Skip to content
Digital Bushido

07 / 08 of 8

忠義

07 / Chūgi 忠義

Loyalty

pronounced choo-gee

Domain: Security culture and insider risk

Guard the clan you belong to, and be worth guarding.

The argument

Protect what has been entrusted to you.

Every security role carries a form of stewardship.

An administrator receives privileged access. An engineer receives production access. A developer receives access to source code. An employee receives access to company information.

That access exists because someone trusts the role.

Security culture becomes effective when people understand that responsibility comes with access. Reporting a suspicious email, challenging an unsafe change or protecting a credential becomes part of doing the job correctly.

Technology can restrict behaviour. It cannot create responsibility.

The failure mode

Loyalty enforced by fear, which manufactures the insider it fears.

When Chugi is absent, security becomes someone else's job. Employees ignore suspicious activity. Administrators treat privileged access as personal capability. Teams assume another department owns the risk.

In practice

1 / 4 Foundation

Make the behaviour explicit and repeatable.

  • Assign system ownership

    Every important system has a named business or technology owner.

  • Define security responsibilities

    Make security duties part of relevant roles.

  • Teach intervention

    Tell people what to do when they see suspicious activity or unsafe behaviour.

Show all 5 practices
  • Provide reporting mechanisms

    Make reporting accessible without requiring specialist knowledge.

  • Define stewardship expectations

    Make clear what responsibility comes with privileged or sensitive access.

2 / 4 Controlled

Embed the behaviour into processes and ownership.

  • Include security in role definitions

    Make security responsibilities explicit for administrators, developers, engineers and system owners.

  • Review responsibility with access

    When sensitive access is renewed, confirm the user's continuing responsibility.

  • Build security into operational processes

    Include security checks in deployment, onboarding, change and decommissioning workflows.

Show all 5 practices
  • Establish vendor responsibility

    Define security responsibilities for third parties with access to company systems.

  • Support responsible reporting

    Ensure employees can report mistakes and suspicious activity without first resolving the issue themselves.

3 / 4 Measured

Verify that the behaviour is happening and that it works.

  • Measure ownership coverage

    Track systems and controls without an accountable owner.

  • Measure reporting behaviour

    Track useful reports of phishing, suspicious activity and control failures.

  • Measure unresolved ownership

    Identify security issues waiting because responsibility is unclear.

Show all 5 practices
  • Review privileged stewardship

    Sample privileged users and verify that access remains justified and understood.

  • Measure security participation

    Track participation in exercises, training and operational security activities.

4 / 4 Adaptive

Use evidence to improve the behaviour and respond to change.

  • Push responsibility toward the edge

    Move appropriate security decisions closer to the teams operating the systems.

  • Integrate security into engineering

    Make security part of normal engineering workflows rather than a separate approval stage.

  • Use incidents to clarify ownership

    Where an incident exposes responsibility gaps, change the operating model.

Show all 5 practices
  • Build security into performance expectations

    Where appropriate, include security responsibilities in team and role objectives.

  • Treat privilege as stewardship

    Review whether privileged access is still supported by the responsibility that justified it.

See the full practice model

Worked examples

Developer access

A developer receives production access to support an application.

They understand that the access exists because the company trusts them with a specific responsibility.

They use it only for that purpose.

Privilege creates a duty to protect the environment it reaches.

Suspicious email

An employee receives a convincing phishing email.

The message appears to come from the CEO.

They report it rather than simply deleting it.

The SOC discovers that several other employees received the same campaign.

Security culture turns individual awareness into collective protection.

Lost laptop

An employee loses a company laptop while travelling.

They report it immediately.

The device is remotely locked and credentials are revoked.

The incident remains contained.

Duty means reporting exposure before embarrassment becomes the priority.

Vendor access

An engineer notices that a third-party vendor still has access to an environment after their maintenance window.

They raise the issue and have the access removed.

They do not assume that somebody else owns the responsibility.

Stewardship means acting when you see a risk, even when it sits between organisational boundaries.

Sharing credentials

A colleague asks for an administrator's password because they need to solve an urgent problem.

The administrator refuses and provides the correct privileged-access process instead.

The incident takes longer to resolve.

The credential remains controlled.

Duty sometimes means refusing the convenient solution.

Mapped controls

Reading: Read as mutual, not demanded: an organisation earns loyalty by being worth defending. Coerced loyalty produces the insider it was meant to prevent, which is why the disciplinary-process mapping (A.6.4) is only partial.

NIST Cybersecurity Framework 2.0

ChūgiNIST CSF 2.0. Table scrolls horizontally.
ControlControl titleStrengthWhy it maps
PR.AT-02Personnel with specialised roles traineddirectTraining people in specialised roles builds the shared competence a security culture runs on.
GV.RR-04Cybersecurity is included in human resources practicesdirectIntegrating security into HR practices is how loyalty is built into the employment relationship rather than demanded of it.

ISO/IEC 27001:2022 — Annex A

ChūgiISO 27001:2022. Table scrolls horizontally.
ControlControl titleStrengthWhy it maps
A.6.1ScreeningdirectScreening establishes mutual trust at the point of hire.
A.6.2Terms and conditions of employmentdirectEmployment terms make the obligations of the relationship explicit on both sides.
A.6.4Disciplinary processpartialA disciplinary process addresses breaches, but coerced loyalty produces the insider it was meant to prevent — so the fit is only partial.
A.6.5Responsibilities after termination or change of employmentdirectDefining responsibilities that survive a role change keeps the obligation mutual through transitions.