Culture as a Cybersecurity Variable

Cybersecurity depends on how people act when controls create friction or no one is watching. Boards need signals that security is treated as a shared operating responsibility, with clear expectations and consistent accountability.

Cyber risk often begins with ordinary human behavior. Boards need to ask whether the organization’s culture supports reporting, accountability, and disciplined action before pressure arrives.


The most common entry point for a cyber event isn’t a technology failure. It’s a human one.

An employee clicks a link in a phishing email. Someone uses a personal device on a corporate network. A contractor bypasses a control because it slows down a workflow. A team adopts a productivity tool that wasn’t reviewed for data exposure.

These aren’t exotic failure modes. They’re routine. And they happen in organizations with strong technical controls as often as in those without.

Cybersecurity is as much about culture as it is about technology. I’ve said this to many boards and I’ll keep saying it. It’s also true for management. The behaviors that create cyber risk don’t pause for board oversight. They happen in daily operations, shaped by how leadership sets expectations and holds people accountable.

Risk culture shows up in the behaviors people exhibit when no one is watching and when following protocol creates friction. It’s shaped by leadership example, by accountability structures, and by whether the organization treats security as a shared operating responsibility or as something IT manages on everyone else’s behalf.

Years ago, at a large multinational financial institution where I worked, cybersecurity training deadlines were enforced in a way that made expectations unmistakable. Miss the deadline, and you received a call from the Office of the CEO.

I’m pretty sure the CEO wasn’t reviewing the list of non-compliance personally, but he made sure someone in his office was. It sent a clear message about what mattered.

For us, as board directors, culture is harder to assess than technical controls. You can’t see it in a dashboard. But there are signals. Does the CISO describe a workforce that reports suspicious activity, or one that avoids reporting to stay out of trouble? Is security training treated as a compliance checkbox or as a functional capability? When a control is bypassed, is the response disciplinary or diagnostic?

Having built and governed risk cultures in organizations of different sizes and regulatory environments, I’ve seen that the ones that hold up under pressure share a few things: defined expectations, visible leadership commitment, and accountability that is proportionate and consistent.

A board that asks about culture, not just controls, is asking the right question.

About the author

Nancy Boehm

Nancy Boehm

Principal

I'm a global technology and risk executive and experienced board director. I help boards modernize safely by strengthening governance around cybersecurity, AI, and enterprise risk, so organizations can innovate while maintaining regulatory and stakeholder confidence.