Practical guide ·

Why employees work around security rules — and how to make them usable

A workaround is a signal to investigate both the behaviour and the work process. Ask what the employee was trying to complete, where the approved route failed and which risk the workaround created. Improve the route, explain the control and retain accountability. Repeating the policy alone rarely explains the obstacle.

What does a workaround tell us?

In an illustrative case, a team sends a large customer file through an unapproved service because the approved channel cannot accept it. The transfer creates a confidentiality risk. Asking only who broke the rule misses the broken delivery path that the next employee will encounter.

Establish the facts without assuming every exception has the same cause. Some involve missing knowledge, some an unusable process and others a deliberate disregard of responsibilities. The response should reflect the evidence.

How do we make the approved route practical?

Observe the task with the people who perform it. Identify the points where they wait, repeat work or seek an exception. Provide a supported way to handle common cases and an escalation route for unusual ones.

For the file-transfer example, agree an approved channel, recipient verification and a way to request extra capacity. Test it with a real workflow using suitable test data. A policy owner should be responsible for the usability of the process as well as its written requirements.

From observed behaviour to a practical intervention
ObservationQuestionPossible improvement
Unapproved file sharingCould the approved route handle the task?Usable secure transfer
Shared accountWas individual access available in time?Timely provisioning and accountability
Ignored warningWas the warning understandable and actionable?Clear instructions and escalation
Repeated exceptionHas the temporary need become permanent?Redesign the process

What should managers demonstrate?

Managers should use the same approved route and explain exceptions through the established process. If urgent work routinely receives informal exemptions, employees learn that speed decides the rule. Record temporary exceptions with an owner, compensating measures and an expiry.

The governance research linked below discusses the interaction of technical measures, leadership and organisational behaviour. In practice, this means involving the process owner and the security owner in the same change rather than handing one team a document to enforce.

How do we measure improvement?

Look at completion of the approved task, recurring exceptions, time to resolve requests and the nature of reported problems. Training attendance alone does not show whether people can apply the procedure.

Make it easy to report an error early, while retaining a fair process for intentional misuse. A temporary increase in reports may reflect better visibility rather than deteriorating behaviour. Read the evidence in context and check whether the same obstacle returns after the change.

Explore in detail: CISO, vCISO or the IT manager? Who owns security.

How Dyasol can help

Dyasol can help review policies, communication and the human factors affecting implementation. The work connects the required protection with the way the organisation actually operates.

Explore human factors and security adoption

Sources and context

Examples are illustrative. Practical recommendations should be adapted to the organisation.