Elnion
No Result
View All Result
Monday, September 14, 2026
  • Login
  • AI
  • Cloud
  • Data
  • Digital Enterprise
  • Telco & Mobile
  • Cyber Security
  • Infrastructure
  • Automation
  • Supply Chain
Subscribe
Elnion
  • AI
  • Cloud
  • Data
  • Digital Enterprise
  • Telco & Mobile
  • Cyber Security
  • Infrastructure
  • Automation
  • Supply Chain
No Result
View All Result
Elnion
No Result
View All Result
Home Cyber Security

Cyber Security Advocacy’s Benefit to SMBs

by Heather Noggle
July 22, 2024
in Cyber Security, Training
0
Share on TwitterShare on LinkedInShare on Facebook

Projects go nowhere without champions. Organisational initiatives compete for scarce resources, and change in any direction can be threatening. For that reason, changes require those champions. For SMBs, cybersecurity improvements are changes that shake the organisation’s culture. The advocate role can help an organisation clarify the what, why, how, and effect of technical and business operational changes that arise when an organisation embraces a new level of cyber security.

What Is Cyber Security?

Cyber Security can be clearly defined as people, processes, and technology working together to protect the confidentiality, integrity, and availability of data and systems.

Because of interrelated world operations connected via the internet – which was built to disseminate information – securing private competitive advantage and personal details is a business pillar.  

Why Does My Organisation Need to Change Regarding Cyber Security?

Smart phones put full computers in our pockets. Products our organisations use add risk to our operations. This was highlighted as recently as this week by cyber security vendor CrowdStrike, who released a flawed software update that disabled Windows computers that received that update.

Even if your organisation wasn’t affected by the CrowdStrike change, cyber security news is a good conversation point, as each company needs to improve its cyber security.  Why?  Technology is changing, and there’s no plan for companies to move their profitable business operations to an offline model. Morphing technology threats and opportunities are, therefore, impactful influences on modern business.

CrowdStrike and its competitors build products to detect threats and help organisations mitigate those threats.  Your organisation can intentionally help its workers to understand the threats it faces, what it’s doing to mitigate risk, and how some of those changes may impact operations.

Enter the advocates.

What Is a Cyber Security Advocate?

NIST – the US National Institute of Standards and Technology – researcher and expert Julie Haney outlines the role in her paper shown here.

Technology and changes that arise from it deeply affect culture within an organisation.  Couple that with confusion about the reason for the change which may seem detrimental to the workers who need to work differently because of it. Additionally, organisations may require workers to add whole new processes and procedures as they mature their cyber security. To those affected, the changes may seem like Unnecessary Toil, which is a great song you can find on Spotify by a group called Artisan and appearing on their album Breathing Space.

Advocates tie the what of the change to the why and impact the change brings now and in the future, and they do so in language workers can understand.  Advocates can expect to receive some pushback and initial distrust, however.

Cultures that foist changes without explanation might find they lose their workers.  Clear advocacy can help offset this and also boost the adoption (and effect) of changes to bolster cyber security efforts.

Emerging technology requires that organisations actively fight technical and security debt, and advocates can help explain why and future impact.

Who Makes a Strong Cyber Security Advocate?

Candidates for cyber security advocacy need to be able to speak both the vernacular language and technology with equal skill. Advocates must both understand what’s at stake and then communicate that to skeptical coworkers who may neither understand nor agree…and do so in words the audience doesn’t find threatening.

Simple, yes.  Easy, no. The advocate must be able to articulate the why of a cyber security relevant change, the positive effect, and how to mitigate any negative consequences to how workers operate.

Cyber security enables the modern workplace to continue to operate. That’s positive but also unclear. How? The organisation doesn’t even seem to be under attack to its workers.

Advocates can explain the “whys” of individual policy and the resulting proposed and implemented process changes. They speak to cause, effect, and what’s in planning and built trust in a pleasant manner. Larger organisations might be able to employ a BISO – a Business Information Security Officer – whose staff members may take this role. For companies and non-profits with fewer staff members, advocates likely also work in  another role – the role for which the person was hired.  Stated another way – cyber security advocacy is often one of those “other duties as assigned” scenarios.

Advocacy is most effective with clear communication. Overall culture benefits from this as well.  Younger generations especially value strong corporate culture, and the cyber security advocacy work can be viewed as service oriented.

Summary

As you review the temperature and successes and failures of corporate culture in light of cyber security and upcoming changes, consider adding cyber security advocates within your ranks. Seek interested individuals who see the value of continuing to mature cyber security practices and related efforts.

Work within your culture and not against it, and the sooner you begin, the more positive impact you will likely realize.

Unify your organisation with cyber security advocacy efforts (and understanding) from members from information technology, cybersecurity, human resources, management, operations, and leadership.  Build beyond compliance and into maturity, and then adopt this same level of communication for non-technical changes that affect staff members.

Tags: change managementCultureCyber Security
Heather Noggle

Heather Noggle

Heather Noggle is the owner of Codistac, a company that provides writing and software guidance to startups and other technology companies. She excels with work that addresses the intersection of people and technology. Heather has built a career consisting of over 25 years of experience in technology and operations, and is a Certified Secure Software Lifecycle Practitioner (CSSLP) by (ISC)² and also holds the Security+ from CompTIA. She regularly shares insights & expertise in blogs & articles on topics such as process and cybersecurity integration, strategic writing, entrepreneurship, SMB advocacy, systems thinking, export compliance and automation, and innovation.

Related Posts

Cyber Security

The Quantum Cybersecurity Imperative: Securing the Mining Enterprise for the Future

August 29, 2026
Cyber Security

Open Secure AI Alliance: A Pragmatic Imperative for Digital Defence

July 31, 2026
Cyber Security

Executive Overview of the Notifiable Data Breaches (NDB) scheme

August 5, 2026
No Result
View All Result

Recent Posts

  • The 80% Crisis: UK Data Leaders Warn Our Data Isn’t Ready for AI
  • The AI Illusion: Craig S. Mullins Exposes The Hidden Costs Crippling Modern Data Architectures In His Latest Book
  • The 80% Crisis: America’s Data Leaders Warn Our Data Isn’t Ready for AI
  • Building No-Regret Quantum Readiness in the Mining Sector
  • The Quantum Cybersecurity Imperative: Securing the Mining Enterprise for the Future
Elnion

© Sociaall Inc.

Navigate Site

  • Home
  • Privacy Policy
  • Contact Us

Follow Us

No Result
View All Result
  • Home
  • Cloud
  • Data
  • Digital Enterprise
  • Telco & Mobile
  • Cyber Security
  • Infrastructure
  • Automation
  • Supply Chain

© Sociaall Inc.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In