Annual surveys work best as a decision input, not a vanity metric. IT leaders should compare current responses with prior years, look for consistent pain points, and use the data to sequence investments in security, device management, and remote work operations. That approach helps teams avoid guessing, aligns priorities with real operational strain, and gives stakeholders a clearer basis for changing direction.
Using survey results to decide what to fix first
Annual admin surveys are most useful when leaders treat them as a prioritisation signal, not a popularity contest. The real value comes from separating recurring operational pain from one-off complaints, then weighting issues by how often they appear and how directly they affect security, endpoint control, and remote access reliability. That keeps decisions anchored in evidence rather than the loudest voice.
When survey answers repeat across years, they usually point to structural friction, such as weak device management, inconsistent access workflows, or remote work controls that are hard to use at scale. Leaders should use that pattern to decide which problems need investment, which need process changes, and which require remote access identity controls before the next operating cycle.
Surveys also help distinguish whether the pain is security-driven, operationally driven, or both. If administrators consistently report workarounds, that is often a sign that the control design is creating risk through bypass behaviour, shadow admin paths, or delayed remediation. The goal is to identify where the current operating model is forcing people to choose between speed and control.
What survey signals should change security and remote work investment?
Not every survey item deserves the same response. Leaders should elevate responses that indicate broad exposure, such as repeated difficulty enforcing device posture, unreliable MFA flows, inconsistent remote access performance, or too many exceptions for privileged work. Those issues affect both user experience and the practical strength of the control environment.
By contrast, isolated dissatisfaction with a tool is less important than a pattern that shows a control is not working as designed. If the survey shows that teams cannot complete admin tasks securely from remote locations, the organisation may need to revisit the access model itself, not just tune a setting. That is where NIST Cybersecurity Framework 2.0 is useful for structuring the decision around govern, identify, protect, detect, respond, and recover.
Survey data is strongest when it is paired with operational evidence. A complaint about remote work friction matters more if it lines up with VPN saturation, exception-heavy access patterns, delayed endpoint compliance, or repeated requests for manual approval. That combination tells leaders the issue is not just sentiment, it is a control and service delivery problem that deserves sequencing in the roadmap.
Turning recurring complaints into a decision roadmap
The best way to use annual surveys is to turn them into a ranked backlog with clear ownership. Leaders can group issues into security, device management, collaboration, and remote access, then decide which items are blockers, which are efficiency gains, and which are tolerance issues that can wait. That prevents survey results from becoming an unfocused wish list.
For example, if the survey shows that admins are spending time on manual access exceptions, weak device compliance, or repetitive authentication issues, the right next step is to target the underlying control path rather than the symptom. In that situation, the strongest improvements often come from tightening identity, access, and endpoint policy together, supported by NIST SP 800-53 Rev 5 Security and Privacy Controls and the account, access, and logging safeguards it formalises.
When remote work is part of the decision, the survey should inform where flexibility is acceptable and where it creates too much operational drag. Some teams may need stronger managed-device requirements, while others may need better split-tunnel policy, session controls, or clearer remote admin paths. The point is to use the survey to decide which friction is justified by risk and which friction is just poor design.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.PO-01 — Policies, Processes, and Procedures | Survey results should shape documented security and remote-work priorities. |
| GV.RM-01 — Risk Management Strategy | Recurring admin pain should feed risk-based sequencing of investments. | |
| PR.AA-05 — Identity Management, Authentication, and Access Control | Remote admin friction often maps to access and authentication controls. | |
| Recommendation — Use survey evidence to update security and remote-work policy priorities. Rank survey-driven issues by risk impact before funding fixes. Tighten access controls where survey feedback points to insecure workarounds. | ||
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | Admin surveys often surface overbroad access and exception-heavy workflows. |
| IA-2 — Identification and Authentication (Organizational Users) | Remote work decisions commonly hinge on strong admin authentication. | |
| AU-6 — Audit Review, Analysis, and Reporting | Survey findings should be checked against logs and operational evidence. | |
| Recommendation — Reduce privileged exceptions where survey data shows routine access friction. Strengthen user authentication paths that admins report as painful or unreliable. Correlate survey complaints with audit data before changing priorities. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Admin survey issues frequently indicate access-control design problems. |
| A.8.5 — Secure authentication | Remote work decisions depend on whether authentication is usable and robust. | |
| A.8.1 — User endpoint devices | Device-management pain is central to many remote-work survey findings. | |
| Recommendation — Adjust access-control policy where survey feedback shows unsafe workarounds. Improve authentication flows that create recurring remote-work friction. Prioritise endpoint controls when surveys show device management strain. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | Survey responses often reveal unmanaged exceptions and weak access governance. |
| Recommendation — Use survey trends to close access exceptions and standardise admin paths. | ||
Practitioner Guidance
What to prioritise: Put repeated, cross-team pain ahead of isolated complaints, especially when the issue affects privileged access, device control, or the ability to work securely from offsite locations. A single severe finding may justify immediate action, but the best prioritisation comes from problems that persist year over year.
What to verify: Check whether the survey result is supported by usage data, ticket trends, or exception rates. If the narrative says remote work is fine but the metrics show heavy workaround use, the survey is describing sentiment, not operational reality.
Decision rule: If a survey issue directly affects secure access or device trust, treat it as a security and operations decision, not an employee preference survey. If it mainly reflects convenience, rank it lower unless it is driving insecure workarounds.
Practitioner takeaway: The most defensible use of annual admin surveys is to identify where security controls, remote work design, and day-to-day operations are misaligned, then fund the fixes that reduce both risk and admin friction.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org