Your security problem is probably a people problem

Most organisations have the rules. What they need is behaviour. Here's why we treat security as a change programme, and what that means in practice.

You've got the policies. The procedures. The compliance requirements, frameworks, controls and technical solutions. On paper, it's all there.

Yet people still don't consistently understand what's expected of them, why it matters or what role they play in reducing risk. Sound familiar?

That gap is adoption: people actually taking the rules on board and acting on them. It's why we believe most organisations don't have a security problem. They have a human behaviour problem.

More reminders won't close the gap

Awareness for awareness' sake rarely changes what someone does. The objective is secure behaviour.

So security communication is a change programme rather than a communications campaign. That means culture change, behaviour design, habit formation and organisational adoption. Security succeeds when it becomes part of everyday decision-making instead of a separate compliance topic.

A launch is only the starting point. The real work is the adoption journey that follows, building habits until the change is anchored.

Begin with what people do

It's tempting to start with the message. Start with the behaviours you need instead. For example:

  • Report suspicious activity immediately

  • Protect confidential information

  • Challenge unknown visitors

  • Follow secure data handling practices

The behaviour is the goal and communications is the means to change it.

Principles

Having worked in the compliance communications space for two decades, we know a thing or two about what works and what doesn't. Boiling it down to three principles:

#1 Policies fade while stories stick.

People rarely remember policies, but they remember stories.

That's why we build a core story before any campaign goes live.

It answers four questions: Why does security matter? Why now? Why should employees care? And what role does every employee play?

#2 Fear gets attention and engagement builds habits.

Fear is a familiar shortcut in security. We'd rather make security relevant, relatable, human and sometimes even enjoyable.

In plain terms, engagement means people want to take part, so the behaviours start to feel like their own.

#3 No one cares if its one kind of security or another

Physical, information and cyber security often reach employees as separate topics.

Whenever possible we recoomend integrate them into one coherent employee experience. To the person at the front desk or the laptop, it's all just security.

From rules to routines: how we work

We help organisations turn security requirements into secure behaviours. We combine behavioural science, storytelling, change communications and employee experience design, bringing strategic thinking with creative execution to build security cultures that people understand, engage with and act upon. It's a human-first way of working.

So, where are you today?

Which behaviours do you need? Which ones are you seeing? And what's standing in between?

If those questions feel worth answering, book a 2 hour workshop to audit current security setups and build a stronger people approach.

Next
Next

Open Talks: The conversations behind meaningful change