Security Culture at Dropbox: Trust as a Company-Wide Habit
Dropbox's Security Team protects roughly one exabyte of data for over half a billion registered users. That responsibility doesn't rest solely on the security team—it requires every employee to make secure decisions daily. The company's first core value, "Be Worthy of Trust," frames security as part of the organizational identity, backed by a dedicated Security Culture Team that works year-round to foster an environment where employees make informed, secure choices.
Many companies approach security culture through gamification or mandatory training. Dropbox does both, but its flagship effort is Trustober, an annual companywide event held during National Cyber Security Awareness Month in October. What started as a way to educate has become one of the company's largest gatherings.
Trustober: A Month of Security Programming
Trustober is designed to help employees understand how Dropbox protects users, data, and physical spaces. In 2017, the Security Team ran over 30 programs globally, ranging from short talks and Q&As to full-day workshops. Topics covered included:
- Social engineering and phishing
- Tailgating and physical security
- Threat modeling
- Account security and two-factor authentication
- Secure coding practices
- Password hygiene and password managers
- First aid and CPR training
- Bug bounty programs
- Business continuity practices
Most sessions were developed in-house with a strong volunteer base and shared across global offices. External speakers from the security community—including Adam Shostack, David Molnar, Charlie Reis, Brad Hill, and Frans Rosén—also contributed talks and research insights.
Immersive Learning and Hands-On Exercises
Dropbox takes an experiential approach to security education. Given that Verizon's 2018 Data Breach Investigations Report found over 90% of breaches involve phishing or social engineering, the team devoted significant attention to this area. One workshop immersed volunteers in a hypothetical scenario involving a malicious insider, requiring collaborative investigation under time pressure. The exercise was designed and led by internal experts and took participants out of their daily routines to see social engineering in action.
The team also ran a hands-on phishing workshop where employees researched, crafted, and presented their own phishing schemes, learning what makes fraudulent emails look legitimate. This is part of a broader effort to create a positive culture around reporting suspicious messages, supported by regular test campaigns.
Historical perspectives add depth to these programs. Dr. Mark Baldwin, an expert on the Enigma Machine, demonstrated how human error and procedural flaws undermined the cipher's technical sophistication. His sessions highlighted that an organization is only as secure as the people operating it.
A standout event is the annual Capture the Flag (CTF) competition, designed and run internally. In 2017, over 200 employees participated in challenges covering topics from disk forensics to writing XSS payloads that bypass CSP. The goal is to teach employees to recognize security flaws while practicing offensive thinking.
Physical safety is also part of the culture. In 2017, Dropbox partnered with the American Red Cross and the Irish Heart Foundation to offer First Aid and CPR certification courses. Over 200 employees signed up for the voluntary workshops and received certifications, strengthening emergency preparedness in the workplace.
Measuring Impact
Assessing the effectiveness of culture programs involves more than tracking attendance. Dropbox observes engagement through internal discussions about topics like badging, tailgating, and CTF challenges—signals that security thinking is becoming part of everyday conversation. While events attract audiences ranging from small groups to over 100 attendees, encouraging participation amid competing commitments remains a challenge.
Employee surveys provide direct feedback. Over 90% of respondents found Trustober content helpful for security and safety in their roles. Comments echoed a shared responsibility for trust and vigilance, with one employee noting that "the bad guys are always learning too."
The scale of Trustober 2017 required 130 volunteers across nearly a dozen offices. The payoff is a library of talks, workshops, and programs that employees can continue to access as the company grows.
Building Your Own Program
For companies looking to start a similar initiative, Dropbox suggests assessing current security behaviors first, then identifying specific areas for improvement and defining clear goals. Programs should be tailored to existing company culture, with close partnerships with stakeholders who can help drive the effort. Sharing goals broadly with employees is key to gaining support.
As one employee put it, "Holy crap, it's crazy out there!" The takeaway is that building a culture of security requires sustained resources, skills, and support—beyond simple awareness campaigns.



