Buy new:
$20.46$20.46
FREE delivery:
July 31 - Aug 1
Ships from: Woodville Books Sold by: Woodville Books
Buy used: $18.79
Other Sellers on Amazon
+ $3.99 shipping
82% positive over last 12 months
+ $3.99 shipping
91% positive over last 12 months
Usually ships within 2 to 3 days.
Download the free Kindle app and start reading Kindle books instantly on your smartphone, tablet, or computer - no Kindle device required. Learn more
Read instantly on your browser with Kindle for Web.
Using your mobile phone camera - scan the code below and download the Kindle app.
Follow the Authors
OK
The Security Culture Playbook: An Executive Guide To Reducing Risk and Developing Your Human Defense Layer 1st Edition
| Price | New from | Used from |
|
Audible Audiobook, Unabridged
"Please retry" |
$0.00
| $7.95 with discounted Audible membership | |
|
Audio CD, CD, Unabridged
"Please retry" | $24.04 | — |
- Kindle
$15.00 Read with Our Free App -
Audiobook
$0.00 Free with your 3-Month Audible trial - Hardcover
$18.79 - $20.469 Used from $10.78 17 New from $16.48 - Audio CD
$24.042 New from $24.04
Purchase options and add-ons
Mitigate human risk and bake security into your organization’s culture from top to bottom with insights from leading experts in security awareness, behavior, and culture.
The topic of security culture is mysterious and confusing to most leaders. But it doesn’t have to be. In The Security Culture Playbook, Perry Carpenter and Kai Roer, two veteran cybersecurity strategists deliver experience-driven, actionable insights into how to transform your organization’s security culture and reduce human risk at every level. This book exposes the gaps between how organizations have traditionally approached human risk and it provides security and business executives with the necessary information and tools needed to understand, measure, and improve facets of security culture across the organization.
The book offers:
- An expose of what security culture really is and how it can be measured
- A careful exploration of the 7 dimensions that comprise security culture
- Practical tools for managing your security culture program, such as the Security Culture Framework and the Security Culture Maturity Model
- Insights into building support within the executive team and Board of Directors for your culture management program
Also including several revealing interviews from security culture thought leaders in a variety of industries, The Security Culture Playbook is an essential resource for cybersecurity professionals, risk and compliance managers, executives, board members, and other business leaders seeking to proactively manage and reduce risk.
- ISBN-101119875234
- ISBN-13978-1119875239
- Edition1st
- PublisherWiley
- Publication dateApril 19, 2022
- LanguageEnglish
- Dimensions6.1 x 1 x 9.1 inches
- Print length256 pages
Frequently bought together

What do customers buy after viewing this item?
- Most purchasedin this set of products
Cyber Defense Matrix: The Essential Guide to Navigating the Cybersecurity LandscapePaperback
Editorial Reviews
From the Inside Flap
An expert demonstration of weaving security into your organization’s culture
In The Security Culture Playbook, two of the world’s foremost experts in security awareness, behavior, and culture deliver actionable insights―grounded in data and their own extensive experience―into how to revamp your organization’s security culture and reduce behavioral risk at every level of your company. You’ll discover the shortcomings in how firms have traditionally approached human risk and strategies and how to understand, measure, and improve every facet of your company’s security culture.
The authors demonstrate what security culture really means and how it can be measured, and identify the seven dimensions that make up a culture of security. You’ll find practical tools for managing your security culture program, including the celebrated Security Culture Framework and Security Culture Maturity Model. Importantly, you’ll also gain critical insights into how to build support within your executive team and Board of Directors to implement your culture management program.
Perfect for cybersecurity professionals, risk and compliance managers, executives, board members, and other business leaders, The Security Culture Playbook delivers a concrete blueprint for producing real change, reducing risk, and proactively managing your company’s exposure to cybersecurity threats. You’ll also find:
- Revealing interviews from security culture thought leaders in a variety of industries
- Strategies for bringing all the security culture pieces together into a coherent program
- Actionable and modern insights from sociology and other academic disciplines
- In-depth explanations of how to implement and shape behavioral outcomes, foster social pressures, and create positive patterns
From the Back Cover
“Perry’s exploration of security as a cultural force, created by processes and communications but separate from them, is a unique look into precisely that zone of our identity.”
― Matt Wallaert, Behavioral Scientist and author of Start At The End: How to Build Products That Create Change
“ Perry has his finger on the pulse of security awareness culture and knows how to bring it to life. His real-world expert advice focuses on what is actionable and most essential for protecting your organization right now.”
―Rachel Tobac, CEO of SocialProof Security and Friendly Hacker
“I can’t think of a better guide for organizational executives trying to reduce their inherent risk via an improved internal security culture.”
―Rick Howard, CSO, Chief Analyst, and Senior Fellow at the CyberWire
“I have seen Kai Roer demonstrate his passion and sincere dedication to improving the security culture of organizations for many years … Kai providing guidance for executives to understand their role and responsibility for creating a secure business ecosystem through using The Security Culture Playbook is a brilliant idea!”
―Rebecca Herold, CEO of The Privacy Professor consultancy, and Privacy & Security Brainiacs SaaS services
“There is no one better placed to present expertise related to security culture than Kai.”
―Raj Samani, McAfee Fellow, Chief Scientist
About the Author
PERRY CARPENTER, C|CISO, MSIA, is an author, podcaster, thought leader, and cybersecurity expert specializing in security awareness and the human factors of security. His research focuses on marketing, communication, behavior science, organizational culture management, sociology, and more.
KAI ROER is the author of several books on security and leadership, a keynote speaker, and a thought leader in the security culture field. In addition to his research, he is an entrepreneur and the inventor of technology and frameworks that transformed the information security industry.
Product details
- Publisher : Wiley; 1st edition (April 19, 2022)
- Language : English
- Hardcover : 256 pages
- ISBN-10 : 1119875234
- ISBN-13 : 978-1119875239
- Item Weight : 1 pounds
- Dimensions : 6.1 x 1 x 9.1 inches
- Best Sellers Rank: #139,936 in Books (See Top 100 in Books)
- #234 in E-commerce Professional (Books)
- #312 in Computer Security & Encryption (Books)
- #325 in Workplace Culture (Books)
- Customer Reviews:
Important information
To report an issue with this product, click here.
About the authors

Perry Carpenter, C|CISO, MSIA, has been a recognized thought leader on security awareness and the human factors of security for well-over a decade. His broad background makes him uniquely positioned to understand nuances of awareness strategy that can be elusive.
Perry’s security awareness-related experience spans multiple pivotal roles: from being a general employee receiving awareness training; to being an awareness program manager running complex global programs; to being the primary market analyst advising security leaders about awareness trends, success practices, and vendor platforms; to now helping lead the efforts of the world’s largest and most successful security awareness and simulated phishing platform. Perry draws from this experience, along with cutting-edge research in the fields of marketing, communication, behavior science, and organizational culture management to inform his perspectives and advice for creating awareness programs that are transformational.
Perry currently serves as Chief Evangelist and Strategy Officer for KnowBe4, the world's most popular security awareness and simulated phishing platform. Before joining KnowBe4, Perry led security awareness, security culture management, and anti-phishing behavior management research at Gartner Research, in addition to covering areas of IAM strategy, CISO Program Management mentoring, and Technology Service Provider success strategies. With a long career as a security professional and researcher, Carpenter has broad experience in North America and Europe, providing security consulting and advisory services for many of the world’s best-known brands.
Perry holds a Master of Science in Information Assurance (MSIA) from Norwich University in Vermont and is a Certified Chief Information Security Officer (C|CISO).
You can connect with Perry on LinkedIn at: https://linkedin.com/in/perrycarpenter.

Kai Roer currently serves as Chief Research Officer for KnowBe4, the world´s most popular security awareness and simulated phishing platform.
Kai has been providing actionable advice founded on empirical evidence to public and private organizations around the world since the 1990’s. His work over the past decades has focused on helping organizations understand what culture they currently have, what culture they would like to have, and more importantly how to get there. Kai works with the information security community on a global stage to educate the importance and impact that security culture has.
In 2010, he created the Security Culture Framework (SCF), a framework and methodology to build and maintain security culture. Kai later gifted the SCF to the Open-Source community, and it evolved into several spin-offs, including the Cybersecurity Culture Framework by The European Union Agency for Cybersecurity (ENISA) in 2015. Kai has authored and co-authored several books on leadership and technology. His popular book “Build a Security Culture” (IT-Governance, 2015) is widely considered as the guiding resource on the topic of security culture.
Before joining KnowBe4, Kai founded the security culture measurement company, CLTRe (pronounced culture), the world’s first SaaS-platform built to measure and manage an organization’s security culture. This new ability to measure security culture made it possible for organizations worldwide to understand exactly where and how to improve their security. KnowBe4 acquired CLTRe in 2019. After which, Kai built KnowBe4 Research, the research arm of KnowBe4, where he leads a team of researchers dedicated to improving the knowledge and understanding of the human factors that influence security.
Recognized by many as a leading global authority on the topic of security culture, he has received several awards, including the Ron Knode Service Award by the Cloud Security Alliance CSA for his extensive voluntary work in the security community around the world. Thanks to his invaluable contributions to the industry and his unique background that combines leadership, communication, and technology, Kai is a popular keynote speaker and guest lecturer. He focuses on presenting complex challenges in easy-to-understand language. He is also a frequent guest on podcasts, radio, and TV, where he explains security in ways that resonates with non-security people.
When Kai is not working, he enjoys riding his motorcycles, spending time in the outdoors, and BBQing with his family and friends.
You can connect with Kai on:
https://www.linkedin.com/in/kairoer
https://twitter.com/kairoer
Customer reviews
Customer Reviews, including Product Star Ratings help customers to learn more about the product and decide whether it is the right product for them.
To calculate the overall star rating and percentage breakdown by star, we don’t use a simple average. Instead, our system considers things like how recent a review is and if the reviewer bought the item on Amazon. It also analyzed reviews to verify trustworthiness.
Learn more how customers reviews work on Amazon-
Top reviews
Top reviews from the United States
There was a problem filtering reviews right now. Please try again later.
I'm an entry-level info sec analyst. However, I aspire to become a subject matter expert in security culture. This book provides some excellent insight for me and others seeking the same lofty goal.
Well written, engaging, thoughtful, and purposeful book.
Cybersecurity - done well - requires well-designed systems, a solid technical layer of protection, and purposefully secure actions of everyday people who interact with technology. Carpenter and Roer will show you how and why.
I distilled a good portion of the book for later review, and my marked-up copy of the physical book looks like I'm conversing with the book as though it were alive.
Pick up a copy and dive in!












