Hi Andrew R.,
I think you raise a very important point about how Information Security is perceived within an organization. In my opinion, it's one of the biggest challenges for anyone working in or leading security.
My own approach revolves around what I would call integrity. Not the integrity of information, but the integrity of decisions, attitudes, guidelines, and processes. If i stay true to the own build security and hold on to a higher Standard, People start to trust me and my decisions. To me, it feels like we're talking about very similar things. I call it "integrity", while you call it "trust".
Regarding metrics, this is actually one of the biggest gaps in our ISMS. Measuring trust is extremely difficult. Personally, I see it more through day-to-day interactions with colleagues than through KPIs or dashboards. You can often feel whether people trust Security long before you can measure it.
As for your second question, the biggest impact came from being transparent about our decision-making. We always try to explain why we are introducing new measures or changing existing processes. Combined with being approachable and available for security discussions, this helped create trust over time.
Best regards
Lars