Good Intentions, Bad Outcomes: How Security Culture Turns Human Behavior Into Defense
2026-10-23 , Redbud A

Cybersecurity often treats people as the weakest link, but what if we're looking at the problem backwards?

Employees rarely intend to create security incidents. They're trying to help a customer, meet a deadline, solve a technical problem, follow instructions, or simply get their job done. Yet reasonable decisions can still produce unreasonable security outcomes.

This session explores how organizations can build a healthy security culture that turns human behavior from a source of risk into an additional layer of defense. We'll examine what happens when employees bypass controls to get their jobs done, hesitate to report mistakes, or place too much trust in technology—including exploring examples of people acting on AI recommendations without fully understanding the consequences.

The goal isn't to create employees who never make mistakes. It's to create an environment where people feel empowered to pause, question, verify, and report—and where security is viewed not as an obstacle to the business, but as something everyone participates in.


What happens when someone is genuinely trying to do the right thing, but the outcome is wrong?

A security analyst follows an AI recommendation that turns out to have a significant operational impact. An employee bypasses a security control because they need to help a customer. Someone notices something suspicious but doesn't report it because they don't want to "bother Security." These aren't necessarily examples of careless employees. They're examples of people making decisions within the culture and systems we've created.

Good Intentions, Bad Outcomes examines the human side of cybersecurity and challenges the idea that employees are simply the "weakest link." Through real-world scenarios and practical lessons, this session explores how security teams can create a culture where people recognize risk, question unexpected situations, ask for help, and report mistakes before they become incidents.

Attendees will leave with practical ideas for building a security culture that doesn't demand perfect human behavior—it makes secure behavior easier, safer, and more natural.

Nicki is an Information System Security Officer with more than a decade of experience in IT, including several years focused on cybersecurity. She specializes in governance, risk, and compliance, security awareness, vulnerability management, incident response, and building practical security programs.

In addition to her professional work, she teaches IT and cybersecurity courses at WSU Tech, where she helps prepare the next generation of technology professionals. She is also active in the cybersecurity community as a speaker and volunteer leader, including involvement with ISC² and the Global Women’s Leadership Network.

Her approach to cybersecurity focuses on making security practical, approachable, and integrated into the way organizations actually work—not simply adding more controls or policies.