Security leaders need to foster a culture where their colleagues do more than just follow the rules, according to a CISO panel at Infosecurity Europe.
Creating a security culture is about more than just encouraging people in the business to report incidents, although this remains important. CISOs should also aim to create environments where the business actively looks to work with security teams. This, in turn, means explaining how security helps everyone in the business meet their goals.
“For us, the goal is to have people follow certain behaviors, based on what they know rather than what they have been told,” said Toks Oladuti, CISO at law firm Dentons. “People make these behavior changes more, if they understand why.”
No tags.