Security Culture
Summary
Security culture is the set of habits, norms, and shared expectations a group develops to protect its members, its operations, and its information from surveillance, infiltration, and accidental disclosure. It sits between the operational discipline captured in digital-security and the broader organising culture a movement needs to sustain its work under pressure.
Body
Security culture is what makes digital security operational rather than aspirational. A group can adopt Signal and a password manager and a threat-modelling checklist and still leak sensitive information through the operational habits of its members — discussing a sensitive campaign in a coffee shop, sharing a screenshot of an internal document with a name attached, leaving a meeting venue without sweeping the room for devices [source: holistic-security-tactical-tech]. The Holistic Security Manual treats security culture as the organisational-security dimension of its three-part framework (digital, psychosocial, organisational) and is explicit that the three dimensions must be planned together; a group with strong digital-security habits and weak security culture will leak through the organisational dimension, and a group with strong security culture but no digital-security habits will leak through the digital dimension [source: holistic-security-tactical-tech].
The habits that make up security culture are mundane. They include: not discussing sensitive operational details in untrusted spaces; using disappearing-message timers consistently rather than only when reminded; treating a screenshot of an internal document as a sensitive artefact that is shared deliberately, not by default; treating meeting venues as potentially surveilled and choosing them with the same care a defender chooses a secure-messaging app; treating doxxing threats as a foreseeable hazard and rehearsing the response before an incident requires it [source: holistic-security-tactical-tech][source: m4bl-toolkit]. The discipline is not that the group never makes a mistake — mistakes are inevitable — but that the group’s shared expectations catch the mistake before it becomes an incident, and that the post-incident review treats the mistake as a culture gap to close rather than as an individual to blame [source: holistic-security-tactical-tech].
EFF’s Surveillance Self-Defense supplies the individual-side discipline that security culture aggregates. The threat-modelling question — what do I want to keep private, who do I want to keep it from, what happens if they succeed — is the unit of analysis at the individual level; security culture is what happens when that question is asked at the group level and answered consistently across the group [source: ssd-eff]. The Movement for Black Lives coalition’s coalition-maintenance toolkit treats security culture as a coalition-wide discipline, with attention to the asymmetric-habits problem when coalition partners have very different security postures — a real challenge when one partner operates with threat-modelling discipline and another operates with broadcast-and-respond habits [source: m4bl-toolkit].
Security culture is closely related to digital-security (the individual discipline it aggregates), protection-planning (the explicit planning it underwrites), holistic-security-tactical-tech (the practitioner source that names the three-part framework), and organizing (the broader culture in which it sits).
Worked examples
- asylum-seekers-on-manus-island-hunger-strike-for-better-conditions — the Manus Island asylum-seekers’ campaign illustrates how security culture (operational discipline under hostile surveillance by both state and contractor actors) is the prerequisite for sustained public witness.
- guinean-citizens-general-strike-for-democracy-2007 — the 2007 Guinean general-strike campaign in which security culture (operational secrecy around strike dates and demands) was a precondition for the campaign’s effectiveness.
Use it for
Designing a security-culture onboarding for a new member; running a security-culture review after an incident; aligning a coalition’s security habits across partners with different postures; choosing the operational habits a group will enforce consistently; closing the gap between digital-security adoption and security-culture discipline.
Related
- digital-security
- protection-planning
- secure-messaging
- encrypted-email
- holistic-security-tactical-tech
- ssd-eff
- m4bl-toolkit
Learn more
- On Wikipedia: Security culture — CC BY-SA 4.0
FAQ
What is security culture?
Security culture is the set of habits, norms, and shared expectations a group develops to protect its members, its operations, and its information from surveillance, infiltration, and accidental disclosure. It sits between the operational discipline captured in digital-security and the broader organising culture a movement needs to sustain its work under pressure. Security culture is what makes digital security operational rather than aspirational.
How does security culture interact with digital security?
A group can adopt Signal and a password manager and a threat-modelling checklist and still leak sensitive information through the operational habits of its members — discussing a sensitive campaign in a coffee shop, sharing a screenshot of an internal document with a name attached [source: holistic-security-tactical-tech]. The Holistic Security Manual treats security culture as the organisational-security dimension of its three-part framework (digital, psychosocial, organisational) and is explicit that the three dimensions must be planned together [source: holistic-security-tactical-tech].
What habits make up security culture?
The habits that make up security culture are mundane. They include: not discussing sensitive operational details in untrusted spaces; using disappearing-message timers consistently; treating a screenshot of an internal document as a sensitive artefact; treating meeting venues as potentially surveilled; and rehearsing the response to doxxing threats [source: holistic-security-tactical-tech] [source: m4bl-toolkit]. The discipline is not that the group never makes a mistake — mistakes are inevitable — but that the group’s shared expectations catch the mistake before it becomes an incident.
What is the EFF threat-modelling discipline?
EFF’s Surveillance Self-Defense supplies the individual-side discipline that security culture aggregates. The threat-modelling question — what do I want to keep private, who do I want to keep it from, what happens if they succeed — is the unit of analysis at the individual level; security culture is what happens when that question is asked at the group level [source: ssd-eff]. The Movement for Black Lives toolkit treats security culture as a coalition-wide discipline with attention to the asymmetric-habits problem [source: m4bl-toolkit].
Sources & verification
- sources/holistic-security-tactical-tech — grounding: primary — Terminal T4 (2026-07-01)
- sources/ssd-eff — grounding: primary — Terminal T4 (2026-07-01)
- sources/m4bl-toolkit — grounding: primary — Terminal T4 (2026-07-01)
