Follow Laura Linkedin
Email Laura Email
Technology
Jun 29, 2022

The Importance of Creating a Cybersecurity Culture

Sponsored Content provided by Laura Rodgers - Business Development/Cybersecurity Compliance, North Carolina Military Business Center

Developing a secure AND compliant cybersecurity program is a daunting and complex task, and organizations often ask, “where should we start?”

After many years of working with quality management systems, I have come up with what I believe is the right answer to the question: start by developing a culture of cybersecurity.

Some of you may remember the time when the quality of products from Japan was very low. By the 1980s the quality of Japanese products far exceeded the quality of products from any other country – including the United States. Why? Japan listened to W. Edwards Deming and embedded quality into the culture of their organization. Quality became a value – not a department within an organization or something to be inspected into a product.

The same philosophy should be applied to cybersecurity. Below are a few tips for developing a cybersecurity culture:

  1. Tone at the top. Owners/leadership must understand and “buy in” to the importance of a secure and compliant cybersecurity program, then convey that buy in to their employees. Lip-service won’t work. You have to truly believe that implementing a cybersecurity program is the right thing to do and will provide benefits to the organization.
  2. Emphasize your commitment to cybersecurity by rewriting your organization’s vision and mission so they both include references to the importance of cybersecurity.
  3. Provide awareness and job-specific training. Just saying the organization needs a cybersecurity program isn’t enough. You must provide the tools employees need to be aware of cybersecurity threats as well as their responsibility for keeping the organization safe.
  4. Frequent communication is key. Changing an organization’s culture is disruptive, so employees need frequent reminders about what will change, and why. Employees need to be included in the culture change process.
  5. Make sure needed resources are available to implement the cybersecurity program. Developing a cybersecurity program is not cheap, but expecting a program to be developed without the necessary resources (people and money) available doesn’t show commitment to your cyber program. A line-item in the budget will do if you are currently strapped for cash.
  6. Manage the development of your cybersecurity program like you would any other project – establish a timeline, make status meetings a priority, and reward outstanding performance.

If you’re not sold on the value of a cybersecurity culture, keep in mind that a federal court denied, in part, a motion to dismiss a securities class action lawsuit against SolarWinds and members of its management team because the company claimed to have a culture of security when in fact they did not. The court found that employees were not aware of the password policy, had not received adequate cybersecurity training, and didn’t have an awareness of the company’s efforts regarding cybersecurity. 

Since creating a new company culture takes time, don’t wait – start developing a cybersecurity culture now!

Defense contractors in North Carolina that need help developing their cybersecurity programs should contact Laura Rodgers at rodgersl@ncmbc.us

Join The Discussion

Ico insights

INSIGHTS

SPONSORS' CONTENT
cape-fear-valley-health ryan-huttinger-do headshott

Leading with heart: Advancing cardiothoracic care and community at Cape Fear Valley Health

Ryan Huttinger, DO - Cardiothoracic Surgeon, Cape Fear Valley Health
fayetteville-state-university greg-mcelveen headshott

Innovation Pathways & Partnerships returns on Oct. 3

Greg McElveen - Assistant Vice Chancellor for Strategic Initiatives and Executive Director, FSU Research Corp,, Fayetteville State University
nc-military-business-center erin-ananian-gentile headshott

Forging the Fleet: Rebuilding America’s Submarine and Shipbuilding Workforce

Erin Ananian-Gentile - Federal Business Development, NC Military Business Center
Ico insights

INSIGHTS

SPONSORS' CONTENT
cape-fear-eye-associates cory-worrell headshott

CTAK (Corneal Tissue Addition for Keratoplasty): Groundbreaking Advancement in Keratoconus Treatment

Cory Worrell - Director of Marketing, Cape Fear Eye Associates
nc-military-business-center erin-ananian-gentile headshott

Forging the Fleet: Rebuilding America’s Submarine and Shipbuilding Workforce

Erin Ananian-Gentile - Federal Business Development, NC Military Business Center
fayetteville-state-university greg-mcelveen headshott

Innovation Pathways & Partnerships returns on Oct. 3

Greg McElveen - Assistant Vice Chancellor for Strategic Initiatives and Executive Director, FSU Research Corp,, Fayetteville State University

In The Current Issue

Thirty, purdy and sturdy

I have now completed three decades on Earth. And I don’t know how to feel about that. It’s one thing to be told you’re getting old by your great-aunt Gertrude, or to pass major life milestones like graduating from high school or college, but there’s


A toast to healthcare: Local heathcare safety net holds 'Toast of the Town' event to support critical fundraising push

For local nonprofit The CARE Clinic, financial sustainability depends entirely on private support—making the 25th annual Toast of the Town fundraising event on Sept. 18 a crucial component of the organization’s annual budget. Photo provided


Teeing up for success: The Bogey Brothers brings multi-sport simulators to Cameron

The Bogey Brothers, located in Cameron, N.C., has four multi-sport simulator bays that promise fun for all ages. Whether it’s your first time hitting a golf ball or you frequent the fairway, this venue offers a new way to experience the sport. In add