Observation

When IT Designs from the Inside Out

21 April 2026 · Author: Lisbeth Loft

The problem is not always that users choose an insecure solution. Sometimes the problem is that the secure solution never took their needs as its starting point.

In many organisations, new IT solutions are chosen based on the existing infrastructure, the technical architecture or the systems the IT department already knows well.

That can be rational from an operations and security perspective.

But if the user’s needs only enter the picture later, the organisation can end up with a solution that fits the technology well – but not the work.

Then people start finding other ways of getting the task done.

When the Official Solution Does Not Fit Reality

It can be employees storing data locally because the approved solution is too cumbersome.

It can be documents ending up in personal iCloud or other personal services, because sharing across the organisation is difficult.

It can be an insecure form built around the official solution, because the existing process does not support the task that actually needs to be done.

Or it can be entirely ordinary workarounds that gradually become part of everyday life, because they work better than the solution the organisation has made available.

When that happens, it is often described as a user problem.

But it may just as well be a design problem.

Inside Out Versus Outside In

An inside-out perspective typically takes as its starting point the existing platform, what can be operated, what can be integrated, and which solutions the IT department already knows.

An outside-in perspective starts somewhere else: which task actually needs to be done, how do users work in practice, which information needs to be moved or shared, and where does the friction arise today?

The aim is not to choose one perspective over the other. Both are necessary. The problem arises when the technical considerations are allowed to dominate so much that the user’s needs only come in afterwards.

The secure solution should not just fit the infrastructure. It should also be the natural way of getting the task done.

Shadow IT Is Often a Signal

Shadow IT is often treated as something to be eliminated.

But it can also be seen as information.

If many employees use the same unofficial solution, share data in a particular way, or build the same workarounds, it tells you something about where the organisation’s official solutions do not fit the need.

That does not mean unofficial solutions are acceptable.

It means they can be symptoms of an underlying problem that the organisation should understand before trying to solve it.

Security Must Fit the Work

Information security works best when it is built into the way the work is actually done.

If security becomes something the user constantly has to work around, there is a greater risk that other solutions will emerge.

That means IT, information security and the business should work more closely together to understand the situation of use before the solution is chosen.

That is not only a question of usability.

It is also a security question.

A solution that is secure on paper, but systematically causes users to go around it, is not necessarily the most secure solution in practice.

When Workarounds Become Part of the Risk Picture

Workarounds, personal cloud services and local files can create problems with, among other things, access, data protection, backup, logging and oversight.

But if the organisation only responds by banning them, without understanding why they arose, there is a risk that the problem simply moves somewhere else.

The relevant question is therefore not only:

How do we stop the use of unauthorised solutions?

It is also:

What need did the unauthorised solution actually meet?

That question can be far more valuable.

From Technical Solution to Organisational Solution

Good IT governance is not only about choosing technology that fits the architecture.

It is also about choosing solutions that fit the organisation.

That requires an understanding of technology, workflows, people and security behaviour.

When those perspectives are brought together from the start, it becomes far easier to create solutions that are both secure and actually used.