top of page
Episode thumbnail: Cultivating Security Culture across the Enterprise - with Daisy Wong

Cultivating Security Culture across the Enterprise - with Daisy Wong

In a world where cyber risk is now a boardroom issue, the oft-repeated mantra that “security is everyone’s responsibility” has never been more relevant — yet it is frequently misunderstood in practice. In a this episode of the Enterprise Tech Talk podcast, Saumitra Kalikar had the opportunity to host Daisy Wong, Head of Security Culture and Awareness at Medibank, for a rich and candid discussion on what it truly means to cultivate security culture across an enterprise.


The conversation went beyond traditional notions of compliance training and explored how organisations can meaningfully shape behaviour, build psychological safety, and align security awareness with real business risk.


From Technology to People: Reframing Security

Daisy’s own career journey sets the tone for the discussion. Coming from a marketing background, she did not enter cybersecurity through a technical pathway. Instead, her early work in penetration testing at a major Australian bank positioned her as a translator — bridging highly technical security findings with business risk in language executives could understand. This experience ultimately led her to specialise in security culture and awareness.


Her core insight is simple yet profound: cybersecurity is not just about technology — it is fundamentally about people, processes, and behaviour.


While organisations invest heavily in technical controls, the “human layer” often remains underdeveloped. Daisy challenges the industry’s common framing that “humans are the weakest link,” arguing instead that people should be empowered to be “politely paranoid” — alert, curious, and confident in reporting potential risks without fear of blame.


Beyond Checkbox Training: Moving from Compliance to Culture

A central theme of the discussion was the evolution of security awareness from compliance-driven training to genuine culture-building.


Historically, many organisations treated security awareness as an annual regulatory requirement — a mandatory e-learning module completed once a year. While necessary, this approach does little to change behaviour.


Daisy outlined a maturity progression:


Compliance — ensuring mandatory training completion.


Awareness — communicating threats and risks in more engaging ways.


Culture — embedding security into everyday decision-making and behaviour.


She emphasised that effective security awareness must be relevant, relatable, and contextual. Employees are far more receptive when they understand how security practices protect not only the organisation, but also their personal lives, families, and communities.


Tailoring Security Awareness to Real Enterprise Risk

One-size-fits-all training is insufficient. Daisy highlighted the importance of aligning awareness programs with actual threat data, working closely with Security Operations teams to understand:


Which employees are most frequently targeted?


What tactics are attackers using?


Where are the organisation’s real vulnerabilities?


Equally important is tailoring messaging to different cohorts. For example, finance teams may respond strongly to examples of CEO impersonation scams, while clinical staff may better relate to real-world incidents where cyberattacks impacted patient safety. Storytelling, rather than instruction, is the most effective tool for engagement.


How Do You Measure Security Culture?

Measuring the impact of security culture is inherently challenging, but Daisy outlined several meaningful indicators:


Baseline assessments before launching programs.


Phishing reporting rates (more important than click rates).


Increase in reported security incidents — a positive sign of awareness, not failure.


Employee confidence surveys regarding risk identification and reporting.


Engagement metrics, such as attendance at security events and participation in cyber champion programs.


For technical teams, more concrete metrics — such as reductions in code vulnerabilities — can also be tracked over time.


Executive Sponsorship: The Critical Enabler

Security culture cannot be built from the bottom up alone. Strong executive sponsorship is essential.


Daisy shared a powerful example of a CEO who openly admitted to falling for a phishing email in a town hall meeting. This transparency signalled to employees that mistakes are human — and that reporting incidents would not lead to punishment. This kind of leadership is instrumental in fostering psychological safety and trust.


Managing Change and Resistance

Resistance to security controls often stems from a lack of understanding. Daisy stressed the importance of explaining the “why” behind security policies, rather than simply dictating rules.


Equally important is providing practical alternatives when restricting behaviour. If employees are told they can no longer use personal email for work, they must be given a secure, workable alternative — otherwise they will create risky workarounds.


The Role of Technology in Security Awareness

While security culture is fundamentally human-centred, technology plays an enabling role. Daisy pointed to emerging tools such as:


Voice-based phishing simulations.


Human risk management platforms with executive dashboards.


AI-assisted content creation for awareness videos.


These tools can help scale programs, visualise risk for executives, and keep training materials fresh and relevant.


Key Lessons for Organisations

As the conversation concluded, Daisy offered three practical takeaways:


Be patient — cultural change takes time.


Prioritise high-risk groups first rather than spreading resources too thin.


Do fewer things well — depth matters more than breadth.


Final Reflections

This discussion reinforced a critical reality: cybersecurity is no longer solely a technical domain — it is a leadership, cultural, and organisational challenge.


As enterprises continue to digitise, adopt AI, and expand their ecosystems of partners and vendors, building a resilient security culture will be just as important as deploying the latest technical controls.


Cultivating security culture is not a program — it is an ongoing journey.

Episode Transcript

FULL TRANSCRIPT


This transcript is based on the episode’s English auto-captions and has been formatted for readability. Please allow for occasional transcription errors in names, acronyms and specialised terms.


[00:00:00]

But how can you create a culture where your employees are empowered to be politely paranoid? That's one thing to really help the board and executives understand their own security. I think it's also really important to help them understand [music] the threat landscape. >> This is only about bringing their sake ops as as a capability or or is it how we culturally change the behavior of the engineers. >> So I think that's why the [music] industry has now been moved shifted into culture. There's a time and place of compliance, but I think when you move into awareness and true culture change and building, it's going to take time. [music] Hello and welcome to the enterprise tech talk. I am your host Sumitra Kalikar. The topic of today's conversation is cultivating security culture across the enterprise. Now we all have heard the slogan that security is everyone's business. But what does that mean in practice? How organizations should approach implementing a successful security awareness program across the enterprise?


[00:01:16]

How the effectiveness of security culture should be measured? And what is the role for senior executives in cultivating that culture? To discuss all these points and more, I have with me today Daisy Wong. She is the head of security culture and awareness at Medibank. Daisy, welcome to the broadcast. >> Thank you so much for having me. I'm super excited. >> So Daisy, before we get into details, it will be good to just give our audience a brief overview of your professional career, how you got into security industry because I gather you didn't start your career in technology. Is that correct? Yeah. No, you're absolutely right. So, I actually did marketing at uni. Um, I didn't even know what like I didn't even think of entering the techn industry, let alone cyber security. Um, so I was just kind of by chance that I got into my first role was, you know, at IBM as a graduate. So, that was my first foray into technology and then I moved over to one of Australia's largest banks in their penetration testing team. and I'd landed into the pen testing team like what is a penetration test? What does it mean? Um and that was a very very technical side of the cyber, you know, world, right? Uh and my role was to translate and really talk to the business and talk to the users of what this the results of the penetration test meant. Um so when we talk about pentest, we're talking about, you know, your testing systems, applications that obviously end up going to your customers and end users. Uh, and while you do that, you need to, you know, make sure you fix all the vulnerabilities, issues, bugs, and all that. Um, and so the team was really technical, and because I wasn't, I think it actually was my superpower because I was able to translate really technical concepts into just normal everyday language, but more importantly, I was able to translate it into business risk because people don't understand security risks, but people understand dollar figures, reputational damage, and all that. Um, so I did that for a few years and then someone said to me something about security culture and awareness and I'm like, "What's that?"


[00:03:21]

And they're like, "Well, it's kind of education. It's kind of training, but you can also use a lot of your marketing skills." So I like to think of it as my role now is to market and sell security to our employees. Um, so that's currently my remit, but hopefully one day I would love to do customers as well. Um so I did the bank for a few years then I went into Victorian government. So I managed the security culture and awareness for the whole of Victorian government back then 3 four years ago. It was nine departments you know multiple entities and and agencies. Um and so I kind of set the strategy and the tone from the top. Uh and then I moved over to one of Australia's largest loyalty programs flybys. I was there doing a very similar role as I am here at Medibank. Did that for about two and a half years and I moved um yeah about a year and a half ago. So that's kind of how I got into cyber. like yeah I sort of fell into it but obviously I had a bit of an interest um and it gives me no like yeah um what what gives me the most joy is when I'm able to explain like I said really complicated comp um concepts and risks to people who don't understand and in turn helping them better protect themselves that is like my goal in this law >> yeah that's a really interesting journey um and um I was doing some research in preparation for this discussion today and what I noted was uh this discipline about security awareness function >> that that is not very common across Australian businesses is definitely there in regulatory industry uh but that true in the big organizations like big banks and of course med bank etc. So for the benefit of our audience maybe we can start that as as a first question as to if you can provide an overview of what is the function about and you being the head of that function what is your responsibility. [snorts] >> Yeah 100%. So I think when a lot of people about sec think about security obviously think you know the media depiction of it right hackers dark room monitor hacking into your systems taking your data exploiting you all that. So that's kind of on an individual level but obviously you scale up right the the larger your organization the larger the risk. Um so I think when it comes to security people always think uh protecting technology or fighting against you know the cyber criminals from a technical point of view right but then you I think we often forget it's a people process technology >> right so I think the people are often left behind so processes I think of governance risk and compliance and there's a lot of um regulatory requirements for you to improve your process have a policy implement and bullet, right? So, that's a process side of things. Technology, there's always new technologies and you always need to secure it. So, perfect example, um I don't think this word will will ever go out of fashion anytime soon. AI.


[00:06:27]

>> So, when AI exploded, we were all trying to secure it, right? To make sure your employees don't, you know, just put personal, you know, company data and confidential information into chat GPT. So, then that's when the formation of co-pilot, right? So in that kind of I feel like that is very much the technical controls how you secure a technical environment right to protect from security risk but then what about your people >> so you know as much as I think AI is great and obviously we've heard a lot about agentic AI and you know a lot of big organizations are now you know making certain roles redundant. Um, last time I checked, we're not replacing everyone with AI yet, and I don't think it ever will. I think, you know, how we did things, I wasn't born, I wasn't involved in it, but I'm sure we used to do things differently. The internet came, so now we do things differently like this. You and I, we do a podcast. I'm, you know, at home, you're at your home. We don't need to be in the same room, right? So, I think we will we we will still do the same kind of work, but it'll look and feel different.


[00:07:33]

So my role heading up the security culture and awareness is all about the people when it comes to the people process technology and it's all about the employees. So because um I I don't like this saying I don't know if you've looked into this um it's very common in my industry but they always say humans are your weakest link. People are your weakest link. >> Um it is true. You can't patch people. >> It's true. You cannot update your iOS. Right. I can't flick a button and have to upgrade your iOS and fix all the security patches. So I think this is when culture and behavior comes in. >> So I think if you go to different c like countries and their cultures, you'll see it's very different. So the Japanese are very renowned to be very strict with their rules. They all line up because that's the culture they've been instilled in them and taught from a very young age. Um, I'm Chinese, so when you go to someone's house, you always take your shoes off. So, think of that. Hold that concept and think about that from a cyber security perspective. How do you create a culture where your employees I stole this from my friend um Rachel Tobach, but how can you create a culture where your employees are empowered to be politely paranoid?


[00:08:51]

>> Do you know what I mean? Like they question. So, you know, they don't just click on every email they see, every link they see. How do you empower and teach your employees that if they work in finance or accounts payable and invoice comes through, they shouldn't question it? >> But what if they have a gut feeling that something doesn't feel right, >> right? How do you help them? But not only that, they also need to be so first of all, they need to be psychologically safe to be able to speak up, but they also need to learn where to go. >> Yeah. >> Um, so yeah. So I think that's kind of Yeah. So, so to sum it up for your audience to help them understand, I think it's really um the people side of the people process technology. It's really helping our employees understand, identify and report security risks and threats to better protect the organization's data systems and in turn your customer um and patients um information as well.


[00:09:52]

>> Yeah. Yeah. One thing I want to unpack u just building on what you said is um typ typically when people think of security compliance first thing comes to mind is those once in a year or once in six month security training um programs right you >> modules etc and that's what we typically people associate uh when it comes to security awareness right and that is not that is definitely not we are talking about gear. Yeah. Right. Uh >> yeah, 100%. >> So how organizations in your view should shift their their approach to this from just stick in the box kind of training awareness program to aligning security awareness to real to their real enterprise risks, >> Yeah. >> Yeah. I think that starts with um I I think you know the way security culture and awareness formed >> as a function within the security team was compliance.


[00:10:53]

>> So maybe 5 years ago you would see that the security culture like training would have sit under governance risk and compliance right. So that's why it's very complianceheavy because like you said so it's right you have to like you know it's it's a it's a tick box. the regulators have asked that all your employees do one module a year. So what do you do? You make sure all your employees do one module a year. So I think that's kind of how um it started. It was very compliance heavy, right? However, I think as time has gone by, people now understand, oh actually hold on, we need people to be aware. So then it became security awareness. But then you realize just because you're aware of something doesn't mean you actually care. I always say this, I know the speed limits. But I don't just because I'm aware of the seat limits doesn't mean I always follow. Now I'm not saying it's right. I'm just saying just because you're aware of it. We're all aware of we should be walking more, drinking less, drink more water. Right? You're aware of it. >> How do you actually change behaviors and make it more tangible? So I think that's why the industry has now been moved shifted into culture which is amazing.


[00:12:01]

>> Now I think going back to your question, how do you change it? I think there is a time and place still for compliance. >> So it's not going to be perfect, right? So I think you know the compliance module side of things will still happen but I think when it comes to changing you know I feel like it's like a process there's a bit of a [clears throat] you know um a maturity model you start with compliance then you move into awareness. So awareness is when you really start, you know, really promoting it, really using those marketing ideas and introducing concepts to your to your employees. And then once you've done that, so you know, you would start doing things like fishing. You would start doing, you know, how do people report? Who do people report to? you know, um, introduce them to different topics because a lot of people don't actually know the nuances, right, between fishing, fishing, cushing, you know, SMS, like it's there's also these all the these different What about whaling or spear fishing, >> right? Spear fishing is really targeted.


[00:13:06]

Then if you ask me, I think spear fishing is like a part of social engineering. But remember, your employees are not hired to be security professionals like me. Yeah, absolutely. >> Right. So, I think it's important that you use more engaging ways and incorporate it in their dayto-day and make it incentivizing. So, that's when I relate it to their home life. If I'm going to teach you something just to protect your organization you work at, you're not going to care as much as if I say, "Hey, what I teach you also protects your mom, your grandparents, and your children." >> Does that make sense? Like, it's making it more relatable. >> Yeah. So I think um I think there's a time and place of compliance but I think when you move into awareness and true culture change and building it's going to take time and it's going to take different way different um yeah you need to do different activities. Um the main thing I always say is always use the language and make it like make it relevant to the people you're talking to. >> Yeah. Yeah. and and how do you make it relevant or maybe I would say more tailored to a specific organization. So yes, there could be a generic approach to improve the security culture right from training program awareness which is the very starting point to to what you said. Uh but every organization has their its own challenges right some organizations might have specific regulatory mandates they need to meet.


[00:14:36]

um there are specific industry specific matters whether finance to healthcare to government etc. So how do you take that into account and tailor that majority curve for that particular organization? M >> so I think it's really important you look at where your risks are coming from >> right so I I think it's really important that security culture and awareness do not sit by themselves they shouldn't sit with HR they don't sit with with coms they sit within the security team and you work really closely with the security operations team to kind of understand hey where are the threats coming who out of all our employees which teams cohorts are being targeted the most and what are the tactics that they're using. >> So I think that's one side you look at the data the source of truth from the security operations team. The other thing is I think it's really important that when you if you're able to to tailor that content for the audience. So for instance I always say this my best friend's a nurse.


[00:15:35]

>> It's very good if you're able to use examples that relate to nursing or an analogy of the same. Right? So, you know, we always say, you know, what's a like um in I know from a nursing concept, if something's not working, they always backtrack >> like the that they go backwards on the steps that they followed. I think it's the same with security. So it's really important and and I think it's important that if you're going to speak to the you know the finance account payable team your examples are did you know as an organization similar and your storytelling as well much more powerful than just me telling you whacking you on the head like do not click on links do not do this do not do that but it's like how can you do your job without opening an email >> it's not going to work right so you're just creating fear for people to not be able function and do their job and it paralyze them right it's not about that I think it's all about you know tailoring it that whoever I draw a presentation to I always look at the audience >> I always ask them examples or hey have you experienced anything like this >> if you don't I've got some examples you know >> um so like the finance one is like you know so the the most talked about example from 2024 or 2025 was you know a um finance controller in Hong Kong received a deep faith video from CEO CIO or that I'm sure you've heard of it.


[00:17:02]

>> Yeah, I've heard of it. >> Um he fell for it and then transferred X amount of dollars. >> But that example probably wouldn't be as effective or powerful to the nurses that are helping our patients. >> Yeah. >> Right. But I think what's more powerful is in Germany a hospital was under a cyber attack and because of that one patient was not sent to hospital quick enough and unfortunately they lost their lives. >> Do you see the difference? >> Yeah. Yeah. >> Both examples both powerful examples but you need to um share it with the right audience otherwise it's not going to be as effective. >> Yeah. Yeah. Agree. So that's good. Um and the other thing um so if we talk about measuring the success of your program right so you have started the journey about security awareness program etc. What what are the key indicators you would typically track right um to see how it is progressing and what indicators you would report to executives and the board level to say that yes we are progressing to the in the right direction or we are there are some gaps challenges there.


[00:18:09]

Perfect. Um, very good uh, question also very hard to answer only because I think um, what what what I do um, the the whole security culture and awareness function is quite intangible. >> I'm not selling a product, right? It's not like, you know, do marketing sales go up. >> Yeah, absolutely. Then >> so it's not like >> like discount product, more units sold, increase revenue. You know what I mean? It's it's it's a bit harder than that. However, there there's definitely some indicators you can do. So, I think it's really important before you report anything to executives or before you set a program is that you baseline. >> So, you do a baseline. So, you know, where is your organization at when it comes to fishing? >> Now, fishing is not the be or end all, right? >> Uh but it is a a good indicator of where you are. Yeah, >> I'm personally much more of a fan of the report rate instead of the click rate >> because depending on the email, right, or the the complexity of the email, how sophisticated the cyber criminals are or the fishing simulation, you can manipulate that click rate, right? But I think but and that's not a behavior you want to reward.


[00:19:27]

>> But but what the what you really want to reward is the report rate. You want your employees to report everything they see that is suspicious. And that includes not only fishing, it includes, hey, I saw someone a bit strange in the office at 700 a.m. >> You know what I mean? Like it's it's so the report rate should, you know, is a good indicator. Another indicator is the security incidents that are reported. So if if your program is doing well, you should see a spike in the in the incidents reported. So it's not a bad >> Yeah. >> Because it means your employees are now proactive. So going from, you know, reactive or inactive, they're now proactively telling you um potential problems, meaning the te that the team can actually focus on, you know, finding the root cause of these issues. >> Yeah. Um and in terms of I think you asked about you know the um executives I think there's a few things I would report. I think click rate you can report with a caveat right that it it's not the most accurate. I think the report rate is another really good one.


[00:20:37]

Um if you have any like uh employee surveys I've been having a question or two about hey are you more confident now in reporting a in identifying and reporting a security incident that is something that you can also you know do like you can also report on that um the less intangible ones which I think are more powerful but harder to quantify are things like people who um talk about food. So for instance, you know, if you have a champion program, how many people want to become a cyber champion who wants to be part of your champion to help champion across the organization? How many people go to your events? >> You know, your lunch and learns and things like that, the engagement is really important as well. >> Yeah. >> Um and also depending what you do. So for instance, you know, um >> positive feedback about the modules you've developed. Um >> there's also different kinds of training as well. So we're I think right now you and I have been speaking a lot about general awareness training for everyone.


[00:21:40]

So it's general security >> um culture training. But let's just say you're doing training for your security engineers or your engineers. >> Then you should be able to correlate training culture better coding less vulnerabilities. >> Yeah. Yeah. Yes. Agree. Because that was my next question actually and you you kind of answered that cuz one aspect is um for technology organization is this engineering discipline and we keep talking about security by design as a as one of the important principles but what again what does that mean right is only about bringing dev sec ops as as a capability or or is it how we culturally change the behavior of engineers to they start taking security more seriously in the they design the solutions. [snorts] >> Yeah, I think that's really important. I think you nailed it. I think it's it's all about, you know, secure by design and not at the very end.


[00:22:38]

>> So that's why I feel like that's the development I believe of application security. >> So when I was in this pentest like you know penetration tests are still important, right? Because you know but throughout it you can't not not have a security person. >> Does that make sense? You need to have a security lens from the start, the inception of an application of a service or whatever and then all the way through to the end and then you do a penetration test. >> Yeah. Yeah. No. Um and I think one one thing uh I wanted to uh understand was uh around and I I think you mentioned this earlier but >> um when you apply or or you roll out this uh security awareness program or you whatever strategy you come up with >> there are different cohorts within the organization right you have executives then you let's say front line then your back office then engineering we talked about then there are wider uh your vendor eosystem team, contractors, etc.


[00:23:38]

So, how do you apply? I guess is it one um I think there shouldn't be a one size fit all kind of approach to this. No. >> So, how do you tailor this to these different cohorts? >> Uh it would be nice to coin me the more it would be good to have more daisies around. Um maybe they can have pink and orange hair so we're different. Okay. But still colored hair. Um I I think it really depends on the resources you have, right? And how big your organization is. >> So if you have a smaller organization, then it'll be easier. But to answer your question, I definitely think it's it's hard. The answer is yes, you need to tailor it. It is absolutely not one sizefits-all >> because people tune it. So that's why I think the general compliance module is one size fits all. It's very generic, high level. Everyone's done that. And then you need to break it into those. Um, usually most organizations have limited resources and funding and capacity when you only have one person.


[00:24:38]

So you would need to um you need to kind of do a risk assessment and see where your high-risk user groups are, >> right? So so you know definitely that um but in terms of like and I think so let's let's talk about the board or the executive group, right? >> Yeah. But what you train there is very different because there is one side they need to understand how valuable their data is. >> Yeah. >> Right. Because it is so easy now to go on uh a CEO any CEO any organization's LinkedIn find when they've done a presentation or when they've attended a conference find a way to find your EA >> deep fake a photo of me and someone someone's CEO and you're the EA. I email you and say, "Hey, I met with Adam, the CEO of, you know, whatever company. They asked me to contact them. Can you please give me their number? They gave it to me, but I lost it. >> Are you It's Do you know what I mean?


[00:25:36]

It's a It's a very true example." >> Yeah. Yeah. >> Like, you know, um and unless you look deeply, unless you actually ask questions, you're not going to question that. Yeah, >> you know, they were able to tell you your CEO's name, when they attended the conference, which conference, the topic they spoke about, and a photo with them. What else is there to question? >> So, I think that's one thing to really help the board and executives understand their own security, right? But I think the other part is to help them understand, you know, obviously they're managing and and um helping an organization, right? whe however big or small that org is. I think it's also really important to help them understand the threat landscape. So what are the threats coming up? Why we need the um why we need the investment >> and what needs to be fixed first and how and um and it just needs to be like a a business priority. So that's kind of the executives, right? Uh and then let's talk about your um what was the other cohort you mentioned that you wanted?


[00:26:38]

>> Well, one cohort maybe we already touched on engineering so maybe you can touch on external the vendors or contractors. >> Yes. So that is a really hard one because if you think about it if I include them in my remitt >> how many more people am I training? Am I then taking away from my full-time employees who need the support to help train these third party contractors? But you're absolutely right. Third party, fourth party, fifth party risks exist, >> right? So I think it's really important then this is when you have to add things into your contracts. >> So you know how any contract any PO you raise you would have things like >> you know code of conduct, >> you know, can't use you know your organization's data to do XY Z. I think it's important to ask whether or not they they like check if they have any certification. So is that organization NIS accredited is that organization ISO 27,0001 because if they have ISO 27,0001 as an accredititation you know that they they do not only security culture and awareness but they do all these other security >> um to protect them. It's not foolproof though, right? It's not it's not bulletproof. >> Um and uh so yeah, that's definitely something that we need to look into as but that's why you then need to rely on your full-time employees >> to be vigilant and be like, "Hey, it's very common we get contractors, but this contractor has been downloading, you know, XY Z.


[00:28:09]

>> Is that not right?" And then yes, you really need people. You want your employees to be your kind of security warriors as well. >> Yeah. Yeah. Cool. Now the other point I want to unpack Resi was uh which I mentioned at the start um around the executive sponsorship or support for these kind of programs because yeah one way you can think of potentially launching or rolling out your security awareness program as a more of a bottomup activity where you try to um generate awareness but we know that for many agenda is a kind of change management activity. So um unless you have a top-down sponsorship for these programs, it they don't go very far. So in your experience so far, how do you see the executive sponsorship has played a role in in improving a successful programs? >> Yeah. Well, I always say this, it's top down, bottom. What is it? Top down, bottom up. Squash everyone in between.


[00:29:09]

Everyone in between is just squashed. Um I think it's really important like you said so you can have really good security culture and awareness from the bottom >> but if you don't have support from the top it doesn't work. So we're talking funding, resourcing, right? Um I think one of the best parts of my job which I like the most is the content creation but it is the most timeconuming and costly but it is the most effective. >> So if you keep using the same content people tune out, people get bored. So I think you know in terms of funding resourcing that's really important um elevating as well. But I think what apart from the funding and and um the funding I think what else seeing executives provide is that psychological safety. >> So what I mean by that is I have had a CEO put their hand up and say Daisy fished me last month. No shame, no embarrassment. I thought I got a free coffee from Starbucks so I clicked. Do you know what I mean? But that's the thing. Everyone is susceptible to fishing. With the right message at the right time, I I guarantee you no one can avoid it.


[00:30:17]

>> Yeah. >> Um, do you know what I mean? But I'm talking right time, right message, right? Um, but I think having that support because when when they came out at a town hall >> and said, "Hey, I got fish last month." It just gave that sense of, "Hey, it's okay. We're human." >> Yeah. Yeah. >> Right. You're not going to be punished. We're all human. Things can happen and even the CEO got >> Yeah. >> got fished. >> Yeah. Yeah. Okay. No, that's good. Um, so and when you roll out these programs, what are the typical change resistance behaviors you see from from the employees in general, right? People are registered to change and and and if something is becoming an overhead for them, for example, people will try to find workarounds, etc. So how do you balance between you are not actually pushing um employees to to do lot of overhead but making sure they are safely doing their work.


[00:31:16]

>> I think that's a really good one. Um so in a true security culture and awareness you shouldn't be like helping with audits you know I mean like that should be a different team but obviously you help out you're from the same team etc. I think it's really important to help people understand the why. >> Yeah. >> So, I think when you educate and you share a message, a lot of the time it's the who, you know, who's telling you, >> what I'm telling you, >> but uh and the how you need to change. So, the change, right? The how. >> But what about the why >> and the what's in it for me? M. >> So, if you've just focused on the who, what, how, you're just telling me what to do. And come on, let's face it. No one likes being told what to do, right? But if you explain to me the why, and I actually understand it, I have a what's in it for me. And remember, if you're able to educate people not only on at work, because I can guarantee you if you go, "Hey, I'm teaching you all this because you're going to better protect the business." you'll be like cool I generally get 8 to 10 hours a day and then that's it.


[00:32:27]

>> Do you know what I mean? Like like >> but if you're able to to relate it to work, play and live, you know. >> Um and if you can kind of help them understand the whatever skills that you've taught them at work also helps them in their home life. Exactly like I said to you before. >> Yeah. >> It'll also help your children protect your children. >> Yeah. Yeah. >> It's going to protect your family. um especially those that are more vulnerable, you're going to be more willing to listen. >> Yeah. And you know what that that is the beauty about cyber security because we're all online >> like so you know like an audit is very workrelated right I cannot I cannot tell my nephew 15 to care about an audit but I can tell him hey >> do you know that you by you putting all that information you know putting a photo of your driver's license you because you got you're you're 18 you're driving now is actually a major security risk because >> Yeah. Yeah. Yeah.


[00:33:23]

>> And they're really honing on the why. >> Yeah. Yeah. And and when you roll out these programs, um, of course, as you said, you work closely with the broader security operation team, right? But apart from that team and maybe some of other technology teams, what is the role or assistance you seek from let's say HR or from legal function within within the organization etc. um in in making sure the awareness is um communicated or chain management teams within the organization so that awareness communicated very clearly across the business. >> So I think um security shouldn't be the security team's responsibility only. Hence why I have a job to educate and help build that culture. So it's intrinsic right to everyone. I think there all the teams above you said are really important in playing a role in creating a good security culture. So legal, so they can look at any of the documents that need to be signed and updated. Um, also to make sure that you know what you're um communicating is accurate. The comm's team is so important as well because you need to make sure whatever content you put out also fits within your organization culture tone.


[00:34:38]

>> You don't want to be too harsh because then again, the security team is just dictating what we should do. They're telling us what to do. They're not understanding. I think it's also really important to understand from your other the other team's perspective. Remember the sales team are there to sell. >> Yeah. >> They're not here to protect your organization because their KPIs are based on selling. But if you're able to help them understand, hey, you can still sell the exact same amount. I just need you to not email your personal Gmail, you know, the the notes from today. But instead of that, let me give you a better solution. >> You can use my notes. Do you know what I mean? I think it's really important that when you take something away, you give a solution. >> Yeah. Yeah. >> The problem you have is when you don't give a solution and people find ways around it. >> Yeah. Yeah. Cool. Um I think we are approaching our time, but couple of points before we wrap up. One, I wanted to quickly touch base on the technology aspect. I I know that this is um your function in particular is not doesn't heavily depend on technology I would imagine but um uh but still are there any particular considerations for your function that you would suggest recommend to a audience in terms of adoption of technology?


[00:35:59]

>> Yeah, of course. So you mean technology that helps with security culture and awareness? >> Yes. Yes. >> Yeah. So I think you know the traditional fishing platforms are now evolving. So you can also do fishing which is voice fishing. So you can you know have um someone call your number and see if you press the buttons provide the information. So I think it's really important. So that that's a really good one. I think you will also see in the security culture and awareness space a lot of the platforms are now moving away from just security culture training. It's also it's now talk about human risk management. So it's really quantifying the risks your employees may or may not bring to your organizations because of their you know lack of knowledge or just not quite mature yet. I think you're going to see that. So I think if you know your audience are listening and thinking how that can they can how can they improve their security culture and awareness program I would say look into humans risk platforms >> and really you know translate those culture those risks into you know those risk management letters >> because those platforms are now able to help you create dashboards so you don't need to manually do it and trust me Leo and I both board and executives love a good dashboard. They love a good traffic light. How many Yeah. So, I think that's one. The other one I would say again is um you know, as much as you know, we're we're all a little bit maybe anxious about AI >> and not knowing how it's going to change how we work, it is very effective as well. >> Like, you know, I have I have reviewed a product where you can say, you know, airline breach that happened last year.


[00:37:38]

You and I both know which one. and then you know these are the talk points and it creates a 30 second video for you. >> Yeah. >> Um so it's a really quick and easy way to create pretty good content. Now is it perfect? Probably not, right? Like as in >> um but it's still better than you know having to engage with a videographer to >> Yeah. >> Yeah. So I think that's where um Yeah. So I think the main thing for your audience to take away is I think first of all keep up to date with technology >> because um it will end up coming to the masses. It'll come to your employees. It's going to come to your customers. How can you be prepared? >> Don't wait for it to come. So I think keeping updated with technology. You don't need to be an expert. You just need to know about it. Um and then think about how you can incorporate those kind of you know um learnings into what you're teaching your content that you're sharing with your employees. >> Yeah. Cool. Uh so before we wrap up couple of last questions um Desi um one is so you have been on this on this journey for a while now right? U you have seen how security culture as a function has evolved for last four five years. >> You might have learned few things as well. Um right are there any key learnings you want to share with our audience as to what mistakes they should avoid while launching these kind of enterprisewide security awareness programs? Yeah, I would say first of all be patient because I think a lot of us um you know again this isn't a upgrade the system you know and then you can tell the bar tells you five five out more hours to update your iOS and then you restart your device done. uh we are talking about comp like we're talking about humans we're talking about there's change like you know the cyber industry just changes so quickly like the threat landscape sorry like there's all there's there's you know you didn't think third parties was a risk one minute and then the next minute an organization's been breached so then you focus on that so I think number one um learning or advice I would say is be patient to build a good solid security culture and awareness program or just security culture within an organization takes that another learning I would say is to if you if you don't have all the resources right but as in you don't have someone there to create content for everyone you don't you're not able to do everyone I would say sit down with the security operations team sit down with your manager or the executives and really find the high-risk users >> and you know really focus on your energy on them as a kind of phase and then work on phase two because it can get very overwhelming very quickly and then I'm a strong I'm a firm believer that you want to do things well um instead of just everyone touches a little bit >> but you haven't done your job if everyone's done a um a module a compliance module I haven't done my job if I send everyone an email of this is this month's security risks that's not effective Right.


[00:40:51]

>> So I think um the the learning number two is do less but do it well. >> Yeah. >> Okay. And uh again final final question is um um many organizations and many people with all intent typically struggle to still bring it to executive attention and make this as an executive level topic. So is there a secret source or is any kind of advice you have to to people as to how they can make generate that awareness at security or board level as well so that becomes at least a topic for conversation at that level. >> So so security culture and not just security at the board. >> Yeah. I I think again it's it's using those concepts that they're very they they are aware of. So for instance you know they I don't believe it but it's true. humans probably are more of a weaker link than a system that you can patch every Tuesday, right? Yeah.


[00:41:48]

>> So, I think it's um I think it's really showing the board that you know our employees are doing really well. they're hitting all the other KPIs, the sales, the, you know, revenue targets, the whatever, what not, but we are seeing a lot of risks and it's all related to people and how can we support our employees. Um, and I think, you know, um, you all, you know, we have a saying, the security team, never let an incident go to waste. I think showcasing some of those um previous incidents and just really sharing with the board and helping them understand and quantify that if you do not support your employees they are going to be a higher risk to you and in turn if anything was to happen it's the reputational damage the operational damage >> like I think it's also good to quantify um how costly an cyber security incident or breach is >> because you know how I A lot of people always think it's not going to be me.


[00:42:50]

But I think it's more a case of if not. It's not about if, it's about when. And you need to be prepared for it. And >> so if you're going to do a fire drill, right, with your building, why are you not and then you train your your staff to know when you hear the alarm, you leave? Because there is a fire. It's the same with security. We need to do these fire drills. We need to constantly train our employees knowledge update. >> Yeah. Okay, I think that's that's it probably. We covered a lot Desi and thanks thanks again for your time and I think audience will take away a lot many uh lessons from this conversation in terms in in terms of particularly how the landscape of security culture and as a function has shifted how they should approach implementing security culture as a program what conversations they should have at executive level versus uh different cohorts um within the organization that there are lot many important and uh insightful um lessons for our audience. So, thanks for your time. >> Awesome. Lori, thank you so much for having me.


[00:43:54]

>> Hope you like today's episode. Please subscribe us on YouTube, LinkedIn and [music] X platforms. Also, if you are passionate about any such enterprise technology topics and want to participate in the discussion, please reach out at inquiry@ enterprisette.com. [music] Also, please visit the website www.enterprisete.com. Enterprised tech.com for more [music] details.


bottom of page