Adoption friction is the effort, confusion, or delay that makes employees avoid a security control or use it inconsistently. High friction turns good controls into optional ones, so governance should treat usability as part of control effectiveness.
Why adoption friction matters
Adoption friction is not just a usability annoyance, it is a control-effectiveness problem. When a security step feels slow, unclear, or hard to repeat, people route around it, create workarounds, or apply it inconsistently, which weakens the control even if the policy is sound.
In practice, friction often shows up where a control asks for too many steps, too much context switching, or too much interpretation. The control may still exist on paper, but the organisation gets partial compliance instead of reliable behaviour.
What creates adoption friction
The main causes are usually operational rather than technical: confusing instructions, repetitive approvals, poor timing, and controls that interrupt the task flow. A rule that is easy to understand but hard to perform will usually be ignored under pressure.
Adoption friction also increases when the control does not match the real work pattern. If a process is designed around idealised behaviour instead of actual workflows, users experience it as overhead rather than protection.
How adoption friction affects security outcomes
Friction changes security outcomes by pushing users toward the fastest path, not the safest one. That can reduce logins, approvals, reviews, or reporting to symbolic actions instead of dependable safeguards.
It also creates uneven control quality across teams. One group may comply because the process suits their work, while another relies on shortcuts, informal approvals, or delayed execution. The result is inconsistent governance and weaker assurance.
Good control design treats usability as part of the control itself, not a separate “nice to have.” If a safeguard is too hard to use, its practical strength declines even when its technical design is strong.
How to think about adoption friction in governance
Governance teams should evaluate not only whether a control exists, but whether it is realistic to use at the moment a decision must be made. A control that is technically correct but operationally awkward will often lose to human behaviour.
That means adoption friction is a signal to simplify the workflow, reduce unnecessary steps, and align the control with the task context. The aim is not to remove protection, but to make the secure path the easiest path.
Practitioner note: The best indicator of adoption friction is usually not complaints, it is inconsistency. If users keep bypassing a control, they are telling you the control does not fit the work.
Risk and Threat Considerations
Adoption friction creates a predictable security exposure: people delay, bypass, or inconsistently apply controls that feel costly to use. Over time, that turns optional behaviour into an attack surface, because the weakest and least-followed step is usually the one adversaries learn to exploit.
Failure mechanism: The control remains nominally in place, but repeated workarounds, exceptions, or manual shortcuts reduce enforcement quality and create gaps between policy and practice.
Impact: Poor adoption can lead to missed approvals, weaker authentication behaviour, delayed remediation, reduced audit confidence, and a larger opportunity window for misuse or compromise.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, CIS Controls v8 and OWASP ASVS set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AT-01 — Awareness and Training | Adoption friction affects whether users can consistently follow security expectations. |
| GV.PO-01 — Policy | Policies fail when they are too hard to execute in normal operations. | |
| Recommendation — Design training and control prompts so users can apply the control correctly at the point of use. Write policies with the actual operational workflow in mind so compliance is achievable. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Access controls lose effectiveness when user friction drives workarounds or inconsistent use. |
| Recommendation — Keep access controls usable enough that employees follow them instead of bypassing them. | ||
| CIS Controls v8 | CIS-5 — Account Management | Account and access processes often fail when administration steps create avoidable friction. |
| Recommendation — Streamline account workflows so users and administrators can complete required actions reliably. | ||
| OWASP ASVS | V13 — Configuration | Security controls that are difficult to configure or use are more likely to be bypassed or misapplied. |
| Recommendation — Reduce configuration complexity so secure settings are easier to adopt and maintain. | ||
Practitioner Guidance
What to watch for: Treat repeated bypasses, exception requests, and low completion rates as a design signal, not just a user problem. They often indicate that the control is asking for too much effort, context switching, or interpretation at the wrong moment.
Governance implication: Measure the real cost of using a control in the workflow where it actually lives. If the secure path is slower or more confusing than the unsafe one, policy will rarely win without redesign.
Related resources from NHI Mgmt Group
- How should organisations improve employee adoption of security controls without creating more friction?
- How should security teams use FedRAMP authorization to reduce cloud adoption friction without weakening governance?
- How should mobile app teams implement passkey adoption without creating extra login friction for users?
- Why does integrating AI security into the platform environment reduce adoption friction for enterprise teams?