Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk How should organisations build a cybersecurity-first culture without…
Governance, Ownership & Risk

How should organisations build a cybersecurity-first culture without creating too much user friction?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 16, 2026 Domain: Governance, Ownership & Risk

Start with leadership, because culture follows executive priorities. Leaders need to treat cybersecurity as a business requirement, not an obstacle to productivity. The practical goal is to make security controls as invisible as possible to end users while still enforcing strong access checks, auditability, and rapid response. That balance reduces resistance and keeps security from being gradually weakened to restore convenience.

Why This Matters for Security Teams

A cybersecurity-first culture fails when security is presented as friction rather than as part of reliable service delivery. The organisations that sustain it usually make the secure path the default path, so people do not have to choose between productivity and protection. That means aligning leadership incentives, reducing repeated manual approvals, and designing controls that are strong but low-noise. Visibility and accountability matter, but so does restraint in the user experience.

One useful benchmark is that 90% of IT leaders say properly managing NHIs is essential for a successful zero-trust implementation, which reflects a broader truth: teams accept security more readily when controls are embedded into the workflow instead of bolted on later. In practice, many security programmes lose trust not because the controls are too weak, but because they are introduced in ways that users learn to bypass.

How It Works in Practice

The most effective model is to shift from manual, exception-heavy security to policy-driven controls that are consistent, low-friction, and observable. That usually means using strong authentication at the right entry points, then reducing day-to-day interruptions through session continuity, conditional access, device trust, and well-scoped permissions. Users should feel that security is mostly present when risk changes, not at every interaction.

A practical implementation sequence is:

  • Design the default workflow so secure actions require the fewest possible extra steps.
  • Use role-based access and least privilege to reduce repeated prompts and unnecessary approvals.
  • Reserve stronger checks for high-risk actions, unusual locations, elevated privilege, or sensitive data access.
  • Instrument audit logging and response workflows so the control is credible even when it is invisible.

This balance matters because friction is often a symptom of poor policy design, not of strong security itself. If every action feels exceptional, users will route around the control, request broad exemptions, or push for weaker shared access patterns. The better approach is to make the secure path predictable and the exception path genuinely inconvenient. Where organisations rely on legacy systems, frequent approval gates, or fragmented identity tooling, these controls tend to break down because users face too many repetitive checks for routine work.

Common Variations and Edge Cases

Tighter security often increases operational overhead, so organisations have to balance user convenience against the risk reduction they actually need. The right answer is different for consumer workflows, regulated environments, and privileged administrative tasks. A sales team, for example, should not experience the same interruption pattern as a production engineer or incident responder.

Current guidance suggests treating friction as a design problem, not a reason to weaken policy. High-friction controls can still be appropriate for rare, high-impact actions, but they should be targeted. By contrast, broad friction on low-risk, high-frequency tasks is a sign that the control layer is misaligned with the workflow. The common mistake is to “solve” resistance by loosening standards instead of reducing unnecessary prompts, duplicated logins, or poorly timed approvals.

In regulated or high-trust environments, some added friction is unavoidable because evidence, review, and accountability are part of the control objective. The key judgement is whether the extra step changes user behaviour for the better or merely creates noise. When users start treating security as administrative drag rather than risk management, the control model is already degrading.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8, NIST Zero Trust (SP 800-207) and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC — Access ControlControls how access is granted with least friction and least privilege.
GV.OV — OversightAligns leadership accountability with security behaviours and productivity trade-offs.
Recommendation — Design access flows that enforce least privilege while minimising unnecessary user interruption. Set leadership oversight so security decisions are measured against business workflow impact.
CIS Controls v86 — Access Control ManagementDirectly governs account access, least privilege, and reducing administrative friction.
Recommendation — Standardise access provisioning and reduce manual exceptions to keep controls usable.
NIST Zero Trust (SP 800-207)3 — Continuous VerificationSupports low-friction security by checking risk at access time instead of relying on static trust.
Recommendation — Apply continuous verification so stronger checks appear only when context changes.
NIST SP 800-63IAL — Identity Assurance LevelHelps tune authentication strength to the assurance needed for each workflow.
Recommendation — Match identity assurance to the sensitivity of the action instead of applying one-size-fits-all checks.

Practitioner Guidance

What to prioritise: Put the highest-friction controls under review first, especially the ones attached to routine tasks. If a control interrupts daily work without materially changing risk, simplify it before asking users to “adapt.”

Decision rule: If the action is low-risk and frequent, optimise for invisibility and consistency. If the action is privileged, irreversible, or sensitive, accept some friction, but keep it targeted and explainable.

What to verify: Check whether users are bypassing controls through shared accounts, exception requests, shadow processes, or informal workarounds. Those behaviours are usually a stronger signal than user complaints about friction.

Practitioner takeaway: The goal is not to eliminate friction everywhere, it is to reserve it for moments where the risk justifies it and remove it everywhere else.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 16, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org