“Kindness as a Security Control” can sound like a slogan. Here is what it means in practice and why it belongs in every security conversation.
When we talk about kindness being a security control, it is meant literally. The way people are treated changes the way security works in an organisation.
Think about how much of security depends on people doing the right thing at the right moment, often when they are tired, busy or unsure. The best technology in the world still relies on someone choosing to report, to ask or to check. Get the human side wrong and you weaken everything that sits on top of it.
Security depends on human behaviour far more than we like to admit. Someone has to report the email that looks wrong. Someone has to admit they clicked the link. Someone has to ask the question that sounds basic, or challenge the assumption everyone else has accepted. These are the moments where risk is either caught or missed.
Fear quietly switches all of that off. If a person was humiliated the last time they raised something, they will think twice before doing it again. If admitting a mistake gets you mocked, mistakes get hidden until they become incidents. The cost does not show up on a dashboard, but it is real.
This is not a problem reserved for difficult workplaces. It happens in good teams, run by well meaning people, simply because nobody noticed the pattern setting in. A sharp word in a meeting, a sigh when someone asks a question, a manager who only ever hears about issues once they have grown into emergencies. None of it looks like a security failure on the day it happens. All of it shapes whether the next person decides to speak.
A control is anything that reduces risk. By that definition, culture is a control. A team where people feel safe to speak reports problems earlier, learns faster and recovers better. A team ruled by fear does the opposite, and looks fine right up until it does not.
It helps to set this beside the controls we already trust. We pay for monitoring so that we find out about problems quickly. We run training so that people know what to do when something looks wrong. Culture works in the same way. A team that feels safe to speak becomes its own early warning system, catching the things that no tool was ever going to see on its own.
What It Looks Like Day to Day
In practice this is quieter than it sounds. It is the analyst who flags a strange login at the end of a long shift because they know they will be thanked rather than blamed. It is the new starter who admits they are not sure how a process works, before they get it wrong at scale. It is the senior engineer who says they are not comfortable with a release, and is actually heard. These small moments are where most real security is decided, long before any framework comes into it.
It Is Measurable
You can see it in the behaviours it produces. How quickly incidents are reported. How many near misses get flagged rather than buried. Whether people challenge a risky decision before it ships. Whether good people stay. These are security outcomes, and they are shaped by how people are treated.
It Is Not About Being Soft
None of this means lowering standards. You can hold people to high standards and treat them with respect at the same time. Rigour and kindness are not opposites. The aim is honest challenge without cruelty, and accountability without humiliation.
When we list our controls we tend to name tools, policies and frameworks. The people using them decide whether any of it works. Treating kindness as a security control simply means taking that seriously.
Final Thoughts
Kindness as a security control is not a soft extra to bolt on once the real work is done. It is part of the real work. If you want fewer surprises, earlier warnings and people who stay long enough to become genuinely good at their jobs, the way you treat each other is the place to start.
If this strikes a chord and you would like to take it further, we would be glad to hear from you. Get in touch with Cyber Kindness at hello@cyberkindness.org.uk.



