The 60 Second CISO · E02

Building a Cybersecurity Culture: Why You Need a Steering Committee

Cyber security culture does not improve because a policy exists or the security team keeps repeating the same message. It improves when leaders, team owners, and key functions are involved in steering decisions together instead of leaving cyber to run in isolation.

E02Direct answerReviewed 2026-07-06The 60 Second CISO

Direct answer

Direct answer

If you want cyber security to become part of the culture, the work needs visible buy-in, cross-functional involvement, and a simple steering rhythm that keeps leaders, process owners, and departments engaged in the decisions. Without that, security stays trapped inside a silo and people are far less likely to feel ownership over what the organisation is trying to improve.

Culture needs ownership

The Power of a Steering Committee

Security culture becomes real when people outside the security function feel that they have a role in shaping it. That means bringing the right leaders, team owners, and process owners into the conversation instead of trying to drive everything through one department. A cyber security steering committee is often the most practical way to do that. It does not need to be over-engineered. In many organisations it can simply be an hour every six months, provided the right people are in the room and the conversation is used to steer real priorities. The point is not to create ceremony. The point is to understand what is actually happening across the organisation, bring decision-makers into the process, and make security part of how the business is run rather than something imposed from the side.

Where culture usually breaks

Why culture breaks down in silos

Security culture weakens when teams work in isolation, make assumptions about each other, and presume that someone else already understands the operational reality. That is how controls drift, communication slows, and buy-in disappears. If departments are not involved, they are far more likely to see cyber as a separate agenda rather than part of the way the organisation makes decisions. Involving them changes that. People become invested because they have contributed to the discussion and can see how the decisions connect to their own responsibilities. That is why good communication matters so much here. A steering rhythm forces the organisation to stop presuming, talk honestly about what is going on, and keep cyber tied to operational truth rather than theory.

What this usually looks like

Signs cyber is still being handled in isolation

When cyber is not yet part of the culture, the problem usually shows up in ownership and communication long before it shows up in a policy review.

  • Security decisions are still being made by one team without regular input from operations, finance, HR, legal, product, or other process owners.
  • Leaders say cyber matters, but there is no simple forum where key stakeholders come together to review priorities or blockers.
  • Departments are surprised by security requirements because they were never involved early enough to understand the reasoning behind them.
  • People work around controls because they do not feel connected to the decisions or do not think anyone has listened to how the work really happens.
  • Important assumptions keep going unchallenged because teams are not speaking openly enough about what is actually happening across the organisation.

What good looks like

What a workable steering rhythm looks like

The aim is not a grand governance machine. It is a simple rhythm that keeps the right people informed, involved, and invested.

  • A steering committee that meets on a practical cadence, sometimes as little as an hour every six months if that is enough for the organisation’s size and pace.
  • Representation from key functions or team leaders who understand operational reality, dependencies, and where security decisions will actually land.
  • A clear view of what is changing in the organisation so cyber priorities are being steered against current reality rather than old assumptions.
  • Open discussion of blockers, trade-offs, and ownership so decisions do not disappear into silence between departments.
  • Follow-through that turns the meeting into a working governance rhythm instead of a one-off discussion nobody feels accountable for afterwards.

Where this usually fits

Need help establishing governance and building a stronger security culture?

If cyber still depends too heavily on one team, one champion, or one periodic conversation, the next step is often a vCISO-style governance route. That gives the organisation a steadier steering rhythm, clearer ownership, and a more practical way to bring the right stakeholders into security decisions over time.

Contact Lateral EdgeBook a discovery callSee Virtual CISO

Useful questions

Frequently asked questions

What is a cyber security steering committee?

It is a simple governance forum that brings together key leaders, team owners, or process owners to review security priorities, blockers, and decisions in a more joined-up way. The purpose is to steer the work with real organisational input rather than leave cyber operating in isolation.

Who should be involved in a steering committee?

That depends on the organisation, but it usually includes leaders or owners from the areas most affected by cyber decisions. Operations, IT, finance, HR, legal, product, and process owners are common examples. The key is to involve people who understand how the organisation really works.

How often should a cyber security steering committee meet?

There is no universal cadence. For some organisations it may only need an hour every six months. For others it may need to meet more often. The right frequency depends on the pace of change, the level of governance pressure, and how much active steering the organisation currently needs.

Can smaller organisations do this without creating bureaucracy?

Yes. The point is not to build a heavy governance layer. Smaller organisations often benefit from a deliberately light-touch version that keeps the right people involved without creating an administrative burden that nobody values.

When should outside help support governance and culture?

Outside help makes sense when leadership wants stronger buy-in and ownership but the current rhythm is inconsistent, siloed, or too dependent on one individual. It is especially useful when the organisation needs someone to help structure the governance pattern and keep it commercially practical rather than theoretical.

Read or route next

Keep the momentum practical

Next route

Browse the series

See the episode archive and future short-form cyber answers.

Next route

Browse all advice

Move from the episode into the wider advice hub for related situations and answers.

Next route

See Virtual CISO

Use this route when the business needs recurring senior ownership and governance rhythm.

Next route

See security programme ownership

See how retained support helps keep roadmap, governance, and follow-through moving together.

Next route

See board security reporting

See how retained support improves executive oversight, reporting rhythm, and clearer leadership decisions.

Need help now?

Need help building governance and a stronger cyber security culture?

If the organisation needs clearer ownership, better cross-functional involvement, or a steadier way to steer security decisions, now is the right time to put a workable governance rhythm in place.

Get governance supportBook a discovery callSee Virtual CISO