Building Trust Between IT Security Teams and Users: Key Strategies for Success
Trust Me, I'm From IT! @channel In preparation for my session at SoSafe Academy earlier this week, I was creating content about how to establish trust between the CISO and the Board. It made me ponder the benefits of trust on a wider scale. It’s an awkward truth, but the IT team is often the least trusted voice in the building👨💻. They show up uninvited, tell people they're doing it wrong, disrupt working flow, and then vanish leaving staff confused and irritated. That’s an issue in itself, but what’s worse is that Security is often perceived as just another part of IT! Is it any wonder therefore, that our messages struggle to get through? 🙉 Trust is a mental shortcut our brains use to decide who's worth listening to under pressure, and who’s opinions have value. We judge advice by how we feel about the messenger, not simply the merits of the message. This technique is used by attackers all the time - look at the 2023 MGM Resorts breach for example. Attackers didn't crack any encryption - they simply rang the IT help desk, sounded confident, and asked for a password reset. The help desk trusted the caller's tone and basic authentication over any advanced verification process. That's authority bias, social proof & years of training a ‘help desk’ to help, working exactly as evolution intended, just weaponised against us. If attackers can build trust in five minutes on the phone, we can surely build genuine trust with our own colleagues. So how can we build trust with our user base instead? Three behavioural levers:
🔄 Reciprocity - always be looking to help. I used to tell my team that the answer to any user request was always “Yes”, we just needed to figure out how to say yes safely. Look for opportunities to add value and make the users life easier. Once you are perceived to be ‘on their side’, things will get much easier.
📶 Consistency - as German (& British!) rail commuters know, it’s difficult to trust a service that is inconsistent. By always having the same helpful response, by showing up every time, by always being calm, regardless of cause, you will become much more approachable to staff. Which leads onto…
🆘 Psychological safety - remove the risk, blame and finger pointing from any engagement. Reward the person who reports "I think I clicked something," fast, publicly, and warmly. That single cultural signal does more for security than any awareness poster you can print.
Trust isn't earned through authority; it's earned through repeated, low-stakes proof that we're on the user’s side. It will spread slowly, user by user, as each one encounters a reason to trust you, so be the colleague who always helps, not the department that judges — and watch engagement follow. Talking Points 1. Do you have any metric tracking trust levels? If so, what does that look like? 2. What’s the one thing your department has done that made the biggest difference to how much the user base trust the Security function?
