Agencies should treat digital transformation as a chance to redesign processes, not just automate old ones. The article argues for a strategic pause to test whether the new workflows, technologies, and operating assumptions still make sense after rapid change. If they do not, teams should adjust them to improve stability and security rather than preserving brittle habits.
Why redesign is usually the safer transformation choice
digital transformation is not just a tooling upgrade. If agencies simply automate a legacy workflow, they often preserve old handoffs, brittle approvals, duplicate data entry, and unclear accountability, only at higher speed. Redesigning the process forces teams to decide which steps still create value, which ones exist only because of historical constraints, and which ones now introduce avoidable operational or security exposure.
The practical test is whether the workflow still matches the current operating model. If the answer is no, preserving it usually means carrying forward inefficiency, control gaps, and failure points into a more connected environment. A redesign can remove unnecessary friction, clarify ownership, and make the process easier to monitor and govern.
When keeping the old workflow becomes a liability
Legacy workflows are often stable only because people know how to work around them. That is not the same as being resilient. When a process depends on manual exceptions, informal approvals, or outdated assumptions about who can do what, automation can amplify the weakness rather than fix it. The result is faster execution of a flawed pattern.
Agencies should be especially cautious where the workflow touches access, data handling, approvals, or inter-team dependencies. In those cases, redesign is not just an efficiency question. It can determine whether the new process has clear controls, reliable auditability, and consistent behaviour under pressure.
How to decide what to preserve and what to change
The best approach is selective redesign, not change for its own sake. Keep only the elements that still support the mission and are proven to work under current conditions. Redesign the rest around the actual service outcome, the current risk profile, and the technology being introduced.
That means testing the workflow against three questions: does it still reduce errors, does it still support accountability, and does it still make sense at scale? If any answer is weak, the process should be reworked before it is automated. In transformation programmes, the most expensive mistake is digitising a process that was never fit for purpose in the first place.
Risk and Threat Considerations
Keeping legacy workflows unchanged can preserve hidden control weaknesses, especially where older steps were built around paper approvals, tribal knowledge, or manual oversight. When those flows move into digital systems without redesign, agencies can inherit overbroad access, weak segregation of duties, poor traceability, and dependency on informal workarounds.
Failure mechanism: Automation increases the speed and reach of an existing process without correcting the underlying design flaw, so a brittle workflow can fail more consistently and at larger scale.
Impact: The agency may see more operational errors, weaker security controls, harder investigations, and greater resistance to future change because the new system now hard-codes an outdated model.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.PO-01 — Policy | The question is about whether to redesign processes during transformation. |
| PR.AA-05 — Managed Access Control | Legacy workflows often embed access and approval steps that need redesign. | |
| Recommendation — Align process redesign decisions to policy so new workflows reflect current operating assumptions. Review workflow access points and remove unnecessary approval or privilege paths. | ||
| ISO/IEC 27001:2022 | A.8.32 — Change management | Transformation requires controlled redesign of processes and supporting systems. |
| Recommendation — Use change management to redesign workflows before automating them. | ||
| NIST SP 800-53 Rev 5 | CM-3 — Configuration Change Control | Workflow redesign during digital transformation is a controlled change activity. |
| Recommendation — Control workflow changes so legacy assumptions are not copied into new systems. | ||
| CIS Controls v8 | CIS-4 — Secure Configuration of Enterprise Assets and Software | Modernising workflows requires reconfiguring systems instead of preserving brittle defaults. |
| Recommendation — Reconfigure transformed systems to match the redesigned process. | ||
Practitioner Guidance
What to prioritise: Review the highest-volume, highest-risk workflows first, especially those with repeated manual exceptions or unclear ownership. Those are usually the best candidates for redesign because they expose the biggest gap between the current process and the digital operating model.
What to verify: Before preserving any legacy step, confirm that it still serves a control purpose, not just a habit. If a reviewer cannot explain why the step exists, what risk it reduces, or what would break without it, the step is probably a candidate for removal or redesign.
Decision rule: If the process only works because people compensate for its weaknesses, redesign it before automation. If a step is still valuable but poorly implemented, re-architect the step rather than copying it into the new toolset.
Practitioner takeaway: Digital transformation should modernise the way work is done, not simply accelerate the constraints of the past. The goal is a process that is simpler to run, easier to govern, and less fragile under change.
Related resources from NHI Mgmt Group
- How should public agencies approach digital transformation when they need to keep essential services running during political instability?
- What breaks when security teams keep relying on legacy SIEM workflows during high-volume investigations?
- How should public sector teams implement low-code platforms when requirements keep changing during digital transformation programmes?
- Why does relying on legacy IAM increase risk during digital transformation?