
Why Intelligent People Circumvent Security, and What Mature Organizations Do About It
Walk into almost any classroom in the country at the beginning of a new school year, and you’ll witness controlled chaos.
Teachers are preparing lesson plans, organizing classrooms, responding to parents, configuring technology, attending meetings, and welcoming a new group of students, all before the first bell ever rings. The pace is relentless, and every minute matters.
Now imagine walking past a cart of student Chromebooks and noticing something unexpected.
A small adhesive label with a student’s name, username, and password affixed directly to the device.
At first glance, it’s easy to criticize the practice. After all, writing credentials on the very device they’re intended to protect undermines one of the most fundamental principles of information security.
But if that’s where the conversation ends, we’ve learned very little. The more interesting question isn’t why someone ignored security.
The better question is: Why did this feel like the best solution in the first place?
That distinction matters because mature cybersecurity is not built by identifying mistakes. It is built through understanding the conditions that make those mistakes seem reasonable.

Intelligent People Rarely Choose Insecurity
One of the most persistent misconceptions in cybersecurity is the belief that policy violations emanate primarily from ignorance, carelessness, or indifference.
In reality, most people are trying to do exactly what they’ve been hired to do. Teachers are trying to teach. Nurses are trying to care for patients. Engineers are trying to deliver systems. Executives are trying to lead organizations. Their objective is not to violate policy.
Their objective is to accomplish meaningful work. When security introduces unnecessary friction into that work, people naturally begin searching for ways to reduce it. Not because they oppose security. Because they are optimizing for progress. The sticky note wasn’t malicious. It was an optimization.
Unfortunately, it optimized the wrong variable.
The Path of Least Resistance
Human beings are remarkably consistent. When presented with multiple ways to accomplish the same objective, we tend to choose the one that requires the least effort. Behavioral psychologists have studied this phenomenon for decades. Economists describe it through concepts like bounded rationality and mental effort. Engineers simply recognize it as good design.
Cybersecurity often forgets it entirely.
Organizations frequently assume that if policies are written clearly enough, people will simply follow them. Experience suggests otherwise. People generally follow the path that requires the fewest decisions, the least interruption, and the least additional effort. That’s not laziness, it’s human nature.
Every unnecessary step added to a security process becomes another opportunity for someone to find a shortcut. And shortcuts have a way of becoming habits.

The Difference Between Immature and Mature Security Programs
Immature organizations respond to incidents by writing another policy. Mature organizations ask a different question.
Why did this make sense to someone?
That question shifts the conversation from blame to design. Consider the classroom example.
Should passwords remain private? Absolutely.
Should credentials ever be attached directly to a device? Of course not. But stopping there ignores the larger lesson. Why did an experienced educator, someone strongly dedicated to their students, conclude that this was the most practical solution?
Perhaps student onboarding was cumbersome. Perhaps the process required frequent password retrieval.
Perhaps the system created more friction than necessary during one of the busiest weeks of the year. Those possibilities deserve just as much attention as the policy itself. Because good security doesn’t merely tell people what not to do. It makes the secure choice the wise choice.
Security Culture Is a Design Problem

Culture is often described as shared values or shared beliefs. In cybersecurity, culture is better measured using shared behaviors. Those behaviors are influenced less by slogans than by systems.
When secure behavior is intuitive, people adopt it naturally. When secure behavior consistently slows people down, even well-intentioned professionals begin inventing workarounds.
The problem isn’t that people prefer convenience. The problem is when convenience and security are placed in opposition to one another. Strong organizations refuse to accept that tradeoff.
Instead, they ask: “How can we design systems where the secure path is also the easiest path?”
That question signifies a profound shift in thinking. Rather than expecting people to overcome human nature, mature organizations design with human nature in mind.
Leadership Beyond Technology: Setting Security Culture by Example
This principle extends far beyond passwords. In practice, organizations sometimes hard-code credentials because rotating them seems cumbersome. Employees reuse passwords because managing dozens of unique ones is impractical without support. Executives may bypass established processes they perceive as slow, sometimes even advocating for policies they themselves neglect. These behaviors highlight how security actions, good or bad, are shaped by leadership priorities and organizational culture.
Frameworks like Zero Trust (ZT) and NIST’s Cybersecurity Framework (CSF) both emphasize the importance of aligning policies and controls with real-world workflows. For example, Zero Trust encourages the principle of ‘never trust, always verify’, but it also emphasizes minimizing user friction by making secure access seamless. Similarly, NIST CSF calls for continuous improvement and adaptation to actual business context, including user experience, as a critical part of protecting information.
A 2024 Verizon Data Breach Investigations Report found that over 80% of breaches involved a human element, whether through error, misuse, or social engineering. This underscores the need to design security with people, not just technology, in mind.
Consider the widely publicized 2023 MGM Resorts breach: attackers gained access not through a technical exploit, but by manipulating an employee via social engineering. The aftermath highlighted both the human cost of poor security design and the value of resilient, well-communicated processes. Mature organizations study such incidents to inform better system and workflow design, not just to enforce stricter rules.
None of these behaviors are unique to education. They are remarkably consistent across industries. Whether it’s healthcare, finance, manufacturing, government, or cloud engineering, it’s the same.
Technology changes, human behavior does not. This is why effective cybersecurity leaders spend as much time understanding organizational behavior, workflow design, and communication as they do learning about technology. Firewalls protect networks, encryption protects data, identity platforms protect access, and leadership shapes behavior.
And behavior, modeled first by leadership, ultimately determines whether those technologies succeed.
Designing for Reality

There is an old saying in engineering: “Don’t design for perfect conditions. Design for the conditions that are the reality.”
Cybersecurity deserves the same mindset. People work under the pressure of deadlines. And many humans are easily distracted.
They make mistakes. They focus on competing responsibilities. Expecting otherwise isn’t leadership. It’s wishful thinking. The strongest security programs acknowledge these realities and build systems that accommodate them.
Not by lowering standards. By lowering unnecessary friction. Good security accounts for human behavior. Great security aligns human behavior with enterprise intent. That is where security culture begins.
Actionable Steps for Leaders:
- Review critical workflows for unnecessary security friction; streamline processes where possible. Invest in user-friendly identity and access management platforms that support secure, seamless authentication (e.g., password managers, SSO).
- Regularly communicate the ‘why’ behind security policies and invite feedback from end users.
- Model secure behaviors at the leadership level; visible adherence by executives sets cultural expectations.
- Align technology investments with both security best practices (ZT, NIST) and the realities of day-to-day business operations.

Final Thoughts: Designing for Humans
Key Takeaways:
- Security workarounds are rarely due to ignorance; they’re often rational responses to unnecessary friction.
- Mature organizations design security systems that align with natural human behaviors and incentives.
- Leadership sets the tone—when executives model secure, user-friendly practices, security culture flourishes.
- Frameworks like Zero Trust and NIST CSF emphasize the importance of user experience and continuous improvement.
- The most resilient organizations prioritize systems that help people succeed, not just avoid failure.
The sticky note attached to the Chromebook was never really about the sticky note. It’s an example that every decision in a security environment reflects a larger system of incentives, constraints, priorities, and, mostly, habits.
More often than not, systems fail because they ask ordinary people to behave in extraordinary ways. Technology rarely fails first. People rarely fail first. The most resilient organizations understand this. They don’t build security around an idealized version of human behavior. They build it around reality.
Because in the end, cybersecurity isn’t simply about protecting systems. It is the discipline of building systems that help people succeed. And perhaps that is the deeper lesson.
Convenience isn’t the enemy of security. Poor design is.
Or, said another way, Strong security cultures are not built by asking people to overcome human nature. They are built by knowing human nature well enough to design systems that coordinate convenience with security.




















