
Using TreeSolution’s Security Awareness Radar (SAR), a total of 88 organization-wide surveys were conducted between 2004 and 2025, involving over 100,000 participants and approximately 4.5 million individual responses. The result is clear: The domains of "Knowledge" and "Values" are at a comparatively high level across all maturity levels. Even organizations with an “insufficient” security culture score an average of 62 points on a scale of 0 to 100 in the “Knowledge” domain—and as high as 83 points in the “Values” domain.
So what explains the difference between a mediocre and an excellent safety culture? The answer lies in other domains. The largest gaps between “insufficient” and “very good” are found in:
Many organizations have created a paradox in which their employees know very well what they should be doing—but still fail to do it consistently in their day-to-day work. The reason: knowledge and behavior are not the same thing. Standing between understanding a safety rule and applying it in daily practice is the organizational reality: unclear processes, a lack of role models, cumbersome reporting channels, and a corporate culture that does not truly prioritize safety.
The consequence: Beyond a certain point, producing more training content yields diminishing returns. Those who want to achieve the next leap in maturity must adjust other levers.
The Security Culture Code describes this shift as the transition from knowledge transfer to organizational attention. It’s not about giving employees even more information. It’s about making security visible, manageable, and second nature in everyday life.
In concrete terms, this means: Leaders discuss security incidents in meetings. Security-related processes are integrated into daily work, not added on as an afterthought. Incident reports are used as learning opportunities, not punished. And security regularly appears on the agenda of leadership bodies—not just when something has gone wrong.
Training and education form the necessary foundation. They provide basic knowledge, raise awareness, and establish minimum standards. But the real leap forward in maturity only occurs when security culture is understood as a leadership responsibility and becomes part of the organization’s communication and decision-making routines. Anyone who wants to decipher the Security Culture Code must think beyond the logic of training.
You can request the full report on 20 years of SAR and the insights it provides HERE free of charge.