Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What is the first thing teams should do…
Governance, Ownership & Risk

What is the first thing teams should do when people security is weak?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 11, 2026 Domain: Governance, Ownership & Risk

Start with the behaviours that most directly change exposure: password reuse, weak multifactor authentication adoption, and slow reporting of suspicious activity. Those are the points where a small improvement can reduce both identity risk and incident dwell time. If employees cannot follow the secure path easily, the programme should fix friction before adding more policy.

Why the first step is to remove the highest-friction, highest-frequency behaviours

When people security is weak, the best first move is usually not a new policy or a broader awareness campaign. Start with the behaviours that most directly change exposure, because those are the points where a modest improvement reduces account takeover risk, shortens dwell time, and makes safer action the easier action.

The practical target is behaviour that sits closest to real incidents: reused passwords, weak multifactor authentication adoption, and slow reporting when something looks suspicious. Those weaknesses tend to persist because they are convenient, familiar, or invisible to users until they become a problem. Fixing the workflow around them usually gives more immediate value than trying to persuade people to remember more rules.

What teams should fix before they add more training or policy

Teams should first identify the smallest set of human behaviours that most directly create avoidable exposure. In most organisations, that means checking whether password reuse is common, whether the current authentication path is too easy to bypass or postpone, and whether employees know how to report a suspicious prompt, message, or login without hesitation.

This is less about teaching people what security should look like and more about removing the conditions that encourage workarounds. If secure access takes too many steps, people will drift toward shortcuts. If reporting a concern feels slow or socially awkward, incidents stay hidden longer. A weak people-security programme often looks like a usability problem before it looks like a training problem.

That is why the first intervention should be operational, not theoretical: make the secure path easy, make suspicious behaviour easy to report, and make the risky habit harder to sustain. Once those basics are improved, broader education and policy reinforcement become more credible because they are backed by a workable process.

What good looks like once the first fix is in place

Good practice is visible in three things: fewer reused passwords, better MFA completion without constant exceptions, and faster escalation of suspicious events by frontline users. If people can complete the secure workflow with little resistance, the programme is probably improving the right layer of the problem.

Teams should also look for whether the control is changing behaviour rather than simply producing compliance language. A security message that is understood but not used is not the same as a control that lowers exposure. The goal is not to create more policy surface, but to reduce the number of easy paths into compromise.

That makes measurement important. A useful first checkpoint is whether users are still working around the control. If they are, the issue is probably friction, not awareness. If they are not, then the organisation can move on to the next set of behaviours with a stronger baseline.

Risk and Threat Considerations

Weak people security creates easy entry points for attackers because the compromise path often begins with reuse, delay, or hesitation. Password reuse can turn one exposed credential into multiple account compromises, weak MFA adoption can leave authentication effectively single-factor in practice, and slow reporting can give an attacker more time to move before defenders know there is a problem.

Failure mechanism: Attackers exploit convenience gaps, credential reuse, and delayed reporting to gain access, maintain access, and extend dwell time before detection.

Impact: A single user mistake can become a broader identity incident, with stolen credentials, unauthorized access, and slower containment across multiple systems.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-63Digital Identity GuidelinesCovers phishing-resistant authentication and MFA adoption, which directly shape this first-step fix.
Recommendation — Prioritise phishing-resistant authenticators and remove enrollment friction.
NIST SP 800-53 Rev 5IA-2 — Identification and Authentication (Organizational Users)Applies because the issue centers on user authentication strength and account access risk.
AU-6 — Audit Record Review, Analysis, and ReportingSupports the need for timely reporting and review of suspicious activity signals.
Recommendation — Strengthen organizational user authentication and reduce weak login paths. Review suspicious activity quickly and route alerts to responders without delay.
CIS Controls v8CIS-5 — Account ManagementAccount and credential hygiene are central when password reuse and weak access practices drive exposure.
CIS-6 — Access Control ManagementLeast-privilege access and controlled authentication paths reduce the impact of weak user behaviour.
Recommendation — Harden account handling and reduce shared or reused access patterns. Enforce access control defaults that make insecure workarounds harder.

Practitioner Guidance

What to prioritise: Fix the highest-volume behaviour first, not the loudest policy gap. If password reuse, weak MFA adoption, or slow reporting is common, that is where the first improvement will usually return the most risk reduction.

What to verify: Check whether the secure path is materially harder than the insecure one. If users are bypassing controls, deferring enrollment, or ignoring suspicious events, the programme needs friction removed before it needs more messaging.

Decision rule: If a control depends on constant reminders to work, treat it as fragile. If it becomes the default path with little user effort, it is probably ready to scale.

Practitioner takeaway: In weak people-security environments, the first win is almost always behavioural and operational, not educational, because reducing friction around the most common unsafe actions changes exposure faster than adding another layer of policy.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org