Group Purchasing
Group Purchasing

Security’s Identity Problem: Why We Fail Our Internal Customers

Security’s Identity Problem: Why We Fail Our Internal Customers (PDF, 2.06MB)Last updated: 27 Aug, 2026
Presented by:

I spent six months redesigning a security team's materials. New structure, clearer guidance, knowledge organised around the questions people ask. It looked great. Within six months, the team reverted to blocking behaviours. We'd rearranged the furniture without changing how security saw itself. That failure taught me something most security culture programmes miss. We spend effort on the visible layer: policies, awareness campaigns, reporting dashboards. When nothing sticks, we blame "the culture." But the root cause is deeper: the security function's own identity. How a security team defines its purpose shapes every interaction the organisation has with it. Existing frameworks target the awareness programme and its maturity. This talk targets what sits beneath: the security team's self-concept. "We protect the organisation" and "we serve the organisation" produce completely different behaviours, metrics, and relationships with the business. I'll introduce a sequenced model for identity-first culture change, tested across two organisations: a technology consultancy and a UK government body. The sequence matters. Change identity, then incentives, then narratives, then systems. The visible behaviours follow. Reverse that order (start with systems, hope behaviours stick) and you get my failure story. I'll share specific artefacts: persona cards for security's customers, service menus that replaced document libraries, and the metrics that replaced "exceptions denied." I'll address the risk nobody calculates: the cost of security information not reaching the people who need it. You'll leave with: A five-step sequence for identity-first culture change A customer experience audit you can run next week Measurement approaches that show the shift is working Language for making the case to leadership, even if you don't set the metrics yourself

SANS Security Awareness Summit 2026