Consider a scenario that plays out in organizations every day. An employee clicks a suspicious link. A brief, alarming browser window appears, then disappears. Their pulse quickens. They close the tab and say nothing. They are not malicious. They are not negligent. They are afraid. They have watched a colleague be publicly ridiculed at a staff meeting for a similar mistake. They have read the company’s security policy, which is written in the language of consequences. They have calculated, quickly and probably correctly, that reporting what just happened will cost them more than staying quiet. And so a potential incident goes unreported, unanalyzed, and unlearned from.
This scenario is not an edge case. It is one of the most common and most costly dynamics in organizational security. The human reporting layer sits between an organization and the information it needs to detect threats early, close vulnerabilities, and improve over time. When that layer is choked off by fear, the security program loses one of its most valuable inputs regardless of how sophisticated its technical controls are.
The concept that explains this dynamic is psychological safety, a term developed by Harvard Business School professor Amy Edmondson to describe a shared belief that a team is safe for interpersonal risk-taking. In psychologically safe environments, people feel free to speak up, ask questions, admit mistakes, and raise concerns without fear of humiliation or punishment. In environments that lack it, they do not. The connection to security reporting is direct and consequential.
The Core Problem
Security programs depend on information flowing upward and laterally through an organization with accuracy and speed. Phishing attempts need to be reported. Unusual system behavior needs to be flagged. Accidents involving sensitive data need to be disclosed so that they can be assessed and, where necessary, acted upon. Every one of these reporting acts requires a person to voluntarily surface something that may reflect poorly on them or on their team.
In organizations where the cultural response to security mistakes is blame, public correction, or career consequence, people make a rational choice to protect themselves by staying quiet. The information that reaches the security team is filtered and distorted by fear before it ever arrives. Security leaders in these environments are managing a program based on incomplete data and do not always know it. They may see clean incident metrics and interpret them as evidence of good culture. In reality, the clean numbers may reflect underreporting rather than good outcomes.
Security leaders in fear-driven environments are managing their programs based on incomplete data. Clean incident metrics may reflect underreporting, not strong security culture.
K.C. Yerrid
The inverse is equally important to understand. Organizations with high psychological safety tend to surface more incidents, near misses, and concerns. At first glance, this can appear to be a sign of a weaker security posture. In practice, it is a sign of a healthier one. More reported incidents mean more opportunities to learn, respond, and improve. The organization that surfaces ten minor phishing clicks and addresses each one is in a far stronger position than the organization that surfaces none because no one feels safe coming forward.
What Leaders Do
Psychological safety in a security context is not built through policy or communications campaigns. It is built through repeated behavioral signals from leadership over time. People watch what happens when someone does report a problem. They watch whether that person is thanked or shamed. They watch whether the response focuses on understanding the failure or assigning blame for it. They draw conclusions from these observations and they calibrate their own behavior accordingly.
Security leaders shape this dynamic whether they intend to or not. The security leader who publicly praises an employee for reporting a phishing click is sending a signal that travels far beyond that individual interaction. The security leader who uses a post-incident review to identify the employee who made the mistake is sending an equally powerful signal in the other direction. Culture is not what organizations declare in policy documents. It is what leaders demonstrate through their behavior in consequential moments.
The Harder Work
Many security leaders inherit cultures where fear-based norms are already well-established. Changing those norms is slower and harder than building good ones from the start, but it is not impossible. The foundational step is an honest acknowledgment that the current environment discourages reporting. This acknowledgment does not need to be dramatic or self-critical. It simply needs to be real. Leaders who name the problem explicitly give their teams permission to believe that something is actually changing.
From there, the work is incremental and behavioral. Each individual interaction around a reported incident is an opportunity to reinforce a different norm. Each post-incident review that focuses on systemic conditions rather than individual fault moves the culture one degree in the right direction. Trust is built slowly, through accumulated experience, and it tends to be lost much faster than it is gained. Security leaders who understand this invest in it accordingly, treating every reporting interaction as consequential rather than routine.
The organizations with the strongest security cultures are not necessarily the ones that have had the fewest incidents. They are the ones where people feel safe enough to say what they have seen, admit what they have done, and ask for help when they need it. That kind of openness does not happen by accident. It is the direct result of leadership behavior that has made honesty feel safer than silence. Building it is one of the most consequential investments a security leader can make, and it costs far less than the incidents that go unreported without it.
