People are influenced by those who are like them or those they find likeable – that is, people flock to birds of a similar feather, as well as to “feathers” they find appealing. People are more likely to comply with requests when these requests are issued by someone in an authority role (or even by someone with the mere accoutrements of authority – badges, white jackets, business attire, etc.). Based on Cialdini’s principles, we recommend the following six strategies to fortify the human firewall against the deceptive techniques of criminals and foster a security-aware organizational culture. 1. Ask employees to sign a security policy. Demonstrating commitment, such as signing a code of ethics,  makes people more likely to follow through and leads to greater cognitive and behavioral adherence with codes of conduct. These policies are written commitments that state an employee will, for instance, treat all sensitive corporate information (e.g., customer and contractual data) confidentially, proceed in the best interest of the organization during on- and offline activities, and report suspicious incidents immediately to the respective internal point of contact. Employees also acknowledge that they will not disclose any sensitive corporate information to any external parties. Within the policy, it’s useful to clearly state which kind of information is sensitive and which is not. (E.g., you can’t ask an employee to not complain about the company’s cafeteria food on social media but you can ask them not to disclose client lists). For example, CISCO requires its employees to annually sign a code of business conduct that reminds them how to protect the company’s intellectual property, as well as confidential information assets. The company requires that its employees not share confidential or proprietary information with people who have no legitimate business need for it and to commit to reporting any observed breaches of such requirement. A corporate culture of blame can discourage employees from reporting suspicious activities, but ensuring they understand the rationale and asking them to sign a policy that signals their responsibility to report suspicious activities can circumvent this issue. It’s important that signing a commitment like this is voluntary — if it’s forced, the subsequent internal impulse to commit will be weaker. But the act of signing fosters personal (inside) and interpersonal (outside) consistency pressures, which makes it more likely they will adhere to the company’s standards. And it’s best if the employees can sign it in the presence of co-workers; once a commitment is public, employees feel obliged to act consistent to the commitment, lest lose face in front of their esteemed colleagues.