Skip to content

Security Culture

Summary

Security culture is the set of habits, norms, and shared expectations a group develops to protect its members, its operations, and its information from surveillance, infiltration, and accidental disclosure. It sits between the operational discipline captured in digital-security and the broader organising culture a movement needs to sustain its work under pressure.

Body

Security culture is what makes digital security operational rather than aspirational. A group can adopt Signal and a password manager and a threat-modelling checklist and still leak sensitive information through the operational habits of its members — discussing a sensitive campaign in a coffee shop, sharing a screenshot of an internal document with a name attached, leaving a meeting venue without sweeping the room for devices [source: holistic-security-tactical-tech]. The Holistic Security Manual treats security culture as the organisational-security dimension of its three-part framework (digital, psychosocial, organisational) and is explicit that the three dimensions must be planned together; a group with strong digital-security habits and weak security culture will leak through the organisational dimension, and a group with strong security culture but no digital-security habits will leak through the digital dimension [source: holistic-security-tactical-tech].

The habits that make up security culture are mundane. They include: not discussing sensitive operational details in untrusted spaces; using disappearing-message timers consistently rather than only when reminded; treating a screenshot of an internal document as a sensitive artefact that is shared deliberately, not by default; treating meeting venues as potentially surveilled and choosing them with the same care a defender chooses a secure-messaging app; treating doxxing threats as a foreseeable hazard and rehearsing the response before an incident requires it [source: holistic-security-tactical-tech][source: m4bl-toolkit]. The discipline is not that the group never makes a mistake — mistakes are inevitable — but that the group’s shared expectations catch the mistake before it becomes an incident, and that the post-incident review treats the mistake as a culture gap to close rather than as an individual to blame [source: holistic-security-tactical-tech].

EFF’s Surveillance Self-Defense supplies the individual-side discipline that security culture aggregates. The threat-modelling question — what do I want to keep private, who do I want to keep it from, what happens if they succeed — is the unit of analysis at the individual level; security culture is what happens when that question is asked at the group level and answered consistently across the group [source: ssd-eff]. The Movement for Black Lives coalition’s coalition-maintenance toolkit treats security culture as a coalition-wide discipline, with attention to the asymmetric-habits problem when coalition partners have very different security postures — a real challenge when one partner operates with threat-modelling discipline and another operates with broadcast-and-respond habits [source: m4bl-toolkit].

Security culture is closely related to digital-security (the individual discipline it aggregates), protection-planning (the explicit planning it underwrites), holistic-security-tactical-tech (the practitioner source that names the three-part framework), and organizing (the broader culture in which it sits).

Worked examples

Use it for

Designing a security-culture onboarding for a new member; running a security-culture review after an incident; aligning a coalition’s security habits across partners with different postures; choosing the operational habits a group will enforce consistently; closing the gap between digital-security adoption and security-culture discipline.

Learn more

FAQ

What is security culture?

Security culture is the set of habits, norms, and shared expectations a group develops to protect its members, its operations, and its information from surveillance, infiltration, and accidental disclosure. It sits between the operational discipline captured in digital-security and the broader organising culture a movement needs to sustain its work under pressure. Security culture is what makes digital security operational rather than aspirational.

How does security culture interact with digital security?

A group can adopt Signal and a password manager and a threat-modelling checklist and still leak sensitive information through the operational habits of its members — discussing a sensitive campaign in a coffee shop, sharing a screenshot of an internal document with a name attached [source: holistic-security-tactical-tech]. The Holistic Security Manual treats security culture as the organisational-security dimension of its three-part framework (digital, psychosocial, organisational) and is explicit that the three dimensions must be planned together [source: holistic-security-tactical-tech].

What habits make up security culture?

The habits that make up security culture are mundane. They include: not discussing sensitive operational details in untrusted spaces; using disappearing-message timers consistently; treating a screenshot of an internal document as a sensitive artefact; treating meeting venues as potentially surveilled; and rehearsing the response to doxxing threats [source: holistic-security-tactical-tech] [source: m4bl-toolkit]. The discipline is not that the group never makes a mistake — mistakes are inevitable — but that the group’s shared expectations catch the mistake before it becomes an incident.

What is the EFF threat-modelling discipline?

EFF’s Surveillance Self-Defense supplies the individual-side discipline that security culture aggregates. The threat-modelling question — what do I want to keep private, who do I want to keep it from, what happens if they succeed — is the unit of analysis at the individual level; security culture is what happens when that question is asked at the group level [source: ssd-eff]. The Movement for Black Lives toolkit treats security culture as a coalition-wide discipline with attention to the asymmetric-habits problem [source: m4bl-toolkit].

Sources & verification