Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security What breaks when organisations keep adding more authentication…
Cyber Security

What breaks when organisations keep adding more authentication prompts and checkpoints to every customer journey?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 17, 2026 Domain: Cyber Security

Excessive security layering often creates user fatigue, operational confusion, and uneven protection. Attackers still only need the weakest control, while legitimate users face more chances to make errors, abandon transactions, or seek workarounds. Over time, the result can be weaker real world security, not stronger security, because friction drives unsafe behavior.

Why piling on prompts creates weaker security, not stronger security

Every additional checkpoint adds friction, but friction is not the same thing as control quality. When the journey becomes too cumbersome, people start to click through prompts without reading, miss legitimate alerts, or choose faster paths that bypass the intended control. The security model then shifts from strong verification to repeated interruption, which is a poor trade-off when the attacker only needs one weak path.

The deeper issue is that layered prompts often fail as a system of controls when they are not clearly differentiated. If every step looks and feels similar, users stop understanding why one prompt matters more than another, and the control loses credibility. That is where MFA fatigue attacks become relevant: repeated challenges can train users to approve out of habit rather than judgment.

Security teams should also account for the fact that customer journey span different risk levels. A low-risk login prompt, a high-risk payment confirmation, and a recovery step after account lockout should not all be treated as interchangeable checkpoints. If the organisation does not distinguish those moments, it ends up applying the same burden everywhere and the same protection nowhere.

Where the operational damage shows up in the customer journey

Too many prompts create operational side effects that are often mistaken for healthy caution. Abandonment rates rise, support tickets increase, and legitimate users begin to work around controls by reusing devices, storing session workarounds, or choosing weaker fallback paths. In practice, that can reduce the real assurance of the journey because the easiest path becomes the one people trust, not the one the policy intended.

There is also a consistency problem. When customers face multiple authentication prompts across different channels or steps, they may experience uneven treatment, such as one journey requiring repeated verification while another relies on stale sessions or weaker recovery. That inconsistency makes it harder to explain the control, audit its behavior, and trust its business impact. For a useful contrast, the Okta breach shows how trust in an identity flow can be undermined when the surrounding control environment is weak.

Another hidden cost is user adaptation. People learn the system they are given. If the system rewards speed over clarity, they will optimise for speed. If it forces repeated interruptions without clear purpose, they will seek shortcuts. That is why more checkpoints can end up increasing risk, not lowering it, especially when the organisation has not measured which prompts actually reduce fraud or abuse.

What practitioners should do instead of adding another checkpoint

The right response is to make prompts risk-based, not universal. Use stronger verification only where the transaction, action, or account state justifies it, and keep low-risk flows low-friction. That means designing for step-up only when there is a material change in risk, rather than treating every customer interaction as if it were equally sensitive.

  • Prioritise: protect high-consequence actions first, such as account recovery, payout changes, credential changes, or access handoffs.
  • What to verify: check whether each prompt adds measurable reduction in abuse, or merely adds annoyance and abandonment.
  • Common mistake: assuming more authentication equals better security without measuring fallback abuse, reset abuse, or bypass behavior.
  • Trade-off: every extra checkpoint consumes attention, so use it only where the security gain is worth the operational cost.

Practitioner takeaway: The best control design is not the most restrictive one, but the one that concentrates friction where attacker gain is highest and keeps the rest of the journey simple enough that legitimate users do not invent their own workarounds.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v86 — Access Control ManagementControls access paths and account friction to reduce overexposed customer authentication flows.
Recommendation — Tune access checks to high-risk actions and remove redundant prompts that do not reduce abuse.
NIST CSF 2.0PR.AA-01 — Identities and credentials are issued, managed, verified, revoked, and auditedRepeated prompts are an identity assurance and lifecycle problem affecting verification quality.
Recommendation — Manage authentication so each step-up prompt has a clear assurance purpose and audited outcome.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 17, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org