• About
  • Subscribe
  • Contact
Wednesday, May 7, 2025
    Login
  • Management Leadership
    • Growth Strategies
    • Finance
    • Operations
    • Sales and Marketing
    • Careers
  • Technology
    • Infrastructure and Platforms
    • Business Applications and Databases
    • Big Data, Analytics and Intelligence
    • Security
  • Industry Verticals
    • Finance and Insurance
    • Manufacturing
    • Logistics and Transportation
    • Retail and Wholesale
    • Hospitality and Tourism
    • Government and Public Services
    • Utilities
    • Media and Telecommunications
  • Resources
    • Whitepapers
    • PodChats
    • Videos
  • Events
No Result
View All Result
  • Management Leadership
    • Growth Strategies
    • Finance
    • Operations
    • Sales and Marketing
    • Careers
  • Technology
    • Infrastructure and Platforms
    • Business Applications and Databases
    • Big Data, Analytics and Intelligence
    • Security
  • Industry Verticals
    • Finance and Insurance
    • Manufacturing
    • Logistics and Transportation
    • Retail and Wholesale
    • Hospitality and Tourism
    • Government and Public Services
    • Utilities
    • Media and Telecommunications
  • Resources
    • Whitepapers
    • PodChats
    • Videos
  • Events
No Result
View All Result
No Result
View All Result
Home Technology Security

Security maturity reveals the potential for breach

FutureCIO Editors by FutureCIO Editors
May 26, 2022
Photo by Miguel Á. Padriñán from Pexels: https://www.pexels.com/photo/japanese-lucky-coin-cat-932261/

Photo by Miguel Á. Padriñán from Pexels: https://www.pexels.com/photo/japanese-lucky-coin-cat-932261/

Security culture is the ideas, customs and social behaviours of an organisation that influence its security. KnowBe4 defines security culture as the ideas, customs and social behaviours that influence an organisation's security.

It lists seven dimensions as determining an organisation's security culture:

  • Attitudes: The feelings and beliefs that employees have toward the security protocols and issues.
  • Behaviours: The actions and activities of employees that have a direct or indirect impact on the security of the organization.
  • Cognition: Employees’ understanding, knowledge and awareness of security issues and activities.
  • Communication: The quality of communication channels to discuss security-related topics, promote a sense of belonging and provide support for security issues and incident reporting.
  • Compliance: The knowledge of written security policies and the extent that which employees follow them.
  • Norms: The knowledge of and adherence to unwritten rules of conduct in the organization.
  • Responsibilities: How employees perceive their role as a critical factor in sustaining or endangering the security of the organization.

KnowBe4 Research developed what it called the security culture maturity model as part of its security culture report. The five maturity levels represent an organisation's security culture in relation to the likelihood of a breach and the cost of remediation.

The 2022 Security Culture Report noted that large organisations reported better attitudes and behaviours than smaller organisations regarding security culture, yet small organisations scored better on all other dimensions of security culture.

Security culture in Asia as seen by organizational size.
Source: KnowBe4 Research, 2022

In Asia, a wide variation of security culture scores across nations exists. While Japan (76) is doing reasonably well, countries like Malaysia (66) and Indonesia (67) show an alarmingly low-security culture index score.

It also noted that in Asia organisational size is a smaller factor compared to other regions. With the exception of medium organizations on the attitudes and behaviours dimensions, organizational size has little impact on security culture.

Perry Carpenter

“Security culture involves how people think about and approach a more secure environment and this report focuses on those key elements,” said Perry Carpenter, chief evangelist and strategy officer, KnowBe4.

He added that in the new trend data, which looked at security culture over the last two to three years, security culture has improved across regions and industries overall. This was the most promising finding from the research and emphasizes that security culture should be viewed as a critical asset used to reduce risk and improve security.

The recommendation is for continuous security awareness training and simulated phishing assessments as well as measurement tools to create a stronger security culture.

Related:  Government should do more to protect against cyber risks
Tags: KnowBe4security culturesecurity maturity
FutureCIO Editors

FutureCIO Editors

No Result
View All Result

Recent Posts

  • Agentic AI-powered AppSec platform launched for the AI era
  • IDC forecasts GenAI alone will grow at a 59.2% CAGR
  • Dataiku brings new AI capabilities to create and control AI agents
  • Microsoft reveals the rise of a new kind of organisation in the AI era
  • St Luke’s ElderCare enhances data security and user experience with Juniper

Live Poll

Categories

  • Big Data, Analytics & Intelligence
  • Business Applications & Databases
  • Business-IT Alignment
  • Careers
  • Case Studies
  • CISO
  • CISO strategies
  • Cloud, Virtualization, Operating Environments and Middleware
  • Computer, Storage, Networks, Connectivity
  • Corporate Social Responsibility
  • Customer Experience / Engagement
  • Cyber risk management
  • Cyberattacks and data breaches
  • Cybersecurity careers
  • Cybersecurity operations
  • Education
  • Education
  • Finance
  • Finance & Insurance
  • FutureCISO
  • General
  • Governance, Risk and Compliance
  • Government and Public Services
  • Growth Strategies
  • Hospitality & Tourism
  • HR, education and Training
  • Industry Verticals
  • Infrastructure & Platforms
  • Insider threats
  • Latest Stories
  • Logistics & Transportation
  • Management Leadership
  • Manufacturing
  • Media and Telecommunications
  • News Stories
  • Operations
  • Opinion
  • Opinions
  • People
  • Process
  • Remote work
  • Retail & Wholesale
  • Sales & Marketing
  • Security
  • Tactics and Strategies
  • Technology
  • Utilities
  • Videos
  • Vulnerabilities and threats
  • White Papers

Strategic Insights for Chief Information Officers

FutureCIO is about enabling the CIO, his team, the leadership and the enterprise through shared expertise, know-how and experience - through a community of shared interests and goals. It is also about discovering unknown best practices that will help realize new business models.

Quick Links

  • Videos
  • Resources
  • Subscribe
  • Contact

Cxociety Media Brands

  • FutureIoT
  • FutureCFO
  • FutureCIO

Categories

  • Privacy Policy
  • Terms of Use
  • Cookie Policy

Copyright © 2022 Cxociety Pte Ltd | Designed by Pixl

Login to your account below

or

Not a member yet? Register here

Forgotten Password?

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Management Leadership
    • Growth Strategies
    • Finance
    • Operations
    • Sales and Marketing
    • Careers
  • Technology
    • Infrastructure and Platforms
    • Business Applications and Databases
    • Big Data, Analytics and Intelligence
    • Security
  • Industry Verticals
    • Finance and Insurance
    • Manufacturing
    • Logistics and Transportation
    • Retail and Wholesale
    • Hospitality and Tourism
    • Government and Public Services
    • Utilities
    • Media and Telecommunications
  • Resources
    • Whitepapers
    • PodChats
    • Videos
  • Events
Login

Copyright © 2022 Cxociety Pte Ltd | Designed by Pixl

Subscribe