Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› How should security teams reduce people risk when…
Governance, Ownership & Risk

How should security teams reduce people risk when users bypass guidance on purpose?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 26, 2026 Domain: Governance, Ownership & Risk

Security teams should treat risky behavior as a mix of awareness, motivation, and workflow design, not just a training gap. The best approach is to tailor messaging by role, show why the control matters in business terms, and remove unnecessary friction. Pair targeted education with trust-building, so employees understand the consequence of unsafe choices and have a practical path to follow security rules.

Why people bypass guidance even when they know the rule

People rarely ignore security advice for a single reason. In practice, bypass behavior usually reflects a mismatch between the rule and the work: the control feels slow, unclear, low value, or disconnected from the outcome employees are trying to achieve. That means the right intervention is not just more awareness, but a better blend of relevance, trust, and usability.

When security guidance is framed only as policy compliance, users often treat it as optional bureaucracy. When it is framed as part of business reliability, customer trust, or operational continuity, it becomes easier to defend in the moment a user is tempted to cut a corner.

Effective security teams therefore look at bypasses as a signal about control design, not only user behavior. If the same guidance is regularly ignored, the issue may be the workflow, the incentive structure, or the control’s placement in the process rather than the message itself.

How to reduce people risk without relying on constant reminders

The most effective reduction strategy is to remove avoidable friction while making the secure path the easiest path. That usually means tailoring guidance to the role, simplifying steps where possible, and giving people a clear reason to comply in terms they can use with their manager or team.

Messaging should be specific to the task and the audience. A generic warning rarely changes behavior, but a short explanation of what could be lost, who would be affected, and what safer alternative exists is much more likely to land. The goal is not to overwhelm users with detail, but to make the secure choice feel practical and defensible.

Trust matters as much as instruction. If employees believe security will punish mistakes or slow them down without helping them succeed, they will look for workarounds. If they see that security helps them complete work safely, they are more likely to raise issues early, ask for help, and follow the intended process.

What good control design looks like in day-to-day operations

Good control design anticipates that some users will test the boundary between convenience and compliance. Strong teams identify the high-friction steps, look for repeated bypass points, and decide which safeguards must be enforced technically versus which can be coached through education and manager support.

That also means measuring whether the control is actually usable. If a rule creates repeated exceptions, shadow processes, or quiet noncompliance, the control may be creating more risk than it removes. In those cases, the practical answer is often redesign, not stricter messaging.

When you do need education, pair it with workflow changes. Users are more likely to change behavior when the secure action is embedded in the tool or process they already use, instead of being added as a separate burden they must remember to do later.

Risk and Threat Considerations

Bypass behavior creates exposure when people learn that exceptions are easier than compliance. That can turn an isolated shortcut into a normal operating pattern, especially when teams are under pressure, controls are slow, or approvals are inconsistent.

Failure mechanism: Users bypass guidance when the immediate cost of compliance feels higher than the perceived chance or impact of being caught. Over time, that weakens control credibility, increases the likelihood of unsafe workarounds, and can leave security teams blind to where the real process failure is occurring.

Impact: Repeated bypasses can lead to weaker access control, poor handling of sensitive data, increased incident likelihood, and reduced confidence that policies reflect actual practice. The operational damage is often larger than the individual shortcut because it normalises exception behavior across the team.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-14 — Security Awareness and Skills TrainingBypass behavior is partly an awareness and behavior issue.
CIS-4 — Secure Configuration of Enterprise Assets and SoftwareReducing friction often requires redesigning the workflow or control path.
Recommendation — Tailor security awareness to role, task, and recurring bypass patterns. Reduce user friction by embedding safer defaults into the workflow.
NIST CSF 2.0PR.AT-01 — Personnel are provided awareness and training so they possess the knowledge and skills to perform general tasks with security risks in mindThe question concerns security messaging, role-specific understanding, and behavior change.
PR.PS-01 — Personnel and devices are verified and authorized prior to performing tasks, responding to incidents, or accessing assets or dataReducing people risk includes ensuring the secure path is the default operating path.
Recommendation — Provide role-specific security training that explains the business consequence of unsafe choices. Require authorized, least-friction workflows for high-risk tasks.
ISO/IEC 27001:2022A.6.3 — Information security awareness, education and trainingThe topic centers on awareness that changes behavior, not generic instruction.
Recommendation — Align awareness content to the risks and decisions people actually face.

Practitioner Guidance

What to prioritise: Start with the controls that users bypass most often and the steps that create the most friction. If a safeguard is both high-impact and routinely ignored, treat that as a design problem to investigate before treating it as an awareness problem.

What to verify: Check whether people understand the business consequence of the rule, whether they have a workable alternative, and whether managers reinforce the same expectation. If any one of those is missing, training alone is unlikely to change behavior.

Practitioner takeaway: The strongest reduction in people risk comes from making secure behavior easier to follow than unsafe workarounds, while reserving escalation for the small set of choices that truly require enforcement.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 26, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org