Evo AU #209 - Cybersecurity Culture: The Missing Link in Most Cybersecurity Strategies
45m 1s
The podcast discusses the critical role of cybersecurity culture in organizational security, emphasizing that breaches often stem from human factors rather than technological shortcomings. Experts highlight that while tools and policies are essential, they fail if security feels obstructive or misaligned with how people work. A strong culture starts with leadership setting the tone and prioritizing security in plain language, ensuring it is integrated from the outset of projects to minimize friction. The panel stresses moving beyond tick-box compliance through continuous efforts like micro-learning, phishing simulations, and engaging sessions that address real-time threats. Measuring behavioral change remains challenging but can be approached via metrics like phishing score improvements and qualitative feedback. Ultimately, fostering a culture where security conversations are routine and incentivized helps mitigate risks and supports both safety and business agility.
Welcome to the Evolution Exchange Podcast, where technology meets leadership. This is a space for sharing fresh ideas, real experiences and practical insights from some of the markets most accomplished technology leaders. Our conversations aim to inspire, challenge and connect. Giving you perspectives you can take back into your own journey. These notes that you shared by our guests are their own and do not necessarily reflect those of their organisations. I'm Joel Hayward from Evolution Recruitment Australia. Today we're tackling something that's often talked about but rarely done well. Cybersecurity culture, the missing link in most cybersecurity strategies. Organisations invest heavily in tools, frameworks and controls. Yeah, breaches still happen. Not because the technology failed but because people worked around it, misunderstood it, ignored it under pressure. So today we're asking why the security controls break down in real world environments. How do we move beyond tick the box awareness programmes? And what does good cybersecurity culture actually look like in practice? Joining me today are four leaders who spent years operating at the sharp end of security, risk and technology. Artikuma, Cybersecurity programme manager and Zurich Kuvamor, Stuart McGraft, programme security architect and centre group, Stanley Chatteru, head of security and IT at Aurokin Group and Nathan Bowen-Wyden, head of product at DataCon. It's great to have you all on the show this morning guys. As far as we do, a quick round of introductions, just introduce who you are and what you do in a bit more detail. Stanley, we'd like to go first. Thanks, Joel. I'm Stan Sardore. I had IT and Cybersecurity for Aurokin Group based in Melbourne, being in tech for about 20 years now and managing IT and Cybersecurity for SME size businesses. Thank you. Stanley, Stuart. Hi, I'm Stuart. I've been doing this for nearly 30 years now. I'm working for centre group making sure all their security programmes are rolled out from an architectural point of view, but involving a lot more of the data, business making sure things have run smoothly and actual programmes align with business outcomes. Thank you, Stuart. I'll see. Hi, everyone. I'm Artie. I come from a background of product management across Australian financial services, but made a pivot into Dizary several years ago. I'm currently a Cybersecurity Program Manager and as part of my role, I also lead security awareness campaigns and security awareness work across our organisations. I'm a member of around 2000 staff. Glad to be here. Thank you, Artie. I'm Nathan. That's a lot of Lisa. Hi, everyone. Nathan, bottom of my name here. I'm the head of product for the managed services portfolio at DataCom. I've probably been in the industry coming up to 30 years also. In that time, I built security practices, delivered security programmes and done security and technology consulting around the world. Really? I keep Nathan. Certainly, a panel of experienced professionals on the call today, which is good. Let's set the context then. Most organisations don't fail at cybersecurity because they lack policies or tooling. They fail because security doesn't align with how people actually work. When controls feel obstructive, people find workarounds. When risk feels abstract, it gets deprioritised. And when security is owned by someone else, accountability quietly disappears. Before we talk, free and works or technology, as opposed we'll start with culture and Stanley your question to the panel makes sense to begin. If we gave your employees the most advanced security technology in the world, but the culture still prioritised speed over safety, would the business actually be any safer? Stanley, would you like to start us off? Yeah, thanks, Joel. So I often found that you can deploy the most expensive or best-empreed tooling, but it does not matter how many tools and how many systems and how many dashboards you're monitoring. Ultimately, it's a human element that plays a key role. So selling the importance of cybersecurity and for employees to actually understand the how or why. Why of cybersecurity is the key element of success of a security awareness program or to embed the cybersecurity culture within a business? And to me, the signal starts from the top. So the language used to write starting with the CEO down as to the importance of security. The challenge I've often found is security always adds a layer of friction. Security creates friction. And business is ultimately about a capitalistic business about making profits. So the security slow things down is how often people see it. So I would say that selling the wild to employees and making them understand that is a key part of success in cybersecurity awareness for staff. And the culture is determined by the language being used at the management level down. Really? Thanks, Sally. Did you have any thoughts on that? Yeah, I suppose you all agree with your question. I suppose for me is how do we best get around the leaders says, oh, can you just give me exemption to this one time while I'm rolling it out? Is probably the biggest challenge around that? How do you address that? How do you actually get that over that hill? And Arty from your perspective, who do you think actually sets the culture? Is it the size or is it the CEO? Is it the front line managers? What's your perspective? Yeah. I think it's a problem worth solving, but I don't know if anyone's got the perfect solution for this. The answer for me actually is everyone has to be involved. Right? So like if I sort of go back to the question that Stanley asked around the most advanced technology, etc, being in place, but the organization's prioritizing speed over sort of safety. So what does that look like? Like personally for me, and I'm sort of talking from probably conversations I have everyday in my role, the situation is very nuanced. I think it's about the context in which you're trying to get speed over security versus security over speed, etc. So context really matters. The important thing for me, certainly from the position I'm in, is that the conversations are actually happening. So you know, speed might be completely fine if the risk you're taking or what you're trying to protect is, you know, it's a lot of risk. It's not something that is going to cause a huge disruption if there's a problem. The conversation must happen though in plain language. I'm going to keep saying this today that, okay, this is what we're trying to do today. And we're going to do this really quickly because the stakes are high from a commercial perspective. However, the risk trade off here is that they might be a security problem in the context of XYZ. Now, if those conversations are actually not happening, of course, it needs to be happening at executive level, but I think even at individual manager level, individual contributor level, if the conversation's not happening, I see that as the cultural red flag. Because there's never going to be a perfect answer on, well, let's just slow down because security should always be considered. You might not have a business at the end of the day if you slow down and don't get your product out there or whatever it is. So I'm just trying to sort of give an extra layer here to say if the conversation's not happening, we've got a problem and we've got a cultural issue. Absolutely. And any further thoughts there? Yeah, it's an interesting one because I've worked with a number of different organizers organizations that are quite large and complex. And there is definitely a Stanley called out friction, but it usually results in slowness jumping through processes. And as you called up before, it leads to people trying to bypass processes. Sometimes that's not possible. But I do quite like the frame that Jonathan Smart applies to it from better, sooner, safer happier, which is the better your breaks, the faster you can go. So what Artie was talking about, I believe, is really you need to be thinking about security from the beginning of the program, rather than as an afterthought at the end. Because if you bring it in, it can be fairly seamless, as long as you've got the right kind of support and the right thinking coming in with the right security teams that aren't just saying no, they're trying to figure out how to mitigate the risk and make the thing happen. And you can kind of balance it. But that's again, like a cultural aspect, is a lot of security professionals unfortunately come from the background of, I must say, no to everything, rather than what's the value of this and how, like, what are the risks? So if you say with this, what's the threat modeling and how do we mitigate the threats? So I think it's like an end to end thing that needs to be involving everybody and they all need to know what art they need to play in the process. Yeah, brilliant. Nathan, where do you typically see culture clash the most? Is it engineering teams, operations, sales, executive level? Across the board, and it's become even more complicated at the moment with the rise of AI. So, you know, there's, you know, shadow AI everywhere. Everybody's using it even though it's, you know, potentially not a company endorsed product with a company endorsed controls around it. It's going to be virtually impossible to protect against kind of the use of those things. So again, doubles down on the importance of establishing the right culture and supporting behaviors that, you know, helps people navigate how to use these.
tools effectively while mitigating risk to the business. Brilliant. Thank you. Excellent. And Stanley, a great question to start as offshore. So culture is the operating system. Let's get specific on how you actually shift the behavior and answer your question to the panel. It's sort of two part question. Security awareness is often treated as a compliance exercise, annual training, fishing, sims, box tick. From your experience, how do organizations measure real behavioral change? And what actually works to reduce risky behavior beyond just awareness? What are you over to? Yeah, well, one thing I definitely know is that just taking the box is not going to give you a behavior change, right? Taking the box does achieve several things, maybe license to continue playing as a company or I don't know, meeting some stakeholders requirements. But I think as security professionals, I'm sure all of us know we definitely need to go deeper. In order to enact actual behavior culture shifts across our organization. So certainly from my side, what I will offer, and I hope this resonates is that, you know, you might have the compliance to the box, but you really need to grab that opportunity to go, okay, how do I actually sort of understand what are the risky behaviors that are going on in the company? And perhaps use the compliance opportunity to make a change. So certainly in my company, like everyone, we absolutely have the annual compliance training, take the box all good. But what is it that you do between that annual cycle that is going to shift the dial? So what do we do or what have I done? We regularly do things like lunch and lunch and lunch and sort of sessions to bring the workforce together to talk about things that are topical from a security perspective, right? Because, you know, you know, annual compliance training isn't going to necessarily be talking about what is the most recent or latest threat that is out there. It's such a dynamic landscape that we operate in. Most of you would be aware that in 2025, I was settling my world, the voice-based fishing attacks were dominating the airwaves with, you know, criminality from scattered spider, shiny hunters, leapses, whatever they called. I mean, I'm actually quite proud to say that we were able to actually, you know, stand up sessions very, very quickly to inform and educate our workforce with regards to sort of the threat, whether the tactics being used, folks that are on the course in the course centers and service desk, you know, teaching them to take a breath, you know, sort of park, trust at the door a little bit, and very importantly, you know, you know, reach out to the right people if anything sounded suspicious. Now, why am I talking about that example? Because, you know, taking a compliance box isn't going to necessarily sort of get us there, you know, security professionals, and the relationships and the connections we have with the executives as well as our business teams is where these sorts of meaningful conversations, well, the need for these meaningful conversations can be, can be created, and then you sort of have to go off and execute on those things. Now, I personally haven't figured out how to actually measure behavior change and I'm very interested to hear everyone's input on this, but I know one thing for sure is that compliance tick box is not going to get to get you the behavior change. It's the stuff you do on top of that, on a repeated basis that helps shift the dial. Yeah, absolutely. Thank you, Arty, and Stanley, any thoughts there on how to measure real behavior change and emerge it speaking? Thanks, Joel. And yeah, after you made some really good points there, and I think we all face common challenges in this space. What I've found is yes, you know, most companies both through this annual cycle of box-taking exercise, you've completed your cyber security awareness training that meets your compliance requirements. What I have found success over the last few years is micro learning. So instead of having this once-a-year exercise, we do forknightly, it could be a shocked video or a short article, and showing real world examples to staff to show, you know, what's a consequence of phishing exercise. And that's the best way to sell it. And getting the conversation started early, as was mentioned earlier in this forum, when you're planning for a project, get the security planning for that done from the beginning. And it shouldn't be after thought that's packed along the list, have you put your security lens over the project? So these are the things. How would I measure it? It's over a period of time. So you set your baseline to look at phishing is a common one that we all do. So to see that, okay, what's your phishing score now? And then six months of running this program has it improved. So that's the general measurement I would use. And also it's specific risks within a business. You know, every business will have some unique risk. And I define that and building some metrics around that would also help. So these are like few of the tactics that I've used. And yeah, as we mentioned, there's no, you know, simple pillar solution to this that solves all. But it's a combination of different tactics and, you know, and trying to find what works in a specific business. Yeah, fantastic. Nathan, what's your view on phishing simulations? You find them helpful, harmful, or depends on how they run? Yeah, so I have to be careful because I've been for the logistics. Product, so it's, so I do believe they work because they, when you run them well and do simulations, and there's a consequence of that people, you know, clicking on links that they shouldn't have, it kind of instills a bit more of an awareness or criticality in their thought around, you know, is there something that's, you know, real or not? But it needs to be surrounded with all of the training material to educate people on what this, you know, what a kind of phishing attempt looks like, or, you know, one of the other kind of channels that you could use as a way of kind of, you know, either attacking or getting, you know, information out of an environment. So phishing simulation only really covers one channel and because of these other channels, I think it's starting to lose some of its impact, but it's still a tool that's useful for doing, because it can help you give gets and quantifiable metrics about whether people are clicking on links that they shouldn't, but there's also other tools like you, you know, user entity, behavior, and analytics tools, which can help you understand different kind of behaviors. But I don't believe there's really any tools that give you the full visibility into how people are working and I don't believe they're really ever will be. So you need to look at what the minimal tooling you need in that space to kind of get some understanding, but you need to complement it with also a qualitative method. And that could be, you know, like what I already talked about in terms of some user engagement sessions where you're getting feedback and you're explaining some of the threats and sort of the attacks that are happening in the organization at the moment, you know, companies that I've worked with, you know, they've had state kind of based attackers trying to, you know, gain access because if, you know, good resources that they're protecting or other things. So the different types of attacks will vary between industry and the organization and what assets and other things that they have. And so it's really about kind of making people aware about who, you know, the value of the organizational assets and how, you know, how they need to be protected who might be attacking or trying to gain access to them or, you know, destroy them or whatever, so that you can have a realistic conversation about what actually could happen rather than hypothetical ones because there's an infinite spectrum of like ways that people can attack and it's getting more sophisticated and complex over time. And so it's to me, it's really just about getting down to what's the most pragmatic thing that you can do and there's usually some basic sort of stuff that will mitigate a lot of proportion of it. You can't do everything. Absolutely, absolutely. I know it's been fairly well covered, but it's been thought to what's the process. Yeah, of course. Yeah, it's a lot of different take on this and sort of leading into something Nathan mentioned before. We've been doing this as like Nathan near 30 years and we were the traditional boys, they're always saying no. And as we so evolve in this industry, we have become more people that we can have a conversation with actually have like a, as a sadge, that normal conversation. One thing we've recently done at the center group was rolled out bug crowd, which was the crowdsource things of vulnerability software, which I thought, yeah, this should be fairly benign sort of thing. But what it's shown to us is actually a different way of thinking and different way approach to way humans would actually it or hackers in theory would approach things. And I was thinking about this also how I was going to expand on this program. And my thinking is this is offering this to the internal staff saying, hey, to get to find some of our issues or risks. If I offered you a half day annual leave day or a pay bonus or some other incentive using that sort of financial carrot in dangling from someone, what systems or what ways can they think of that we may not be doing because we spent years studying our industry and followed many methodologies. But sometimes that lateral thinking does come from something like someone else who's on the front line doing something different. Actually, I've done this way and if I've never thought of doing it that way or actually you're right, that's actually a good way of doing things. Yeah, no?
Yeah, something that you just talked about just made me remember something that's really important, which is incentivization. So you can have incentives that, you know, support and encourage particular behaviors and you can have penalty incentives. And in one prior organization that I worked at, if you didn't do your compliance training, you basically didn't get a bonus. If you failed the fishing attempts too many times, you wouldn't get a bonus. So there was lots of penalties. There's, I've seen other organizations that have had more positive incentives like public praising from executives about, you know, being security conscious and a security champion for the organization. But if you want to drive, behavior change, those other things are incredibly important, not just the sort of tools and things that you used to measure. Yeah, I'll stick over there. Sorry, I just wanted to say, yes, absolutely, the positive incentives is, I just wanted to say it works. And we have, without giving too much data the way we talk about data as well, but we actually have a program where, you know, we stay away from punitive measures and punishments and you know, flip it on the head and go, well, you know, you might be clicking on fishing emails in the simulations. But if you're reporting on those things, you are actually going to go into a monthly draw or something like that to win a voucher. And we've been running something like that for a while now. And it's actually driving a lot of good positive engagement. I mean, good positive engagement, people that are actually running to the problem rather than sort of saying what is going on here. And I have actually seen that translate into healthier, more positive behaviors. So big ban of using the carrot rather than the stick with these things. Yeah, I think, I think that's very much how our industry needs to start moving towards is that we've always been synodied to people that say no. And why to change that image is that positive ring? What's been in our area? Absolutely. Now some great points there for sure. Fantastic. So we can measure shape and behavior at least to some degree for sure. So let's talk around the massive reality, which is workarounds and steering your question for the panel. Most breaches don't start with malicious intent. They start with a workaround. How do we design a culture where workarounds are detected early, surface safely and turn into bathroom outcomes instead of hidden risk? Take it away. Yeah. Yeah. So yeah, look, as the program I'll take at the moment, one of our jobs is about rolling out tools. And how do we roll out the tool successfully? It's not doing it just in the confines of our team. So one thing we very much tried on is we get champions and the business actually involved in a lot of the early testing. So we will go ahead and get a collection of people who understand technology a bit more. And they should give them the experience and say, okay, go and find the problem and tell us what you're experiencing. And so using that not just rely on purely on a technical or an abstract sort of testing model, actually getting people in the business to do the modeling and allowing the business to the freedom say, okay, look, if it breaks, it breaks. It's that's okay. And so giving a frictional environment where they have the certain autonomy to say, okay, I'm going to report this in a safe way. And through those mechanisms, we've actually made some quite vantage streams in that because we are getting that user input because we're not using just that technology lens. It's that human lens, that business lens, which the key to all security initiatives is getting that sponsorship because security only works when it's along with business. And the sooner you get the business involved and to the point earlier, the sooner security is involved in any of the programs, then the key to that success is that early stage. That's how we get around the workarounds. And if someone comes us with an exemption, so I want to get an exemption, my question is what, why did you need an exemption for what, what should use case that we're blocking and what we have when we addressed in our program, that means you need to work around. And so doing, taking that approach, flushes those things out. So people can report that to you sooner and quicker. And as a result, you can actually make your system more effective because you've actually taken the time to endorse the system. And to the point before we said about positive variance enforcement, that person thinks of the fact you've listened to what I've said and made a premium base on something I've said. So that engagement, that sort of feel of ownership gets higher as I see one more. Thank you, Stuart. Stanley, what's your view to you? You know, what you're, why do you think people create workarounds in the first place that are around time pressure, friction? Quite often it's time pressure because you want to get things done quickly. This process involved in coming and talking to the security team or IT teams internally and trying to find a solution can often take longer. So yeah, people find the quickest way to get the job done. I personally feel yes, tooling would help with detection of any anomalous behavior or the work around someone has done. But setting a psychological safety of a culture where you're not going to be punitive to anyone if they report it is, I think the key. I think that the team has been covered here just a few minutes ago. It's basically having that feeling that, you know, like if you know if I had to do something in a hurry or rush, I can come and talk to the team and understand that. And I've often seen that, you know, sometimes you can use some of these examples as a real case study and present it to the same as a good story of, you know, what happened, what did they do and how can we use this example to improve security? Really, thank you. You mentioned psychological safety there. What do you think psychological safety looks like in security? Yeah, look and maybe I can actually comment on this because I don't necessarily traditionally come from a security background, but I think it should be this concept of make it safe, make it a safe environment to speak up, right? So I might not be inside the security. I'm in some business based in product team or whatever. And if I'm getting friction because those security teams have put this nasty technical control in the way I'm working, I should feel free to speak up about it and explain why this is causing friction. And conversely, I shouldn't be looked upon as there's a person who's complaining all the time about our control, if that makes sense. And this is, I think this is actually one of the hardest things because I think all of us need to just in the organization park our egos or whatever it is at the door and actually come together and go, okay, what is the problem here? Right? There's a security control that's been put in because we are concerned about a particular risk and all of our threat modeling, whatever is saying that there's a problem here. And this is why we've got this control. But for the person who's trying to do their work, the control's not working and no one's bothered to actually explain to them, what is it that we're trying to protect and why this thing exists? So that person is not complaining, no one's listening and now they're doing the work around. So the culture apart for me is actually about people being able to have robust conversations like these where they might not agree on a problem to be solved or whatever it is. But the culture should be that the robust conversation should be encouraged so that people can actually understand each other. For me, that's what psychological safety looks like. I should be able to raise my concern on friction with the way I work without feeling like I'm going to get shamed for it. And conversely, whoever has put the control, I mean, I'm going to say security as a vertical should be ready to accept the feedback and then be able to explain hopefully in plain language on why the thing exists and perhaps take some feedback to go and maybe reduce the friction a little bit. Thanks, I need to. And later, what do you think a good learning loop looks like? How do you convert work around into a sort of improved controller process? It all comes down to communication, collaboration and knowledge. Like sometimes these work around the merge because they're not really the people that are designing a new system or product or technology. They're not really aware of all of the security standards controls and other things that need to be in place for them to execute into. If there was more knowledge up front or like, you know, blueprints or architectures supported architectures that were aware of, then they could design to that and then it would make it a bit more seamless and they maybe could avoid some of the work around. So there's a bit of a loop of like, you know, identifying the work around figuring out what the, you know, what changes to the architecture is communicating that out to the people that are actually implementing technology change into organizations that have an impact on security. And then also the depth of their protections and mechanisms because you could allow a work around, you know, if it's a non-critical system or there's other mitigations around it. So it's a bit of a difficult thing to kind of just say there's one answer because it depends on the context and the situation and the criticality of, you know, what the work around might expose or enable. So the first product teams, you know, will have a tech dev backlog where they're capturing things like that so that, you know, they can come back and address it later on because for companies that are launching new products, they need to get to market and test the value of it and then, you know, you'll typically see the security controls come in. So there's, you know, there is like a pattern of that feedback loop from client like through value to control. And I think, you know, for enterprise organizations, it's just really about thinking about how we institute those feedback loops so that people can, you know, provide the feedback in a safe way and then that gets actioned and the knowledge gets shared so that people can kind of consider that from there to doing something in future. Excellent guys. Well, I think that's very well covered as well.
really practical insights there. And obviously the threat landscape is changing very fast with AI. I suppose we'll finish on the last question and the human layer. And that's Nathan, your question. As deep fakes and AI voice cloning become more mainstream. Technical authentication is struggling to keep up. Does the future of security culture rely less on compliance and more on verification? Teaching humans to challenge what their eyes and ears are telling them. Take it away. Yeah, I guess I've got two young boys and like I'm just thinking through in my mind, how do I tell them what's real and what's not and even five, six, seven years ago, observing some fishing campaigns that were very, that was spearfishing and they were very sophisticated and like it was very difficult to tell even them that it was an external attack. So the fact that with AI, you can kind of generate people's voices and images. It's becoming even more complicated to detect those things. And I don't think the detection tools will ever really keep up. So to me, it feels like the only answer is really turning people into the detectors for the security organization and making sure at the edge where they're interacting with technologies and ecosystems and other people that they're thinking about what this means and whether they're present they're interacting with. In a team's call, it's actually real and the person that they're talking to, they're meant to be talking to. So we're going to have to create kind of new training programs that really help help people kind of understand these risks and what it means in, you know, probably see a few organizations in the news soon. Yeah, absolutely. It's funny. A colleague of mine was saying a couple of weeks ago he rang a plumber to come and fix an issue at the house and an AI assistant answered the phone when he called and he took him about two to three minutes of engaging with this assistant to realize it was AI. It was an actual person. So it's rapidly developing for sure. Stanley, any further thoughts there? This one is an interesting one because we have seen some real exploits in the last few years. I think the one that I don't know the specifics, but it was I think a issue with a bank in Hong Kong where it's a person. Yeah, so it was I think it was something to the tune of 10 million or something where they created the big portion of their CFO and a big organization often you don't, you know, interact with a senior staff member on a daily basis and yeah, they lost the significant sum of money there. So using that example, like I would approach I would take his targeted training for sensitive areas of business like finance to make sure that if a new shell request is being made, then they use more than one channel to verify to make sure that they're talking to the right person. His level of sophistication in the last few years is just mind boggling. What AI has done is it's made the task of faking, you know, a people's voices or even actual videos much simpler. What would I take in a panel of people or experts weeks or months to develop can be done in minutes. So yeah, it's scary and it's all we can do is just educate people off the dangers or the latest trends in sub-scams and yeah, and try to prevent it that way. Sure, if you've got ideas or tips on verification, habits should become standard. Do things. Simultonaton, I've got a young daughter and I'm not sure everyone's been seeing over Christmas period, but on Instagram there's this cat people dancing, moji that's going around and the moment my daughter saw when she went, that's AI. But to me, I think there is definitely an avenue to start teaching at Rhode Island. I wrote a paper about 10 years ago and how the key to that is getting the humans on that journey. And I think AI is another one on that where we have to start training from an early age, feeling people to start thinking about things. In the age now on misinformation, don't always trust what you see or read. Do your own verification. But to the point of validation, one thing that I've used in the past, which is a bit old school, but I think it's a great way of doing it, is having a pre-determined safety or password that is only known by handful of people. So the CFO knows that so if the CFO rings into the service this and rings into the account staff, the account staff are told, if the CFO calls for whatever reason, please make sure you verify this word or some where they use a saying in that way that they know that is only determined now. It's sharing information for email. You can't do it because we know emails can be hacked or they're sick. So working an old school method maybe writing a letter and just posting a letter to that CFO, posting a letter to someone else's business. So therefore, it's stored somewhere in a paper coffee that he has only seen on the desk, adding that extra layer, that extra layer of resistance. And that's probably the biggest challenge all this is adding every bit of resistance. That gives the chance for the person to sit down and is this actually the person who they say they are? Is the person making me ask the pay a $5 million transfer? Is this a limited request? Why is the CFO coming to me over? Why is he not going to my line manager or why is he going in that direction? Things like that. Giving people a moment of base, just think about that and that could be in the form of a simple text-based password to give that space. I'll tell you the thoughts there that in terms of how you sort of roll this out without creating any paralysis and teams that get scared to write. Yeah, no, I'm sort of going to say I agree with some of the that's sort of maybe going a bit old school here with regards to security. So like, I mean, on the personal side, I've got a small 10 year old daughter as well. But yeah, like we're looking to sort of maybe put a base, I don't know, it's like a safe word that we have in our family WhatsApp with grandparents and all of that just, you know, so everyone sort of knows, yeah, don't fold for that scam where someone's messaging their grandparents to say, I mean, just help, etc. But we'll see how this goes. Look, I think from a work perspective though, I have a slightly different take and like I completely respect the conversation around, you know, these AI has just changed the name of the game here with regards to security defense, etc. But if I use sort of email fishing as an example, so yes, absolutely true that attackers are using AI for very well crafted emails now with, you know, natural language and all of that in in the picture. And they sort of putting that out at scale and it's going to a new level. But on the defensive side, you know, we have good tools. We still have very good email defense tools and there's ongoing investments from an AI perspective into those tools as well. So, you know, slightly glass half full on this topic is that, you know, the, you know, fishing and all of that, the very, very dangerous, but they're, they only become dangerous if they slip through into the hands of the human at work. So I'm still quite interested in making sure the fundamentals that we do, you know, in traditional security awareness still holds true. We still need to educate our workforce around social engineering, maybe not trusting things so much, etc. And of course, the conversation about AI has to be part of that, but I don't want the AI stuff to sort of kind of eclipse the fundamental that we still need to make sure everyone knows and understands because that's still, I don't know if we've ever sought that problem, to be honest. So everything now needs to be done. Jocful life. Yeah, completely agree about the fundamentals being where the focus should be, because that will mitigate most of the, their risks. And I think it's also back to the old school, kind of thinking the people that have access to high value assets probably need to have more, rigorous controls, whether it's the special code that you share or other security controls around them, just to have an elevated level of protection around what they have access to or how you identify and authorize what they're trying to do, just to, again, like basic stuff, but it just brings it, it'll add a bit more friction to the executives and other important people in the organization, but again, like it's like balancing their risk versus, you know, what could potentially happen if people had an inverted access to things. So Nathan, sorry to throw out bonus question, IE, but if you could implement one new control to sort of counter deepfakes, what would it be? I'm sure there's going to be advances in, you know, the analysis and detection of deepfake produced things, but I think ultimately it just comes down to educating people to a bit more questioning around what they're consuming. And looking for like the discrepancies, like the other day, we were looking at a video worship, like a fake shark attack, and it looked very, very real, and I'm like, we're not wearing a pack of shoes.
where's all of the air coming from? So it's like with the older email attacks where there was discrepancies, we'll have I think a while with the dick where you'll be able to spot some little inconsistencies, but I'm sure that over time that will get eliminated and be seamless. So we're going to need to just get people going back to first principles and thinking through it probably. Brilliant. Excellent everyone. Well look I suppose we'll land the plane with a practical take away each then and that is what's one thing a business can do in the next 30 days to materially improve cybersecurity culture and perhaps what they should stop doing immediately as well if you've got any insights there. Stanley, would you like to give you also? Sure, I've had 30 days to implement one measure. I'll go to the safe and tried and tested measure. I'd probably run a gamified fishing campaign for 30 days. You know like three different curated or carefully crafted emails and have some metrics around how quickly and how good the reporting has been and with some incentives like coffee vouchers or lunch or something like that. So if I had 30 days that's probably the one that I would go with. So gamified fishing campaign. That's it. Thanks, Stanley. Arty. Look I think if there's one thing or one step organizations can take and my pick would be to drop drop the jargon, drop the compliance theatre, drop the risk theatre and start talking about things in plain language. I think I think a lot of the problems we're trying to solve when it comes to cybersecurity culture is because folks just don't understand each other. I think the more we talk about our risks and threats in plain language and that takes effort by the way and confirm the audience actually understands what is it that you're trying to protect from or what are we protecting? What are we protecting? I think the better the chances of actually making a difference in the organization. So let's drop the jargon, let's start talking in plain language. Love it. Thanks Arty. Stuart, any key takeaway from you sir? Yeah, I'm slightly too prone because I'd slightly cheeky too. In the respects that is do the magic genie say look to the organization send them out say look I'm in your genie I can grant you one security wish. What one security thing is your biggest challenge or problem and what and would you might want to make it appear? How would you make it here? And then we'll look at through that through that look at the kind of themes coming through and work out. These are the problems that any user experiencing. What can we do to make those systems go away? Is it the fact that we change passwords too much? Okay, can we look at password list? Is it too much MFA? Can we look at some sort of ring fencing around that sort of thing? Look what your biggest friction points are from the organization point of view not from a security point of view. Therefore you're instantly moving that land straight away to buying them buying into that culture, buying into that journey. And so as an organization you move forward because everyone has been put into how the security has moved forward not just the security team. Thank you Stuart. And lastly Nathan. One of the easiest things that I've seen work fairly repeatedly well across security and other demands in terms of culture changes actually forcing discussions. So as an example in some mining organizations that I had had the opportunity to work for at the beginning of every single meeting you have to do a safety show where because safety is such a critical important, critically important thing in their their organization and culture to make sure people don't have accidents and you know, dying of mind sight or whatever they spend a lot of time talking about you know a safety concern and how you can mitigate it. So a very simple way you can get started with instilling a security culture is from the top. Say for the next 30 days we're going to for in the five minutes of the beginning every every meeting we're going to have a security safety share where people you know maybe explain like a fishing attempt at DevSync or something that they've heard about or read about and what was done about it and what the impacts are and that just raises awareness of what security threats are out there and how they might be kind of used and what we can do to mitigate them. Really, Nathan and thank you everyone sharp and practical insights there for sure and that just about wraps up the those episode of the evolution exchange cybersecurity culture the missing link in most cybersecurity strategies a big thank you to our panel for sharing the experiences and perspectives and if you'd like to be a part of a future episode or suggest a topic shaping the future of technology and security then please do connect with me directly on LinkedIn. I'm Joel Hayward from Evolution recruitment Australia thank you for tuning in and we will see you all next time.
Podcast Summary
Key Points:
Cybersecurity culture is often the missing link in security strategies, as breaches frequently occur due to human behavior—like workarounds or ignoring protocols—rather than technological failures.
Effective culture requires leadership commitment, clear communication of security's importance, and integrating security considerations early in business processes to reduce friction and align with operational goals.
The podcast discusses the critical role of cybersecurity culture in organizational security, emphasizing that breaches often stem from human factors rather than technological shortcomings. Experts highlight that while tools and policies are essential, they fail if security feels obstructive or misaligned with how people work. A strong culture starts with leadership setting the tone and prioritizing security in plain language, ensuring it is integrated from the outset of projects to minimize friction.
The panel stresses moving beyond tick-box compliance through continuous efforts like micro-learning, phishing simulations, and engaging sessions that address real-time threats. Measuring behavioral change remains challenging but can be approached via metrics like phishing score improvements and qualitative feedback. Ultimately, fostering a culture where security conversations are routine and incentivized helps mitigate risks and supports both safety and business agility.
FAQs
Breaches frequently happen not because technology fails, but because people work around it, misunderstand it, or ignore it under pressure, highlighting the importance of human behavior in cybersecurity.
Organizations should supplement annual compliance training with continuous micro-learning, real-world examples, and regular engagement sessions to foster genuine understanding and behavioral change.
Leadership sets the tone from the top by prioritizing security in language and actions, ensuring accountability, and fostering conversations about risk trade-offs in plain language across all levels.
Security should be integrated from the start of projects, with teams focusing on risk mitigation rather than saying 'no,' and balancing safety with business speed through collaborative conversations.
Measure change by tracking metrics like phishing click rates over time, using user behavior analytics, and combining quantitative data with qualitative feedback from engagement sessions and risk-specific assessments.
Phishing simulations can be helpful when combined with education on recognizing threats, but they should be part of a broader strategy that includes other channels and real-world attack awareness.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.