Left Arrow Icon
All articles

Security's Most Powerful Tool Is A Culture Of Shared Responsibility

The Security Digest - News Team
Published
August 3, 2026

UniFirst Information Security Manager Edward Matthews on why culture beats tooling in cybersecurity and how AI works best as a force multiplier for capable teams.

Credit: The Security Digest

Make The Security Digest one of your go-to sources on Google

Google Icon
Add The Security Digest on Google
Quote Icon
Security is reactive by nature, but the shift to being proactive starts with culture. You can't just do that overnight.

Edward Matthews

Information Security Manager

Edward Matthews

Information Security Manager
UniFirst

The cybersecurity market sells technology as the answer. Every vendor pitch, every product launch, every RFP frames the next tool as the thing that will finally close the gap. But the organizations that actually shift from reactive to proactive security rarely get there by buying more alone. They change how their people think about security, which is slower, harder, and far more durable than any platform purchase. The biggest differentiator is whether security has become everyone's responsibility or stayed the security team's problem.

Edward Matthews is the Information Security Manager at the uniform and workwear services company UniFirst and host of the Matthews Cybercraft podcast. He holds a GIAC certification and a master's degree, and his resume includes security engineering leadership roles at Mass General Brigham and Bright Health, where he oversaw threat and vulnerability management and security operations teams. That background across highly regulated industries shapes his conviction that the hardest part of security maturity is cultural, not technical.

"Security is reactive by nature, but the shift to being proactive starts with culture. You can't just do that overnight," he says. That framing puts the emphasis where Matthews believes it belongs, on the slow work of changing how an organization relates to security rather than on the fast fix of a new acquisition.

Reactive by nature, proactive by design

Security begins as a reactive discipline because threats arrive on their own schedule. Something happens, the team responds, and the cycle repeats. Becoming proactive means getting ahead of that cycle and anticipating risk rather than answering it, and that shift does not come from a product. "You can buy the best tools in the world, but if the culture isn't there, you're still going to be reactive. The tools help, but they don't change the mindset on their own," Matthews asserts.

He's direct that the cultural change is the harder project precisely because it cannot be purchased or rushed. It requires sustained effort to move an organization from treating security as the security team's job to treating it as a shared responsibility. The transition happens person by person and team by team, over a timeline measured in years rather than quarters.

The payoff is that a proactive culture compounds. Once security thinking is embedded across functions, every employee becomes a sensor and a first line of defense, which extends the security team's reach far beyond what its headcount alone could cover.

Security as everyone's responsibility

The core of the cultural shift is distributing ownership. When security lives only inside the security team, the rest of the organization has no reason to think about it, and the team spends its time chasing problems that better habits elsewhere would have prevented. When security becomes everyone's responsibility, the dynamic changes. "The goal is to get to a place where people across the organization are thinking about security in their day-to-day work. Not because we're forcing them to, but because it's part of how they operate," Matthews says.

Reaching that state depends on two things he emphasizes repeatedly: leadership buy-in and cross-functional collaboration. Without leadership visibly backing security as a priority, the message that it matters never fully lands because employees take their cues from what leadership actually reinforces. And without collaboration across departments, security remains siloed, unable to influence the workflows where risk actually originates. "You need leadership bought in, because that's what gives you the ability to work across teams. If the top isn't behind it, you're constantly fighting for attention and resources," Matthews notes.

The collaboration piece matters because the security team doesn't own most of the systems, processes, or decisions where vulnerabilities enter. Engineering, operations, HR, and every other function make choices that affect the organization's risk posture. Security's job is to influence those choices, which is only possible through relationships built across functional lines.

Metrics that show progress over time

Cultural change is notoriously hard to measure, which makes it hard to fund and hard to sustain. Matthews addresses that by focusing on metrics that demonstrate progress over time rather than snapshots that capture a single moment. "You have to show progress. Leadership wants to see that what you're doing is working, and that means metrics that trend in the right direction over time, not just a number at one point."

The distinction between trend and snapshot is important. A single vulnerability count or a one-time phishing test result says little about whether the organization is getting more secure. A metric tracked consistently over months and years shows whether the culture and the program are actually maturing. That trend line is what justifies continued investment and what proves the slow cultural work is paying off.

Matthews frames metrics as the connective tissue between the security team's daily work and leadership's confidence in it. The right measures translate security activity into a story leadership can follow, which in turn sustains the buy-in that makes the cultural change possible. The relationship is reciprocal: leadership support enables the work, and metrics demonstrating progress sustain the leadership support.

AI as a force multiplier

On AI, Matthews is optimistic but measured, and his framing is consistent with his people-first thesis. AI matters not because it replaces the security team, but because it removes the repetitive work that consumes the team's time, freeing them to focus on the strategic priorities that actually require human judgment. "AI is going to be huge, but as a force multiplier. It takes the repetitive, time-consuming work off your plate so your people can focus on the things that actually need a human."

The value is in reallocating human attention. Security teams spend enormous effort on repetitive tasks: triaging alerts, correlating data, handling routine analysis. AI can absorb much of that load, which doesn't shrink the team's importance but redirects it toward the higher-order work of anticipating threats, improving processes, and building the proactive posture that culture makes possible.

That framing keeps AI in its proper place within Matthews's argument. It's a tool that amplifies a capable, well-organized team without substituting for the cultural foundation, and an organization that deploys AI without doing the cultural work will simply automate its reactive posture rather than becoming proactive. The technology accelerates whatever is already there, which is why the people and culture have to come first.