Analysis
Why Don’t People Follow Security Procedures?
1 October 2026 · Author: Lisbeth Loft
Before we try to change behaviour, we need to understand the factors that shape it.
When security procedures are not followed, the explanation is often quickly given: employees lack awareness, have not understood the rules, or are simply doing something wrong.
That can of course be part of the explanation. But reality is often more complex.
Human behaviour is shaped by the situation people work in: technology, workflows, time pressure, organisational demands, leadership, culture, skills and the concrete choices that systems present to them.
If we want to understand security behaviour, it is therefore not enough to ask:
Why did the employee not do what the procedure said?
We should also ask:
Which conditions made the expected behaviour difficult, unnatural or less likely?
Security Behaviour Emerges in a Context
A procedure can be correct on paper and still be difficult to follow in practice.
That can happen, for example, when:
- the procedure requires several manual steps in a busy workflow
- the system makes the secure option slower or more cumbersome
- the employee must choose between completing their primary task and following the security procedure
- the rules are unclear or differ across the organisation
- employees have developed informal shortcuts because the official processes do not fit the work
- management’s signals about speed, service or productivity are experienced as more important than the security rules
In such situations, the behaviour is not necessarily an expression of lacking knowledge. It can be a rational response to the conditions the employee works within.
When Solutions Are Designed from the Inside Out
In many organisations, IT and security solutions are to a large extent designed from the inside out.
The starting point may be the existing infrastructure, systems the organisation already knows, solutions that fit the technical architecture well, or new technology the organisation is keen to adopt.
That is not necessarily wrong. But if the user’s actual needs are not involved from the start, a gap can emerge between the official solution and the way the work is actually done.
That can for example lead to:
- data being stored locally because the approved solution is difficult to use
- employees developing informal workarounds because the systems do not support the actual task
- information being moved to personal cloud services or private devices to get the work done
- manual solutions or insecure forms emerging because the official solution does not fit the need
When that happens, the problem is easily described as poor security behaviour.
But it may just as well be a sign that the organisation has not designed a secure solution that actually fits the work.
That changes the question from:
Why do employees not follow the procedure?
to:
Have we given them a solution that makes it possible to work securely?
That is an important difference, because the solution is then not necessarily more training. It may be a better technical solution, a simpler workflow or a change to the process itself.
Awareness Matters – but Is Rarely the Whole Answer
Awareness training plays an important role in cybersecurity.
Employees need to understand relevant risks, know the organisation’s requirements and know how to respond when something looks wrong.
But if the problem primarily lies in the workflow, the system design or the organisational constraints, more training will not necessarily change behaviour.
It amounts to telling people once again what they ought to do, without first examining why they are not already doing it.
Awareness should therefore not stand alone. It should be seen as one possible part of a broader effort, where the first step is to understand the cause of the observed behaviour.
The Human Factor Is Not Just “Human Error”
The concept of the human factor is often used in connection with cyber incidents and information security.
But if the concept is reduced to “people make mistakes”, we risk overlooking what matters most.
People work as part of technical and organisational systems. Their actions are influenced, among other things, by:
- how systems are designed
- which information they have access to
- how clear the rules are
- which incentives the organisation creates
- what colleagues and managers actually do
- how much time and attention a task requires
- previous experience and the perception of risk
An error can therefore be a symptom of a broader problem.
If the same type of circumvention or unsafe behaviour occurs again and again, it is worth examining whether the problem really lies with the individual employee – or whether the organisation has created conditions that make the behaviour likely.
From Assumptions to Knowledge
Organisations often already have an explanation for why employees act as they do.
“They have not understood the procedure.”
“They do not take security seriously.”
“They need more awareness.”
But an assumption is not necessarily an explanation.
If we want to change behaviour, it can therefore be useful to examine it first.
That can be done through, for example:
- interviews and focus groups
- observation of workflows
- survey data
- analysis of incidents and patterns
- comparison across functions or employee groups
- combining qualitative and quantitative data
The method should depend on the question.
The purpose is not necessarily to carry out a large analysis. It is to gain enough knowledge for the organisation to act where the problem actually lies.
Security Behaviour Is Also a Question of Leadership and Design
When security procedures are not followed, it is tempting to place responsibility with the individual employee.
But the organisation also has a responsibility to create conditions in which secure behaviour is possible and realistic.
That means looking, among other things, at:
- whether procedures fit the actual work process
- whether security is built into the systems
- whether requirements and responsibilities are clear
- whether different goals in the organisation pull in the same direction
- whether employees receive useful feedback
- whether management itself supports the desired behaviour
The most effective solution is therefore not always more training.
Sometimes it is a better workflow. A technical change. A clearer responsibility. A change in management’s expectations. Or a combination.
Before We Try to Change Behaviour, We Should Understand It
People are a central part of information security.
That does not mean they should be seen as the problem.
It means their behaviour should be understood as part of the overall system the organisation is trying to protect.
When we know why a particular behaviour arises, it also becomes easier to choose the interventions most likely to work.