Security culture
What employees do about security when nobody is watching: reporting, verifying, asking. It is built through practice, not posters.
Full definition
Security culture is the set of behaviors, habits and attitudes toward security that employees sustain when nobody is watching: whether they report the suspicious email, verify before paying, and ask without fear when something feels off.
It differs from compliance in that it cannot be decreed: a company can have one hundred percent of its courses completed and a culture where reporting a mistake is embarrassing. The most reliable signal of a healthy culture is a rising report rate, because reporting is a voluntary act that only happens when habit and trust exist.
Culture is built through repeated, blame-free practice: frequent simulations that normalize mistakes as training data, immediate feedback, and metrics that reward reporting instead of hiding. Security behavior and culture programs formalize that work.
Related terms
Report rate
The percentage of people who report a simulation or a real attack. It is the best early indicator of a security culture that works.
Security awareness
Programs that teach employees to recognize and report threats. Completing courses does not equal changed behavior: that is validated with a retest.
Human factor
The human dimension of cybersecurity risk: the decisions and habits of people that an attacker can exploit. It is not a synonym for blame.
From definition to data: measure your company's human risk
Fensivo detects leaked credentials, simulates real attacks and validates with retests that behavior changed.