely changes day-to-day behaviour. Culture is shaped by what people see leaders do, how easy secure choices are, and whether reporting a mistake is safe. Training is one input, but without reinforcement, easy secure defaults and visible leadership, it changes very little.
How do you measure security culture?
Use behavioural indicators rather than completion rates. Track phishing simulation click and report rates over time, the speed and volume of staff reporting suspicious activity, and how often secure processes are followed versus bypassed. A rising report rate and a falling click rate show genuine cultural change far better than the percentage who finished a module.
What is a just culture in cybersecurity?
A just culture treats honest mistakes as learning opportunities rather than grounds for punishment, while still holding people accountable for reckless behaviour. It matters because staff who fear blame hide incidents, and a hidden incident is far more damaging than a reported one. The goal is fast, fearless reporting of anything that looks wrong.
How often should we run phishing simulations?
Monthly or at least quarterly, varied in difficulty and theme, works better than rare large campaigns. Frequent, realistic simulations build a habit of scrutiny and keep awareness current. Always pair them with immediate, non-punitive coaching for those who click, and celebrate the people who report, so the exercise builds trust rather than resentment.
Who is responsible for security culture?
Everyone contributes, but visible ownership must sit with senior leadership. When executives follow the same controls as everyone else, talk about security in business terms and fund it properly, culture follows. The security team enables and measures it, but culture is set at the top by what leaders consistently do and reward.
Need this handled for your organisation?
Confidential and no obligation. We respond the same business day — on-site same day / next business day, or remote, Australia-wide. Prefer to talk now? Call us 24/7 on 07 2112 8502.