Controls that slow people down create pressure to bypass them, especially in time sensitive business processes. When users see security as an obstacle, they may share passwords informally, ignore guidance, or revert to unsecured channels to meet deadlines. That behaviour weakens governance and increases the chance of data exposure, lost revenue, and regulatory issues.
Why Friction Turns Controls Into Bypass Candidates
Controls fail when they are experienced as repeated friction rather than as a clear boundary that helps people finish work safely. If a workflow adds approvals, re-authentication, or manual handoffs at every turn, users will often look for the shortest path that still gets the task done. That is where shadow workarounds start: not always from malice, but from a practical judgement that the control is too costly to follow every time. The NIST Cybersecurity Framework 2.0 is useful here because it frames security as an organisational outcome that depends on workable governance, not just on policy intent. In practice, many teams first notice bypass behaviour after the control has already become normalised as "how we get things done."
How Workarounds Form in Real Workflows
Shadow workarounds usually appear when the control design and the business process are out of sync. A person facing a deadline will not experience a control as a neutral safeguard if it interrupts a high-frequency task, blocks collaboration, or forces them to wait for help every time they need access. At that point, the control competes with delivery. The more often the interruption repeats, the more likely users are to invent a parallel path that feels faster and less disruptive.
Common examples include shared logins, offline file transfers, personal messaging apps, copy-pasting data into unsanctioned tools, or asking someone else to approve or perform a task on their behalf. Those shortcuts are attractive because they remove delay, but they also remove visibility, accountability, and policy enforcement. Security teams should treat that as a design signal, not just a user discipline problem. If the authorised route is harder than the unofficial one, the unofficial one will win.
- Frequent prompts can cause users to batch or ignore controls instead of following them consistently.
- Slow approvals encourage informal delegation that is never recorded properly.
- Unclear ownership makes users route around controls rather than wait for a decision.
- Overly rigid workflows push people toward consumer tools that are easier to access but harder to govern.
NIST SP 800-53 Rev 5 is relevant because it shows that access, logging, and accountability controls need to be implemented in ways that actually support operational use. Where that balance is absent, the control may exist on paper but fail in practice. The point is not to remove all friction, but to put the friction where it adds security value rather than where it only blocks routine work. The guidance breaks down when the process is so tightly coupled to speed or exception handling that users can only succeed by stepping outside the approved path.
When Legitimate Exceptions Become Normal Behaviour
Tighter control often increases user burden, requiring organisations to balance stronger enforcement against the pressure to keep work moving. That tradeoff becomes most visible in time-sensitive or exception-heavy processes, where a "temporary" workaround can quietly become the default way of operating. In those cases, the real risk is not only policy non-compliance but also the loss of reliable audit evidence, because the organisation can no longer tell which actions were authorised and which were merely convenient.
One important nuance is that not every shortcut is equally dangerous. Some are isolated and easily corrected; others become embedded in team habits because they solve a repeated workflow problem. There is no consensus that every workaround signals a broken control, but there is broad agreement that repeated workarounds indicate a control design issue worth fixing. Teams should also avoid assuming that more steps always means more security. Beyond a certain point, extra steps can reduce adherence so much that the control weakens the overall posture instead of improving it.
If users are bypassing a control because the process is cumbersome, the correct response is often to simplify the workflow, narrow the control to the risky step, or change the approval model rather than to demand more compliance messaging. Security that people can only follow intermittently is usually security that will eventually be routed around.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC — Identity Management, Authentication and Access Control | Workarounds often emerge when access controls are too cumbersome. |
| GV.OV — Oversight | Governance should detect when controls create operational pressure and unsafe bypasses. | |
| Recommendation — Align access controls with real workflow steps so users do not bypass them. Review control friction as an organisational risk indicator, not just a user complaint. | ||
| CIS Controls v8 | 6 — Access Control Management | Too many steps in access governance encourage informal sharing and bypasses. |
| 8 — Audit Log Management | Shadow workarounds hide activity from logging and accountability controls. | |
| Recommendation — Reduce avoidable access friction while preserving least-privilege enforcement. Ensure bypass-prone workflows still produce reviewable audit evidence. | ||
Practitioner Guidance
What to prioritise: Focus first on the controls that sit in the highest-frequency business paths, because those are the controls most likely to generate informal bypasses. A low-friction control that covers the right decision point is usually stronger than a heavy control that users abandon under pressure.
What to verify: Look for evidence that users are completing the same task through multiple channels, especially where the approved path has more delays, more approvals, or more handoffs than the unofficial one. The key question is whether the control is being followed as designed when work is urgent, not when it is convenient to demonstrate compliance.
What practitioners underestimate: Shadow workarounds are often a usability signal before they are a policy signal. If the same workaround appears repeatedly across teams, the control is probably misaligned with how the work actually happens.
Practitioner takeaway: The best way to reduce shadow workarounds is to make the secure path the easiest path for routine work, while reserving heavier friction for genuinely high-risk actions.
Related resources from NHI Mgmt Group
- Why do strict security policies sometimes increase shadow IT risk?
- Why does authentication complexity increase security risk even when controls are stronger?
- Why does too much context increase security risk?
- Why does AI-assisted development increase security risk even when developers use familiar controls?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 9, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org