An honest look at how executive habits shape security culture, for better or worse
The Example Nobody Means to Set
Most executives would never describe themselves as a security risk. And yet in many organisations, the sticky note under the keyboard, the shared inbox password, and the assistant who handles the two-factor prompts are open secrets. Not because anyone intends harm, but because security has quietly slipped into the category of things that are somebody else's job.
The trouble is that leadership behaviour is contagious. When a CEO visibly treats security protocols as an inconvenience, the organisation notices. Sixty thousand employees don't read the security policy; they read the room.
"I Don't Have Time for This"
It's a fair objection on the surface. Running a company is genuinely demanding, and every new process competes for attention with deals, strategy, and a hundred daily decisions.
But the honest comparison is rarely flattering. A two-factor prompt takes ten seconds. A security briefing takes half an hour a quarter. Set against the meetings that fill an executive calendar, the time cost of good security hygiene is close to zero. When it consistently loses out anyway, the real message isn't "I'm busy". It's "this isn't worth my time", and that message travels.
"I'm Not Technical"
The good news: nobody needs you to be. Modern security asks executives for habits, not expertise. Approving a 2FA prompt, using a password manager, pausing before clicking an unexpected link. These are on a par with learning to use email or unmuting yourself on Teams, and every executive got there in the end.
"I'm not technical" made sense as an objection when security meant configuring firewalls. Today it mostly serves as permission to opt out of things that take less effort than ordering a flat white.
How Apathy Trickles Down
Here's the pattern security teams see again and again:
A leader shares a password with a couple of colleagues to save time. The VP of Sales notices and decides credential-sharing must be acceptable, so his team follows. The regional managers copy them. Within six months, the "secure" CRM has hundreds of people behind a few dozen shared logins, and nobody can say who did what.
A leader grumbles about password policy in a meeting. Finance quietly stops enforcing it. The CISO's training emails start going unread, because everyone has absorbed the idea that security is paranoia for specialists rather than a shared responsibility.
None of these steps feels dramatic. Together they build a culture in which the biggest vulnerability isn't the external attacker. It's the tone set at the top.
The 2025 Reality Check
Meanwhile, the stakes keep rising:
- The average ransomware payment hit £2.1 million in 2024
- 71% of breaches involved compromised credentials
- Executive email accounts trade for £40,000+ on the dark web
- Security posture increasingly features in due diligence, insurance pricing, and enterprise procurement
An acquisition can stall when due diligence turns up a weak security culture. A flotation gets harder to sell when investors ask pointed questions about resilience. These are board-level outcomes with their roots in everyday habits.
Retiring the Old Excuses
"2FA is annoying" - less annoying than explaining a £8 million ransomware loss to shareholders.
"Password requirements are too complex" - a password manager makes them somebody else's problem, permanently.
"Security slows me down" - a genuine incident stops the entire operation, often for weeks.
"We haven't been hacked yet" - neither had British Airways, Tesco, or the NHS before WannaCry. Past performance is no guarantee.
The Mirror Test
A useful exercise for any leader: honestly ask whether you'd pass the standard you expect of your staff. When did you last change a shared password? Have you lent out credentials in the past month? Have you rolled your eyes at a security measure in front of your team?
Nobody enjoys the answers, but the exercise matters because executives are disproportionately targeted and disproportionately imitated. The same visibility that makes a CEO's habits influential internally makes their accounts valuable externally.
The Bottom Line
Executive security habits aren't a personal quirk; they're an organisational signal. In 2025's threat landscape, visible apathy at the top compounds into real business risk, and boards are increasingly right to ask about it.
The encouraging part is how cheap the fix is. Enable 2FA. Adopt a password manager. Sit in on the next security briefing and ask one good question. Small, visible acts of taking security seriously travel through an organisation just as quickly as the eye-rolls did.
The leaders who get this right rarely make headlines, and that's rather the point.
P.S. - If this article prompted you to finally enable 2FA, your security team will be quietly delighted. They may even say so.