Cyber Kindness started as a security world idea before growing into something wider. The campaign, which Lisa Ventura MBE FCIIS founded and which now runs under the AI and Cyber Security Association, asks a simple question of anyone working online: stop and consider your actions, at work and anywhere your words reach another person. The framing is blunt on purpose. Abuse is not expertise. Silence is not neutrality. Kindness is not weakness.

Read this way, Cyber Kindness looks like a conduct campaign, and a conduct campaign is exactly what the founders set out to build. What gets missed is the security argument sitting underneath the campaign. Psychological safety is not a wellbeing add-on next to a security programme. Psychological safety is one of the load-bearing walls.

The Same Argument, Made Before On This Blog

This connects directly to an earlier post here, Why Reporting Culture Matters More Than Click Rates, which put the mechanism plainly: if a mistake gets punished, the rational response is not to stop making mistakes. The rational response is to stop admitting to them. Cyber Kindness names the missing ingredient the reporting culture argument depends on. A colleague only reports a mistake, a near miss, or a piece of harassment in the team channel when the room feels safe enough to say so out loud.

What Psychological Safety Means

Harvard researcher Amy Edmondson defined psychological safety in 1999 as a shared belief: a team is safe for interpersonal risk-taking, meaning nobody gets punished or humiliated for speaking up with a question, a concern, or a mistake. The concept sat mostly inside academic and leadership circles until Google put the idea under a research microscope.

Between 2012 and 2014, Google’s internal research effort known as Project Aristotle studied 180 teams and 250 team attributes, looking for what separated the strongest teams from the rest. Psychological safety came out top, ahead of dependability, structure, meaning, and impact. Worth noting this account comes through a secondary write-up, Psych Safety’s summary of the research, rather than Google’s own published material checked directly for this piece, so confirm the detail against Google’s original re:Work material before quoting the figures in a client-facing deck.

The Same Finding, From A Different Industry

Software operations teams learned a version of this lesson the hard way, through the blameless postmortem, a practice PagerDuty’s incident documentation traces back to Etsy. The idea is simple: examine how a mistake happened, not who made the mistake. PagerDuty puts the security risk of skipping this step directly: engineers hesitate to speak up when incidents occur for fear of being blamed, and this hesitation lengthens the time needed to notice and fix the problem. Blame does not prevent the next failure. Blame teaches people to hide the last one.

Security teams run the same risk every time an employee clicks a bad link, misconfigures a system, or misses a warning sign, and every time a colleague considers reporting a mistake made by someone else. A harsh word in a Slack channel or a public dressing-down in a meeting has the same chilling effect as a punitive security policy. Both teach people silence is the safer option.

What Cyber Kindness Asks Of A Security Team

Cyber Kindness sets out 4 principles, and each one translates directly into a habit worth building inside a security or awareness function.

  • Challenge ideas, not people. Question a decision or a piece of advice as hard as needed. The person behind the advice stays out of the argument.
  • Respect people, including colleagues who made the wrong call. A colleague who fell for a phishing email is a witness to how the attack worked, not a suspect.
  • Raise standards honestly. Check a claim before passing the claim along, inside a security team as much as anywhere else, and resist the urge to pile on when a colleague gets something wrong in public.
  • Support people under pressure. A colleague being blamed publicly for a breach, online or in the office, needs a hand held up on their behalf, not silence from the people who know better.

The Honest Position

Kindness will not stop a phishing email landing in an inbox. Kindness lowers the cost of admitting a mistake once one does, and this single change is the exact lever behind every metric this blog has argued for instead of click rates: reporting speed, voluntary disclosure, and colleagues who ask for help before a small problem becomes a large one. The Cyber Kindness Pledge on the campaign site is a reasonable starting point for a team wanting to test the idea, not because a pledge changes behaviour by itself, but because signing one out loud, as a team, is itself a small act of interpersonal risk-taking worth practising.

Further Reading And Sources