When controls become cumbersome, users look for shortcuts, and those workarounds often undo the security benefit. People reuse credentials, bypass approved steps, or create informal access paths that are harder to monitor. Effective programs balance protection and usability, so teams can raise assurance without pushing users toward insecure behavior that increases identity risk.
Why adding more controls can backfire when the user experience gets harder
Security controls work best when people can follow them consistently. If each added step slows work, users naturally look for ways around it, and those shortcuts often become the real control path. The result is not just inconvenience, but weaker assurance because the organisation starts depending on informal behaviour that was never designed, reviewed, or monitored.
Once friction rises, the control can fail at the human layer even if the technical design is sound. Teams may see lower completion rates, more helpdesk work, more shared access, and more “temporary” exceptions that outlive the original need. The security posture then depends on whether users tolerate the process, not whether the policy exists.
That is why balanced design matters: a control that is technically stronger but operationally unusable may deliver less protection than a simpler control people will actually follow. In practice, the risk is especially visible where authentication, approvals, or access reviews are made so cumbersome that users choose reuse, delegation, or ad hoc workarounds instead of the intended path. For background on how identity controls, least privilege, and access governance are supposed to hold together, see Ultimate Guide to NHIs, Standards.
Where the security loss usually shows up first
The first sign is usually compensating behaviour, not a direct breach. People reuse credentials, save passwords in unsafe places, share accounts, bypass approved workflows, or create parallel access paths that are easier to use than the official one. Those choices reduce friction locally, but they increase blast radius, weaken accountability, and make later investigation much harder.
This also creates a measurement trap. A control may look successful because it is present, while the real security outcome deteriorates elsewhere. For example, a stricter approval gate can reduce visible misuse but increase shadow access channels, or a more aggressive challenge flow can reduce successful attacks while driving users toward weaker fallback methods. The control should therefore be judged by the security behaviour it induces, not by the number of checks it adds.
Well-known control frameworks reflect this practical balance. NIST SP 800-53 Rev 5 Security and Privacy Controls and CIS Controls v8 both support the idea that account management, access control, auditability, and configuration need to be implemented in ways users can sustain. Where access friction is the problem, the practical answer is often a tighter, simpler control set rather than more layers.
What good control design looks like in practice
The goal is not to minimise security controls, but to remove unnecessary friction from the path that users must follow every day. Good design makes the secure path the easy path: clear authentication, predictable approvals, minimal exception handling, and review cycles that are proportionate to the risk being protected. When users understand why a control exists and can complete it without constant workarounds, compliance improves naturally.
For identity-heavy environments, this usually means reducing repeated prompts, eliminating redundant approvals, and aligning assurance level with actual business risk. It also means watching for the hidden cost of exceptions, because temporary access, shared credentials, and informal delegation often become long-lived when the process is painful. The right question is not “did we add another safeguard?” but “did we reduce the chance that people will route around it?”
Architecture guidance that helps here includes ISO/IEC 27001:2022 Information Security Management and NIST SP 800-207 Zero Trust Architecture, both of which reinforce the need for controlled access without assuming users will tolerate arbitrary friction. In cloud environments, the same principle is reflected in the CSA Cloud Controls Matrix, especially where access, audit, and governance must work together rather than compete.
Risk and Threat Considerations
When control burden rises faster than usability, the organisation creates a predictable bypass pattern. Users stop following the intended process, and attackers benefit from the resulting reuse, shared access, weak fallback methods, and unreviewed exceptions. The risk is not only policy noncompliance, but a broader expansion of the attack surface through informal access paths and reduced accountability.
Failure mechanism: Excessive friction drives compensating behaviour, such as credential reuse, account sharing, bypassed approvals, and unmanaged exceptions, which weakens monitoring and makes abuse harder to detect.
Impact: The organisation loses assurance while believing it has increased it, and that gap can translate into unauthorized access, harder incident response, and higher identity risk across the environment.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5, CIS Controls v8 and NIST Zero Trust (SP 800-207) set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Directly governs credential lifecycle and reuse pressure in access controls. |
| AC-6 — Least Privilege | Controls excessive access that users may otherwise bypass or delegate informally. | |
| Recommendation — Reduce friction by managing authenticators so users do not rely on unsafe reuse or shared access. Limit access to the minimum needed so workarounds do not expand blast radius. | ||
| CIS Controls v8 | CIS-5 — Account Management | Addresses account handling and access paths where friction can drive unsafe shortcuts. |
| Recommendation — Streamline account management so approved access paths remain easier than shadow ones. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Requires access control to be implemented consistently without creating avoidable bypass pressure. |
| Recommendation — Design access control so users can follow the approved path without resorting to workarounds. | ||
| NIST Zero Trust (SP 800-207) | Zero Trust Architecture | Supports verifying access decisions while keeping controls aligned to actual trust needs. |
| Recommendation — Apply zero trust principles to remove unnecessary broad access and reduce shortcut incentives. | ||
Practitioner Guidance
What to prioritise: Measure whether a control changes user behaviour before you declare it effective. High abandonment, repeated exceptions, and helpdesk-driven workarounds are strong signals that the control is pushing risk somewhere else instead of reducing it.
Decision rule: If a safeguard causes users to route around it for routine work, simplify the workflow or raise only the assurance step that is truly needed for the protected action. Do not add friction broadly and assume the security outcome will improve automatically.
Practitioner takeaway: The most secure control is the one people can keep using correctly; if usability collapses, the organisation often inherits a less visible but more dangerous set of informal access practices.
Related resources from NHI Mgmt Group
- How should security teams add identity verification to signup flows without creating excessive user friction?
- What happens when insurers add eKYC without enough privacy, security, and compliance controls?
- What happens when security teams focus on attacker friction without reducing internal complexity?
- What happens when security teams add browser-based controls to identity workflows without a SIEM?