Part II · Chapter 10

Security communication

Security culture is not built by more training sessions. It is built by communication that lands and changes what people actually do. This chapter works through why security messages so often stop at having been sent, what separates information from communication, and which conditions have to be in place for knowledge to turn into behaviour.

  • CISOs and security leads
  • Boards and leadership teams

Last reviewed

Almost every organisation trains its staff in information security. Considerably fewer can show that the training changed anything. The annual session is held, attendance is recorded, and then everyone carries on exactly as before. This chapter is about why the gap arises and what it takes to close it.

It begins with the diagnosis, why security communication so rarely lands despite being sent out. Then it draws the distinction between information and communication, which sounds like a matter of wording but is the decisive point of the whole chapter. After that comes the step from knowledge to behaviour through capability, opportunity and motivation, a model that explains why employees who know perfectly well what they ought to do still do not do it. Often the answer is that the right behaviour is more cumbersome than the wrong one. The chain of effect shows how communication is planned backwards from the business objective rather than forwards from the message, and one section describes what a communication architecture for information security can look like over time. Then follows the shift from compliance control to co creation, the change that determines whether employees report mistakes or hide them. The role of the leadership is treated as a precondition rather than as a sender, followed by the link to the requirement areas of the Cybersecurity Act. One section deals with the digital footprint of the employee, which is the surface attackers work against according to chapter 2 on the threat actors.

Why now comes down to two things. Cyber hygiene and training is explicitly one of the ten requirement areas of the law, which means the work has to be demonstrable and followed up. And attack routes increasingly run through people rather than through technical vulnerabilities, which moves the centre of gravity in the defence to where technology does not reach. The consequence is that communication has to be planned with the same care as a technical control, and followed up on effect rather than on sessions held.

This page shows what the chapter covers and why communication is a security tool rather than a support function. The models, the architecture and the practical examples are in chapter 10 of the book.

If the message is not received it has not been said. Communication is not what you send, but what the recipient understands.

Key insights

  • A message that is not received has not been communicated, however many people got the email.
  • Knowledge is not enough. Behaviour also requires capability, opportunity and motivation.
  • Control and compliance demands create avoidance. Co creation creates reporting, which is what gives early detection.
  • The behaviour of the leadership is the strongest signal in the organisation and cannot be offset by campaigns.
  • Cyber hygiene and training is one of the requirement areas of the Cybersecurity Act, so it is not optional.

Tools that belong to this chapter

The templates and interactive tools are in the Toolbox, free of charge.

  • System tools

    Platforms for recurring training and security awareness.

Read on

Next step

Where does your organisation stand?

The self-assessment gives you a maturity profile against the ten requirement areas of the Cybersecurity Act in a few minutes, right on screen.