Skip to content
Digital Bushido

03 / 08 of 8

03 / Jin

Benevolence

pronounced jin

Domain: Usable security and human-centred design

Wield the power to restrict as a duty to protect.

The argument

Protect the people who must use the control.

Security controls change how people work.

A control that creates constant friction will produce workarounds. Users will share credentials, bypass processes, create unmanaged solutions or ask for exceptions.

That behaviour is predictable. Design for it.

MFA, privileged access, endpoint restrictions, DLP and access controls must account for the legitimate work users need to perform.

The objective is to make the secure path usable enough that people can follow it.

The failure mode

Controls so hostile that the workaround becomes the real process.

When Jin is absent, security creates friction. Users work around controls. Engineers request permanent privileges. Developers move workloads to unmanaged platforms. Security becomes something people try to escape.

In practice

1 / 4 Foundation

Make the behaviour explicit and repeatable.

  • Identify the user

    For every important control, identify who operates it and what legitimate task they need to complete.

  • Document the secure path

    Make the approved way to perform common tasks clear and accessible.

  • Provide a security support path

    Give users a practical way to resolve security-related blockers.

Show all 5 practices
  • Make reporting easy

    Provide simple mechanisms for reporting phishing, lost devices, suspicious activity and accidental exposure.

  • Explain the reason

    Tell users what a control protects and what behaviour is expected.

2 / 4 Controlled

Embed the behaviour into processes and ownership.

  • Automate the safe path

    Automate access requests, credential rotation, approved software deployment and similar repetitive tasks.

  • Design with users

    Test security workflows with administrators, developers and business users before deployment.

  • Build approved alternatives

    When blocking a risky activity, provide a supported way to accomplish the legitimate business requirement.

Show all 5 practices
  • Measure friction

    Track access-request time, authentication failures, exception requests and security-related support demand.

  • Review workarounds

    Treat repeated bypasses as signals that the control or process needs examination.

3 / 4 Measured

Verify that the behaviour is happening and that it works.

  • Measure abandonment

    Identify security workflows that users start but do not complete.

  • Track exception demand

    Look for teams repeatedly requesting the same exception.

  • Measure secure-path adoption

    Determine whether users actually use the approved workflow.

Show all 5 practices
  • Test usability after deployment

    Reassess controls after major changes in technology or business processes.

  • Correlate friction with incidents

    Look for relationships between difficult controls and unsafe workarounds.

4 / 4 Adaptive

Use evidence to improve the behaviour and respond to change.

  • Remove recurring friction

    Prioritise engineering work that eliminates repeated security workarounds.

  • Use risk-based controls

    Apply stronger controls where risk requires them and reduce unnecessary friction elsewhere.

  • Continuously redesign workflows

    Treat security user experience as an operational product that needs maintenance.

Show all 5 practices
  • Automate exception alternatives

    Where the same exception appears repeatedly, determine whether it should become a supported pattern.

  • Measure security by behaviour

    Include user adoption and workaround rates when evaluating whether a control is successful.

See the full practice model

Worked examples

MFA fatigue

Employees receive repeated MFA prompts during the day.

They start approving prompts without checking them.

The security team changes the authentication design to phishing-resistant authentication and risk-based access.

The number of prompts falls.

Users can recognise meaningful authentication events.

Reduce the friction that trains users to ignore security signals.

Password rotation

A company requires service-account passwords to change every 30 days.

Hundreds of applications depend on those accounts.

Engineers start storing passwords in scripts and configuration files because the rotation process is difficult.

The company introduces managed service identities and automated credential rotation.

The security control becomes easier to operate correctly.

If the secure process is harder than the workaround, expect the workaround to win.

Privileged access

Administrators must request temporary access through PAM.

The process initially takes 30 minutes.

Administrators begin asking for permanent elevated accounts because emergency work cannot wait.

The organisation redesigns the workflow so normal elevation takes two minutes while emergency access remains controlled and logged.

Security must fit the operational reality.

Endpoint restrictions

Developers cannot install approved development tools because endpoint controls require manual security approval.

Developers start using personal machines and unmanaged cloud environments.

The security team creates an approved software catalogue with automated deployment.

The control remains in place while the workaround disappears.

Good security removes unnecessary reasons to bypass security.

Phishing reporting

Employees are told to report suspicious emails.

The reporting process requires opening a ticket and completing several fields.

Almost nobody reports anything.

The company adds a single-button reporting mechanism and automatically collects the email metadata.

Reporting increases significantly.

Make the safe action the easy action.

Mapped controls

Reading: Every mapping here is partial by design. Neither framework has a control that says do not make security so painful that people route around it, which is the whole of Jin.

NIST Cybersecurity Framework 2.0

JinNIST CSF 2.0. Table scrolls horizontally.
ControlControl titleStrengthWhy it maps
PR.AT-01Personnel awareness and trainingpartialAwareness training touches the human side of security but not whether the controls themselves are usable.
GV.RR-04Cybersecurity is included in human resources practicespartialHR practices bring security into the employee lifecycle without addressing the friction that drives workarounds.

ISO/IEC 27001:2022 — Annex A

JinISO 27001:2022. Table scrolls horizontally.
ControlControl titleStrengthWhy it maps
A.6.3Information security awareness, education and trainingpartialTraining helps people cope with controls; it does not make the controls humane.
A.5.10Acceptable use of information and assetspartialAcceptable-use rules govern behaviour but not whether compliance is realistic for the people bound by them.