Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security Who should be involved when improving enterprise security…
Cyber Security

Who should be involved when improving enterprise security resilience across tools and users?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 7, 2026 Domain: Cyber Security

Enterprise resilience should be shared across IT, business teams, and end users. Security works better when the people closest to the work help shape controls, especially in SaaS and BYOD environments. Organisations also need visibility into shadow IT, active accounts, MFA coverage, and password rotation to prevent loss of control.

Who Needs a Seat at the Table for Security Resilience Decisions?

Improving enterprise security resilience across tools and users is not an IT-only exercise. The people who own business workflows, administer SaaS, manage endpoints, and rely on everyday access all shape whether controls are usable and durable. When security decisions are made without those groups, organisations often overcorrect with friction-heavy controls or miss the operational realities that cause workarounds, drift, and abandoned policies.

That is why resilience should be treated as a shared operating concern rather than a back-office control task. NIST’s control catalog makes the same basic point through its emphasis on coordinated governance, access management, and monitoring across people, process, and technology: NIST SP 800-53 Rev 5 Security and Privacy Controls. In practice, many security teams discover the real failure mode only after a business unit, SaaS owner, or end user has already adopted an unsanctioned workaround.

How Cross-Functional Involvement Makes Resilience Work in Practice

Resilience improves when the organisation matches responsibility to the part of the environment that can actually see and influence the risk. IT and security teams usually control policy, identity systems, endpoint posture, logging, and incident response. Business teams understand which applications are essential, which exceptions are tolerable, and where a control would break a time-sensitive process. End users reveal whether a control is practical, confusing, or easy to bypass.

That division matters because enterprise resilience is not just about blocking bad activity. It also depends on reducing the conditions that create shadow IT, unmanaged access paths, and inconsistent enforcement. In SaaS and BYOD environments, for example, visibility into active accounts, MFA coverage, password hygiene, and offboarding discipline often matters more than adding another control layer. The right question is not only whether a control is strong, but whether the people who must live with it can actually sustain it.

A useful way to structure involvement is to assign each group a different decision role:

  • Security and IT define the minimum control baseline and the monitoring requirements.
  • Business owners approve workflow exceptions and decide which service interruptions are acceptable.
  • Application and platform owners confirm where accounts, integrations, and device trust are created or lost.
  • End users validate whether the control can be followed without creating shadow behaviour.

The strongest programmes treat resilience as a feedback loop. They test controls against real workflows, check whether adoption matches policy, and revise rules when users repeatedly route around them. That approach is especially important where SaaS sprawl or personal devices expand the number of places control can fail. Where visibility is poor, the organisation may think it has resilience when it really has undocumented dependence on a few informal workarounds.

The guidance breaks down when the organisation cannot identify who owns the tool, who approves exceptions, or who can prove that access is still valid.

Where Resilience Gets Lost in Mixed SaaS, BYOD, and Shadow IT Environments

Tighter control over tools and users often increases administrative overhead, so organisations have to balance resilience against speed and usability. That tradeoff becomes most visible when teams adopt new services faster than governance can track them. The question is not whether shadow IT exists, but whether it is being absorbed into a controlled operating model or left to create blind spots.

Common variations change where involvement matters most. In a highly regulated environment, governance and auditability may outweigh convenience, so business sponsors and compliance stakeholders need earlier involvement. In a fast-moving product team, the priority may be preserving workflow continuity while still enforcing strong authentication and access review. In a distributed workforce, device ownership and user autonomy become central, so endpoint and identity decisions must be aligned before controls are rolled out.

There is no consensus that a single operating model fits every enterprise, but there is broad agreement that resilience weakens when controls are designed in isolation from the people who must use them. The practical test is whether the organisation can keep visibility over active accounts, approved tools, and authentication state without relying on informal memory or local exceptions. If it cannot, the control is probably too detached from the way work actually happens.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM — Risk Management StrategyEnterprise resilience across tools and users needs shared governance and risk ownership.
ID.AM — Asset ManagementVisibility into tools, accounts, and shadow IT depends on knowing what exists.
PR.AA — Identity Management, Authentication and Access ControlMFA, active accounts, and access control are central to resilience in SaaS and BYOD.
Recommendation — Align resilience decisions to risk owners and operating priorities across business and IT. Inventory tools, users, and access paths before treating the environment as resilient. Enforce authentication and access controls that remain workable for real users.
CIS Controls v85 — Account ManagementActive accounts and offboarding are core to preventing loss of control.
6 — Access Control ManagementShared ownership and least-privilege access decisions shape resilience across teams.
8 — Audit Log ManagementResilience depends on visibility into usage, drift, and uncontrolled access.
Recommendation — Review, disable, and remove accounts that no longer have a valid business need. Restrict access paths to approved users and validate exceptions regularly. Monitor logs for shadow access, failed authentication, and policy drift.

Practitioner Guidance

What to prioritise: Start with the control points that reveal whether the environment is still governable: ownership, active access, authentication coverage, and offboarding. If those signals are unclear, resilience work will drift into policy language without changing real exposure.

What to verify: Confirm that each important tool has a named business owner, a technical owner, and a review path for exceptions. Also verify that users understand which access paths are approved and which are not, because ambiguity is one of the main drivers of shadow use.

What practitioners underestimate: People do not usually reject security controls outright; they reject controls that fail to match the way work is actually done. The result is often silent bypass rather than open resistance, which makes the environment look more controlled than it really is.

Practitioner takeaway: Security resilience becomes durable only when the groups closest to the work help shape the controls, because adoption and enforceability are part of the control itself.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 7, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org