Section outline

    • SUMMARY

      As mission-driven organizations, we often emphasize our programs and the communities we serve above all else. But overlooking cybersecurity can be costly and even harmful to our internal teams and the people we are trying to help in the outside world.

      One way to prioritize cybersecurity is to build a "security culture" within your organization. There is no one-size-fits-all method for emphasizing security within your teams, but in this lesson, we'll review some basics to help you get started. In this lesson, you'll learn: 

      💡 We recommend you pay special attention to the section discussing who should be designated a security champion within your organization. It's not just your IT department!

  • The checklist shows actions you can take to implement your learning in your organization. Use it to keep track of your security to-dos.

    • Create a Security Culture

       

      Recruit Security Champions

       

      Promote Security In Your Organization

       

      Run Tabletop Exercises

       

      Create a Positive Culture 

    • SLIDES

       

    • SLIDES

       

    • If your organization launched a new initiative that involves driving to a remote location, you wouldn’t have people without a license drive the car. In your planning, you would also provide ample time for the drive so that the driver wouldn’t have to speed.

      Road safety has become such a part of our culture that these statements seem rather obvious. For organizations that work in high-risk locations, such as a conflict zone, the same is true for physical security. But for cybersecurity, this still often isn’t the case, even for those organizations which are at high risk of digital threats, a category which many NGOs fall under.

      So what is the solution to making cybersecurity a central part of your organization? Consider creating a security culture.

       

      Security Culture: An Environment Where Staff Prioritize Cybersecurity

      A security culture is an environment in which staff members understand the importance of a strong cybersecurity posture and actively participate in protecting the organization from digital risks. Such a culture is important and really helps organizations become more resilient against digital threats while also helping them respond to them more quickly when incidents occur.

      Building a security culture isn’t easy or quick, nor is it something that can be done through a handful of training sessions or by installing a specific tool – even if both of these efforts may play a role. This brief guide helps organizations start to build such a culture.

       

      Empower Members of Your Staff to Become Security Champions

      The fact that you are reading this guide suggests that you have some interest in cybersecurity. Even if this interest comes from the fact that cybersecurity is part of your job description, this is great! You are now your organization’s first security champion.

      Security champions are a group of people throughout the organization that help it build and maintain a security culture. Ideally, being a security champion is included in someone's job description and some time is set aside for this work in their weekly schedule. In practice, formalizing the existence of security champions may be something the security champions will need to do themselves as one of their first tasks.

       

      Why People Across the Organization Should Be Security Champions

      It may be tempting to select security champions among the IT and security staff, but it is important that people throughout the organization are part of this team. For example, the finance department is a prime target for financial fraud, while it is part of the HR department's job to open email attachments from unknown senders, so having people from these departments on board is crucial. Technical understanding of cybersecurity isn't necessary to become a security champion, but a desire to learn and to share this knowledge is important. Understanding how the organization works is also really helpful.

       

      Sharing, Discussing, and Practicing: The Role of Security Champions

      Security champions can share relevant security news stories within their team or with the whole organization, maybe through a newsletter or an internal blog. They may also host talks on security topics by people from within the organization or by external speakers. Many security professionals love to talk about their work and many security companies have outreach programs that you could benefit from.

      One important thing security champions can do is organize discussions among staff (or, for larger organizations, within a team) on cybersecurity, in particular as it affects the organization. These discussions can help staff understand the security risks facing their organization and what procedures and protections are, or could be, in place to mitigate those risks.

      More formally, the discussions could take the form of a tabletop exercise

       

      Use Tabletop Exercises to Simulate Your Response to a Threat 

      A tabletop exercise is a discussion-based event that simulates a particular security scenario, such as a ransomware incident or the hack of an email account. As the scenario evolves, it could also involve non-malicious events such as the unavailability of a crucial third-party service.

      The first goal of the exercise is to document the strengths and weaknesses of the organization’s security defenses as well as the procedures in place to handle the incident. The second goal is then to learn from those weaknesses and improve them. A good tabletop exercise involves serious planning and many follow-up activities, but when run well, is truly worth the effort. As a nice side effect, those involved in the exercise will be forced to think about the security of the organization rather than taking it for granted. 

      In another module, you will learn how to plan, run and evaluate tabletop exercises.

       

      Security Training Isn't a One-Size-Fits-All Solution 

      Training sessions play an important role in building a security culture. They also help emphasize that everyone plays a role in keeping the organization more secure.

      However, training sessions are not the only solution to securing an organization. It is always better, if possible, to prevent staff from taking a certain action (such as opening certain types of email attachments) than to train them not to do it.

      It is also important to not use training sessions to spread the message that staff members are to blame for security mistakes they unintentionally make. The goal of good security training is to make people feel empowered rather than scared and to encourage good behavior rather than discourage bad behavior.

      In a good security culture, wins are celebrated. This isn’t natural in cybersecurity, which often revolves around incidents and mistakes, but it is important to recognize the many steps individuals, teams and the whole organization are taking to improve overall security.