In the introduction, Embedded in Culture was the first feature of a successful program. Selecting this option first is not an accident. To run a secure company, we want users to think about security implications at all times. Whether an employee is reading email, selecting new software, reviewing client data, sharing information with a co-worker, or coding new software, they should be thinking about security.

To show employees that security is top of mind, leadership needs to demonstrate that they are always thinking about security. Leaderships' responsibility includes ensuring that knowledgeable resources are available to answer questions, discussing issues on a regular cadence with staff (see next week's article), and building processes that continuously assess issues.

With the established security mindset above, all employees will actively work together to achieve security goals, more actively participate in training, and feel comfortable asking questions when they arise.

