Is your culture interfering with data security?

Business is global. This isn’t new, nor is it surprising that cultural differences, international laws, and workplace practices differ around the world. Businesses have long sought to harness the strengths of particular cultures and, in other situations, to transplant the culture and values of the company’s mother country onto a global labor force. For example, a company with sites in Japan or Italy may have trouble being notified of security issues due to Italy’s “bella figura” or Japan’s “mentsu” concept of keeping face. Employees in those countries may not share the information out of concern for potentially shaming their global counterparts. In such cases, the parent organization may try to impress the value of open communication upon employees from those countries. On the other hand, a company might open research and development offices in Switzerland, Finland, or Singapore due to their high degree of intellectual property rights protection.
Enterprise-wide security programs should consider how security will be effective in different cultures, the differences in legal and regulatory requirements, how company property is viewed, encryption limitations, and language barriers in order to manage security effectively around the world.
Security programs can be more or less effective in different cultures so it is important to not only gather support and feedback from top management but also from leaders in regional centers with differing cultures. For example, separating the office into different security zones, each requiring authentication, may be well received in Western countries such as the United States but Eastern countries like Japan may think this rude and untrustworthy. Similarly, perceptions and priorities of security may differ between countries as shown in this global security survey.
Another important global difference is legal and regulatory requirements. The European Union differs greatly from the United States in their privacy laws, so a security program will need to ensure that the requirements of each country’s laws are met while still maintaining at least the organizational defined minimum standard of security. Employees from multiple regions working on a single project or the same data will need to follow appropriate procedures to ensure they are complying.
An organization’s response and transparency in handling incidents is related to the legal and regulatory requirements, but also impacts a company’s brand image.


