Risk culture is the part of cybersecurity you can’t buy. You can buy tools, but that does not determine how people behave around risk every day. Most breaches begin with human actions like clicking phishing links, reusing passwords, bypassing controls, or silence after errors, not with exotic zero-days.
Risk culture comprises the beliefs that shape habits. The tone from the top shapes culture; leaders’ priorities and attitudes influence the organization. Pushing technology to meet deadlines without safeguards signals that safety and resilience are secondary – revenue over resiliency. Actions speak louder than words. For example:
- Shared beliefs: whether people see cybersecurity as everyone’s job or IT’s problem.
- Everyday norms: whether people feel safe reporting mistakes, challenging risky decisions or escalating suspicious activity.
- Leadership tone: whether executives treat cyber as a strategic risk alongside financial and operational risks or as a technical detail.
ERM/GRC systems and advanced monitoring can be purchased, but they can create a false sense of security if an organization fails to address the underlying human factors.
How culture quietly overrides your controls
Even when controls look perfect on paper, culture determines how they perform in practice. Practitioners’ insights and expert commentary reveal the same patterns:
- Policies exist, but a lack of clear ownership and accountability renders them merely regulatory documentation. Risk appetite is documented but not incorporated into operations, and asset and data inventories are missing, access controls are poor and change procedures are confusing.
- Annual tests and phishing simulations showed improvement, but staff still lack ownership and understanding of risk and controls. They bypass controls, don’t report issues or view training as a checkbox because of a lack of ownership and leadership support. Training feels like an annual chore, not ongoing learning.
- GRC systems and reporting create dashboards, but communication gaps and fear of blame hide issues early. Pressure to avoid conflict persists and outspoken staff are labeled troublemakers. To maintain harmony, risk discussions are avoided, leaving problems unresolved. The environment presents an “all good” facade but struggles with obsolescence, outdated systems and poor change management. Incidents are common and may be underestimated to manage perceptions.
- Repeated audit findings year after year on the same basic hygiene issues, i.e., misconfigurations, patching and privilege access reviews. Little time is devoted to discussing repeat audit findings because there is no clear accountability or ownership.
- Leaders often view cyber as solely the CISO’s problem rather than a business risk. Leadership communications include conflicting messaging, such as promoting “security is everyone’s job” while rewarding sales metrics. Cyber is treated as a side issue, with risk appetite not reflected in decisions and accountability unclear. Business units buy SaaS without security review, viewing the official process as a hindrance. Sometimes, no official process exists.
- Internal support staff, such as IT help desks, lack understanding of cyber hygiene and data protection. The absence of an organization-wide leaver process to manage data and equipment poses a high risk of data leakage, which should be a board concern.
These are cultural and governance gaps behind a “hoodie,” not technology flaws. Incidents appear as cyber issues – such as unpatched systems and stolen credentials – but are often organizational: weak processes, unclear accountability, poor follow-up and a risk-tolerant culture. The “hoodie” is superficial; the real vulnerability lies in organizational behavior and risk management.
What risk culture really means
A CISO described culture as “the invisible risk” that isn't visible on a dashboard. It becomes apparent when someone bypasses a control because it was created for compliance purposes and does not reflect actual work practices.
Cybersecurity risk culture encompasses shared beliefs and daily behaviors around technology-related risks. A strong culture integrates cybersecurity into work, not as a regulatory burden. Weak culture leads to workarounds, shadow IT, and ignoring controls, even in regulated environments.
Practical moves for leaders and boards to improve risk culture
You don’t need to be a cybersecurity specialist to shape risk culture; you do need to be consistent. Governance needs an independent voice and should be led by independent board directors.
- Clarify appetite and tolerance in plain language. For example: “Zero risk appetite for any loss of customer data.”
- Ask for a report that maps incidents and near‑misses to appetite and tolerance. Sense-check how incidents are rated. A high volume of incidents with low ratings may indicate a larger systemic issue.
- In board and risk committee packs, insist that top cyber risks be described in business terms: customer impact, operational disruption and regulatory exposure – not in metrics and numbers that do not tell the full story and create a false sense of security that there are no breaches.
- Ask key material risk-takers about ownership and processes. An ambiguous answer signals a lack of responsibility and accountability. Reliance on board attestations may be inadequate for governance and independent oversight.
Practical tips teams can start using now
For audit, risk, privacy and cybersecurity professionals, here are concrete levers you can pull:
- In audits, test behavior, not just design. For example, sample actual approvals, access revocations or SaaS sign‑ups to see whether people follow the spirit of the policy or understand it.
- For risk teams, in risk registers, link potential failures and control weaknesses to cultural drivers (incentives, ownership, process friction).
- For privacy teams, embed privacy‑by‑design checklists into product and project tollgates so that asking early is the easy default.
- For cybersecurity teams, collaborate with business heads to establish a common language for identifying and measuring risks.
Each of these elements may be small on its own, but collectively they transform “cybersecurity theater” into real practice. Awareness of risks begins with humility. Organizations that consider themselves the best often foster hubris. True value emerges when employees stay curious about cybersecurity best practices and integrate them into their daily routines.
About the author: Adeline Chan is a governance and risk leader and an accredited board director based in Singapore. Her background in strategy, cybersecurity, and financial crime risk helps boards make decisions on AI, cyber, data, and conduct that align with organizational purpose, stakeholder trust, and responsible growth. With more than 25 years of corporate experience, she has led banking transformations, designed risk frameworks for global entities, and strengthened regulatory engagement. Adeline holds a Master’s Degree in International Management from Thunderbird School of Global Management and is recognized as an IT Governance Leader, a Top Woman in Security (ASEAN), and a Global Fintech Institute Fellow.