Mega trends

A new age of cybersecurity culture

Published on
April 30, 2024

Cyber Human Risk Management (HRM) is essential to cybersecurity culture, as the way people manage technology is the window through which threat actors can infiltrate organisations.

In all organisations, but particularly ones with diverse ways of working across geographies, building a comprehensive and sustained cybersecurity culture can be challenging. Cybersecurity culture complexities can include how to overcome change resistance, how to adopt emerging technologies securely without slowing down innovation, how to manage interconnected systems securely, how to make the most of metrics and measurement, and more.

KPMG, along with Cybersecurity at Massachusetts Institute of Technology (MIT) Sloan (CAMS), part of Sloan Management School Cybersecurity Research Division, set out to gain a better understanding of cybersecurity culture, its challenges, and how AI could make an impact.

Read the full survey findings to learn how AI can impact cybersecurity culture, and in turn CRQ.

Our blog

Latest Insights

The latest from the CRI community.
Resilience

A risk-based approach to cyber budgets

Cybersecurity budgets are often poorly aligned with the actual level of risk to the organisation. Such misalignment can be driven by local challenges measuring and quantifying cyber risk, but it is compounded by the challenge of mapping perceived risk levels to security staff levels, controls, and approaches to risk mitigation. This article suggests a practical framework for leaders on how risk can become the driver of budgeting decisions.
Akhilesh Tuteja
July 24, 2026
3 min read
Resilience

The evolving intersection of risk and resilience

A board decision lens for rebalancing prevention, containment, questions for deciding what to prevent, what to contain, and what to withstand.
James Hanbury and David Ferbrache
June 24, 2026
11 min read
Resilience

The Future of MDR: From reactive monitoring to intelligence-led attack disruption

In today’s threat landscape, where attacks span identity, cloud, endpoint, data and third-party ecosystems, metrics such as alerts triaged, tickets closed and response times are no longer enough. What matters is whether an organisation can identify the threats that matter, disrupt them before they become business events, and use that insight to make better risk decisions.
Salil Shukla
June 2, 2026
4 min read

See CRI in action

Book a personalised demo and discover how CRI can help you make smarter cyber risk decisions.