First Principles of Cybersecurity: Essays on Leadership, Trust, and Organizational Maturity – Part I

The Hidden Cost of Convenience in Cybersecurity

Why Intelligent People Circumvent Security,
and What Mature Organizations Do About It

Walk into almost any classroom in the country at the beginning of a new school year, and you’ll witness controlled chaos.

Teachers are preparing lesson plans, organizing classrooms, responding to parents, configuring technology, attending meetings, and welcoming a new group of students, all before the first bell ever rings. The pace is relentless, and every minute matters.

Now imagine walking past a cart of student Chromebooks and noticing something unexpected.

A small adhesive label with a student’s name, username, and password affixed directly to the device.

At first glance, it’s easy to criticize the practice. After all, writing credentials on the very device they’re intended to protect undermines one of the most fundamental principles of information security.

But if that’s where the conversation ends, we’ve learned very little. The more interesting question isn’t why someone ignored security.

The better question is: Why did this feel like the best solution in the first place?

That distinction matters because mature cybersecurity is not built by identifying mistakes. It is built through understanding the conditions that make those mistakes seem reasonable.

Intelligent People Rarely Choose Insecurity

One of the most persistent misconceptions in cybersecurity is the belief that policy violations emanate primarily from ignorance, carelessness, or indifference.

In reality, most people are trying to do exactly what they’ve been hired to do. Teachers are trying to teach. Nurses are trying to care for patients. Engineers are trying to deliver systems. Executives are trying to lead organizations. Their objective is not to violate policy.

Their objective is to accomplish meaningful work. When security introduces unnecessary friction into that work, people naturally begin searching for ways to reduce it. Not because they oppose security. Because they are optimizing for progress. The sticky note wasn’t malicious. It was an optimization.

Unfortunately, it optimized the wrong variable.

The Path of Least Resistance

Human beings are remarkably consistent. When presented with multiple ways to accomplish the same objective, we tend to choose the one that requires the least effort. Behavioral psychologists have studied this phenomenon for decades. Economists describe it through concepts like bounded rationality and mental effort. Engineers simply recognize it as good design.

Cybersecurity often forgets it entirely.

Organizations frequently assume that if policies are written clearly enough, people will simply follow them. Experience suggests otherwise. People generally follow the path that requires the fewest decisions, the least interruption, and the least additional effort. That’s not laziness, it’s human nature.

Every unnecessary step added to a security process becomes another opportunity for someone to find a shortcut. And shortcuts have a way of becoming habits.

The Difference Between Immature and Mature Security Programs

Immature organizations respond to incidents by writing another policy. Mature organizations ask a different question.

Why did this make sense to someone?

That question shifts the conversation from blame to design. Consider the classroom example.

Should passwords remain private? Absolutely.

Should credentials ever be attached directly to a device? Of course not. But stopping there ignores the larger lesson. Why did an experienced educator, someone strongly dedicated to their students, conclude that this was the most practical solution?

Perhaps student onboarding was cumbersome. Perhaps the process required frequent password retrieval.

Perhaps the system created more friction than necessary during one of the busiest weeks of the year. Those possibilities deserve just as much attention as the policy itself. Because good security doesn’t merely tell people what not to do. It makes the secure choice the wise choice.

Security Culture Is a Design Problem

Culture is often described as shared values or shared beliefs. In cybersecurity, culture is better measured using shared behaviors. Those behaviors are influenced less by slogans than by systems.

When secure behavior is intuitive, people adopt it naturally. When secure behavior consistently slows people down, even well-intentioned professionals begin inventing workarounds.

The problem isn’t that people prefer convenience. The problem is when convenience and security are placed in opposition to one another. Strong organizations refuse to accept that tradeoff.

Instead, they ask: “How can we design systems where the secure path is also the easiest path?”

That question signifies a profound shift in thinking. Rather than expecting people to overcome human nature, mature organizations design with human nature in mind.

Leadership Beyond Technology: Setting Security Culture by Example

This principle extends far beyond passwords. In practice, organizations sometimes hard-code credentials because rotating them seems cumbersome. Employees reuse passwords because managing dozens of unique ones is impractical without support. Executives may bypass established processes they perceive as slow, sometimes even advocating for policies they themselves neglect. These behaviors highlight how security actions, good or bad, are shaped by leadership priorities and organizational culture.

Frameworks like Zero Trust (ZT) and NIST’s Cybersecurity Framework (CSF) both emphasize the importance of aligning policies and controls with real-world workflows. For example, Zero Trust encourages the principle of ‘never trust, always verify’, but it also emphasizes minimizing user friction by making secure access seamless. Similarly, NIST CSF calls for continuous improvement and adaptation to actual business context, including user experience, as a critical part of protecting information.

A 2024 Verizon Data Breach Investigations Report found that over 80% of breaches involved a human element, whether through error, misuse, or social engineering. This underscores the need to design security with people, not just technology, in mind.

Consider the widely publicized 2023 MGM Resorts breach: attackers gained access not through a technical exploit, but by manipulating an employee via social engineering. The aftermath highlighted both the human cost of poor security design and the value of resilient, well-communicated processes. Mature organizations study such incidents to inform better system and workflow design, not just to enforce stricter rules.

None of these behaviors are unique to education. They are remarkably consistent across industries. Whether it’s healthcare, finance, manufacturing, government, or cloud engineering, it’s the same.

Technology changes, human behavior does not. This is why effective cybersecurity leaders spend as much time understanding organizational behavior, workflow design, and communication as they do learning about technology. Firewalls protect networks, encryption protects data, identity platforms protect access, and leadership shapes behavior.

And behavior, modeled first by leadership, ultimately determines whether those technologies succeed.

Designing for Reality

There is an old saying in engineering: “Don’t design for perfect conditions. Design for the conditions that are the reality.”

Cybersecurity deserves the same mindset. People work under the pressure of deadlines. And many humans are easily distracted.

They make mistakes. They focus on competing responsibilities. Expecting otherwise isn’t leadership. It’s wishful thinking. The strongest security programs acknowledge these realities and build systems that accommodate them.

Not by lowering standards. By lowering unnecessary friction. Good security accounts for human behavior. Great security aligns human behavior with enterprise intent. That is where security culture begins.

Actionable Steps for Leaders:

  • Review critical workflows for unnecessary security friction; streamline processes where possible. Invest in user-friendly identity and access management platforms that support secure, seamless authentication (e.g., password managers, SSO).
  • Regularly communicate the ‘why’ behind security policies and invite feedback from end users.
  • Model secure behaviors at the leadership level; visible adherence by executives sets cultural expectations.
  • Align technology investments with both security best practices (ZT, NIST) and the realities of day-to-day business operations.

Final Thoughts: Designing for Humans

Key Takeaways:

  • Security workarounds are rarely due to ignorance; they’re often rational responses to unnecessary friction.
  • Mature organizations design security systems that align with natural human behaviors and incentives.
  • Leadership sets the tone—when executives model secure, user-friendly practices, security culture flourishes.
  • Frameworks like Zero Trust and NIST CSF emphasize the importance of user experience and continuous improvement.
  • The most resilient organizations prioritize systems that help people succeed, not just avoid failure.

The sticky note attached to the Chromebook was never really about the sticky note. It’s an example that every decision in a security environment reflects a larger system of incentives, constraints, priorities, and, mostly, habits.

More often than not, systems fail because they ask ordinary people to behave in extraordinary ways. Technology rarely fails first. People rarely fail first. The most resilient organizations understand this. They don’t build security around an idealized version of human behavior. They build it around reality.

Because in the end, cybersecurity isn’t simply about protecting systems. It is the discipline of building systems that help people succeed. And perhaps that is the deeper lesson.

Convenience isn’t the enemy of security. Poor design is.

Or, said another way, Strong security cultures are not built by asking people to overcome human nature. They are built by knowing human nature well enough to design systems that coordinate convenience with security.

Multi-Factor Authentication: Boring, Annoying, Essential

In cybersecurity, we get excited about new technologies like AI, zero trust, and quantum encryption. But ask any practitioner what quietly stops the most breaches day to day? It’s still MFA.

Multi-Factor Authentication may not be exciting. It can slow people down and sometimes feels awkward. Even so, it remains one of the best ways to stop credential theft, which is the most common way attackers get into any network.

Why MFA Matters

• Passwords are weak. People reuse them across accounts, attackers buy them on the dark web, and “123456” still shows up in breach data.
• Phishing is effective. Users still click links and enter credentials. MFA blocks stolen passwords from being enough.
• Attacks are automated. Bots hammer login pages at scale. MFA breaks that automation by forcing a second factor.

Despite everything we know, MFA is still the easiest and most effective step in cyber defense. It often makes the difference between stopping an incident and having to respond to one.

The Pushback Problem

When we first rolled out MFA our district, the resistance was loud.

“It’s annoying.”
“It slows us down.”
“We don’t have time for that.”
“Why do I need this if I’m just checking email?”

At first, security changes can feel like a big hassle for everyone, whether you’re a teacher, technician, or leader. But a few seconds of extra effort can save us from days or even weeks of problems.

To make sure everyone accepted MFA, we took our time and built support step by step:

• Continuous staff education. Regular updates explained the “why” behind MFA, not just the “how.”
• Knowledge-base articles gave our help desk a clear playbook, no scrambling when someone was locked out or confused.
• Anticipating questions became part of the rollout strategy. From custodians logging into shared workstations to the superintendent approving district-wide communications, everyone got personalized guidance.

We kept the message clear: MFA is not a burden. It’s part of how we protect our entire staff and precious student PII, and PHI data. We aways have to remain FERPA, COPPA, CIPA, and PPRA compliant.

Over time, the complaints faded. Now, using MFA is second nature. It’s simply part of our routine.

The Fix

• Enforce MFA on all critical systems.
• Use phishing-resistant methods (authenticator apps, hardware keys) and worst-case scenario SMS.
• Train users that a few extra seconds of friction is the cost of resilience.

The Parallel

Using MFA is similar to wrapping your hands before boxing. It might seem tedious when you’re just getting started, but it protects you. If you skip it once, you might be fine, but skip it again, and you risk real trouble.

Security, like weightlifting, CrossFit, martial arts or meal prep it works best when the basics become instinct.

Again, MFA is boring. But, it’s also one of the most powerful shields you have.

Top 5 Cybersecurity Mistakes I See Every Week (and How to Fix Them)

1. Weak or Reused Passwords

mike epps, top flight security, friday after next

The problem: People still lean on “123456” or reuse the same password across 10 accounts. Attackers love this.
The fix: Use a password manager and enable multi-factor authentication (MFA) everywhere it’s offered.

2. Ignoring Updates and Patches

The problem: That little “remind me later” button gets clicked… and suddenly, a known vulnerability is wide open for weeks.

The fix: Automate updates where possible. For servers and enterprise systems, schedule a patch management routine — monthly at minimum.

3. Cloud Misconfigurations

the breakdowns can be voluminous

The problem: Buckets, blobs, and databases left wide open to the internet. It’s not just bad practice — it’s a breach waiting to happen.
The fix: Review permissions regularly. Use least privilege access. Run configuration scans against frameworks like CIS Benchmarks.

4. Phishing Clicks

who's got your six? matt shannon security pro

The problem: A single click on a fake invoice or “urgent” email can compromise a network. It still works because people are busy and distracted.
The fix: Train employees continuously, not just once a year. Teach them to hover over links, verify senders, and report suspicious emails.

5. Lack of Logging and Monitoring

The problem: Breaches often go undetected for weeks because no one’s watching the logs.
The fix: Centralize your logging (think SIEM, EDR, or even cloud-native tools) and set alerts for suspicious activity. Logs don’t stop attacks — but they stop you from being blind.

Closing Thoughts

Best Practices to Secure Data in a K-12 Environment

1. Implement Strong Access Controls

  • Role-Based Access Control (RBAC): Ensure that only authorized personnel have access to sensitive data. Assign permissions based on roles and responsibilities.
  • Multi-Factor Authentication (MFA): Require MFA for accessing sensitive systems and data to add an extra layer of security.

2. Regular Security Training and Awareness

  • Staff Training: Conduct regular cybersecurity training sessions for teachers, administrators, and support staff to recognize phishing attempts, social engineering, and other common threats.
  • Student Awareness: Educate students about safe online behaviors, the importance of password security, and how to avoid suspicious links and downloads.

3. Use Strong Password Policies

  • Complex Passwords: Enforce the use of strong, complex passwords that include a mix of letters, numbers, and special characters.
  • Password Management: Encourage the use of password managers to help staff and students manage their passwords securely.

4. Network Security

  • Firewalls: Deploy firewalls to protect the school’s network from unauthorized access and malicious traffic.
  • Intrusion Detection and Prevention Systems (IDPS): Implement IDPS to monitor and respond to potential threats in real time.
  • Segmentation: Segment the network to limit access to sensitive data and reduce the attack surface.

5. Data Encryption

  • Encryption at Rest and in Transit: Ensure that all sensitive data is encrypted both when stored and when transmitted over the network.
  • Secure Communication Channels: Use secure protocols like HTTPS, SSL/TLS, and VPNs for remote access and data transfer.

6. Regular Updates and Patch Management

  • Software Updates: Keep all software, including operating systems, applications, and security tools, up to date with the latest patches and security fixes.
  • Automated Patch Management: Use automated tools to manage and apply patches consistently and promptly.

7. Regular Backups and Disaster Recovery Planning

  • Data Backups: Perform regular backups of critical data and store them securely offsite or in the cloud.
  • Disaster Recovery Plan: Develop and regularly test a disaster recovery plan to ensure quick recovery from data breaches, ransomware attacks, or other disruptions.

8. Endpoint Security

  • Antivirus and Anti-Malware: Install and maintain up-to-date antivirus and anti-malware solutions on all devices.
  • Mobile Device Management (MDM): Use MDM solutions to manage and secure mobile devices used by students and staff.

9. Application Security

  • Secure Software Development: Ensure that applications developed or used by the school follow secure coding practices and are regularly tested for vulnerabilities.
  • Third-Party Applications: Vet and monitor third-party applications for security compliance before integrating them into the school’s IT environment.

10. Physical Security

  • Secure Access to Facilities: Implement physical security controls like locks, access badges, and surveillance cameras to protect areas where sensitive data is stored.
  • Device Management: Ensure that devices such as laptops, tablets, and USB drives are securely stored and tracked.

11. Incident Response and Management

  • Incident Response Plan: Develop and maintain a comprehensive incident response plan outlining steps to take in the event of a data breach or security incident.
  • Regular Drills: Conduct regular incident response drills to ensure that staff are prepared to handle security incidents effectively.

12. Compliance and Auditing

  • Regulatory Compliance: Ensure compliance with relevant regulations such as FERPA (Family Educational Rights and Privacy Act) and COPPA (Children’s Online Privacy Protection Act).
  • Regular Audits: Conduct regular security audits and assessments to identify and address vulnerabilities and ensure ongoing compliance with security policies.