Skip to content
Sections
All notes

All notes · Programme

Working With Security

Security controls are a major source of friction and a legitimate requirement. How to have the conversation productively.

Programme · Analysis

A significant share of what a DEX programme finds was put there deliberately by somebody protecting the organisation. That makes this the most delicate relationship the programme has.

The recommendations in “Working With Security” need visible ownership, review time and a way to show whether the change reduced effort for the affected group. An organisation can use this supporting resource to coordinate that implementation work and compare workloads, without treating hours or activity as a complete measure of digital employee experience.

For an independent benchmark, compare this approach with CISA Secure Our World guidance; the useful test is whether the evidence remains proportionate, accessible and understandable to the people whose work is being measured.

Where the friction comes from

Authentication: repeated sign-ins, short session lifetimes, multiple factors for low-risk systems.

Approval chains for access, which the access note covers.

Endpoint agents, several of which run simultaneously and compete for the same resources.

Scanning that runs during the login window.

Blocked tooling, which produces workarounds rather than compliance.

The wrong approach

Presenting security controls as problems to be removed.

It ends the conversation, correctly, because the person on the other side is accountable for something you are not.

And it produces the pattern where the programme and security work past each other for a year.

The approach that works

Bring evidence of the workaround.

A control that produces widespread circumvention is not providing the protection it was designed for, and security teams respond to that argument because it is their argument.

"Forty per cent of this department uses a personal device for this task because the approved route takes six minutes" is a security finding, not a complaint about security.

Risk-proportionate rather than uniform

The productive framing: full controls on sensitive systems, lighter ones elsewhere.

Most organisations apply the strictest control uniformly because it is simpler to administer.

Showing the cost of uniformity in waiting time gives the security team a basis to differentiate, which many want and few are asked for.

Agent collision

A specific and common technical issue: endpoint security, management, backup, DEX and sometimes more, all running at once.

Each is individually justified and the combined footprint is substantial.

Measure it — its own note covers agent weight — and take the total to whoever owns the endpoint standard, not to each supplier separately.

What security gets from the programme

Telemetry about what is actually installed and used, which supports their own work.

Evidence of where controls are circumvented.

And a route to hear about friction before it becomes shadow adoption.

Offer these early. A programme that arrives with something to give is received differently.

Where you will not win

Regulated controls.

Controls introduced after a specific incident, which carry institutional memory.

Accept these, document them as accepted friction with the reason, and stop re-reporting them.

What to check

How many endpoint agents run on a typical machine, and what do they cost together?

Where do people work around a control, and does security know?

Are your authentication requirements uniform or risk-proportionate?

And have you offered security anything?

The point

A control that is widely circumvented is not providing the protection it was designed for.

That is a security finding, not a complaint about security.

Underlying all of this

Everything in this collection reduces to four habits: find the friction cheaply before buying anything, fix what needs no budget first, report the worst tenth rather than the average, and keep the data about systems rather than about people. None requires a better platform, and a programme doing all four changes more than one twice its size.

The recurring pattern

The recurring pattern across every section here is the same: the measurable is mistaken for the important. Device health stands in for experience, ticket categories for causes, a composite score for a finding. Each substitution is convenient, each produces confident decisions on thin ground, and each is corrected by going and looking at the thing itself.