Cybersecurity Leadership Conversations
When Employees Make Mistakes: Creating a Culture of Growth, Not Fear
Bob Shannon and Dan Pitre explore what happens when employees make security mistakes—and why punishment-based approaches backfire.
Watch on YouTubeFull Transcript
Trust as the Foundation
Dan Pitre: So trust is basically the bottom line when it comes to integrating cybersecurity into the culture of an organization. You gave an example of someone clicking on something and being hesitant to speak up. That example can be demonstrated across roles.
Bob Shannon: We may have introduced a tool set that introduced a vulnerability. We may have developed a new software module that had some vulnerabilities that weren't recognized right away. When we can come to the table and be honest about things that were missed, the risk it has introduced—that builds trust amongst your peers. As opposed to hiding that and having someone else bring it to the table.
Integrity from Both Sides
Dan Pitre: What I liked about what you said was looking at it from the integrity of the leadership of the organization. You've introduced this process, procedure, or system. While we think it's the best available for the organization, there may be flaws we just don't know about.
Bob Shannon: The natural tendency is to be defensive—"I'm sure that it worked, you must have done something else." Instead of saying "wait a minute, this is an issue. Own it. I own the problem, it's my system. Tell me, because I want to stop this and take a deeper dive." That's integrity. That's an integrity model demonstrated from the organizational leadership side.
Building Relationships Across the Business
Dan Pitre: Achieving trust is through the building of relationships. Being transparent and candid when issues occur, but also proactively building relationships across the business.
Bob Shannon: Cybersecurity is not just the role of IT or the security team—it's the role of the entire organization. IT and the security team need to proactively reach out to all business units, starting from the C-Suite level, upper and middle management. Build one-on-one relationships. Understand the subculture within their departments. Understand what's important to them, what keeps them up at night—not just from an IT perspective, but what's on their roadmap, their objectives, goals, and deadlines.
Organizational Turbulence
Bob Shannon: We call it organizational turbulence. We've all been on airplanes with mild turbulence—no big deal. But if you've ever been on one where you're wondering if it's going to stay in the air, that's the type of constant change that can happen in an organization. It puts people in a fear paradigm. Then they get out of proactive accountability into reactive accountability. People put their head down, and then you get malicious compliance.
The Growth Mindset
Dan Pitre: When teams are going through exercises where there are setbacks and leadership is right there along with the team, guiding them through—that lessens the fear aspect. If people are allowed to make mistakes and the focus is on "how do we remediate this? How do we move forward?"—that's the teamwork that makes a team more resilient.
Bob Shannon: We call that the growth mindset. There's going to be hiccups, there's going to be turbulence. I used to look at it as punitive—something bad was going to happen. We actually turned that mindset to "this is a growth opportunity." Now we have transferable knowledge and skills to avoid or see things in the future.
Bob Shannon: Unfortunately, a lot of organizations don't do that. Somebody makes a mistake and they're out of there. They lose out on a good employee that may have just had a simple mistake—and it might have been on the fault of the leadership team themselves.
Resilience Through Growth
Bob Shannon: Resilience is built by allowing people to go through that growth. So now they're resilient—they know they can get through the next one. Their mindset is open: "Let's look for these things in the periphery that just haven't happened yet." Now they're looking for ways to grow. What a great place for an organization to be.
Change Management and Executive Sponsorship
Dan Pitre: It's important to be tapped into the change management structure and processes and build relationships with the leaders in that space and their middle management staff.
Bob Shannon: When you're introducing cybersecurity tools into the organization, or when your security team has to assess other changes being introduced—you can be perceived as the blocker, the unit that's going to delay the rollout. When you build relationships amongst that change management board, you all get to understand where each person is coming from. That reduces friction across teams.
Dan Pitre: It's important to have that executive-level sponsorship. When the executive team is advocating for the change, people are more invested in finding a way to make it work. Rather than "this is something we can't do because of XYZ," it's more of "you really need to be aware that this is what you're going to be doing to this company. How do we work through that?"
Bob Shannon: The C-Suite should be focused on growing the organization. What is the future? Where are our threats? Where are we going? I was listening to a McKinsey podcast about the impact AI is having on the C-Suite—they're running with their hair on fire trying to get ahead of this. What's new and important today is last week's news. It's moving so fast. But cybersecurity is all part of it, especially when AI is introduced.
Dan Pitre: AI and cybersecurity are no longer separate entities. They're not mutually exclusive—one doesn't exist without the other. Whether we're talking about tools that aid cybersecurity in finding threats and processing data points, or innovation and productivity drivers for how AI helps streamline that. The foundation needs to be a strong cybersecurity posture.