Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What happens when organisations try to build cybersecurity…
Governance, Ownership & Risk

What happens when organisations try to build cybersecurity without a people-centric approach?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 27, 2026 Domain: Governance, Ownership & Risk

Programmes that focus only on tools often miss insider risk, user behaviour, and the need for practical training. The result is a weaker security posture, more friction for staff, and less executive confidence that the programme will hold up under real conditions. A people-centric model helps turn employees into participants in security rather than passive sources of risk.

When security is built around controls instead of people

A security programme can be technically sound and still fail in practice if it treats employees as obstacles to work rather than part of the control environment. The gap shows up when policies look strong on paper, but users bypass them, misunderstand them, or create shadow processes to get work done. People-centric security is about designing for how work actually happens, not how a policy document assumes it happens.

That difference matters because many security outcomes depend on behaviour: whether staff report suspicious activity, follow a safe workflow, challenge unexpected requests, and use security tooling correctly under time pressure. The operational question is not whether a control exists, but whether ordinary teams can apply it consistently without creating avoidable friction.

What breaks first when the human layer is ignored

The first failure is usually adoption. If controls are too rigid, too slow, or too disconnected from day-to-day work, people route around them, which weakens visibility and makes exceptions normal rather than exceptional. A Secure by Design mindset helps here because it treats usability and secure defaults as part of the control, not as optional polish after deployment.

The second failure is that insider risk and error are underweighted. Most organisations do not suffer only from malicious insiders, they also suffer from hurried staff, unclear ownership, inconsistent training, and poor feedback loops. That is why security awareness, role clarity, and practical guidance have to be treated as operating controls, not as annual compliance content.

The third failure is executive credibility. Leaders lose confidence when teams cannot explain what security actually changes in the real working environment, or when incidents reveal that the formal programme never matched practice. At that point, the issue is not just technical weakness, it is control assurance: the organisation cannot show that the security model survives normal business pressure.

How a people-centric model changes the security outcome

A people-centric model turns security into a shared operating habit. Instead of asking employees to absorb security as a burden, it aligns controls with the workflows they already use, then adds clear decision points for reporting, approvals, and escalation. That makes the programme more observable and usually improves the quality of the signals security teams receive.

This approach also improves control selection. For example, training should be task-specific, role-specific, and scenario-based, because generic awareness rarely changes behaviour when a real business deadline is involved. If a control depends on humans making good decisions, the organisation should verify those decisions with realistic exercises, not with assumptions about policy compliance.

People-centric design also supports better security culture. Employees are more likely to participate when they understand why a control exists, what it protects, and what the path is when a control blocks legitimate work. That reduces the common trade-off where security and productivity are treated as opposing goals rather than two outputs that have to be balanced together.

Risk and Threat Considerations

When organisations ignore the human layer, they create predictable exposure: workarounds, poor reporting, inconsistent control use, and a wider gap between policy and reality. That gap is attractive to attackers because it makes social engineering, credential abuse, and misuse of legitimate access easier to sustain.

Failure mechanism: Controls that are hard to use, poorly explained, or mismatched to business workflows get bypassed, while insider mistakes and deceptive requests are less likely to be caught early.

Impact: The programme becomes less resilient in real incidents, with weaker detection, more accidental exposure, higher support burden, and lower confidence that staff will respond correctly under pressure.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-14 — Security Awareness and Skills TrainingPeople-centric cybersecurity depends on role-aware, practical user training.
Recommendation — Deliver role-specific training that matches real workflows and common attack paths.
NIST CSF 2.0PR.AT-01 — All personnel are provided cybersecurity awareness and trainingThe question centers on how staff behaviour affects security outcomes.
GV.OC-03 — Cybersecurity roles and responsibilities are coordinated and aligned with internal roles and external partnersA people-centric approach requires clear ownership across business and security teams.
Recommendation — Provide awareness and training that changes day-to-day security behaviour. Align security responsibilities with business roles and operational handoffs.
ISO/IEC 27001:2022A.6.3 — Information security awareness, education and trainingThe subject concerns making security effective through employee awareness and practice.
A.5.2 — Information security roles and responsibilitiesPeople-centric security depends on defining who owns security decisions and responses.
Recommendation — Run awareness and training programs that reflect actual work and risk conditions. Assign and communicate clear security responsibilities across the organisation.

Practitioner Guidance

What to prioritise: Start with the workflows that create the most friction or the most exposure, not with the controls that are easiest to measure. If users regularly interrupt the intended process to get work done, that is a design problem, not a training problem.

What to verify: Check whether staff can explain the security action they are being asked to take, whether they know when to escalate, and whether the control still works during normal operational pressure. If the answer depends on perfect user attention, it is too fragile.

What good looks like: A mature people-centric programme produces fewer unsafe workarounds, faster reporting of suspicious events, and clearer executive evidence that security is being used rather than merely published.

Practitioner takeaway: The goal is not to make every employee a security expert, it is to make the secure path the easiest defensible path for normal work.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 27, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org