When organisations lead with prohibitions, employees hear noise instead of direction. The article argues for telling people what to do instead, because positive actions are easier to remember and less defensive to receive. That approach is more effective for habits like updating software, backing up data, enabling two-step authentication, and using password managers consistently.
Why prohibition-heavy messaging backfires
People process security advice through attention, memory, and motivation, so a list of “don’ts” often fails twice: it is harder to remember, and it gives no clear replacement behavior. That creates compliance theater, where teams can recite restrictions but still miss the routine actions that actually reduce exposure, such as updating software, backing up data, enabling two-step authentication, and using password managers consistently.
When the message is framed negatively, employees also tend to infer that security is primarily about avoiding mistakes, which can make them cautious without making them effective. A better pattern is to pair each restriction with a concrete action, because security habits stick when the expected behavior is specific and repeatable.
What positive instruction changes in practice
Positive instruction changes the quality of execution. Instead of asking people to mentally translate a ban into a safe alternative, it gives them the next step in plain language, which reduces hesitation and helps standardize behavior across a team. That is especially important for controls that depend on routine use rather than one-time approval.
This approach also improves consistency across audiences with different technical backgrounds. A developer, analyst, or non-technical employee can all act on “do this” more reliably than on “do not do that,” because the latter leaves too much room for interpretation. In security programs, ambiguity is often where controls decay.
There is a practical trade-off, though: positive guidance only works when the replacement action is concrete enough to adopt. Telling people to “be secure” is no better than saying “do not be careless.” The instruction has to name the behavior, the trigger, and the expected outcome.
How to rewrite security guidance so it is usable
The most effective rewrites keep the rule short, action-oriented, and context-specific. A useful test is whether a person could follow the instruction without asking a second question. If not, the message is still too abstract.
- Replace “do not reuse passwords” with “use a password manager to create a unique password for every account.”
- Replace “do not ignore updates” with “install software updates as soon as your device prompts you.”
- Replace “do not share credentials” with “use the approved access-sharing process when someone needs temporary access.”
That structure works because it connects the rule to a visible behavior. It also makes follow-up training easier, since managers can observe whether the action happened rather than whether someone understood a prohibition.
Risk and Threat Considerations
Overreliance on negative messaging creates a control gap: people may know what is forbidden, but not what to do when the safe choice matters most. In practice, that can leave software unpatched, backups incomplete, and authentication hygiene weak, which increases the chance of avoidable compromise or operational disruption.
Failure mechanism: Prohibitions without replacement actions increase interpretation burden, lower recall, and encourage workarounds, so the intended control is not consistently executed.
Impact: The organisation gets weaker day-to-day security behavior, less reliable adoption of basic safeguards, and a false sense that awareness alone has reduced risk.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-14 — Security Awareness and Skills Training | Positive security instructions improve usable awareness and behavior change. |
| Recommendation — Teach staff specific protective actions instead of prohibition-only messaging. | ||
| NIST CSF 2.0 | PR.AT-01 — Identities and credentials are managed and protected appropriately | Clear user guidance helps people follow protective identity and account behaviors. |
| Recommendation — Provide action-based guidance for account protection and secure habits. | ||
| ISO/IEC 27001:2022 | A.6.3 — Information security awareness, education and training | Awareness messaging must be understandable and behavior-shaping to support control adoption. |
| Recommendation — Design awareness content around explicit, repeatable user actions. | ||
Practitioner Guidance
What to prioritise: Rewrite the highest-frequency security instructions first, especially the ones tied to patching, authentication, backup, and credential handling, because those are the behaviors most likely to become habitual.
What to verify: Check whether each message names an observable action and a clear trigger. If staff cannot tell when to perform the control, the guidance is still too abstract to trust.
Common mistake: Treating awareness as successful because people can repeat a rule. In this context, comprehension is not enough; the real test is whether the safer behavior appears in routine work without extra prompting.
Practitioner takeaway: Security communication works best when it reduces decision-making at the moment of action, not when it merely increases the number of things people are told to avoid.
Related resources from NHI Mgmt Group
- What happens when organisations try to improve security culture with AI alone?
- What breaks when organisations try to improve login security by adding more prompts to every session?
- What happens when organisations try to save money on security testing without preserving coverage and response capacity?
- What happens when organisations try to manage enterprise identity security with too many point tools?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org