Home » Psychological Safety Key to Strong Cybersecurity Culture

Psychological Safety Key to Strong Cybersecurity Culture

By Ayomide Otitoju

Cybersecurity training remains essential, but experts warn it is insufficient without a workplace culture that encourages employees to speak up without fear. Effective corporate security awareness, they say, is built on psychological safety — an environment where staff feel comfortable reporting concerns, questioning instructions and admitting mistakes.

Anna Collard, Senior Vice President of Content Strategy at KnowBe4 Africa, describes psychological safety as an overlooked but critical element of organisational cyber resilience. “It refers to an environment where employees feel confident they can slow down to question suspicious activities, report concerns, admit mistakes and challenge instructions without fear of blame or retaliation,” she said.

Collard compared the dynamic to parenting. Harsh reactions to honest admissions, she noted, teach children to lie. “If a child tells you they broke a vase and you react with anger, they learn that telling the truth leads to a bad outcome.”

She warned that even organisations with top-tier security awareness training must ask what happens when employees confess significant cybersecurity errors — and what consequences staff expect.

According to Collard, several toxic workplace dynamics undermine security reporting. A blame-first culture is the most damaging, she said, as employees quickly learn to hide incidents to avoid punishment. Perfectionist management styles, siloed security teams and inconsistent messaging from leadership further discourage open communication.

“Employees become silent when they fear consequences,” she said. “And when security is framed as perfect compliance or failure, staff avoid admitting uncertainties.”

However, organisations can reverse these trends. Collard highlighted the value of “blameless post-mortems,” citing GitLab’s 2017 incident where an administrator accidentally deleted a production database. The company responded transparently and treated the event as a learning opportunity rather than a failure. “A culture of openness meant the issue was addressed immediately, with no cover-ups,” she said.

She also recommended appointing security champions across departments, rewarding proactive reporting and encouraging leaders to model vulnerability and continuous learning. Framing employee mistakes as insights into attack sophistication, rather than user failure, helps reinforce positive feedback loops.

Collard further urged leaders to adopt zero-trust principles, which rely on continuous verification — a model that only functions when employees feel safe raising concerns. Digital mindfulness, she added, also strengthens organisational resilience by encouraging staff to slow down and seek help instead of rushing under pressure.

“The most secure organisations are not those that expect perfection,” Collard said, “but those that enable people to speak up, learn and respond quickly when something goes wrong. Psychological safety is a critical foundation for any organisation serious about cybersecurity resilience.”

Comments (0)

Your email address will not be published. Required fields are marked *