Security Culture: From cyber awareness to assurance

Practical research, tools and guidance to help you test your people, strengthen your AI decisions and protect what your organisation cannot afford to lose.

Array

Awareness is measured. Assurance is proven.

Most organisations have run security awareness programmes for years, and their people can recite what to watch for. Cyber resilience depends on what happens next: whether an employee raises a concern about a colleague, how the organisation demonstrates that an AI decision was approved, and its ability to keep critical services running during an incident.

The ISF Cyber Resilience Resource Kit helps security leaders move from awareness to assurance. Drawing on ISF research and the experience of Member organisations, it covers insider risk, AI governance and operational resilience. Each section gives you questions to put to your own organisation and practical resources to act on the answers.

Unclear crisis roles have topped ISF exercise findings since 2021

ISF has run crisis simulation exercises with hundreds of organisations. Every year since 2021, the most common finding has been the same: unclear crisis roles, responsibilities and decision-making authority.

Most of the people in those exercises had completed their awareness training, yet the gap only appears once they are tested under pressure.

Three moments that test your resilience

  • A line manager notices a colleague downloading files they have no reason to touch
  • An auditor asks who approved the AI tool your finance team already relies on
  • A ransomware attack takes out a core system on a Monday morning

Each one tests judgement, ownership and preparation, and none of them shows up in a training report.

Questions worth putting to your own organisation

Would anyone say something?

A quarter of insider incidents are malicious. Line managers are best placed to notice, yet most never consider insiders a threat.

Could you defend your AI decisions?

Only half of organisations have an AI policy, and just 4% of those can show basic governance maturity.

What could you not afford to lose?

Few organisations have defined the handful of services they cannot function without, agreed it across the business and tested it.

Download your ISF Cyber Resilience Resource Kit

Inside your kit:

  • spot the insider behaviours that matter and test whether your people would raise them
  • put six questions to your AI governance and see whether your decisions stand up to scrutiny
  • identify what your organisation cannot afford to lose and prove it holds

 

*We’ll email your resource kit link straight to your inbox, so please provide a valid work email address.

ISF Cyber Awareness Webinar Showcase

5 – 15 October 2026

Two weeks of expert-led webinars exploring key topics including: insider threat, supplier security, AI governance, post-quantum cryptography, cyber regulations and strategies for safeguarding your organisation’s crown jewels.

Explore and register for the series