Start with leadership, because culture follows executive priorities. Leaders need to treat cybersecurity as a business requirement, not an obstacle to productivity. The practical goal is to make security controls as invisible as possible to end users while still enforcing strong access checks, auditability, and rapid response. That balance reduces resistance and keeps security from being gradually weakened to restore convenience.
Why This Matters for Security Teams
A cybersecurity-first culture fails when security is presented as friction rather than as part of reliable service delivery. The organisations that sustain it usually make the secure path the default path, so people do not have to choose between productivity and protection. That means aligning leadership incentives, reducing repeated manual approvals, and designing controls that are strong but low-noise. Visibility and accountability matter, but so does restraint in the user experience.
One useful benchmark is that 90% of IT leaders say properly managing NHIs is essential for a successful zero-trust implementation, which reflects a broader truth: teams accept security more readily when controls are embedded into the workflow instead of bolted on later. In practice, many security programmes lose trust not because the controls are too weak, but because they are introduced in ways that users learn to bypass.
How It Works in Practice
The most effective model is to shift from manual, exception-heavy security to policy-driven controls that are consistent, low-friction, and observable. That usually means using strong authentication at the right entry points, then reducing day-to-day interruptions through session continuity, conditional access, device trust, and well-scoped permissions. Users should feel that security is mostly present when risk changes, not at every interaction.
A practical implementation sequence is:
- Design the default workflow so secure actions require the fewest possible extra steps.
- Use role-based access and least privilege to reduce repeated prompts and unnecessary approvals.
- Reserve stronger checks for high-risk actions, unusual locations, elevated privilege, or sensitive data access.
- Instrument audit logging and response workflows so the control is credible even when it is invisible.
This balance matters because friction is often a symptom of poor policy design, not of strong security itself. If every action feels exceptional, users will route around the control, request broad exemptions, or push for weaker shared access patterns. The better approach is to make the secure path predictable and the exception path genuinely inconvenient. Where organisations rely on legacy systems, frequent approval gates, or fragmented identity tooling, these controls tend to break down because users face too many repetitive checks for routine work.
Common Variations and Edge Cases
Tighter security often increases operational overhead, so organisations have to balance user convenience against the risk reduction they actually need. The right answer is different for consumer workflows, regulated environments, and privileged administrative tasks. A sales team, for example, should not experience the same interruption pattern as a production engineer or incident responder.
Current guidance suggests treating friction as a design problem, not a reason to weaken policy. High-friction controls can still be appropriate for rare, high-impact actions, but they should be targeted. By contrast, broad friction on low-risk, high-frequency tasks is a sign that the control layer is misaligned with the workflow. The common mistake is to “solve” resistance by loosening standards instead of reducing unnecessary prompts, duplicated logins, or poorly timed approvals.
In regulated or high-trust environments, some added friction is unavoidable because evidence, review, and accountability are part of the control objective. The key judgement is whether the extra step changes user behaviour for the better or merely creates noise. When users start treating security as administrative drag rather than risk management, the control model is already degrading.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, CIS Controls v8, NIST Zero Trust (SP 800-207) and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC — Access Control | Controls how access is granted with least friction and least privilege. |
| GV.OV — Oversight | Aligns leadership accountability with security behaviours and productivity trade-offs. | |
| Recommendation — Design access flows that enforce least privilege while minimising unnecessary user interruption. Set leadership oversight so security decisions are measured against business workflow impact. | ||
| CIS Controls v8 | 6 — Access Control Management | Directly governs account access, least privilege, and reducing administrative friction. |
| Recommendation — Standardise access provisioning and reduce manual exceptions to keep controls usable. | ||
| NIST Zero Trust (SP 800-207) | 3 — Continuous Verification | Supports low-friction security by checking risk at access time instead of relying on static trust. |
| Recommendation — Apply continuous verification so stronger checks appear only when context changes. | ||
| NIST SP 800-63 | IAL — Identity Assurance Level | Helps tune authentication strength to the assurance needed for each workflow. |
| Recommendation — Match identity assurance to the sensitivity of the action instead of applying one-size-fits-all checks. | ||
Practitioner Guidance
What to prioritise: Put the highest-friction controls under review first, especially the ones attached to routine tasks. If a control interrupts daily work without materially changing risk, simplify it before asking users to “adapt.”
Decision rule: If the action is low-risk and frequent, optimise for invisibility and consistency. If the action is privileged, irreversible, or sensitive, accept some friction, but keep it targeted and explainable.
What to verify: Check whether users are bypassing controls through shared accounts, exception requests, shadow processes, or informal workarounds. Those behaviours are usually a stronger signal than user complaints about friction.
Practitioner takeaway: The goal is not to eliminate friction everywhere, it is to reserve it for moments where the risk justifies it and remove it everywhere else.
Related resources from NHI Mgmt Group
- How should security teams implement context-aware authentication without creating too much user friction?
- How should small businesses implement MFA without creating too much user friction?
- How should organisations verify identity documents without creating too much friction?
- How should organisations verify vendor payment changes without creating too much friction?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 16, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org