1
00:00:00,000 --> 00:00:00,990
In this lesson,

2
00:00:00,990 --> 00:00:03,270
we're going to cover how to create a culture of security

3
00:00:03,270 --> 00:00:04,830
in your organization.

4
00:00:04,830 --> 00:00:06,450
Now, establishing a culture of security

5
00:00:06,450 --> 00:00:08,940
is extremely important in your organization.

6
00:00:08,940 --> 00:00:11,550
After all, you can install all the high-tech firewalls

7
00:00:11,550 --> 00:00:12,990
and encryption systems you want,

8
00:00:12,990 --> 00:00:14,970
but if your employees don't value security,

9
00:00:14,970 --> 00:00:16,320
then they're simply going to bypass

10
00:00:16,320 --> 00:00:18,000
or ignore these technical solutions,

11
00:00:18,000 --> 00:00:19,290
and the threat actor will be able

12
00:00:19,290 --> 00:00:21,060
to infiltrate your networks.

13
00:00:21,060 --> 00:00:22,470
Creating a culture of security

14
00:00:22,470 --> 00:00:23,850
involves weaving cybersecurity

15
00:00:23,850 --> 00:00:26,580
into the very fabric of your organization's ethos,

16
00:00:26,580 --> 00:00:28,320
behaviors, and everyday decisions

17
00:00:28,320 --> 00:00:30,450
being made by all of your employees.

18
00:00:30,450 --> 00:00:32,460
This transformation is a complete shift

19
00:00:32,460 --> 00:00:34,320
in the mindset of your organization,

20
00:00:34,320 --> 00:00:36,570
and must use organizational change management,

21
00:00:36,570 --> 00:00:39,210
strategic development, comprehensive execution,

22
00:00:39,210 --> 00:00:40,980
and constant monitoring and reporting

23
00:00:40,980 --> 00:00:43,440
to achieve your new security-focused culture.

24
00:00:43,440 --> 00:00:44,940
Our goal here is clear:

25
00:00:44,940 --> 00:00:47,970
to ingrain cybersecurity into every part of our organization

26
00:00:47,970 --> 00:00:49,710
so that we can all make better decisions

27
00:00:49,710 --> 00:00:51,660
to protect and defend our organization

28
00:00:51,660 --> 00:00:53,520
and its valuable information.

29
00:00:53,520 --> 00:00:55,050
Now, to create this change,

30
00:00:55,050 --> 00:00:56,370
we're going to rely on the principles

31
00:00:56,370 --> 00:00:59,730
of organizational change management, or OCM.

32
00:00:59,730 --> 00:01:01,500
Now, organizational change management

33
00:01:01,500 --> 00:01:04,200
begins by understanding the human elements role in security

34
00:01:04,200 --> 00:01:06,810
by acknowledging that most sophisticated security systems

35
00:01:06,810 --> 00:01:09,360
can falter without your staff being fully engaged

36
00:01:09,360 --> 00:01:11,820
and adhering to your policies and procedures.

37
00:01:11,820 --> 00:01:13,200
So to be effective,

38
00:01:13,200 --> 00:01:14,760
your organizational change management

39
00:01:14,760 --> 00:01:17,070
should begin at the top of your organization,

40
00:01:17,070 --> 00:01:18,960
within your executive leadership team

41
00:01:18,960 --> 00:01:20,910
to illustrate their commitment to security

42
00:01:20,910 --> 00:01:21,900
so that the tone is set

43
00:01:21,900 --> 00:01:23,940
for all of your organization's personnel,

44
00:01:23,940 --> 00:01:26,430
internal relationships, and operations.

45
00:01:26,430 --> 00:01:27,990
Your leaders must communicate

46
00:01:27,990 --> 00:01:29,460
the importance of cybersecurity,

47
00:01:29,460 --> 00:01:31,080
not as a mandated directive,

48
00:01:31,080 --> 00:01:32,670
but as a corporate responsibility

49
00:01:32,670 --> 00:01:34,590
that is shared equally by everybody,

50
00:01:34,590 --> 00:01:36,390
all the way from the executive suite

51
00:01:36,390 --> 00:01:39,780
to your low-level, seasonal, or part-time employees.

52
00:01:39,780 --> 00:01:41,790
First, we enter the development phase

53
00:01:41,790 --> 00:01:43,020
of our security programs,

54
00:01:43,020 --> 00:01:45,270
where strategic planning takes center stage.

55
00:01:45,270 --> 00:01:47,070
It's not enough to declare that cybersecurity

56
00:01:47,070 --> 00:01:48,840
is a priority for your organization,

57
00:01:48,840 --> 00:01:51,300
but you also must create specific and actionable plans

58
00:01:51,300 --> 00:01:53,760
that are backed up with the proper resource allocations

59
00:01:53,760 --> 00:01:55,530
to make them a reality.

60
00:01:55,530 --> 00:01:56,610
During this phase,

61
00:01:56,610 --> 00:01:58,290
you sould create comprehensive policies

62
00:01:58,290 --> 00:02:00,450
that outline the acceptable practices and protocols

63
00:02:00,450 --> 00:02:01,590
in your organization,

64
00:02:01,590 --> 00:02:04,200
as well as educating your employees about potential threats,

65
00:02:04,200 --> 00:02:06,060
like phishing and social engineering,

66
00:02:06,060 --> 00:02:07,227
and implementing clear guidelines

67
00:02:07,227 --> 00:02:10,320
for handling your organization's sensitive data.

68
00:02:10,320 --> 00:02:12,090
Beyond rules and restrictions, though,

69
00:02:12,090 --> 00:02:14,880
this phase must also build a foundation for empowerment

70
00:02:14,880 --> 00:02:16,950
so that your employees feel confident in their ability

71
00:02:16,950 --> 00:02:19,980
to recognize and respond to potential cyber threats.

72
00:02:19,980 --> 00:02:21,840
Now, once the development is concluded,

73
00:02:21,840 --> 00:02:23,820
the execution phase will begin.

74
00:02:23,820 --> 00:02:26,100
It's important to realize that the execution phase

75
00:02:26,100 --> 00:02:27,660
isn't a one-time event, though,

76
00:02:27,660 --> 00:02:29,730
but it's more of a continual process.

77
00:02:29,730 --> 00:02:31,320
This involves rolling out new policies

78
00:02:31,320 --> 00:02:33,240
and conducting training sessions to mark the start

79
00:02:33,240 --> 00:02:36,000
of what must be a sustained effort over time.

80
00:02:36,000 --> 00:02:37,710
After all, the security landscape

81
00:02:37,710 --> 00:02:39,900
is ever-changing and ever-evolving,

82
00:02:39,900 --> 00:02:43,440
so your strategies and tactics must also adapt over time.

83
00:02:43,440 --> 00:02:45,120
Your organization must also ensure

84
00:02:45,120 --> 00:02:46,560
that regular training updates,

85
00:02:46,560 --> 00:02:47,670
simulated cyberattacks,

86
00:02:47,670 --> 00:02:49,590
and consistent communication about threats

87
00:02:49,590 --> 00:02:51,510
are part of your standard operating practices

88
00:02:51,510 --> 00:02:52,980
on a daily basis.

89
00:02:52,980 --> 00:02:55,050
This is the key to making security considerations

90
00:02:55,050 --> 00:02:56,610
a habit in your organization,

91
00:02:56,610 --> 00:02:58,020
and not just an afterthought.

92
00:02:58,020 --> 00:03:00,180
So it's crucial that you always embed these practices

93
00:03:00,180 --> 00:03:01,980
into your everyday workflows.

94
00:03:01,980 --> 00:03:03,900
However, without a system for reporting

95
00:03:03,900 --> 00:03:05,010
and monitoring in place,

96
00:03:05,010 --> 00:03:06,570
even the most thorough strategies

97
00:03:06,570 --> 00:03:08,310
will ultimately face failure.

98
00:03:08,310 --> 00:03:10,110
To ensure the strategy is successful,

99
00:03:10,110 --> 00:03:11,730
you should begin with some initial monitoring

100
00:03:11,730 --> 00:03:13,980
after the rollout of a new security program

101
00:03:13,980 --> 00:03:16,770
to address any immediate issues that must be identified.

102
00:03:16,770 --> 00:03:19,410
Then you should move into a more recurring set of check-ins

103
00:03:19,410 --> 00:03:21,120
that helps to maintain the program's integrity

104
00:03:21,120 --> 00:03:22,560
over the long term.

105
00:03:22,560 --> 00:03:24,480
This approach means that we are monitoring the network

106
00:03:24,480 --> 00:03:25,650
for potential breaches,

107
00:03:25,650 --> 00:03:27,840
as well as ensuring that we're tracking employee compliance

108
00:03:27,840 --> 00:03:29,430
with our security protocols,

109
00:03:29,430 --> 00:03:31,710
assessing the effectiveness of our current strategies,

110
00:03:31,710 --> 00:03:34,680
and identifying any areas for potential improvements.

111
00:03:34,680 --> 00:03:37,230
Additionally, all of your employees must be educated

112
00:03:37,230 --> 00:03:40,140
on how and where they can report any suspicious activities

113
00:03:40,140 --> 00:03:41,790
within your organization.

114
00:03:41,790 --> 00:03:43,140
An atmosphere where staff members

115
00:03:43,140 --> 00:03:44,760
are hesitant to report incidents

116
00:03:44,760 --> 00:03:47,040
because they fear being blamed for a potential issue

117
00:03:47,040 --> 00:03:48,840
is considered to be very counterproductive

118
00:03:48,840 --> 00:03:51,090
to our goal of increasing our security.

119
00:03:51,090 --> 00:03:53,550
Instead, we are aiming to cultivate an environment

120
00:03:53,550 --> 00:03:55,890
that encourages the reporting of potential incidents

121
00:03:55,890 --> 00:03:58,830
and one where employees' input is valued highly

122
00:03:58,830 --> 00:04:01,890
to help us improve our organization's security measures.

123
00:04:01,890 --> 00:04:04,230
To help with this, we need to create feedback loops

124
00:04:04,230 --> 00:04:05,520
to ensure that any insights gained

125
00:04:05,520 --> 00:04:07,290
from our monitoring and reporting activities

126
00:04:07,290 --> 00:04:09,870
will be directly influencing our future actions,

127
00:04:09,870 --> 00:04:11,700
so that our program can continue to evolve

128
00:04:11,700 --> 00:04:13,440
and increase in its effectiveness.

129
00:04:13,440 --> 00:04:15,180
This cycle of learning and adapting

130
00:04:15,180 --> 00:04:16,649
is what really helps organizations

131
00:04:16,649 --> 00:04:19,140
to stay ahead of any new or novel cyber threats

132
00:04:19,140 --> 00:04:21,149
that may be introduced over time.

133
00:04:21,149 --> 00:04:23,310
So remember, creating a culture of security

134
00:04:23,310 --> 00:04:24,870
is a comprehensive endeavor

135
00:04:24,870 --> 00:04:26,580
that is all about making the organization

136
00:04:26,580 --> 00:04:28,680
more resilient against the cyberattack

137
00:04:28,680 --> 00:04:30,960
by ensuring that each individual understands their role

138
00:04:30,960 --> 00:04:33,960
in safeguarding the organization's sensitive digital assets.

139
00:04:33,960 --> 00:04:36,540
When security becomes second nature in your organization,

140
00:04:36,540 --> 00:04:37,950
you're going to see that employee vigilance

141
00:04:37,950 --> 00:04:40,500
becomes an inherent trait inside of your culture,

142
00:04:40,500 --> 00:04:41,370
and that your organization

143
00:04:41,370 --> 00:04:43,860
doesn't just protect its interests against current threats,

144
00:04:43,860 --> 00:04:45,390
but it also becomes better equipped

145
00:04:45,390 --> 00:04:46,380
to face the uncertainties

146
00:04:46,380 --> 00:04:48,660
that may appear further out in the future.

147
00:04:48,660 --> 00:04:50,910
By having a more proactive security posture,

148
00:04:50,910 --> 00:04:52,980
your organization will build its reputation

149
00:04:52,980 --> 00:04:54,420
on the basis of trust,

150
00:04:54,420 --> 00:04:55,650
and it will allow your organization

151
00:04:55,650 --> 00:04:56,970
to improve its operations

152
00:04:56,970 --> 00:04:59,870
while maintaining the security of its most sensitive data.

