Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› How should security teams reduce risky user behavior…
Governance, Ownership & Risk

How should security teams reduce risky user behavior without making controls harder to use?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 26, 2026 Domain: Governance, Ownership & Risk

Security teams should simplify the control path so the secure choice is also the easiest choice. The report shows that most users know risky actions are dangerous, yet still choose convenience and speed. User-friendly controls, paired with targeted education, are more likely to change behavior than friction-heavy policies that users work around or ignore under pressure.

Why friction-heavy controls fail to change behavior

People rarely choose the risky option because they believe it is safe. More often, they choose it because the secure path is slower, harder to find, or interrupts urgent work. When a control adds extra steps without reducing uncertainty or effort, users learn to bypass it, defer it, or invent workarounds that preserve speed but weaken security.

That is why “more enforcement” is not the same as “better control.” If the control path conflicts with how people actually work, the organisation is left with policy compliance on paper and inconsistent behavior in practice. The real design goal is to lower the effort cost of the secure action until it competes with the risky shortcut.

What makes the secure choice easier to follow

Reducing risky behavior usually means removing unnecessary decision points, not adding more reminders. Teams should prefer controls that are obvious, consistent, and available at the moment of action, because users are least tolerant of friction when they are busy, under time pressure, or trying to recover from an exception.

Effective controls also reduce ambiguity. Clear defaults, safe pre-configuration, and just-in-time prompts work better than broad warnings because they tell the user exactly what to do next. Education helps when it is tied to the specific risky action, but education alone rarely survives a workflow that keeps rewarding speed over caution.

Where possible, the secure path should be the shortest path. That can mean fewer approvals, cleaner interfaces, safer defaults, or automation that handles routine decisions while still preserving review for genuinely high-risk cases.

How to balance usability and control strength

The right question is not whether a control is strict enough, but whether it changes behavior without creating a shadow process. A control that users can predict, understand, and complete quickly is more likely to be followed consistently than one that is technically strong but operationally brittle.

Teams should segment controls by risk level. Low-risk activities should be low-friction; high-risk actions should trigger stronger checks only where the extra effort is justified by the blast radius of the action. This keeps controls proportionate and avoids training users to treat every safeguard as an obstacle.

Good programs also test controls with real users before broad rollout. If people routinely fail a step, delay it, or ask peers to do it for them, that is a usability defect as much as a policy issue. The design should be revised before the pattern becomes normalised.

Risk and Threat Considerations

Friction-heavy controls often create the exact behavior they are meant to prevent: users route around them, reuse weaker alternatives, or postpone secure steps until after the risky action has already happened. That creates exposure in both insider and external threat scenarios, because attackers often benefit when people normalise shortcuts and exception handling.

Failure mechanism: The secure workflow becomes slower than the insecure workaround, so users choose convenience under pressure and the organisation loses control over where risky actions happen.

Impact: Control adoption drops, shadow processes grow, and security teams get weaker visibility into real user behavior, which makes both prevention and detection less reliable.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8, NIST CSF 2.0, NIST SP 800-53 Rev 5 and OWASP ASVS set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-5 — Account ManagementAccount workflows shape how easily users follow secure access paths.
Recommendation — Simplify account and access workflows so the secure option remains the default.
NIST CSF 2.0PR.AA-01 — Identity and Access Management Policy and ProceduresUsability and consistent access procedures affect whether protective controls are followed.
Recommendation — Design access procedures that are easy to use and consistently applied.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeLeast-privilege enforcement should limit risky action while avoiding unnecessary friction.
Recommendation — Apply least privilege so users only face extra steps for genuinely high-risk actions.
ISO/IEC 27001:2022A.5.15 — Access controlAccess controls must be practical enough to be used consistently by real users.
Recommendation — Implement access controls that users can follow without resorting to workarounds.
OWASP ASVSV15 — Secure Coding and ArchitectureSecure-by-design workflow choices reduce user friction in security-sensitive interfaces.
Recommendation — Build security into the workflow so safer actions are easier to complete.

Practitioner Guidance

What to prioritise: Remove the top one or two workflow frictions that most often push users toward shortcuts. The highest-value fixes are usually the ones that reduce repeated interruptions, unclear prompts, or unnecessary manual approvals.

What to verify: Check whether users can complete the secure path in the same context where the risky action occurs, without having to open a separate process, wait for another team, or remember an exception procedure. If they cannot, the control is likely to be bypassed.

Common mistake: Treating education as a substitute for design. Training helps people understand the risk, but it does not compensate for a control that is slower or harder than the unsafe alternative.

Practitioner takeaway: The best controls change the default behavior of the workflow, not just the tone of the policy, so security teams should optimise for adoption and repeatability as much as for restriction.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 26, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org