Watch or listen to the book review here:

I’ve read plenty of books about cybersecurity culture and security awareness. So when I picked up Bryan Perkola’s Energized Cybersecurity Culture: A Marketing Approach to Build Excitement and Increase Participation in Your Security Awareness Program, I had a pretty obvious question: What makes this one different?
The answer comes early: marketing.
Bryan is Senior Vice President of Information Security at First Community Credit Union here in Houston, and I’ve known him for a while. He’s a well-respected CISO who brings something different to the security-awareness problem: experience working deeply with marketing and graphic design teams.
That background shapes the entire book.
In fact, this is one of those rare books where I’ll tell you not to skip the introductory material. I’m guilty of doing that myself, but Bryan uses the opening to explain how his marketing experience influenced his approach to cybersecurity culture. Without that context, you’re going to miss some of what makes the rest of the book work.
The basic idea is that we need to stop approaching security awareness purely as an engineering problem.
Cybersecurity people love engineering problems. Give us systems, controls, vulnerabilities and data, and we’re happy. People are different.
Bryan illustrates that nicely when he describes employees as part of the security stack and talks about updating their “firmware” through training. Taken by itself, that could sound cold. But that isn’t how he approaches people at all. There’s a lot of empathy in this book.
People aren’t machines. They learn differently. They respond to different messages. You can’t throw the same annual training at everybody and expect them to absorb it.
That’s where marketing comes in.
Marketing thinks about target audiences. It thinks about campaigns, positioning and how to get people to pay attention. Bryan walks security practitioners through those fundamentals and shows how they can be applied to awareness programs that people might actually engage with instead of clicking through as quickly as humanly possible.
He also doesn’t ignore the business case.
Security culture costs money, and sooner or later you have to explain to management why the organization should invest in it. Bryan provides plenty of statistics and supporting material that security leaders can use to make that argument. As he puts it, humans are among the most attacked resources in an organization, and they can become either a liability or an asset to the cybersecurity program.
And for those security practitioners getting nervous about all this marketing talk, don’t worry. Bryan hasn't forgotten his audience. There are some solid mathematical approaches in here, too. You’ll still get your chance to geek out.
What I like most is that Bryan makes potentially unfamiliar territory approachable. He takes marketing concepts that some security professionals might dismiss—or simply don't understand very well—and demonstrates how they can solve a problem our traditional methods haven’t solved particularly well.
If you’re responsible for cybersecurity culture or security awareness, if you’ve struggled to build an effective program, or if what you’re doing today simply isn’t generating engagement, Energized Cybersecurity Culture is worth your time.
Sometimes the answer isn’t more security training.
Sometimes we need to get better at selling security.

