How Boards Should Measure Cyber Culture (Not Just Compliance) A 100% cybersecurity training completion rate does not mean you have a cyber-aware organisation.
It means everyone completed the training. Those are two very different things. For years, Boards have been presented with cybersecurity dashboards containing reassuring numbers. Training completion: 98%. Policies acknowledged: 100%. Phishing simulation failure rate: 4%. Critical patches completed: 97%. These metrics have value. They provide evidence that important activities are taking place. But they don't necessarily tell a Board whether people will make good decisions when confronted with a real cyber threat. They don't tell you whether an employee will challenge an unusual payment request. Whether someone will question an AI-generated answer before acting on it. Whether a manager will report a potential data breach immediately. Or whether an employee who accidentally clicks a malicious link will feel safe enough to tell someone within five minutes. Those behaviours are influenced by something much harder to measure. Culture. And if Boards want to understand how cyber resilient their organisations really are, they need to start measuring it. Compliance Matters—But It Isn't the Destination Let's be clear. Compliance is important. Policies matter. Training matters. Technical controls matter. Regulatory requirements matter. The problem occurs when organisations mistake evidence of compliance for evidence of resilience. Consider two organisations. Both have 100% cybersecurity training completion. In the first organisation, employees rarely discuss cybersecurity, hesitate to report mistakes, don't understand the organisation's AI policy, and assume security belongs to IT. In the second, employees regularly report suspicious activity, managers discuss cyber risks with their teams, Cyber Champions encourage questions, and staff feel confident challenging unusual requests. On a compliance dashboard, these organisations may look almost identical. Culturally, they are worlds apart. Which organisation would you rather lead during a cyber incident? What Is Cyber Culture? Cyber culture is the collective set of behaviours, attitudes, beliefs and expectations that influence how people respond to cyber and AI risks. It answers questions such as: Do people think before they click? Do they challenge unusual requests? Do they understand why security matters? Do they know how to use AI responsibly? Do they feel safe reporting mistakes? Do managers reinforce good cyber behaviours? Does leadership demonstrate that cybersecurity matters? Culture is what happens when nobody is checking whether the policy is being followed. Boards Need to Measure Behaviour, Not Just Activity Traditional cyber metrics often measure activity. How many people completed training? How many phishing simulations were sent? How many policies were acknowledged? Culture metrics should go further. They should help Boards understand how people actually behave. For example: 1. Reporting Rates How many suspicious emails, unusual requests, mistakes and potential incidents are employees reporting? Interestingly, an increase in reporting can be a positive sign. A Board looking purely at incident numbers might see more reports and conclude that risk is increasing. A mature Board might ask whether employees have simply become better at recognising and reporting concerns. Context matters. 2. Time to Report This may be one of the most valuable human-centric cyber metrics an organisation can measure. How long does it take between someone noticing something unusual and reporting it? At Cyberplanz, we believe: The most important five minutes in any cyber incident are the five minutes after someone realises something might be wrong. If employees report concerns quickly, incident response teams have more opportunities to contain potential damage. If employees wait because they fear blame, embarrassment or disciplinary consequences, small incidents can become much larger ones. Boards should therefore consider time to report alongside traditional technical metrics. 3. Employee Confidence Ask employees simple questions. Do you know how to report a cyber concern? Would you feel comfortable reporting a mistake? Do you know which AI tools you are permitted to use? Would you challenge an unusual request from a senior executive? Do you understand your role during a cyber incident? These questions reveal far more about organisational resilience than training completion alone. 4. Leadership Participation Cyber culture is heavily influenced by what leaders do. Boards should ask: Are executives completing the same awareness activities expected of employees? Do managers regularly discuss cyber and AI risks? Are leaders following security policies themselves? Are cyber incidents and near misses discussed openly? When leaders bypass controls because they are inconvenient, employees notice. Culture follows behaviour. 5. Near-Miss Reporting Near misses are one of the richest sources of information available to an organisation. A finance employee questions an unusual invoice before payment. An employee nearly uploads confidential information into an unapproved AI platform but checks first. Someone receives a convincing deepfake call supposedly from an executive and verifies it independently. Nothing bad happened. But something valuable happened. The organisation learned. Boards should encourage near-miss reporting because it provides insight into emerging threats before they become incidents. Measure the Questions People Ask There is another cultural indicator that rarely appears on cybersecurity dashboards. Questions. Are employees asking: "Is this AI tool approved?" "Can I share this information?" "Does this email look right?" "Should we verify this payment request?" "Who should I report this to?" Questions demonstrate engagement. Silence doesn't necessarily demonstrate security. Sometimes it demonstrates uncertainty. A healthy cyber culture encourages curiosity. Don't Turn Phishing Simulations Into Punishment Phishing simulations can provide useful insight. But they can also damage culture when handled badly. If employees who click simulated phishing links are publicly embarrassed, punished or repeatedly labelled as security risks, the organisation may unintentionally teach people something dangerous: Don't admit mistakes. The objective of simulations should be learning. Boards should therefore look beyond click rates and ask: Did reporting increase? Did people recognise the warning signs? Did teams discuss what happened? Did behaviours improve over time? A phishing simulation should create learning, not fear. AI Governance Needs Cultural Metrics Too As Artificial Intelligence becomes embedded across organisations, Boards need visibility into AI culture as well as cyber culture. Traditional compliance measures might tell you whether an AI policy exists. Cultural measures tell you whether anyone understands it. Boards should ask:
Cyber Champions Provide Valuable Cultural Intelligence Cyber Champions can provide Boards and leadership teams with insights that dashboards often miss. Because Champions operate within departments, they hear the questions people ask. They see where policies create friction. They identify emerging AI usage. They recognise where employees lack confidence. And they can highlight positive behaviours worth reinforcing. This creates a valuable feedback loop: Board → Leadership → Cyber Champions → Employees → Cyber Champions → Leadership → Board Good governance should not simply flow downward. Insight must flow upward. Build a Board Cyber Culture Dashboard Rather than presenting Boards with dozens of technical metrics, organisations could develop a simple Cyber Culture Dashboard. For example: Employee confidence in reporting cyber concerns Average time to report potential incidents Suspicious activity reporting trends Near-miss reporting Cyber Champion engagement Leadership participation AI governance awareness Employee confidence challenging unusual requests Lessons implemented following incidents The objective is not to create another complicated reporting exercise. It is to give Directors a clearer picture of whether secure behaviours are becoming embedded across the organisation. Look for Trends, Not Perfect Scores Culture cannot be reduced to a single percentage. Nor should organisations aim for artificial perfection. A healthy cyber culture may actually produce more reported incidents, more questions and more near misses because employees are increasingly engaged. Boards should therefore look for trends. Is reporting becoming faster? Is employee confidence increasing? Are people asking more questions? Are lessons being implemented? Are departments discussing cyber and AI risks more frequently? Is leadership becoming more visible? These trends tell a story. And that story matters more than a single score. The Questions Boards Should Ask At the next Board meeting, instead of simply asking: "Has everyone completed their cybersecurity training?" Try asking: "Do our people know what good cyber behaviour looks like?" Instead of: "How many employees failed the phishing test?" Ask: "How quickly did people recognise and report it?" Instead of: "Do we have an AI policy?" Ask: "Do our people understand how to use AI responsibly?" Instead of: "How many cyber incidents did we have?" Ask: "What did we learn from them, and what changed as a result?" Different questions create different conversations. Different conversations create different behaviours. And behaviours shape culture. What Gets Measured Gets Discussed Boards influence organisations through the questions they ask and the measures they prioritise. If the Board focuses exclusively on compliance, management will naturally focus on compliance. If the Board asks about behaviours, confidence, trust, reporting and learning, those things become organisational priorities too. This does not mean abandoning traditional cybersecurity metrics. It means complementing them with human metrics. Because technology can tell you what your systems are doing. Compliance can tell you whether your processes are being followed. But culture tells you what your people are likely to do when something unexpected happens. And that is when resilience matters most. From Compliance to Capability The most cyber-resilient organisations will not necessarily be those with the highest training completion rates. They will be the organisations where people: Recognise unusual behaviour. Challenge assumptions. Ask questions. Use AI responsibly. Report concerns quickly. Learn from mistakes. And feel empowered to protect the organisation. That is why Boards must move beyond asking whether the organisation is compliant. They need to understand whether the organisation is capable. Because ultimately: Compliance tells you what the organisation has done. Culture tells you what your people will do. And when the next cyber incident occurs, it is what people do that can make all the difference. Cyber resilience isn't built by technology. It's built by leadership, enabled by governance, and delivered by people.
0 Comments
Leave a Reply. |
AuthorPatrick – Founder of Cyberplanz | Business Strategist | Cyber Governance Advocate Archives
September 2026
Categories |
RSS Feed