Human layer

What is Security Culture?

A business guide to security culture, why most breaches come down to people and how to build and measure one that lasts.

Key takeaways
  • Security culture is the shared attitudes, habits and norms that decide how people handle security day to day, not a policy document or an annual training slide.
  • Around 62% of breaches involve a human element, so how people behave is now the deciding factor in most incidents (Verizon DBIR, 2026).
  • A strong culture shows up in behaviour. People report suspicious messages quickly, verify unusual requests and feel safe admitting mistakes.
  • Blame drives silence. When staff fear punishment for clicking a link they hide it, and the attacker gets more time inside.
  • Leadership sets the tone. If the board treats security as optional, everyone else will too. NIST CSF 2.0 puts governance at the centre.
  • Awareness training is a start, not the whole job. Culture is reinforced by habits, systems and consequences that make the safe choice the easy one.
  • Under NIS2, transposed in Sweden as Cybersäkerhetslagen since 15 January 2026, security awareness training is a legal duty and boards can be held personally accountable.
  • You can measure culture with proxy signals such as phishing-simulation reporting rates, how fast people report, training completion and staff surveys.
  • Most named breaches trace back to a person being manipulated, from Twitter’s vished staff to MGM’s help-desk call, rather than a clever technical exploit.
  • Third-party risk is a culture problem too. In August 2025 one Swedish supplier compromise disrupted around 200 of Sweden’s 290 municipalities.

Security Culture Defined in Plain Terms

Security culture is the shared set of attitudes, habits and norms that shape how people in an organisation handle security every day. It is the gap between staff who quietly work around a control and staff who report a suspicious email without being asked. Technology sets the rules. Culture decides whether people follow them.

This matters more than it used to. The 2026 Verizon Data Breach Investigations Report found that around 62% of breaches involved a human element such as an error, social engineering or misuse. Attackers have worked out that the fastest way past good technology is a person who is busy, trusting or afraid to ask.

A security culture is not a policy document or an annual training slide. Those are inputs. Culture is what people actually do when a message looks slightly off and no one is watching. In Sweden it is now also a legal expectation, not only good practice.

Why Security Culture Matters

Every organisation runs on people making quick decisions. A finance clerk approves a payment. A manager resets a password. An employee opens an attachment. Each of those moments is a security decision and attackers design their work to exploit them.

Why Security Culture Matters

The evidence is consistent. Social engineering was the third most common attack pattern in the 2026 Verizon report and attackers keep moving to where people are least guarded. In the 2026 report’s simulation data, phone and text-based social engineering succeeded around 40% more often than email phishing in part because people are more trusting on a call and more distracted on a phone.

The cost is not abstract in Sweden. In August 2025 a ransomware attack on the IT supplier Miljödata cascaded across around 200 of Sweden’s 290 municipalities and exposed the personal data of about 2.2 million people including sick-leave and school records. One weak supplier reached most of the country’s local government.

A strong security culture will not stop every attack. It does something more useful. It shrinks the number of people who can be tricked, speeds up the moment someone raises the alarm and buys your responders time. That is often the difference between a contained incident and a public breach.

The Building Blocks of a Security Culture

A security culture is built from a few reinforcing parts. Weaken one and the others start to give. These are the building blocks worth investing in.

  • Leadership and Tone: When leaders treat security as part of the job and follow the rules themselves, staff take it seriously. When they ask for exceptions, the culture erodes.
  • Shared Awareness: People understand the common threats and their own part in stopping them. This is where training earns its place.
  • Safe Reporting: Staff can flag a mistake or a suspicious message without fear of blame so problems surface early rather than staying hidden.
  • Everyday Habits: Verifying unusual requests, locking screens and questioning odd logins become automatic rather than effortful.
  • Clear Accountability: Everyone knows what they are responsible for and security duties are written into roles rather than left vague.
  • Low-Friction Security: The secure path is the easy path. When a control gets in the way people route around it so good design keeps the safe choice convenient.

The NIST Cybersecurity Framework 2.0, published in 2024, put governance at the centre of managing cyber risk. That is a formal way of saying culture starts at the top and runs through everything below it.

Security Culture Examples

Culture is easiest to understand through behaviour. Here is what a strong security culture looks like in practice and what a weak one looks like.

A Strong Security Culture in Action

  • An employee forwards a suspicious email to the security team within minutes and gets a thank you rather than a lecture.
  • A finance officer pauses a large payment to confirm the request on a phone number they already hold.
  • A help-desk agent declines to reset a password until the caller passes an identity check even when the caller sounds senior and impatient.
  • A developer flags that a shortcut would expose a credential and the team fixes it instead of shipping.
  • A manager admits in a team meeting that they nearly fell for a scam which makes it safe for others to speak up too.

What a weak security culture looks like

  • Passwords are shared over chat so the team can move faster.
  • Staff who report a mistake are blamed so the next person stays quiet.
  • Employees use unapproved apps and AI tools out of sight of IT. In the 2026 Verizon report this shadow AI use had tripled and is now a leading source of data leakage.
  • Security reviews are skipped to hit deadlines with leadership’s blessing.
  • The same annual training is clicked through and forgotten.

The difference is rarely about intelligence or effort. It is about what the organisation makes normal and easy.

Real-World Cases

The clearest lesson from major breaches is how few of them start with a technical masterstroke. Most start with a person. Three well-documented cases show the pattern.

Twitter, 2020: A Phone Call Past the Front Door

Real-World Cases -Security Culture

In July 2020 attackers took over high-profile Twitter accounts and ran a Bitcoin scam. They did not break the technology. They phoned Twitter staff, posed as the IT department and talked several employees into handing over their login details.

Multi-factor authentication was in place, but the attackers walked the employees through it. The New York State Department of Financial Services which investigated, found the company had no chief information security officer and urged regular training and phishing exercises. The scam took at least 118,000 dollars.

A culture where staff treat an unexpected IT call with suspicion and verify it on a known internal channel would have stopped the calls cold.

Uber, 2022: One Approval Too Many

In September 2022 an attacker bought the login details of an Uber contractor then bombarded them with repeated multi-factor approval prompts. When the contractor hesitated, the attacker messaged them on WhatsApp claiming to be Uber IT and told them to approve a prompt to make the alerts stop.

The contractor approved and the attacker was inside. Uber’s own account of the incident describes this sequence. The warning sign was there, an approval request nobody had asked for but the habit of pausing and reporting was missing.

Two habits close this gap. Never approve a prompt you did not trigger and report a flood of prompts straight away. Phishing-resistant multi-factor authentication removes the choice altogether.

MGM Resorts, 2023: Ten Minutes on the Help Desk

In September 2023 attackers reached MGM Resorts by phoning its IT help desk, impersonating an employee they had researched online and asking for access to be reset. According to the attackers’ account and later reporting, the call took about ten minutes.

MGM told the United States securities regulator that the disruption knocked around 100 million dollars off its quarterly results. The systems were sound. The process for proving who was on the phone was not.

A help desk that verifies identity in a way a phone call cannot fake, backed by staff who are empowered to refuse a senior-sounding caller would have ended it at the first request.

Security Culture and Compliance

Security culture used to be good practice. In Sweden and across the EU it is now written into law and regulators are enforcing the organisational side not only the technical one.

NIS2, transposed into Swedish law as Cybersäkerhetslagen (SFS 2025:1506) and in force since 15 January 2026 requires in-scope organisations to provide security awareness training under Article 21. Under Article 20 the management body must approve and oversee security measures and board members can be held personally accountable.

Fines reach up to 10 million euro or 2% of global turnover for essential entities. Our NIS2 compliance guide covers the detail.

GDPR Article 32 requires appropriate technical and organisational measures to protect personal data and the organisational half carries real weight. In September 2026 Sweden’s data protection authority, IMY, fined Miljödata 1.8 million kronor under Article 32 finding it had not properly vetted new software and lacked real-time monitoring. The failure was as much process as technology. Our GDPR compliance guide sets out the obligations.

For financial entities, DORA Article 17 requires a managed process for handling ICT incidents, overseen by Finansinspektionen. ISO 27001, control 6.3, requires that staff and contractors receive information security awareness, education and training suited to their role. Each of these regimes treats how people are trained and managed as part of security, not an afterthought.

How to Measure Security Culture

You cannot manage what you never look at and doing the annual training is not a measure of culture. Culture shows up in behaviour so measure behaviour.

  • Reporting Rate: How many staff report a simulated or real phishing message. A rising reporting rate is the single most encouraging signal because it means people are engaged and unafraid.
  • Time to Report: How quickly the first report arrives after a suspicious message lands. Speed limits how long an attacker has to work.
  • Simulation Results: Click rates on phishing simulations, read as a trend rather than a pass or fail. One bad month is a prompt to coach, not to punish.
  • Training Completion and Freshness: Who has done training and how recently. Stale training is close to no training.
  • Culture Surveys: Anonymous questions about whether staff feel able to report whether leaders model good behaviour and whether security helps or hinders their work.

Treat every one of these as a proxy rather than the truth. A low click rate can hide a team that never reports. A high completion rate can sit on top of a blame culture where nobody admits mistakes. Watch several signals together, follow the trend and stay honest that numbers only ever approximate how people really behave.

How to Build a Security Culture

Building a security culture is a programme, not a project. It runs across people, process and technology and it needs to be led from the front. Start with these steps and keep at them.

  • Lead from the top. Have leaders talk about security, fund it and follow the same rules as everyone else. Nothing shapes culture faster than what executives actually do.
  • Make reporting easy and blameless. Give people a one-click way to report and thank them when they use it even for a false alarm.
  • Train little and often. Replace the annual marathon with short role-specific sessions and let finance, HR and the help desk practise the scenarios they will really face.
  • Build verification into the work. Require a second known channel for payment changes and access requests so verifying is the default rather than a favour.
  • Remove friction from the safe path. If a control is painful people avoid it so fix the design until the secure option is also the convenient one.
  • Rehearse under pressure. Run realistic phishing and vishing exercises and walk through a live incident on a tabletop so the habits hold when it is real.
  • Measure and adjust. Track the behavioural signals covered above, share the trend openly and improve where the culture is weakest.

Do these consistently and culture stops being a poster on the wall. It becomes the way your organisation works which is the only kind of security that reaches every person you employ.

Myths & Facts

Myth

Security is the IT department's job.

One annual training session is enough.

A strong culture means punishing people who click.

If we buy enough security tools, culture does not matter.

Our staff are not technical, so they cannot help.

You cannot measure something as soft as culture.

Fact

Around 62% of breaches involve a human element across the whole business, so finance, HR and frontline staff are part of the defence, not bystanders (Verizon DBIR, 2026).

Knowledge fades and threats change through the year. Culture is built by regular short reinforcement and by habits people use daily, not a single slide deck.

Punishment makes people hide mistakes. A blameless reporting culture surfaces incidents faster, which is what limits the damage.

People route around controls that get in their way. Tools only work when the culture supports using them properly.

Non-technical staff are often the first to notice an odd email, a strange call or an unexpected login. Give them an easy way to report and they become active sensors.

You can track reporting rates, phishing-simulation results, time to report and survey scores, then improve against them over time.

Test Yourself

Four real-world scenarios, then six knowledge questions. See how prepared you would be under pressure.

Scenario Simulation

  1. Late one evening your phone lights up with repeated login approval requests you did not start. Minutes later a WhatsApp message says it is from IT and asks you to approve one so the alerts stop.

    What do you do?

    • Approve one prompt so the alerts stop
    • Deny the prompts and report the flood to security straight away
    • Ignore it and put your phone on silent
  2. A caller reaches the IT help desk, says they are a senior executive locked out before an urgent meeting and demands an immediate password reset.

    What should the help-desk agent do?

    • Reset it quickly because the caller is senior and in a hurry
    • Follow the identity-verification process before any reset, whoever the caller claims to be
    • Ask the caller to email from their work address and reset if they do
  3. You clicked a link in an email and entered your password before realising it looked wrong. You feel embarrassed and worried about getting into trouble.

    What is the best thing to do?

    • Say nothing and hope nothing happens
    • Report it to security immediately so they can act
    • Change your password and decide not to mention it
  4. A senior manager asks your team to skip the usual security review to hit a launch deadline, saying it will be fine just this once.

    What is the healthiest response for a security culture?

    • Skip the review because a manager approved it
    • Name the risk, offer a fast-tracked review and escalate if needed
    • Do the review quietly after launch

Knowledge Test

  1. Roughly what share of breaches involved a human element in the 2026 Verizon report?

    • About 20%
    • About 40%
    • About 62%
    • About 90%

    The 2026 Verizon Data Breach Investigations Report put the human element in around 62% of breaches.

  2. What best describes security culture?

    • A signed policy document
    • The shared habits and norms that shape how people handle security
    • A firewall configuration
    • An annual training certificate

    Culture is what people actually do day to day, not a document or a single training event.

  3. Is one annual training session enough to build a strong security culture?

    • Yes, once a year covers it
    • No, culture needs regular reinforcement and daily habits

    Knowledge fades and threats change, so short regular reinforcement beats a single yearly session.

  4. Why does a blameless reporting culture make an organisation safer?

    • It removes the need for training
    • It means staff report mistakes early instead of hiding them
    • It guarantees no one will ever click a link
    • It replaces technical controls

    When people are not punished for honest mistakes, incidents surface faster and responders gain time.

  5. Under NIS2, in force in Sweden as Cybersäkerhetslagen, who can be held accountable for security measures?

    • Only the IT team
    • The management body, including board members
    • External auditors only
    • Nobody

    Article 20 makes the management body responsible, and board members can be held personally accountable.

  6. Which is the most encouraging single signal when measuring security culture?

    • A falling training budget
    • A rising rate of staff reporting suspicious messages
    • Fewer security tools
    • A lower number of help-desk calls

    A rising reporting rate shows people are engaged and unafraid to raise the alarm.

Take It with You

Share the Summary PDF with Your Team

A short distilled brief in PDF: key findings, red flags and action steps.

Download summary PDF

Why Training Matters

Training is where security culture starts to take shape. It gives people a shared language for risk and the confidence to question an unusual request instead of complying with it. The Verizon Data Breach Investigations Report found the human element in around 62% of breaches in 2026, and most began with someone being manipulated rather than a system being broken.

Under NIS2, in force in Sweden as Cybersäkerhetslagen since 15 January 2026, security awareness training is a legal duty and the board is accountable for it. The training that works is short, regular and role-specific, so finance teams practise payment verification and help-desk staff practise identity checks. eBuilder Security runs Sweden-based security awareness and phishing-simulation training that turns this knowledge into daily habits.

Frequently Asked Questions

What is security culture?

Security culture is the shared attitudes, habits and norms that shape how people in an organisation handle security every day. It covers whether staff report suspicious messages, verify unusual requests and feel safe admitting mistakes. A strong culture makes the secure choice the normal choice, rather than something imposed by policy alone.

Why is security culture important?

Security culture is important because around 62% of breaches involve a human element, so how people behave decides most outcomes (Verizon DBIR, 2026). Good technology can be bypassed by a single manipulated employee. A strong culture turns staff into an active line of defence rather than an easy target for attackers.

What are examples of a good security culture?

Examples of a good security culture include staff reporting phishing without being asked, employees verifying payment or access requests through a known second channel and help-desk teams confirming identity before resetting a password. People admit mistakes early, and leaders visibly follow the same rules they set.

How do you build a security culture?

You build a security culture by leading from the top, making reporting easy and blame-free and reinforcing safe habits with short regular training rather than one annual session. Set clear norms, remove friction from the secure path and measure progress so the culture keeps improving over time.

How do you measure security culture?

You measure security culture with proxy signals rather than a single score. Useful metrics include phishing-simulation reporting and click rates, how quickly staff report incidents, training completion and anonymous culture surveys. Track these over time and watch the trend, because one number rarely captures behaviour on its own.

Is security culture the same as security awareness training?

No. Security awareness training teaches people what to do, while security culture decides whether they actually do it under pressure. Training is one input. Culture is the wider set of habits, incentives and leadership behaviour that determine how staff act when no one is checking.

Is a security culture legally required?

In many cases yes. Under NIS2, transposed in Sweden as Cybersäkerhetslagen since 15 January 2026, in-scope organisations must provide security awareness training and boards can be held personally accountable. GDPR and ISO 27001 also require appropriate organisational measures, which include how people are trained and managed.

Whose responsibility is security culture?

Security culture is everyone's responsibility, but it starts with leadership. The board and executives set the tone, fund the work and model the behaviour. Under NIS2 the management body is accountable by law. Managers reinforce the norms day to day, and every employee contributes by reporting and verifying.

You Understand the Risk.
Now See Where You Stand.

Book a 30-minute briefing with one of our analysts, or run the free breach check first to find out what attackers already know about your organisation.

Book a 30-Min Briefing
No sales pitch, just a straight assessment

How eBuilder Security Can Help

Awareness is the first layer. These are the services that turn it into measurable protection.