
The Quality Hub · 2026-08-12 · 16 min
Key moments - from our scoring
Substance score
52 / 100
Five dimensions, 20 points each
Building a mature ISO 27001 culture requires organizations to stop measuring compliance metrics like training completion rates and incident counts, and instead track behavioral indicators such as employee phishing reporting, self-reported security issues, and near-miss disclosures. Tracy Baer emphasizes that a mature security culture shows employees actively participating in defense rather than just clicking through training. For cross-functional alignment across HR, Operations, Legal, and Marketing departments, the key is translating security compliance into department-specific language and automating workflows so security becomes embedded in existing processes rather than adding extra steps. In remote and hybrid environments, organizations face distinct challenges around visibility and employee isolation, requiring automation of human error safeguards (like mandatory lock screens), psychological safety nets that encourage reporting without fear of punishment, and training tailored to home office scenarios. Baer stresses that ISO 27001 certification is a starting point, not an endpoint - sustainability requires treating security like an ongoing fitness routine with sustained micro-learning, public recognition of security wins, and continuous process redesign as risks evolve. The metaphor of security as brakes on a race car captures the core message: proper controls enable faster, more confident business operations.
Track behavioral indicators like how many employees report phishing emails, submit self-reported security issues, and disclose near-miss incidents. These show employees are taking responsibility for the management system and aware of cybersecurity risks, rather than just clicking through training or avoiding incidents.
Translate compliance requirements from technical jargon into department-specific language so each team understands how security solves their day-to-day problems. Automate security tasks within their existing workflows - such as embedding training reminders in HR onboarding platforms - so security feels seamless rather than burdensome.
Use technical enforcements like mandatory lock screens after five minutes, create psychological safety so remote workers report mistakes without fear of firing, and provide home-specific training (like changing router passwords). Build a digital culture of trust alongside safeguards rather than relying on surveillance.
Treat security as an ongoing fitness routine with sustained micro-learning, address emerging risks, redesign processes to remove dangerous workarounds, publicly celebrate security wins, and regularly review whether security is slowing down business - certification is the starting line, not the finish line.
Organizations often treat certification as completion and put the documentation away until the next audit, rather than recognizing that ISO 27001 is a living management system requiring continuous attention, adaptation, and cultural reinforcement as risks evolve.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode delivers several substantive ideas about security culture - shifting from negative metrics to behavioral tracking, localizing compliance to departmental contexts, and treating security as continuous rather than post-certification - but relies heavily on repetition of these core themes rather than introducing new framings. The advice is practical and grounded in the ISO 27001 context but not densely packed; there is noticeable filler (affirmations, throat-clearing) that dilutes insight per minute.
don't look at the training completion rates. That just proves people are uh, taking the training and clicking next. It doesn't show anything about retention
you have to stop making it about security and make it about a day to day problem in that particular area
The core insights - using behavioral metrics instead of compliance metrics, framing security as a cultural issue not an IT issue, and the brakes-on-a-racecar analogy - are sensible but not novel within the ISO/cybersecurity practitioner community. The emphasis on psychological safety and remote-work considerations is somewhat fresh, but the overall framing recycles well-worn security culture language without sharp contrarian takes or first-principles challenges.
stop measuring compliance, the check boxes and start measuring human behavior
Brakes don't exist to make a car go slow. They may seem like they're there to make a car go slow, but in true form, it's so that the driver has confidence to go incredibly fast
Tracy Baer is a Manager of Audit Services at Core Business Solutions, which positions her as a mid-level practitioner with audit experience rather than a C-level operator or exec who has scaled security at a large organization. She speaks competently about ISO 27001 implementation but lacks the visible track record (founding, leading major transformations, or operating at enterprise scale) that would elevate guest caliber. She is a credible ISO expert but not a standout practitioner.
Manager of Audit Services here at Core Business Solutions
to me as well is something that I discuss in detail with customers
The episode provides minimal concrete examples and no quantified data. The phishing simulation, home router password, and Excel-to-HR-platform migration examples are illustrative but generic; no specific companies, incident counts, timelines, or measured impact figures are cited. The advice remains at a moderate level of abstraction - useful for ISO practitioners but lacking the granular detail (e.g., specific metrics, timeframes, outcomes) that would ground claims in measurable reality.
most organizations will track training. They may have a separate spreadsheet in Excel
mandatory lock screen times. If a courier knocks on an employee's front door and walks away, the laptop will lock after five minutes
The host asks reasonable, open-ended questions that invite the guest to elaborate, but rarely pushes back, challenges claims, or probes nuance. Questions like 'what metrics should leadership look at?' and 'how can you align 27001 across teams?' are solid setup questions, but the host accepts answers at face value and mostly affirms rather than follow up with skepticism or deep drilling. The dialogue feels collaborative and friendly but lacks the intellectual tension that would deepen learning.
That's a really interesting take because we talked about it being a maturing of the system
Okay, okay. So and you can look at that as a, you say continual improvement
Computed from the transcript - who did the talking, and the words that came up most.
This week on the Quality Hub, it’s Part 2 of our conversation on building a security-first culture. Host Xavier Francis is joined by Tracy Bear, Manager of Audit Services at Core Business Solutions, to explore how organizations can keep ISO 27001 active and meaningful long after certification. They discuss measuring employee behavior instead of simply tracking compliance, creating a blame-free environment that encourages fast reporting, supporting hybrid and remote employees with practical safeguards and more. The episode also highlights the importance of ongoing training, celebrating security wins, and treating ISO 27001 as a living management system that helps employees work confidently, efficiently, and securely. Helpful Resources: ISO 27001: Who Needs ISO 27001?: The Benefits of ISO 27001: For All Things ISO 9001:2015: Contact us at 866.354.0300 or email us at info@thecoresolution.com ISO 9001 Standards: Articles: ISO 9001 Consulting:
Transcribed and scored by The B2B Podcast Index.
Speaker A: Foreign.
Speaker B: And thanks for listening to the Quality Hub chatting with ISO experts. I'm your host, Xavier Francis and today I'm here with our guest Tracy Baer, Manager of Audit Services here at Core Business Solutions. Glad you could join us.
Speaker A: I'm um, glad to be here.
Speaker B: Great to have you back. Now, uh, last week we started talking about how to build a security first culture. This is part two. So let's just continue that conversation. How about that, Tracy?
Speaker A: Absolutely.
Speaker B: Okay, so let's say an organization, they've done some of this already, but when they're trying to mature that culture in 27001, what metrics or KPIs indicators should Leadership look at to measure the cultural adoption? And that's a real interesting question I want to hear your take on because just saying, oh, we've only had one incident this year. Is that really the metric you should be looking at?
Speaker A: That's an issue that a lot of companies face is they tend to look at metrics that are very negative or just tick the box.
Speaker B: Mhm.
Speaker A: And that's not really looking at or it's not a good gauge of how the 27001 is working if that culture has been adopted.
Speaker B: Okay.
Speaker A: If you really want to see that your system's maturing, don't look at the training completion rates. That just proves people are uh, taking the training and clicking next. It doesn't show anything about retention, it doesn't show anything about what they've learned and them actually using what they've learned in practice.
Speaker B: Okay.
Speaker A: You need to look at their behav. So for an example, quite commonly companies will do phishing simulations and they'll look at how many people click the bag link and they'll look at the retraining required for that. A, uh, mature culture goes from looking at that and looks at things like how many employees are actually participating in the defence, how many people reached out and said, hey, I received a phishing email because they're the things that you need to track and measure that is showing that they're being responsible for, for their management system and they are aware of what the cybersecurity risks are and they're asking questions. It's the employees that ask questions that are keeping things safe. Okay, so track how often staff report flaws, minor slip ups, incidences, all those things. If self reporting goes up and people see that it's just a normal thing and you talk about those self reportings, more and more people will come forward, it'll become high trust and it'll become a Blame free culture. Okay. So you can't manage what you don't measure. Okay, stop measuring compliance, the check boxes and start measuring human behavior. And you'll get a true picture of how information security is progressing and maturing in the organization.
Speaker B: That's a really interesting take because we talked about it being a maturing of the system and that's really important because if you don't have the blame game going on, people don't feel that they're going to be taken to task because they made a mistake. You have clear policies that say this is how you report something that's suspicious and now people are doing it. That certainly shows those first two worked or didn't if they're not. But make it clear, hey, it's okay to report these things. It's okay if it's not anything bad. It's better that you are safe and then look at that. And uh, I don't think that companies always make that clear. Say hey, it's okay to report it. Okay, yes. Oh, they do phishing tests. Yeah, that's just a phishing one. I'll just delete it and let it go. But hey, I think this is one that I should report. Uh, that's a big difference. And it's an extra step than just deleting the email and saying that's shouldn't touch it versus hey, this might be a problem. I like that metric and it becomes
Speaker A: a culture thing where you can actively see that it's not just a metric. You're actually seeing the responses to the information and they're following and doing the right thing.
Speaker B: Yeah, yeah, absolutely. So what are the most effective ways to align 27,001 with cross functional teams like HR Operations, Legal, Marketing. They all have different jobs. So how do you kind of align those?
Speaker A: I would say the biggest secret to aligning 27001 across a company is simple. You have to stop making it about security and make it about a day to day problem in that particular area. So you have to translate the compliance from the specific over the top jargon into each department. Make it personal so that understand.
Speaker B: Okay.
Speaker A: And again as always implementing cybersecurity into an organization there are some slow points m it happens. There's additional steps that need to be taken. Let's look at using the iTEAM to perhaps automate as much as you can so that security is being built into their existing processes and they're not having to do too many additional steps. So they improve the workflows, they make it seamless, don't add extra steps and frame it as their ultimate shield against risk. A tool that actually helps their job. It's a powerful competitive advantage that helps them.
Speaker B: Mhm.
Speaker A: As an example, most organizations will track training.
Speaker B: Mhm.
Speaker A: They may have a separate spreadsheet in Excel that they use. And it takes extra time to work out who's done what and log it into the Excel sheet. Let's put it in the HR onboarding platform. Most onboarding platforms have the ability to do that and it becomes an annual reminder and an easy check and balance for HR to track and manage.
Speaker B: Okay.
Speaker A: Um, and then that way, the end of it, you'll see all areas, you know, not as an IT auditing headache. They see it as a modern upgrade that'll help with their paperwork and help with their processes. Okay, so just take that time with it to go. Okay, I need to do these extra steps. Is there anything system wise, it can help me with mhm to make this more efficient so they don't see it as a hindrance.
Speaker B: Gotcha. Gotcha. Okay. So. And you can look at that as a, you say continual improvement. That can be something that if you're handing off all the security stuff to it, uh, which you're not supposed to do, it's supposed to be cultural. But let's. They're the ones that heads it up, let's put it that way. Give them some tools too, or ask them to look into it. You know, what can we do to automate some of this that makes it easier for you so it's not such a headache or you feel like it's something that you don't usually do every day. But it's just that compliance thing we have to manage. I like that. So this is a question I really am interested in. Uh, for organizations operating in a hybrid or remote work environment, which a lot of us are now I know I'm somebody who works hybridly. How does building a security first culture become more challenging under 27001? And what strategies help maintain accountability and really secure behavior at scale?
Speaker A: I must admit I love this question. Um, it's something that to me as well is something that I discuss in detail with customers. Because primarily a lot of workforces now are hybrid. Some are 100% fully remote. And it's not as though they're going to turn around and say to the employees, hey, can we do an audit and do a camera, walk around and check out what your stuff is like? That can be a little bit personal. Some people aren't going to want to do that.
Speaker B: Right, Right.
Speaker A: So when you've got those boundaries, security completely evaporates in a lot of ways. Because you're not having a corporate office where someone can see something and fix it. Hey, that person left their laptop open. Let's just quickly lock their screen or shut it or put it in the drawer or that kind of thing. So the biggest challenge with remote working, of course, is visibility. They're isolated, there's the temptation for shortcuts. It's much higher. And it can become a silent priority when people work from home. So one of the things you can do is you automate the human error side so you don't rely on remote workers to lock their laptops. You enforce a system wide policy that does it for you. You use tech to enforce some of those shortfalls. Mandatory lock screen times. If a courier knocks on an employee's front door and walks away, the laptop will lock after five minutes. There's no risk of anything happening there. Build a psychological safety net. This is the most critical point that's required. If a remote worker clicks a phishing link or loses their company phone, they are sitting alone in their house. If they are terrified of getting fired, they will hide it. M Again, leadership has to build that culture where reporting a remote mistake is met with praise for speed rather than a punishment.
Speaker B: Okay. Okay.
Speaker A: And one of the big things that organizations should do, make the training and information about them and give them scenarios related to them working from home. Discuss with employees or bet Elliot show them how to change their home router to a unique password which most people don't do.
Speaker B: Right, Right.
Speaker A: An extra layer of protection for themselves, you know, personally as well, because they're also using that wi fi, you know.
Speaker B: Right, right.
Speaker A: Accountability in a remote world isn't about installing any form of creepy surveillance systems or doing spot checks or spying on your staff. You need to build that same digital culture of trust.
Speaker B: Mhm.
Speaker A: With the technology to put in as many safeguards as possible. You want the team to protect the house no matter what room they are working from. And that culture is where you'll get your best information security and cybersecurity practices.
Speaker B: I like that. And that's one thing I will say, uh, in our journey here at CORE with cybersecurity, which has probably been a good seven, eight years at this point. I know a lot of this is like, oh my gosh, I need to do that home. Or oh my gosh, I need to secure. I need to make sure MFA is on my personal financial documentation.
Speaker A: Absolutely.
Speaker B: I personally pay for Password manager for my family because I don't want my wife to be like, oh, you know, I'm just going to do this and put it in an unsafe place or my child. And it's those types of things. So I think if you're working remote, if you can bring it to that focus of, hey, we're going to help you not just secure what's work, but help you secure the whole house, not just for us, but also for the family. And they see it as a personal thing, like you were saying, that can really help. And again, the culture of blame just, it can't be there. You know, people, phones drop out of pockets, phones drop out of purses. It happens. You know, things fall on the ground, you know, you accidentally click on things. You're. It happens. And really given that, like, hey, it's okay, let's just make sure it's taken care of and report it. That makes a lot of sense. I really like that. So looking long term, how can organizations really sustain this security first culture after they get certified and it's achieved, and let's say you've even matured a little bit, how can you ensure 27001 remains, you know, a living management system that continually shapes behavior? And even with growing changes in cybersecurity,
Speaker A: we find when people get their ISO 27001 certification, the most dangerous day for a company is the day after. It's kind of like it's a sigh of relief. It's, um, done, the paperwork is done, it's put in the drawer. Let's just forget about it until the next year's audit. ISO 27001 is a living, breathing management system. Risk is always going to be there. It's not something that you can mitigate with all the tools under the sun. There is always going to be risk. Right?
Speaker B: Right.
Speaker A: So to sustain that culture, long term leadership has to treat security like a fitness routine. You hit your goal weight, you don't stop working out because you put the weight back on again. You know, you got to make sure that you keep working out and you keep addressing it. You have, you know, sustained micro learning.
Speaker B: Mhm.
Speaker A: And review and adapt as the organization changes and the risk environment changes. You know, be aware of what's going on in the marketplace. Talk to your team. Is security slowing you down anywhere? Is there anything we can do to help that? You know, have people work with it to redesign processes, making them seamless so that the employees aren't doing dangerous workarounds. You know, again, publicly celebrate the Wins turn security champions into corporate heroes. Someone prevents a breach or suggests a safer workflow. Don't just send them, uh, a private thank you. Call them out in a newsletter or in a meeting and say, hey, these are all the people that come forward. That's great. Don't even have to name their names. If they feel uncomfortable, just say, we've had some really great people come forward and announce the following. Talk about it. At the end of the day, certification isn't a finish line. It's the starting line. A truly sustainable security culture isn't the piece of paper that's sitting on the wall. It's built in the thousands of small, safe decisions your team make every single day. They open a document, they read a document, they send an email, all these kinds of things. No end date. It's an ongoing business strategy that makes your team move fast but stay safely.
Speaker B: I like that. I like that. So to summarize, this podcast I hear, don't just make it a security exercise. That's checking a box. Don't just hand it off to it. Make it personal. Don't have blame, don't make people feel guilty if they have a breach, if they feel that they did something wrong. Make sure the policies are clear. And what I mean by that isn't just like, you have to do this, but make sure that, hey, if there is, you need to take these steps and you're not going to get in trouble for it. You got to report a potential phishing email that might just be one from your testing. So we know that celebrate victories, celebrate catches. That's a victory because it didn't get past a certain point. And also really to maintain it. Continue with the training, continue with the whole culture. When new risks come up, make sure you address them. Make sure that your security culture is addressing them. Would that be about what we talked about?
Speaker A: Absolutely. Absolutely. Because at the end of the day, 27001 is not just a shield to satisfy an auditor. Take it as an example to be the brakes on a race car. Brakes don't exist.
Speaker B: It's kind of important.
Speaker A: It's true. It's true. Brakes don't, um, exist to make a car go slow. They may seem like they're there to make a car go slow, but in true form, it's so that the driver has confidence to go incredibly fast without crashing.
Speaker B: I like that.
Speaker A: And that's what a security first culture does for a business. You know, it allows employees to go fast and know that they've got that safety net protecting them.
Speaker B: Mhm Mm.
Speaker A: Like a set of brakes.
Speaker B: I like that. Great analogy. Great analogy. Well, Tracy, I love it when you're here. I really want to thank you for being here. I know it's not your favorite thing to do, but you do it so well. So, uh, I hope to have you on again in the future. A couple hundred times. Okay. Maybe not that many. We really do appreciate you being here. Thanks so much as always.
Speaker A: X. It's always a pleasure, uh, working with you.
Speaker B: Thank you. And we want to give a big thank you to everyone who's tuned into today's episode. We hope you found it helpful and walked away with something valuable. Now, if you'd like to learn more about Core Business Solutions, now proudly part of the LRQA family, and how we can support you with ISO certification, cybersecurity, or customized training, we'd love to hear from you. Just email us at infothecoresolution.com or visit us online at www.thecoursesolution.com. and if you haven't already, make sure to follow the Quality Hub podcast on your favorite podcast platform or YouTube so you don't miss our next episode dropping in a week. Thanks again for listening and have an awesome day.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.