ENISA-Report: Cybersecurity Culture Guidelines

#
Publications
#
Awareness Measurement
#
Trends
ENISA Report: Person points to a virtual mind map on IT security.
The ENISA report examines scientific approaches to behavioural change in cyber security. An ideal model sensitises and analyses organisations and shows intervention possibilities for behavioural change. Dr. Thomas Schlienger is one of the authors of the report.

Already announced in September 2018, we can now finally tell you about the ENISA-Report on "Cybersecurity Culture Guidelines: Behavioural Aspects of Cybersecurity". Dr. Thomas Schlienger worked on this report last year, together with Professor Angela Sasse and Professor Adam Joinson.

To produce the report, the authors analysed scientific approaches to behavioural change in cybersecurity. The most commonly occurring models were poorly suited “for understanding, predicting, or changing cyber security behaviour (1)”. Models that demonstrate constructive possibilities are more effective and useful than those that attempt to change behaviour through punishment or fear of threats. An ideal model sensitises and analyses organisations and points out intervention options, “to systematically plan and implement changes to address human aspects of cyber security (2)”. Security specialists and management-level role models are important pillars of a functioning cybersecurity. The process for improving security behaviour should be continuous and iterative. At the end of the report, the authors provide recommendations for different people in charge within a company.

TWISK Security Awareness Radar®, our "Organisational Behaviour Model", demonstrates how to analyse security culture in organisations at different levels and where to intervene. The model identifies specific points for improving cybersecurity culture. Experience shows that behaviour can be positively influenced if the working environment is also changed.

We would be delighted to advise you on our model and how you can achieve effective behavioural changes.


(1): Page 4, 2nd paragraph
(2): Page 4, 4th paragraph

Newsletter

Don't miss any more news about cyber security awareness and get tips and tricks for employee training in your company.

Vielen Dank für Ihre Newsletter Anmeldung.
Beim Absenden des Formulars ist etwas schief gelaufen.
Umschlagsymbol

Form, E-mail, Phone

You can fill out a short form or send us an email. We will get back to you within two working days. You can also call us directly. Click on "Contact" and you will receive all the necessary contact details.

Kalendersymbol

Free online consultation

If you would prefer to book a specific appointment, you can do so by clicking on the blue button below. The online booking system will open in a new window and you can schedule your free consultation.