Join our Newsletter — 33% off our NHI Course

Why does adding security sometimes increase business risk instead of reducing it?

Security can increase risk when it is so cumbersome that users or teams start bypassing it. That creates shadow processes, weak exceptions, and inconsistent enforcement. The article argues that organisations often treat security as a productivity tax, but poor adoption can expose systems more than the original control would have protected them.

Why Security Controls Become a Business Risk When Adoption Fails

Security only reduces risk when people can actually use it in the flow of work. If a control adds too much friction, teams tend to work around it with shared accounts, informal approvals, or one-off exceptions. That shifts risk from the control itself to the behaviour it drives, especially when bypasses become routine and invisible.

The core issue is that security is part of the operating model, not a bolt-on barrier. A control that is technically strong but operationally rejected can create inconsistent enforcement, weaker accountability, and a larger attack surface than the original baseline.

One useful way to think about this is that the apparent protection of a hard control can be offset by the damage caused when users stop following it. For example, controls around secrets and access often fail not because they are absent, but because teams need a practical path that matches delivery speed and application ownership. NHI Mgmt Group’s Ultimate Guide to Non-Human Identities is a useful reference point here because poor rotation, weak offboarding, and excess privilege all become more likely when controls are hard to operate.

Where the Risk Actually Emerges

The business risk is usually not the security policy itself, but the shadow process it creates. When teams cannot complete work through the approved control, they invent workarounds, and those workarounds often bypass logging, review, rotation, or least-privilege checks.

That is why “stronger” security can produce weaker outcomes if it increases exception volume or normalises informal access paths. A control that looks effective on paper can conceal the real exposure by pushing activity into unmanaged channels.

In practice, the danger compounds when bypasses become operational habit. The organisation ends up with multiple inconsistent versions of the same control, which makes incident response, audit, and remediation slower and less reliable. The breach pattern described in TruffleNet BEC Attack shows how stolen credentials can be abused once controls stop being consistently followed, and the problem becomes broader than the original safeguard.

Risk and Threat Considerations

When users bypass cumbersome security, the organisation creates a secondary exposure: unmanaged access paths that are harder to monitor, harder to revoke, and easier to abuse. The security loss often arrives through exceptions, shared workarounds, and delayed remediation rather than through the original control failure itself.

Failure mechanism: Friction drives workarounds, workarounds create shadow processes, and shadow processes bypass the control properties that were supposed to reduce exposure, such as visibility, accountability, and timely revocation.

Impact: The business can end up with broader privilege, weaker auditability, slower incident response, and a larger blast radius than if the control had been simpler or more aligned to real workflows.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack surface, NIST CSF 2.0 and CIS Controls v8 set the technical controls, and PCI DSS v4.0 define the regulatory obligations.

Framework Control / Reference Relevance
NIST CSF 2.0 PR.AC — Access Control Controls access paths and least-privilege enforcement when security workarounds create exposure.
GV.OC — Organizational Context Requires security decisions to fit business operating realities and user adoption constraints.
Recommendation — Align access controls with usable workflows so users do not bypass them. Assess whether a control fits operational reality before rolling it out.
CIS Controls v8 6 — Access Control Management Directly addresses account and access governance when cumbersome controls trigger exceptions and bypasses.
Recommendation — Tighten access governance while keeping approved access paths practical to use.
OWASP Non-Human Identity Top 10 NHI-01 — Secrets and Credential Management Poorly adopted controls around credentials and secrets increase bypasses, leaks, and unmanaged access.
NHI-03 — Identity Lifecycle and Offboarding Workarounds often delay revocation and leave credentials active beyond their intended lifetime.
Recommendation — Reduce friction in secrets handling so teams do not store or share credentials unsafely. Make revocation and offboarding simple enough that teams complete them on time.
PCI DSS v4.0 7 — Restrict Access by Business Need to Know Business-need access is undermined when controls are so hard to use that people bypass them.
8.6 — System and Application Accounts and Authentication Factors Cumbersome account controls often push teams toward shared or unmanaged credentials.
Recommendation — Apply least-privilege access in a way that users can follow consistently. Control system and application accounts so convenience does not drive credential bypass.

Practitioner Guidance

What to prioritise: Treat adoption quality as part of the control’s security value. If a safeguard increases exceptions, shared access, or manual overrides, measure the resulting exposure instead of assuming the control is helping.

What to verify: Check whether teams can complete routine tasks without creating permanent exceptions. If the approved path is slower than the informal one, expect the informal path to become the real control surface.

Common mistake: Measuring security by policy presence rather than by actual usage. A control that looks strict but is widely bypassed often increases enterprise risk because it obscures where authority really sits.

Practitioner takeaway: The goal is not maximum friction, it is durable enforcement. Security reduces risk only when the control is usable enough that teams keep using it under pressure.