Organizational culture
In all my experience so far with several organizations, the only common thing was a huge emphasis on driving a resilient risk culture.
If you take away one lesson from this chapter, let the following be it.
Important note
Nothing impacts an organization’s behavior toward risk management more than its culture and nothing impacts an organization’s culture more than senior management.
An organization’s culture toward risk management can be divided into five parts:
- Vulnerable: Neither senior management nor employees care about the organization’s risk and the response is always after the risk has materialized.
For example, the IT admin only updates the antivirus after the infection has happened.
- Reactive: The response is based on the complaints of the employees or when required for compliance with contractual or non-contractual obligations.
For example, the organization is undergoing an external...