Join our Newsletter — 33% off our NHI Course
Home› FAQ› Cyber Security› Why does telling people what not to do…
Cyber Security

Why does telling people what not to do often fail as a security strategy?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 18, 2026 Domain: Cyber Security

Directive security messaging often fails because it focuses on prohibition rather than outcomes. People are more likely to follow guidance when they understand the risk, the safer alternative, and what to do if they still make a mistake. A harm reduction approach lowers negative consequences without pretending human behaviour can be fully controlled. That makes the guidance more usable in real environments.

Why prohibition alone is weak security communication

Telling people what not to do often fails because it gives them a rule without helping them make a better decision in the moment. In real environments, people are balancing speed, uncertainty, workload and imperfect context. A message that only says “don’t” is easy to ignore, hard to remember under pressure, and weak when the user still has to complete a task.

The practical problem is that prohibition does not explain the threat model behind the rule. If people do not understand what failure looks like, they cannot judge when the warning matters, when it is safe to proceed, or which action is the safer substitute. That is why outcome-based guidance usually works better than blanket restriction, especially when the work itself creates pressure to improvise.

Security teams also run into a usability gap. Rules that are too absolute tend to create workarounds, shadow processes, or “just this once” exceptions. The more often users see a prohibition that conflicts with operational reality, the more likely they are to treat the next warning as background noise rather than meaningful guidance.

What effective harm-reduction guidance adds

Effective security messaging gives people three things at once: the risk, the preferred action, and a fallback if they still make a mistake. That structure matters because it turns a policy statement into a decision aid. It is easier to follow a rule when the safer path is explicit and the consequence of error is contained rather than catastrophic.

This is the same reason harm reduction is often more resilient than pure prohibition. In many workflows, the goal is not perfect obedience, but lower exposure and faster recovery. If a user clicks the wrong link, reuses a password, pastes a secret into the wrong place, or approves an unsafe action, the guidance should reduce blast radius, speed up reporting, and make the next step obvious.

For security communication, the strongest guidance is usually specific enough to be actionable and narrow enough to be believable. Users need to know what “safe” looks like in their own context, not just what is forbidden in the abstract. That is also why plain-language examples, visible safer alternatives, and error-recovery paths tend to outperform strict negative language alone.

How to make guidance more usable in practice

Practitioners should design messaging around decision points, not just policy boundaries. If a control depends on human judgement, the guidance should explain the trigger, the safer default, and the escalation path. A user who understands when to pause and where to go next is more likely to comply than one who only sees a warning banner or a list of forbidden actions.

  • What to prioritise: make the preferred action the easiest action, and make exception handling explicit rather than improvised.
  • What to verify: test whether users can repeat the guidance under time pressure, because comprehension in calm conditions does not prove behaviour in production.
  • Common mistake: replacing usable instructions with blanket prohibitions, then treating non-compliance as a user problem instead of a design problem.

When the subject is secret handling or identity-related workflows, the stakes are higher because one mistake can create broader exposure than the user expects. NHIMG’s Ultimate Guide to Non-Human Identities shows how often weak operational controls turn into persistent access problems, and the same lesson applies to human-facing guidance: controls work better when they reduce the chance of misuse and shorten the time to containment. The most useful security instruction is the one that helps a person recover safely after a slip, not the one that assumes slips will never happen.

Practitioner takeaway: The best security messaging changes behaviour by making the safer choice clear, fast, and recoverable, while pure prohibition usually fails because it asks for compliance without supporting decision-making.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AT-01 — Awareness and TrainingBehavioural security guidance depends on people understanding risk and safe action.
PR.IV-01 — Identity Verification and AuthenticationHuman error in account and secret handling is reduced by clear, repeatable identity workflows.
Recommendation — Design training to explain risk, safer alternatives, and escalation paths. Standardise user actions so authentication decisions are unambiguous and consistent.
CIS Controls v814 — Security Awareness and Skills TrainingUsable security messaging is a core awareness control, not just a policy statement.
Recommendation — Teach users the reason, the safe action, and the reporting step.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on September 18, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org