Back Issues This Week → Calendar → Current Issue → Popular →

All issuesVolume 341, Issue 1IT NewsCxO

How CISOs Can Use Risk Assessments to Drive Security Culture

TechTarget, Tuesday, August 4th, 2026

Risk assessments become powerful culture-building tools when their findings are communicated beyond the security team.

Organizations often conduct risk assessments but fail to share findings beyond security teams, leaving business stakeholders to view controls as barriers rather than protections.

CISOs can use assessments to drive cultural change by translating cyber risk into business language, securing executive buy-in, and reinforcing security-aligned behavior through repeated messaging.

Key strategies include assessing baseline security attitudes, rewarding positive behavior, treating failures as learning opportunities, and staying accessible to employees. Success requires years of effort involving leadership alignment, transparent communication, and consistent reinforcement.

more →  ·  More from CxO →