Why is behaviour change on this topic so difficult?
As we hear (far too) often, human behaviour is THE weak link in cybersecurity. Personally, I'm rather among those who prefer to say it is the first line of defence. The nuance matters, I assure you.
Cybercriminals have clearly understood that technology can be hard to outwit. So they bet on our reflexes and behaviours to force open the door to our personal and/or professional data. Keep in mind that your employees are your best assets for spotting vulnerabilities day to day "on the ground": mobilising them is therefore essential.
Informing vs. raising awareness
I've had the chance to support various large companies on this major issue that is cybersecurity. At the start, the finding is always the same: we inform employees but we don't raise their awareness. It's then hard for them to acquire new habits and take action. We often see a mass broadcast of security rules, without guiding and supporting employees in putting them into practice: "Your passwords must contain a number, the maiden name of four Spice Girls, the correct spelling of an Ikea bookcase (I'm barely exaggerating)…", "USB devices are forbidden on your work equipment…". And unfortunately, all this becomes nothing but a long list of rules and constraints often misunderstood by employees.
Connecting to a public wifi network in one click, sharing documents in real time across different email addresses, using free online tools: that's the world your users live in today…
In our digital habits today, it's easier to ignore the rules than to apply good "cyber-hygiene."
To give it meaning, you have to motivate the action. Prompting an individual's behaviour change means informing them of the causes and consequences of their actions, otherwise it will serve no purpose (or almost none). You have to understand the path an individual will follow to change, by building actions suited to each stage.
How do you create a cybersecurity culture?
The first question to ask is: "why do employees behave this way, despite the fact that it's forbidden or strongly discouraged?"
I often compare the challenge of cybersecurity awareness to that of protecting the environment.
In terms of motivational levers, here are 4 points that make the two subjects quite similar when it comes to change management:
- We rarely see the immediate consequences of our bad behaviour, so it's "easy" to "choose" to ignore them.
- Adopting the right behaviour often seems more constraining in the moment.
- On an objective logic, the "right behaviour" is the one individuals should naturally adopt, because it is, in essence, the best for them, for the planet or for the company. Yet the "right" behaviour isn't driven by ideas alone.
- Individuals often know the rules, but they don't apply them systematically.
A behavioural approach
One of my clients wanted to create a strong cybersecurity culture within a large group (more than 100,000 employees), with the main objective of reducing security breaches linked to the human factor. During this project, we started with a very rich analysis phase, to understand what motivates an individual to change.
It was on this occasion that I drew on an extremely interesting theory of change: the transtheoretical model of change, by James O. Prochaska and Carlo C. DiClemente. This model describes the change process between the moment an individual has no intention of changing their behaviour (pre-contemplation) and the moment the newly adopted behaviour becomes an integral part of their habits (maintenance). This approach is also used to support people with addictions, helping them give up deeply ingrained behaviours.
And guess what? It has also proven itself in awareness campaigns on the theme of protecting the environment!
Implementation in your projects
In our client's specific case, we customised this approach into 5 stages. For each, here are examples of actions that were carried out:
- Pre-contemplation: at this stage, the employee has no intention of changing and, above all, isn't aware that their behaviour is problematic. Priority to communication: users must become aware of the problem and of the benefits of changing. Forget anxiety-inducing or guilt-tripping approaches; believing that creating fear changes attitudes is false. Example: an internal-communication video saga aimed at challenging users about their behaviours.
- Contemplation: awareness is there, but no change in sight. A 50-page user charter doesn't work and never will. You have to make people practise: bet on demos, corners, go and meet users and show them that other practices are possible. Example: a Cyber Corner, "Create and remember a strong password in 2 min," "1 min to detect a phishing email."
- Preparation: change is arriving in small steps. Bet on engagement, which will lead to action. Example: invite users to be actors of their own change, provide USB-key decontamination stations, cheat sheets…
- Action: the change is under way, but nothing is won yet. Lead by example and value the sharing of experience. Nothing beats having employees talk about their own successes (video testimonials, games, digital escape game). Careful: we're not trying to test their knowledge, but their reflexes and their ability to act better.
- Maintenance: you have to avoid backsliding. After engagement, correlate the new behaviour with belonging to a group, a network. Example: communities for sharing best practices, and a network of "Cyber Partners" (Champions/Ambassadors) to keep cyber topics visible internally.
From experience, I find this change journey extremely interesting. It lets you offer far more personalised support, knowing which stage to guide each of your employees toward.