Cyberplanz Cyber Culture Dashboard
Measuring Behaviour. Building Confidence. Strengthening Resilience.
Compliance tells you what the organisation has done. Culture tells you what your people will do.
The Cyberplanz Cyber Culture Dashboard provides Boards and executive teams with six practical measures for understanding whether cyber resilience is becoming embedded within their organisation.
The objective is not to achieve perfect scores.
It is to identify trends, encourage better conversations and provide Boards with greater visibility of the human factors influencing cyber and AI risk.
1. CONFIDENCE
Do our people know what to do?
Measure
Employee confidence in recognising and responding to cyber and AI-related risks.
Board should monitor:
If something didn't feel right tomorrow, would our people know what to do?
Suggested Indicator:
🟢 Strong | 🟠 Developing | 🔴 Attention Required
Current Status: __________
Trend: ↑ Improving | → Stable | ↓ Declining
2. REPORTING
Are our people speaking up?
Measure
The willingness of employees to report suspicious activity, mistakes, near misses and concerns.
Board should monitor:
More reporting can indicate greater awareness and trust.
Board Question
Do our people feel safe enough to say, "I think something might be wrong"?
Current Status: __________
Trend: ↑ Improving | → Stable | ↓ Declining
3. SPEED
How quickly do our people respond?
Measure
The time between someone recognising a potential cyber or AI-related issue and reporting it.
At Cyberplanz, we believe:
The Cyberplanz Five-Minute Rule™
The most important five minutes in any cyber incident are the five minutes after someone realises something might be wrong.
The faster concerns are reported, the greater the organisation's opportunity to investigate, contain and respond.
Board should monitor:
Are we creating a culture where people report first rather than wait and hope?
Current Status: __________
Trend: ↑ Improving | → Stable | ↓ Declining
4. ENGAGEMENT
Is cyber resilience part of everyday work?
Measure
How actively employees participate in building cyber and AI resilience.
Board should monitor:
Engagement measures participation.
Board Question
Are our people actively contributing to resilience—or simply completing mandatory training?
Current Status: __________
Trend: ↑ Improving | → Stable | ↓ Declining
5. LEADERSHIP
Are our leaders modelling the behaviours we expect?
Measure
The extent to which Boards, executives and managers visibly demonstrate and reinforce cyber and AI governance expectations.
Board should monitor:
If leaders bypass security controls, employees notice.
If leaders openly discuss cyber resilience, employees notice that too.
Board Question
Are our leaders demonstrating that cyber resilience is genuinely an organisational priority?
Current Status: __________
Trend: ↑ Improving | → Stable | ↓ Declining
6. LEARNING
Are we becoming stronger because of what happens?
Measure
The organisation's ability to learn from incidents, near misses, exercises and employee feedback.
Board should monitor:
It learns.
Board Question
What have we changed because of what we've learned?
Current Status: __________
Trend: ↑ Improving | → Stable | ↓ Declining
Compliance tells you what the organisation has done. Culture tells you what your people will do.
The Cyberplanz Cyber Culture Dashboard provides Boards and executive teams with six practical measures for understanding whether cyber resilience is becoming embedded within their organisation.
The objective is not to achieve perfect scores.
It is to identify trends, encourage better conversations and provide Boards with greater visibility of the human factors influencing cyber and AI risk.
1. CONFIDENCE
Do our people know what to do?
Measure
Employee confidence in recognising and responding to cyber and AI-related risks.
Board should monitor:
- Confidence recognising suspicious activity
- Confidence challenging unusual requests
- Knowledge of reporting procedures
- Understanding of responsible AI use
- Confidence asking for help
If something didn't feel right tomorrow, would our people know what to do?
Suggested Indicator:
🟢 Strong | 🟠 Developing | 🔴 Attention Required
Current Status: __________
Trend: ↑ Improving | → Stable | ↓ Declining
2. REPORTING
Are our people speaking up?
Measure
The willingness of employees to report suspicious activity, mistakes, near misses and concerns.
Board should monitor:
- Suspicious activity reports
- Near-miss reporting
- Cyber and AI concerns raised
- Employee willingness to report mistakes
- Quality of reporting channels
More reporting can indicate greater awareness and trust.
Board Question
Do our people feel safe enough to say, "I think something might be wrong"?
Current Status: __________
Trend: ↑ Improving | → Stable | ↓ Declining
3. SPEED
How quickly do our people respond?
Measure
The time between someone recognising a potential cyber or AI-related issue and reporting it.
At Cyberplanz, we believe:
The Cyberplanz Five-Minute Rule™
The most important five minutes in any cyber incident are the five minutes after someone realises something might be wrong.
The faster concerns are reported, the greater the organisation's opportunity to investigate, contain and respond.
Board should monitor:
- Average time to report
- Percentage of incidents reported promptly
- Delays caused by uncertainty or fear
- Reporting trends following awareness initiatives
Are we creating a culture where people report first rather than wait and hope?
Current Status: __________
Trend: ↑ Improving | → Stable | ↓ Declining
4. ENGAGEMENT
Is cyber resilience part of everyday work?
Measure
How actively employees participate in building cyber and AI resilience.
Board should monitor:
- Cyber Champion participation
- Team discussions
- Awareness programme engagement
- Questions raised by employees
- Responsible AI conversations
- Participation in simulations and exercises
Engagement measures participation.
Board Question
Are our people actively contributing to resilience—or simply completing mandatory training?
Current Status: __________
Trend: ↑ Improving | → Stable | ↓ Declining
5. LEADERSHIP
Are our leaders modelling the behaviours we expect?
Measure
The extent to which Boards, executives and managers visibly demonstrate and reinforce cyber and AI governance expectations.
Board should monitor:
- Leadership participation in cyber initiatives
- Board engagement with cyber and AI risk
- Manager-led discussions
- Leadership adherence to security policies
- Visible support for Cyber Champions
- Recognition of positive behaviours
If leaders bypass security controls, employees notice.
If leaders openly discuss cyber resilience, employees notice that too.
Board Question
Are our leaders demonstrating that cyber resilience is genuinely an organisational priority?
Current Status: __________
Trend: ↑ Improving | → Stable | ↓ Declining
6. LEARNING
Are we becoming stronger because of what happens?
Measure
The organisation's ability to learn from incidents, near misses, exercises and employee feedback.
Board should monitor:
- Lessons identified
- Actions implemented
- Near misses reviewed
- Policy or process improvements
- Lessons communicated to employees
- Recurring behavioural issues
It learns.
Board Question
What have we changed because of what we've learned?
Current Status: __________
Trend: ↑ Improving | → Stable | ↓ Declining
THE BOARD VIEW
|
Measure
Confidence Reporting Speed Engagement Leadership Learning |
Status
🟢 🟠 🔴 🟢 🟠 🔴 🟢 🟠 🔴 🟢 🟠 🔴 🟢 🟠 🔴 🟢 🟠 🔴 |
Trend
↑ → ↓ ↑ → ↓ ↑ → ↓ ↑ → ↓ ↑ → ↓ ↑ → ↓ |
Board Discussion
Do people know what to do? Do people feel safe speaking up? Are concerns reported quickly? Are people actively involved? Are leaders modelling expectations? Are lessons creating change? |
Three Questions for Every Board Meeting
Rather than asking only:
"Are we compliant?"
Boards should regularly ask:
1. What are our people telling us?
What concerns, questions, incidents and near misses are being reported?
2. What are our behaviours telling us?
Are reporting speed, confidence and engagement improving?
3. What have we changed?
What tangible improvements have resulted from incidents, exercises, employee feedback and lessons learned?
Don't Chase a Perfect Score
Cyber culture should not become another compliance exercise.
A healthy organisation may report more suspicious activity.
It may identify more near misses.
Employees may ask more questions.
These can all be positive indicators.
The Board should therefore focus on direction of travel, not simply absolute numbers.
Ask:
Are we improving?
Are people becoming more confident?
Are they reporting sooner?
Are leaders more engaged?
Are we learning faster?
The Outcome: Human Advantage
When all six measures strengthen together:
CONFIDENCE
People know what to do.
↓
REPORTING
People feel safe speaking up.
↓
SPEED
Concerns are raised quickly.
↓
ENGAGEMENT
Cyber resilience becomes everyone's responsibility.
↓
LEADERSHIP
Positive behaviours are reinforced from the top.
↓
LEARNING
The organisation continually becomes stronger.
↓
HUMAN ADVANTAGE
People move from being perceived as a cyber risk to becoming an active source of organisational resilience.
A Final Board Question
At your next Board meeting, don't simply ask:
"Have our people completed their cybersecurity training?"
Ask:
"What evidence do we have that our cyber culture is getting stronger?"
The answer will tell you far more about your organisation's resilience.
Cyberplanz
Cyber resilience isn't built by technology. It's built by leadership, enabled by governance, and delivered by people.
Helping Boards build secure, resilient and AI-ready organisations.
Download your copy here:
Your browser does not support viewing this document. Click here to download the document.