Skip to content
CISOteria
Back to Insights
Governance

The Policy Says One Thing. The Organisation Does Another. Why?

August 13, 2026 7 min read CISOteria
Table of Contents

Approved on Paper. Ignored in Practice

Most organisations already have security policies.

They explain how employees should handle data, approve access, share files, use devices, and report incidents. On paper, the rules are clear. Responsibilities are assigned, controls are documented, and the organisation can point to a formal process.

Then the policy meets daily work.

An employee cannot complete a task quickly enough through the approved system, so they create a workaround. A manager uses a faster channel because the official process feels too slow. A team adopts an unauthorised tool because the approved one does not fit the work.

The problem is not always that employees do not know the rules. The policy describes how work is supposed to happen, while employees deal with how work actually happens.

On Paper, Everything Works

Knowing the Policy Is the Easy Part

Recent research on information security policy compliance shows that awareness alone is not enough. Employees may understand the rules and still behave differently when the approved process feels difficult, time-consuming, unclear, or disconnected from the pressures of their role. The research describes this as a “knowing-doing” gap: people may know what the organisation expects without consistently following it in practice.

Organisations often assess policy strength through formal evidence: an approved document, completed training records, and a successful audit review. Those signals show that the process exists, but they reveal far less about how employees behave under pressure.

Deadlines, slow systems, unclear instructions, and competing business demands often shape daily decisions more than the policy itself.

Green Checks Can Hide Grey Practices 

A policy may be formally approved, communicated across the organisation, included in training, and reviewed during an audit, yet still remain weakly connected to daily work. From a governance perspective, those visible signs can create a level of confidence that the organisation has not fully earned.

Leadership can see the document, the completion records, and the audit result. It has far less visibility into the small decisions employees make when the official process slows them down, creates extra work, or conflicts with an urgent business need. A team may use an unapproved tool, a manager may accept an informal exception, or an employee may skip a step that seems unnecessary in the moment. None of these actions may appear serious on their own, but together they can create a growing gap between the control environment described in policy and the one that actually exists.

The difficulty is that formal evidence usually records whether a process was designed, approved, or reviewed. It rarely shows how consistently that process is followed under pressure. As a result, an organisation may report strong compliance while the day-to-day reality depends on workarounds, local habits, and decisions that never reach the formal governance process.

Good Intentions Can Create Bad Security 

The Employee Followed Security – Just Not Yours 

A 2025 study examined what the researchers call shadow security practices – unofficial security-related workarounds created by employees who still believe they are protecting the organisation.

An employee may save important files on a personal device because the approved backup system is slow. The intention is protective, but the result is still outside the organisation’s control and may violate data-handling rules.

Shadow security is difficult to manage because the employee may still be trying to protect the organisation. They are balancing a business task with a security requirement, but doing so through a method the organisation cannot see or govern. 

Too Much Security Can Drive Work Underground 

The same study surveyed 433 office workers and found that information security overload increased employees’ intention to use unofficial security practices. When people felt that security duties added pressure, delayed their work, or made primary tasks harder, they were more likely to create their own solution.

This does not mean controls should disappear whenever they create friction. Some friction is necessary because the risk justifies it.

The problem begins when the organisation adds controls without understanding their combined effect. One approval, one authentication step, and one reporting requirement may each seem reasonable. Employees, however, experience the full process. When those requirements accumulate, the approved path may become harder to follow than the workaround.

Another Training Session Will Not Fix the Process 

Security Communication or Security Noise?

The shadow security study found that employees were less likely to create workarounds when they understood how security measures worked, why management required them, and what outcomes the measures were meant to achieve.

However, the study also found that excessive communication can increase overload. More emails, more warnings, and more training do not automatically create better behaviour. They can create confusion, fatigue, and pressure.

The goal should therefore not be maximum communication. It should be useful communication that explains the risk, the reason for the rule, and the practical way to follow it.

Culture Decides Which Rules Survive 

The 2025 systematic review found that policy compliance is influenced by employee attitudes, perceived effectiveness of security measures, management support, awareness, and organisational culture.

Employees notice whether leaders follow the same rules they promote. They notice whether managers reward speed while security demands caution, and whether reporting a problem leads to support or blame.

A policy may say that security is everyone’s responsibility, but the organisation teaches a different lesson when deadlines always win or exceptions are quietly ignored.

Training cannot fix that on its own. If the approved process is too slow, another awareness session will not make it faster. If employees are rewarded for speed and punished for delay, a reminder about compliance will not change the incentive.

Workarounds Are Also Evidence

A workaround should not be accepted simply because the employee had good intentions. Unapproved practices can still create serious risk.

But they should be studied.

A workaround shows where the official process and actual work have separated. It may reveal a missing tool, unclear ownership, a slow approval chain, or a policy that was written without enough operational input.

The organisation should examine both the employee’s decision and the conditions that made the approved process difficult to follow.

Approved, Published, Forgotten  

A policy becomes useful when the organisation can see how it is being applied.

That requires clear ownership, defined controls, evidence, exceptions, and regular review. It also requires visibility into where practice is moving away from policy.

For organisations using CISOteria, this means connecting policies to the controls, owners, evidence, risks, and compliance requirements they are meant to govern. The value is not simply in storing the policy. It is in showing whether the policy is active, who is responsible for it, what proves that it is being followed, and where gaps remain.

CISOteria does not enforce employee compliance. It gives the organisation visibility into whether policy and practice remain aligned.

Conclusion:

The Rules That Survive Pressure Are the Rules You Actually Have 

Every organisation has two versions of its security policy. One is written, approved, and presented during audits. The other is shaped by daily decisions, management behaviour, informal exceptions, and the pressure employees face when they try to get work done.

Good governance begins with recognising the gap between the two. The organisation needs to understand where practice has moved away from policy, why that happened, and whether the right response is stronger enforcement, clearer communication, a better process, or a revised policy.

Because the written policy shows what the organisation intends to do. Daily behaviour shows what it has actually made possible.

For Further Reading

This blog post is based on insights and analysis from:

Frequently Asked Questions

Want to learn more?

Subscribe for the latest insights on cyber program management and security leadership.

See Plans