The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Ops/The Quality Hub
The Quality Hub artwork

Episode 26 - S4 - ISO 27001 - How to Build a Security-First Culture Part 2

The Quality Hub · 2026-08-12 · 16 min

0:00--:--

Key moments - from our scoring

Substance score

52 / 100

Five dimensions, 20 points each

Insight Density12 / 20
Originality10 / 20
Guest Caliber11 / 20
Specificity & Evidence9 / 20
Conversational Craft10 / 20

Building a mature ISO 27001 culture requires organizations to stop measuring compliance metrics like training completion rates and incident counts, and instead track behavioral indicators such as employee phishing reporting, self-reported security issues, and near-miss disclosures. Tracy Baer emphasizes that a mature security culture shows employees actively participating in defense rather than just clicking through training. For cross-functional alignment across HR, Operations, Legal, and Marketing departments, the key is translating security compliance into department-specific language and automating workflows so security becomes embedded in existing processes rather than adding extra steps. In remote and hybrid environments, organizations face distinct challenges around visibility and employee isolation, requiring automation of human error safeguards (like mandatory lock screens), psychological safety nets that encourage reporting without fear of punishment, and training tailored to home office scenarios. Baer stresses that ISO 27001 certification is a starting point, not an endpoint - sustainability requires treating security like an ongoing fitness routine with sustained micro-learning, public recognition of security wins, and continuous process redesign as risks evolve. The metaphor of security as brakes on a race car captures the core message: proper controls enable faster, more confident business operations.

Key takeaways

  • →Measure behavioral metrics like employee phishing reports and self-reported security incidents rather than training completion rates to assess true culture adoption.
  • →Translate ISO 27001 requirements into department-specific language and automate security tasks within existing workflows so cross-functional teams see compliance as a tool that improves their work, not a burden.
  • →In remote work environments, enforce technical safeguards like mandatory lock screens and build psychological safety so employees report mistakes without fear of punishment rather than hiding them.
  • →Treat ISO 27001 as a living management system sustained through continuous micro-learning, public celebration of security wins, and regular process redesign - not as a checkbox completed after certification.
  • →Frame security controls as confidence-enabling brakes that allow employees to move fast safely, making compliance culturally ingrained rather than compliance-driven.

Guests

Tracy Baer

Topics in this episode

ISO 27001 certificationRisk management systemsphishing simulation testingemployee self-reporting metricshybrid and remote work securitypsychological safety in cybersecuritysecurity training automationHR onboarding platformsmandatory lock screen policiessecurity champions

Questions this episode answers

What metrics should leadership use to measure ISO 27001 cultural adoption instead of incident counts?

Track behavioral indicators like how many employees report phishing emails, submit self-reported security issues, and disclose near-miss incidents. These show employees are taking responsibility for the management system and aware of cybersecurity risks, rather than just clicking through training or avoiding incidents.

How do you align ISO 27001 across different departments like HR, Operations, Legal, and Marketing?

Translate compliance requirements from technical jargon into department-specific language so each team understands how security solves their day-to-day problems. Automate security tasks within their existing workflows - such as embedding training reminders in HR onboarding platforms - so security feels seamless rather than burdensome.

What strategies help maintain security culture and accountability in hybrid or remote work environments?

Use technical enforcements like mandatory lock screens after five minutes, create psychological safety so remote workers report mistakes without fear of firing, and provide home-specific training (like changing router passwords). Build a digital culture of trust alongside safeguards rather than relying on surveillance.

How can organizations prevent ISO 27001 from becoming dormant after certification?

Treat security as an ongoing fitness routine with sustained micro-learning, address emerging risks, redesign processes to remove dangerous workarounds, publicly celebrate security wins, and regularly review whether security is slowing down business - certification is the starting line, not the finish line.

Why is the day after ISO 27001 certification the most dangerous day for a company?

Organizations often treat certification as completion and put the documentation away until the next audit, rather than recognizing that ISO 27001 is a living management system requiring continuous attention, adaptation, and cultural reinforcement as risks evolve.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

12 / 20

The episode delivers several substantive ideas about security culture - shifting from negative metrics to behavioral tracking, localizing compliance to departmental contexts, and treating security as continuous rather than post-certification - but relies heavily on repetition of these core themes rather than introducing new framings. The advice is practical and grounded in the ISO 27001 context but not densely packed; there is noticeable filler (affirmations, throat-clearing) that dilutes insight per minute.

don't look at the training completion rates. That just proves people are uh, taking the training and clicking next. It doesn't show anything about retention
you have to stop making it about security and make it about a day to day problem in that particular area

Originality

10 / 20

The core insights - using behavioral metrics instead of compliance metrics, framing security as a cultural issue not an IT issue, and the brakes-on-a-racecar analogy - are sensible but not novel within the ISO/cybersecurity practitioner community. The emphasis on psychological safety and remote-work considerations is somewhat fresh, but the overall framing recycles well-worn security culture language without sharp contrarian takes or first-principles challenges.

stop measuring compliance, the check boxes and start measuring human behavior
Brakes don't exist to make a car go slow. They may seem like they're there to make a car go slow, but in true form, it's so that the driver has confidence to go incredibly fast

Guest Caliber

11 / 20

Tracy Baer is a Manager of Audit Services at Core Business Solutions, which positions her as a mid-level practitioner with audit experience rather than a C-level operator or exec who has scaled security at a large organization. She speaks competently about ISO 27001 implementation but lacks the visible track record (founding, leading major transformations, or operating at enterprise scale) that would elevate guest caliber. She is a credible ISO expert but not a standout practitioner.

Manager of Audit Services here at Core Business Solutions
to me as well is something that I discuss in detail with customers

Specificity & Evidence

9 / 20

The episode provides minimal concrete examples and no quantified data. The phishing simulation, home router password, and Excel-to-HR-platform migration examples are illustrative but generic; no specific companies, incident counts, timelines, or measured impact figures are cited. The advice remains at a moderate level of abstraction - useful for ISO practitioners but lacking the granular detail (e.g., specific metrics, timeframes, outcomes) that would ground claims in measurable reality.

most organizations will track training. They may have a separate spreadsheet in Excel
mandatory lock screen times. If a courier knocks on an employee's front door and walks away, the laptop will lock after five minutes

Conversational Craft

10 / 20

The host asks reasonable, open-ended questions that invite the guest to elaborate, but rarely pushes back, challenges claims, or probes nuance. Questions like 'what metrics should leadership look at?' and 'how can you align 27001 across teams?' are solid setup questions, but the host accepts answers at face value and mostly affirms rather than follow up with skepticism or deep drilling. The dialogue feels collaborative and friendly but lacks the intellectual tension that would deepen learning.

That's a really interesting take because we talked about it being a maturing of the system
Okay, okay. So and you can look at that as a, you say continual improvement

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker A57%
  • Speaker B43%

Most-used words

culture17security16help8remote8sure8system7report7training6phishing6employees6cybersecurity6first5email5feel5extra5personal5

Episode notes

This week on the Quality Hub, it’s Part 2 of our conversation on building a security-first culture. Host Xavier Francis is joined by Tracy Bear, Manager of Audit Services at Core Business Solutions, to explore how organizations can keep ISO 27001 active and meaningful long after certification. They discuss measuring employee behavior instead of simply tracking compliance, creating a blame-free environment that encourages fast reporting, supporting hybrid and remote employees with practical safeguards and more. The episode also highlights the importance of ongoing training, celebrating security wins, and treating ISO 27001 as a living management system that helps employees work confidently, efficiently, and securely. Helpful Resources: ISO 27001: Who Needs ISO 27001?: The Benefits of ISO 27001: For All Things ISO 9001:2015: Contact us at 866.354.0300 or email us at info@thecoresolution.com ISO 9001 Standards: Articles: ISO 9001 Consulting:

Full transcript

16 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Foreign.

Speaker B: And thanks for listening to the Quality Hub chatting with ISO experts. I'm your host, Xavier Francis and today I'm here with our guest Tracy Baer, Manager of Audit Services here at Core Business Solutions. Glad you could join us.

Speaker A: I'm um, glad to be here.

Speaker B: Great to have you back. Now, uh, last week we started talking about how to build a security first culture. This is part two. So let's just continue that conversation. How about that, Tracy?

Speaker A: Absolutely.

Speaker B: Okay, so let's say an organization, they've done some of this already, but when they're trying to mature that culture in 27001, what metrics or KPIs indicators should Leadership look at to measure the cultural adoption? And that's a real interesting question I want to hear your take on because just saying, oh, we've only had one incident this year. Is that really the metric you should be looking at?

Speaker A: That's an issue that a lot of companies face is they tend to look at metrics that are very negative or just tick the box.

Speaker B: Mhm.

Speaker A: And that's not really looking at or it's not a good gauge of how the 27001 is working if that culture has been adopted.

Speaker B: Okay.

Speaker A: If you really want to see that your system's maturing, don't look at the training completion rates. That just proves people are uh, taking the training and clicking next. It doesn't show anything about retention, it doesn't show anything about what they've learned and them actually using what they've learned in practice.

Speaker B: Okay.

Speaker A: You need to look at their behav. So for an example, quite commonly companies will do phishing simulations and they'll look at how many people click the bag link and they'll look at the retraining required for that. A, uh, mature culture goes from looking at that and looks at things like how many employees are actually participating in the defence, how many people reached out and said, hey, I received a phishing email because they're the things that you need to track and measure that is showing that they're being responsible for, for their management system and they are aware of what the cybersecurity risks are and they're asking questions. It's the employees that ask questions that are keeping things safe. Okay, so track how often staff report flaws, minor slip ups, incidences, all those things. If self reporting goes up and people see that it's just a normal thing and you talk about those self reportings, more and more people will come forward, it'll become high trust and it'll become a Blame free culture. Okay. So you can't manage what you don't measure. Okay, stop measuring compliance, the check boxes and start measuring human behavior. And you'll get a true picture of how information security is progressing and maturing in the organization.

Speaker B: That's a really interesting take because we talked about it being a maturing of the system and that's really important because if you don't have the blame game going on, people don't feel that they're going to be taken to task because they made a mistake. You have clear policies that say this is how you report something that's suspicious and now people are doing it. That certainly shows those first two worked or didn't if they're not. But make it clear, hey, it's okay to report these things. It's okay if it's not anything bad. It's better that you are safe and then look at that. And uh, I don't think that companies always make that clear. Say hey, it's okay to report it. Okay, yes. Oh, they do phishing tests. Yeah, that's just a phishing one. I'll just delete it and let it go. But hey, I think this is one that I should report. Uh, that's a big difference. And it's an extra step than just deleting the email and saying that's shouldn't touch it versus hey, this might be a problem. I like that metric and it becomes

Speaker A: a culture thing where you can actively see that it's not just a metric. You're actually seeing the responses to the information and they're following and doing the right thing.

Speaker B: Yeah, yeah, absolutely. So what are the most effective ways to align 27,001 with cross functional teams like HR Operations, Legal, Marketing. They all have different jobs. So how do you kind of align those?

Speaker A: I would say the biggest secret to aligning 27001 across a company is simple. You have to stop making it about security and make it about a day to day problem in that particular area. So you have to translate the compliance from the specific over the top jargon into each department. Make it personal so that understand.

Speaker B: Okay.

Speaker A: And again as always implementing cybersecurity into an organization there are some slow points m it happens. There's additional steps that need to be taken. Let's look at using the iTEAM to perhaps automate as much as you can so that security is being built into their existing processes and they're not having to do too many additional steps. So they improve the workflows, they make it seamless, don't add extra steps and frame it as their ultimate shield against risk. A tool that actually helps their job. It's a powerful competitive advantage that helps them.

Speaker B: Mhm.

Speaker A: As an example, most organizations will track training.

Speaker B: Mhm.

Speaker A: They may have a separate spreadsheet in Excel that they use. And it takes extra time to work out who's done what and log it into the Excel sheet. Let's put it in the HR onboarding platform. Most onboarding platforms have the ability to do that and it becomes an annual reminder and an easy check and balance for HR to track and manage.

Speaker B: Okay.

Speaker A: Um, and then that way, the end of it, you'll see all areas, you know, not as an IT auditing headache. They see it as a modern upgrade that'll help with their paperwork and help with their processes. Okay, so just take that time with it to go. Okay, I need to do these extra steps. Is there anything system wise, it can help me with mhm to make this more efficient so they don't see it as a hindrance.

Speaker B: Gotcha. Gotcha. Okay. So. And you can look at that as a, you say continual improvement. That can be something that if you're handing off all the security stuff to it, uh, which you're not supposed to do, it's supposed to be cultural. But let's. They're the ones that heads it up, let's put it that way. Give them some tools too, or ask them to look into it. You know, what can we do to automate some of this that makes it easier for you so it's not such a headache or you feel like it's something that you don't usually do every day. But it's just that compliance thing we have to manage. I like that. So this is a question I really am interested in. Uh, for organizations operating in a hybrid or remote work environment, which a lot of us are now I know I'm somebody who works hybridly. How does building a security first culture become more challenging under 27001? And what strategies help maintain accountability and really secure behavior at scale?

Speaker A: I must admit I love this question. Um, it's something that to me as well is something that I discuss in detail with customers. Because primarily a lot of workforces now are hybrid. Some are 100% fully remote. And it's not as though they're going to turn around and say to the employees, hey, can we do an audit and do a camera, walk around and check out what your stuff is like? That can be a little bit personal. Some people aren't going to want to do that.

Speaker B: Right, Right.

Speaker A: So when you've got those boundaries, security completely evaporates in a lot of ways. Because you're not having a corporate office where someone can see something and fix it. Hey, that person left their laptop open. Let's just quickly lock their screen or shut it or put it in the drawer or that kind of thing. So the biggest challenge with remote working, of course, is visibility. They're isolated, there's the temptation for shortcuts. It's much higher. And it can become a silent priority when people work from home. So one of the things you can do is you automate the human error side so you don't rely on remote workers to lock their laptops. You enforce a system wide policy that does it for you. You use tech to enforce some of those shortfalls. Mandatory lock screen times. If a courier knocks on an employee's front door and walks away, the laptop will lock after five minutes. There's no risk of anything happening there. Build a psychological safety net. This is the most critical point that's required. If a remote worker clicks a phishing link or loses their company phone, they are sitting alone in their house. If they are terrified of getting fired, they will hide it. M Again, leadership has to build that culture where reporting a remote mistake is met with praise for speed rather than a punishment.

Speaker B: Okay. Okay.

Speaker A: And one of the big things that organizations should do, make the training and information about them and give them scenarios related to them working from home. Discuss with employees or bet Elliot show them how to change their home router to a unique password which most people don't do.

Speaker B: Right, Right.

Speaker A: An extra layer of protection for themselves, you know, personally as well, because they're also using that wi fi, you know.

Speaker B: Right, right.

Speaker A: Accountability in a remote world isn't about installing any form of creepy surveillance systems or doing spot checks or spying on your staff. You need to build that same digital culture of trust.

Speaker B: Mhm.

Speaker A: With the technology to put in as many safeguards as possible. You want the team to protect the house no matter what room they are working from. And that culture is where you'll get your best information security and cybersecurity practices.

Speaker B: I like that. And that's one thing I will say, uh, in our journey here at CORE with cybersecurity, which has probably been a good seven, eight years at this point. I know a lot of this is like, oh my gosh, I need to do that home. Or oh my gosh, I need to secure. I need to make sure MFA is on my personal financial documentation.

Speaker A: Absolutely.

Speaker B: I personally pay for Password manager for my family because I don't want my wife to be like, oh, you know, I'm just going to do this and put it in an unsafe place or my child. And it's those types of things. So I think if you're working remote, if you can bring it to that focus of, hey, we're going to help you not just secure what's work, but help you secure the whole house, not just for us, but also for the family. And they see it as a personal thing, like you were saying, that can really help. And again, the culture of blame just, it can't be there. You know, people, phones drop out of pockets, phones drop out of purses. It happens. You know, things fall on the ground, you know, you accidentally click on things. You're. It happens. And really given that, like, hey, it's okay, let's just make sure it's taken care of and report it. That makes a lot of sense. I really like that. So looking long term, how can organizations really sustain this security first culture after they get certified and it's achieved, and let's say you've even matured a little bit, how can you ensure 27001 remains, you know, a living management system that continually shapes behavior? And even with growing changes in cybersecurity,

Speaker A: we find when people get their ISO 27001 certification, the most dangerous day for a company is the day after. It's kind of like it's a sigh of relief. It's, um, done, the paperwork is done, it's put in the drawer. Let's just forget about it until the next year's audit. ISO 27001 is a living, breathing management system. Risk is always going to be there. It's not something that you can mitigate with all the tools under the sun. There is always going to be risk. Right?

Speaker B: Right.

Speaker A: So to sustain that culture, long term leadership has to treat security like a fitness routine. You hit your goal weight, you don't stop working out because you put the weight back on again. You know, you got to make sure that you keep working out and you keep addressing it. You have, you know, sustained micro learning.

Speaker B: Mhm.

Speaker A: And review and adapt as the organization changes and the risk environment changes. You know, be aware of what's going on in the marketplace. Talk to your team. Is security slowing you down anywhere? Is there anything we can do to help that? You know, have people work with it to redesign processes, making them seamless so that the employees aren't doing dangerous workarounds. You know, again, publicly celebrate the Wins turn security champions into corporate heroes. Someone prevents a breach or suggests a safer workflow. Don't just send them, uh, a private thank you. Call them out in a newsletter or in a meeting and say, hey, these are all the people that come forward. That's great. Don't even have to name their names. If they feel uncomfortable, just say, we've had some really great people come forward and announce the following. Talk about it. At the end of the day, certification isn't a finish line. It's the starting line. A truly sustainable security culture isn't the piece of paper that's sitting on the wall. It's built in the thousands of small, safe decisions your team make every single day. They open a document, they read a document, they send an email, all these kinds of things. No end date. It's an ongoing business strategy that makes your team move fast but stay safely.

Speaker B: I like that. I like that. So to summarize, this podcast I hear, don't just make it a security exercise. That's checking a box. Don't just hand it off to it. Make it personal. Don't have blame, don't make people feel guilty if they have a breach, if they feel that they did something wrong. Make sure the policies are clear. And what I mean by that isn't just like, you have to do this, but make sure that, hey, if there is, you need to take these steps and you're not going to get in trouble for it. You got to report a potential phishing email that might just be one from your testing. So we know that celebrate victories, celebrate catches. That's a victory because it didn't get past a certain point. And also really to maintain it. Continue with the training, continue with the whole culture. When new risks come up, make sure you address them. Make sure that your security culture is addressing them. Would that be about what we talked about?

Speaker A: Absolutely. Absolutely. Because at the end of the day, 27001 is not just a shield to satisfy an auditor. Take it as an example to be the brakes on a race car. Brakes don't exist.

Speaker B: It's kind of important.

Speaker A: It's true. It's true. Brakes don't, um, exist to make a car go slow. They may seem like they're there to make a car go slow, but in true form, it's so that the driver has confidence to go incredibly fast without crashing.

Speaker B: I like that.

Speaker A: And that's what a security first culture does for a business. You know, it allows employees to go fast and know that they've got that safety net protecting them.

Speaker B: Mhm Mm.

Speaker A: Like a set of brakes.

Speaker B: I like that. Great analogy. Great analogy. Well, Tracy, I love it when you're here. I really want to thank you for being here. I know it's not your favorite thing to do, but you do it so well. So, uh, I hope to have you on again in the future. A couple hundred times. Okay. Maybe not that many. We really do appreciate you being here. Thanks so much as always.

Speaker A: X. It's always a pleasure, uh, working with you.

Speaker B: Thank you. And we want to give a big thank you to everyone who's tuned into today's episode. We hope you found it helpful and walked away with something valuable. Now, if you'd like to learn more about Core Business Solutions, now proudly part of the LRQA family, and how we can support you with ISO certification, cybersecurity, or customized training, we'd love to hear from you. Just email us at infothecoresolution.com or visit us online at www.thecoursesolution.com. and if you haven't already, make sure to follow the Quality Hub podcast on your favorite podcast platform or YouTube so you don't miss our next episode dropping in a week. Thanks again for listening and have an awesome day.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • EP1014: Opportunities for innovationIBS Intelligence Global FinTech Interviews · on Risk management systems73 / 100
  • Debunking Cybersecurity Misconceptions, with Michael IrwinIT Matters · on ISO 27001 certification69 / 100
  • CCT 355: Zapier Breach Lessons For Cloud Security and Setting Up TPRM Program in 15 MinutesCISSP Cyber Training Podcast · on ISO 27001 certification69 / 100
  • Tomorrows Business, Today's AIAI For Small Business Growth · on ISO 27001 certification34 / 100
  • The CMMC Trap: Why Certification Isn’t ComplianceTrust Issues · on ISO 27001 certification

More from The Quality Hub

All episodes →
  • Episode 22 - S4 - ISO Internal Audits - Not Blame Just Better Processes47 / 100
  • Episode 26 - S4 - ISO 27001 - How to Build a Security-First Culture Part 1
  • Episode 25 - S4 - What is Supplier Resilience and Quality - Lessons from Disruptions Part 2
  • Episode 25 - S4 - What is Supplier Resilience and Quality - Lessons from Disruptions Part 1
  • Episode 24 - S4 - Interview with an AI - Celebrating World AI Day
Explore the best B2B Ops podcasts →
All The Quality Hub episodes →