Security Culture Defined in Plain Terms
Security culture is the shared set of attitudes, habits and norms that shape how people in an organisation handle security every day. It is the gap between staff who quietly work around a control and staff who report a suspicious email without being asked. Technology sets the rules. Culture decides whether people follow them.
This matters more than it used to. The 2026 Verizon Data Breach Investigations Report found that around 62% of breaches involved a human element such as an error, social engineering or misuse. Attackers have worked out that the fastest way past good technology is a person who is busy, trusting or afraid to ask.
A security culture is not a policy document or an annual training slide. Those are inputs. Culture is what people actually do when a message looks slightly off and no one is watching. In Sweden it is now also a legal expectation, not only good practice.
Why Security Culture Matters
Every organisation runs on people making quick decisions. A finance clerk approves a payment. A manager resets a password. An employee opens an attachment. Each of those moments is a security decision and attackers design their work to exploit them.

The evidence is consistent. Social engineering was the third most common attack pattern in the 2026 Verizon report and attackers keep moving to where people are least guarded. In the 2026 report’s simulation data, phone and text-based social engineering succeeded around 40% more often than email phishing in part because people are more trusting on a call and more distracted on a phone.
The cost is not abstract in Sweden. In August 2025 a ransomware attack on the IT supplier Miljödata cascaded across around 200 of Sweden’s 290 municipalities and exposed the personal data of about 2.2 million people including sick-leave and school records. One weak supplier reached most of the country’s local government.
A strong security culture will not stop every attack. It does something more useful. It shrinks the number of people who can be tricked, speeds up the moment someone raises the alarm and buys your responders time. That is often the difference between a contained incident and a public breach.
The Building Blocks of a Security Culture
A security culture is built from a few reinforcing parts. Weaken one and the others start to give. These are the building blocks worth investing in.
- Leadership and Tone: When leaders treat security as part of the job and follow the rules themselves, staff take it seriously. When they ask for exceptions, the culture erodes.
- Shared Awareness: People understand the common threats and their own part in stopping them. This is where training earns its place.
- Safe Reporting: Staff can flag a mistake or a suspicious message without fear of blame so problems surface early rather than staying hidden.
- Everyday Habits: Verifying unusual requests, locking screens and questioning odd logins become automatic rather than effortful.
- Clear Accountability: Everyone knows what they are responsible for and security duties are written into roles rather than left vague.
- Low-Friction Security: The secure path is the easy path. When a control gets in the way people route around it so good design keeps the safe choice convenient.
The NIST Cybersecurity Framework 2.0, published in 2024, put governance at the centre of managing cyber risk. That is a formal way of saying culture starts at the top and runs through everything below it.
Security Culture Examples
Culture is easiest to understand through behaviour. Here is what a strong security culture looks like in practice and what a weak one looks like.
A Strong Security Culture in Action
- An employee forwards a suspicious email to the security team within minutes and gets a thank you rather than a lecture.
- A finance officer pauses a large payment to confirm the request on a phone number they already hold.
- A help-desk agent declines to reset a password until the caller passes an identity check even when the caller sounds senior and impatient.
- A developer flags that a shortcut would expose a credential and the team fixes it instead of shipping.
- A manager admits in a team meeting that they nearly fell for a scam which makes it safe for others to speak up too.
What a weak security culture looks like
- Passwords are shared over chat so the team can move faster.
- Staff who report a mistake are blamed so the next person stays quiet.
- Employees use unapproved apps and AI tools out of sight of IT. In the 2026 Verizon report this shadow AI use had tripled and is now a leading source of data leakage.
- Security reviews are skipped to hit deadlines with leadership’s blessing.
- The same annual training is clicked through and forgotten.
The difference is rarely about intelligence or effort. It is about what the organisation makes normal and easy.
Real-World Cases
The clearest lesson from major breaches is how few of them start with a technical masterstroke. Most start with a person. Three well-documented cases show the pattern.
Twitter, 2020: A Phone Call Past the Front Door

In July 2020 attackers took over high-profile Twitter accounts and ran a Bitcoin scam. They did not break the technology. They phoned Twitter staff, posed as the IT department and talked several employees into handing over their login details.
Multi-factor authentication was in place, but the attackers walked the employees through it. The New York State Department of Financial Services which investigated, found the company had no chief information security officer and urged regular training and phishing exercises. The scam took at least 118,000 dollars.
A culture where staff treat an unexpected IT call with suspicion and verify it on a known internal channel would have stopped the calls cold.
Uber, 2022: One Approval Too Many
In September 2022 an attacker bought the login details of an Uber contractor then bombarded them with repeated multi-factor approval prompts. When the contractor hesitated, the attacker messaged them on WhatsApp claiming to be Uber IT and told them to approve a prompt to make the alerts stop.
The contractor approved and the attacker was inside. Uber’s own account of the incident describes this sequence. The warning sign was there, an approval request nobody had asked for but the habit of pausing and reporting was missing.
Two habits close this gap. Never approve a prompt you did not trigger and report a flood of prompts straight away. Phishing-resistant multi-factor authentication removes the choice altogether.
MGM Resorts, 2023: Ten Minutes on the Help Desk
In September 2023 attackers reached MGM Resorts by phoning its IT help desk, impersonating an employee they had researched online and asking for access to be reset. According to the attackers’ account and later reporting, the call took about ten minutes.
MGM told the United States securities regulator that the disruption knocked around 100 million dollars off its quarterly results. The systems were sound. The process for proving who was on the phone was not.
A help desk that verifies identity in a way a phone call cannot fake, backed by staff who are empowered to refuse a senior-sounding caller would have ended it at the first request.
Security Culture and Compliance
Security culture used to be good practice. In Sweden and across the EU it is now written into law and regulators are enforcing the organisational side not only the technical one.
NIS2, transposed into Swedish law as Cybersäkerhetslagen (SFS 2025:1506) and in force since 15 January 2026 requires in-scope organisations to provide security awareness training under Article 21. Under Article 20 the management body must approve and oversee security measures and board members can be held personally accountable.
Fines reach up to 10 million euro or 2% of global turnover for essential entities. Our NIS2 compliance guide covers the detail.
GDPR Article 32 requires appropriate technical and organisational measures to protect personal data and the organisational half carries real weight. In September 2026 Sweden’s data protection authority, IMY, fined Miljödata 1.8 million kronor under Article 32 finding it had not properly vetted new software and lacked real-time monitoring. The failure was as much process as technology. Our GDPR compliance guide sets out the obligations.
For financial entities, DORA Article 17 requires a managed process for handling ICT incidents, overseen by Finansinspektionen. ISO 27001, control 6.3, requires that staff and contractors receive information security awareness, education and training suited to their role. Each of these regimes treats how people are trained and managed as part of security, not an afterthought.
How to Measure Security Culture
You cannot manage what you never look at and doing the annual training is not a measure of culture. Culture shows up in behaviour so measure behaviour.

- Reporting Rate: How many staff report a simulated or real phishing message. A rising reporting rate is the single most encouraging signal because it means people are engaged and unafraid.
- Time to Report: How quickly the first report arrives after a suspicious message lands. Speed limits how long an attacker has to work.
- Simulation Results: Click rates on phishing simulations, read as a trend rather than a pass or fail. One bad month is a prompt to coach, not to punish.
- Training Completion and Freshness: Who has done training and how recently. Stale training is close to no training.
- Culture Surveys: Anonymous questions about whether staff feel able to report whether leaders model good behaviour and whether security helps or hinders their work.
Treat every one of these as a proxy rather than the truth. A low click rate can hide a team that never reports. A high completion rate can sit on top of a blame culture where nobody admits mistakes. Watch several signals together, follow the trend and stay honest that numbers only ever approximate how people really behave.
How to Build a Security Culture
Building a security culture is a programme, not a project. It runs across people, process and technology and it needs to be led from the front. Start with these steps and keep at them.
- Lead from the top. Have leaders talk about security, fund it and follow the same rules as everyone else. Nothing shapes culture faster than what executives actually do.
- Make reporting easy and blameless. Give people a one-click way to report and thank them when they use it even for a false alarm.
- Train little and often. Replace the annual marathon with short role-specific sessions and let finance, HR and the help desk practise the scenarios they will really face.
- Build verification into the work. Require a second known channel for payment changes and access requests so verifying is the default rather than a favour.
- Remove friction from the safe path. If a control is painful people avoid it so fix the design until the secure option is also the convenient one.
- Rehearse under pressure. Run realistic phishing and vishing exercises and walk through a live incident on a tabletop so the habits hold when it is real.
- Measure and adjust. Track the behavioural signals covered above, share the trend openly and improve where the culture is weakest.
Do these consistently and culture stops being a poster on the wall. It becomes the way your organisation works which is the only kind of security that reaches every person you employ.



