Creating a Just Culture: Why Employees Must Feel Safe Reporting Cyber Mistakes Imagine this scenario.
An employee receives an email that appears to come from a trusted supplier. Everything looks legitimate. The branding is correct. The language is professional. The request seems routine. Without realising it, they click a link and enter their credentials. Within seconds, they suspect something isn't right. Now they face a decision. Do they report it immediately? Or do they hope nobody notices? That decision may determine whether the organisation experiences a minor security event—or a major cyber incident. The greatest cyber risk is often not the mistake itself. It is the delay in reporting it. We Are All Human Every employee makes mistakes. Directors make mistakes. CEOs make mistakes. IT professionals make mistakes. Cybersecurity specialists make mistakes. Even experienced security professionals occasionally click suspicious links or overlook warning signs. Cybercriminals understand this. Modern cyber attacks are no longer crude or obvious. They use Artificial Intelligence. They research social media. They impersonate trusted colleagues. They exploit urgency, curiosity and human emotion. Their objective is not to defeat technology. It is to exploit perfectly normal human behaviour. Organisations should not expect perfection. They should expect humanity. The Cost of Silence In many organisations, employees hesitate to report cyber mistakes because they fear:
Unfortunately, they can significantly increase organisational risk. An email reported within five minutes may affect one employee. The same email reported six hours later may affect hundreds. Time matters. The sooner an organisation knows about an incident, the more options it has to contain it. What Is a Just Culture? A Just Culture recognises an important truth. People should not be punished for making honest mistakes. Instead, organisations should seek to understand: What happened? Why did it happen? How can we reduce the likelihood of it happening again? A Just Culture does not remove accountability. Deliberate misconduct, reckless behaviour and intentional policy violations still require appropriate action. However, honest mistakes become opportunities for learning rather than occasions for blame. High-performing industries such as aviation and healthcare have embraced this approach for decades because they understand that learning depends on openness. Cybersecurity should be no different. Fear Is the Enemy of Resilience Many organisations invest heavily in security technology while unintentionally creating cultures where employees fear speaking up. This creates a dangerous contradiction. Leaders ask employees to report incidents immediately. Employees worry they will be criticised if they do. The result is predictable. Problems remain hidden. Opportunities to contain incidents are lost. Resilience suffers. Trust is built when people believe they can admit mistakes without fear of unfair consequences. Boards Set the Tone Culture starts in the boardroom. Boards influence organisational behaviour through the questions they ask, the behaviours they recognise and the values they reinforce. Directors should ask:
It is to ensure mistakes become learning opportunities. Managers Shape Everyday Behaviour While Boards establish expectations, managers influence daily culture. Employees watch how leaders respond when something goes wrong. If the first response is: "Who made this mistake?" Employees quickly learn to remain silent. If the response becomes: "What can we learn from this?" The conversation changes completely. Managers should thank employees for reporting concerns. Recognise honesty. Focus on solutions. Celebrate transparency. People repeat behaviours that are acknowledged and valued. Shadow AI Makes Trust Even More Important Artificial Intelligence has introduced new reporting challenges. Imagine an employee accidentally uploads confidential information into a public AI platform. Will they immediately report it? Or will they hope nobody notices? As AI becomes more common, organisations will inevitably experience accidental misuse. The organisations that respond most effectively will be those where employees feel safe admitting what happened. AI governance depends as much on culture as it does on policy. Near Misses Are Valuable Intelligence One of the most overlooked sources of organisational learning is the cyber near miss. Examples include:
Rather than asking, "Who was responsible?" Leaders should ask, "What can this teach us?" Near misses often reveal weaknesses before they become major incidents. Building a Reporting Culture Creating a Just Culture requires deliberate effort. Organisations should:
Cyber Champions Can Help Cyber Champions play an important role in building trust. Because they work within individual teams, colleagues often feel more comfortable discussing concerns with them than approaching IT directly. Cyber Champions encourage conversations. Answer questions. Support colleagues. Promote responsible AI use. Most importantly, they help create an environment where seeking advice becomes normal rather than something to avoid. Trust Is a Competitive Advantage Customers trust organisations that respond openly to incidents. Employees trust leaders who support learning. Investors trust Boards that demonstrate strong governance. Trust is built long before an incident occurs. It is built every time an employee feels confident enough to say: "I think I've made a mistake." Without fear. Without blame. With confidence that the organisation will help solve the problem. The Future Belongs to Learning Organisations Technology will continue to improve. Artificial Intelligence will continue to evolve. Cyber threats will become even more sophisticated. The organisations that remain resilient will not be those with the most advanced technology alone. They will be those where people feel trusted. Where leaders encourage openness. Where reporting is recognised as a strength rather than a weakness. Because in cybersecurity, silence is often far more dangerous than mistakes. The most resilient organisations understand that culture is not simply another security control. It is the foundation upon which every other control depends. Creating a Just Culture is not about accepting failure. It is about creating an organisation that learns faster, responds sooner, and becomes stronger because its people are confident enough to speak up. In today's digital world, that may be one of the greatest competitive advantages any organisation can build.
0 Comments
Leave a Reply. |
AuthorPatrick – Founder of Cyberplanz | Business Strategist | Cyber Governance Advocate Archives
August 2026
Categories |
RSS Feed