Cybersecurity conversations often focus on technology.
Firewalls
Monitoring
Threat intelligence
Compliance frameworks
But when I sat down with members of my networking group recently, the conversation went somewhere more interesting:
How do you actually encourage people to behave securely day-to-day?
Not just during training week.
Not just before an audit.
Not just when someone from IT sends another reminder email.
But consistently.
What followed was a genuinely useful discussion across different industries, business sizes and operational environments.
And despite very different businesses, some common themes emerged surprisingly quickly.
Security Culture Starts with Making Things Easy
One point came up repeatedly:
People are far more likely to follow secure processes if those processes fit naturally into how they already work.
Several business owners mentioned that overly complicated procedures often create the opposite effect:
- workarounds
- disengagement
- ignored policies
- “temporary” exceptions that quietly become permanent
The businesses seeing the best results tended to focus on:
- clarity
- simplicity
- consistency
—not overwhelming staff with documentation.
Leadership Behaviour Matters More Than Policies
Another strong theme was visibility from leadership.
Teams notice very quickly whether security is treated as:
- a genuine operational priority
- or simply a compliance exercise
One business owner explained that even small behaviours make a difference:
- using MFA consistently
- following access procedures properly
- avoiding password-sharing shortcuts
- discussing incidents openly instead of hiding mistakes
That consistency creates trust in the process.
And importantly, it normalises secure behaviour instead of treating it as “extra admin”.
Real Examples Land Better Than Generic Warnings
A few members discussed how staff engage far more with:
- real incidents
- operational examples
- near misses
- sector-specific risks
than with generic awareness slides.
People tend to care more when they understand:
- how disruption would affect customers
- what downtime would mean operationally
- how phishing impacts real workflows
- how small mistakes escalate
That operational context matters.
Security Is Increasingly Becoming a Supply Chain Issue
One of the most interesting parts of the discussion was how many organisations are now experiencing pressure externally.
Not necessarily from regulators directly.
But from:
- customers
- procurement teams
- larger supply chains
- security questionnaires
- contractual requirements
For many businesses, cybersecurity expectations are no longer internal decisions.
They are becoming part of commercial trust.
The Businesses Handling This Best Treat Security as Operational
The strongest organisations in the discussion did not seem to separate:
- operations
- security
- compliance
Instead, they treated them as interconnected.
That usually meant:
- clearer processes
- better visibility
- more consistent evidence
- fewer last-minute surprises
And interestingly, it often reduced operational friction rather than increasing it.
Final Thought
One thing became very clear during the conversation:
Most people are not resisting security.
They are resisting unnecessary complexity.
The organisations building strong security cultures are usually the ones making secure behaviour:
- understandable
- practical
- visible
- and sustainable
That is very different from simply producing more policies.
Thanks
A huge thank you to everyone in the networking group who contributed perspectives and experiences to the discussion.
It was refreshing to hear practical, operational conversations about cybersecurity instead of just theoretical ones.
Contributors
Zayed from Akhirah Lab www.akhirahlab.com
Expert web development, SEO, Meta Ads, and PPC lead generation tailored for wellness, fitness, healthcare, real estate, and trade businesses.
Peter Williams SMS tech www.sms-tech.org
Support businesses to digitalise operational areas – they also hold accreditation in ISO 27001
