The glass ceiling of security culture—and how to break through it

#
Awareness Measurement
#
Information Security
#
Security Awareness
#
Awareness Strategy
A pie chart illustrating safety culture and its levels

In management research, the “glass ceiling” describes an invisible barrier that prevents advancement to the highest levels. A structurally similar phenomenon exists in security culture: Many organizations reach a solid mid-level—and rarely go beyond it.

The plateau as an empirical reality

The long-term analysis of the Security Awareness Radar (SAR) over 20 years reveals a remarkable pattern: Despite general professionalization, the proportion of organizations with a “very good” security culture remains within a range of 10–13%. At the same time, the proportion of insufficient cultures has fallen from around 40% (2004–2012) to 13% (2019–2025).

The conclusion: Broadly speaking, there has been clear progress—security is no longer a marginal issue. But the path from “good” to “very good” is far more difficult. Meeting basic requirements is achievable for many; a deeply rooted, cross-functional culture of excellence remains the exception.

What keeps organizations stuck at the “good” level

The data provide a clear answer as to why many organizations fail to break through the ceiling. It is not due to a lack of knowledge or a poor attitude. These factors are already at a high level even at the “good” stage. The decisive differentiating factors lie in:

  • Problem management: Are incidents handled with a focus on learning or on punishment?
  • Motivation: Does commitment to safety go beyond merely fulfilling one’s duties?
  • Role modeling: Is safe behavior visible and consistent at all levels of the hierarchy?
  • Cultural embedding: Is security part of the organizational identity or just an add-on?

Path 3 of the roadmap: strategic breakthrough

The Security Culture Code outlines a specific development path (path 3) for organizations moving from “good” to “very good.” The focus is not on additional sets of rules or training content, but on the quality of social embedding. Specifically, this means:

  • Building a positive reporting culture: Security incidents must be reportable without fear of blame.
  • Systematically using near-misses as learning opportunities rather than as scandals.
  • Security champion networks that communicate security issues in a decentralized and credible manner.
  • Visible recognition of safety-compliant behavior—not just penalties for violations.

Why case study B is so informative

A multinational organization (25,000–50,000 employees) increased its Security Awareness Indicator from 49.1 to 71.1 over the course of seven years—a jump of nearly 45%. The secret: training, communication, problem management, and work design were improved simultaneously and in a coordinated manner. This case demonstrates that significant strides in maturity are possible—but not through isolated measures, rather by simultaneously activating multiple cultural levers.

Conclusion: excellence is no accident

The glass ceiling is real, but not insurmountable. Organizations that break through it share the common trait of viewing safety not as a compliance obligation, but as part of their professional and organizational identity. This requires visible leadership, psychological safety in dealing with errors, and the consistent embedding of safety into the organization’s cultural operating system.

You can request the full report on 20 years of SAR and the insights it provides HERE free of charge.

Reach us using our contact form

If you need support write a short description of the problem in the “Message”.

Thank you very much! We will answer your request as soon as possible.
Oops! Something went wrong when submitting the form.

Please contact us directly at info@treesolution.com.
Newsletter

Don't miss any more news about cyber security awareness and get tips and tricks for employee training in your company.

Thank you for subscribing to our newsletter.
Something went wrong when submitting the form.

Related blog articles

#
Awareness Strategy
#
Security Awareness
#
Information Security
#
Cyber Security

What are the real benefits of security awareness and how to demonstrate the ROI of prevention

#
Trends
#
Cyber Security
#
Awareness Kampagnen
#
Security Awareness

Phishing 2025: How modern social engineering attacks work—and how to spot them

#
Security Awareness
#
Information Security

Security Awareness Webinars for Employees

Umschlagsymbol

Form, E-mail, Phone

You can fill out a short form or send us an email. We will get back to you within two working days. You can also call us directly. Click on "Contact" and you will receive all the necessary contact details.

Kalendersymbol

Free online consultation

If you would prefer to book a specific appointment, you can do so by clicking on the blue button below. The online booking system will open in a new window and you can schedule your free consultation.