Security Table Stakes Should Be Simple
Some parts of security should feel ordinary.
MFA should be enabled. Laptops should be encrypted. Systems should be patched. Backups should get tested. Access should disappear when someone leaves.
These are table stakes.
They should take very little human effort to keep running.
Yet companies often build large processes around them.
Process Has a Cost
Every approval takes time.
A ticket waits in a queue. Someone reviews it. Another person approves it. An engineer waits for access before getting back to work.
Multiply that across hundreds or thousands of employees and the cost becomes significant.
Security teams tend to measure the control. They rarely measure how much time the control consumes across the company.
That time matters.
Make the Basics Automatic
A new laptop should arrive encrypted.
MFA should already be required. Logging should turn on when infrastructure is created. Endpoint protection should install automatically. Access should expire when the business need ends.
People should not have to remember how to secure the basics every time they do something.
Build those controls into the environment.
Automation also gives you consistency. The same control gets applied every time without depending on someone remembering a step in a document.
Manual Process Creates More Process
Manual controls eventually fail.
Someone forgets a ticket. An approval sits for a week. A spreadsheet gets stale. An exception stays open long after anyone remembers why it exists.
The usual response is another review step.
Then another approval gets added. More evidence gets collected. Another person gets copied.
Soon the organization spends more time operating the process than managing the risk that created it.
Friction Changes How People Work
People still have jobs to do.
If getting an approved tool takes weeks, someone may find another tool. If access takes days, a team may start sharing an account. If procurement becomes painful, someone may enter a credit card into a SaaS product and move on.
Now you have a different security problem.
The secure path needs to be easy enough that people naturally use it.
Save People for the Hard Problems
There are plenty of security problems that need human judgment.
A new production architecture may create an unexpected attack path. A vendor may need access to sensitive systems. An acquisition may bring years of unknown infrastructure. An active incident may require decisions with incomplete information.
Those problems deserve people’s time.
Resetting passwords, provisioning standard access, patching laptops, collecting logs, and enforcing basic configuration should consume as little of it as possible.
Security Should Know Its Cost
Every control has an operating cost.
Sometimes that cost is money. Often it is employee time.
A security requirement that adds fifteen minutes to something done ten times a year barely registers. Add fifteen minutes to something done ten thousand times a month and you have built a large productivity tax.
Measure that.
Security should understand both the risk being reduced and the effort required to reduce it.
Final Thought
Get the basics right and make them easy.
Automate everything that has a predictable answer.
Save process, discussion, and human judgment for the security problems that deserve them.