Consider this scenario from an IT security perspective:
A security warning appears on screen. The employee sees it. They have probably seen something similar dozens, perhaps hundreds, of times before. They may read:
- “Are you sure you want to continue?”
- “This file may be unsafe.”
- “This message came from outside your organisation.”
- “Your password is about to expire.”
- “Suspicious sign-in detected.”
- “Do not click links in unexpected emails.”
Despite seeing all of the warnings, the employee still clicks Continue.
From the security team’s perspective, it looks like a failure of awareness. After all, the organisation has invested so much time in training. The warning was clearly displayed and the risk was explained beforehand. Nevertheless, the employee ignored it.
But, this misses an important behavioural component.
People don’t respond to security warnings in isolation. They respond to them as part of an environment filled with notifications, authentication requests, pop-ups, banners, prompts, policies, deadlines and other competing demands for attention.
Over time, even a legitimate security warning turns into mere background noise.
Research into security fatigue has found that when people are overwhelmed by repeated security decisions, it can contribute to feelings of resignation, frustration, risk minimisation and decision avoidance.
Recent National Institute of Standards and Technology (NIST) research on human-centred cybersecurity has similarly argued that awareness training alone isn’t enough, which emphasises the need to address the underlying security processes, technologies as well as the organisational conditions in which employees actually work.
For enterprises, this should lead to changing the perspective from asking why employees don’t listen to security warnings and flipping the script to determine what has happened to make the warnings no longer meaningful.
Cybersecurity Warnings Compete for Attention
A warning is seen as an intervention method by security teams. It’s something that appears at the precise moment an employee is about to do something risky. In an ideal world, the employee would see it and just stop what they’re doing.
However, from the employee’s perspective, it’s not a security intervention. They tend to see it as yet another interruption to their work.
Say someone is trying to join an online meeting with a customer. At the same time that meeting is happening, they also have emails to answer, a presentation to finish and a colleague waiting on them to send through a document. Then, a security prompt appears.
With all of that going on in the background, the employee has to decide whether the warning represents a genuine threat, whether they understand what it means and whether the requested action is important enough to interrupt what they are doing. This cognitive decision may have to be made by the employee repeatedly.
NIST research into security fatigue found that people can become overwhelmed by the number of security-related decisions they are expected to make on any given day. To cope with this overload, the employee might simply choose the easiest option, avoid making decisions altogether or prioritise more immediate goals over security.
The employee’s ultimate goal ends up not being bypassing security but rather finishing their tasks. The security warning is competing against that objective.
Habituation: The Warning Becomes Part of the Environment
One of the most important psychological mechanisms behind ignored security warnings is habituation.
Habituation is the process through which a person’s response to repeated stimulus decreases over time. In the cybersecurity realm, that can mean the first warning attracts devoted attention. But, the tenth receives less attention and the hundredth barely registers.
This doesn’t necessarily mean the person has consciously decided that security is unimportant or not a priority. Research on habituation implies that repeated exposure to similar stimuli can reduce the attention people give them over time.
Phishing Defense After the Click
Why boards must fund full-chain visibility, from browser sessions to TI feeds, to keep modern phishing from bypassing legacy controls.
Research presented at the USENIX Symposium on Usable Privacy and Security found that repeated exposure to ordinary notifications could reduce attention to security warnings that looked similar. Most crucial is that researchers found that this effect could carry over from non-security notifications to more serious security warnings. That creates a particularly difficult problem for enterprise technology.
Modern software is deliberately designed around familiar interaction patterns. Pop-ups, banners, consent boxes, notification badges and confirmation dialogs are everywhere. The more similar a critical security warning looks to an ordinary notification, the harder it may be for the user to distinguish it as something that deserves a higher level of attention.
Consistency in user interface is known as a positive thing to strive for because it makes technology easier to use and learn. However, that very consistency can potentially work against security significance.
When Warning Fatigue Turns Security Into Background Noise
Habituation may explain why an individual warning can potentially lose its impact. But, warning fatigue takes the problem a step further.
Employees may be exposed to security messages across email, browsers, endpoint software, identity platforms, collaboration tools and internal communications. Each of those individual warnings may be reasonable. Collectively, they can become exhausting. The result is a paradox.
Naturally an organisation wants employees to make safer decisions so it increases the number of security controls. But every additional security decision added also creates another opportunity for the employee to become disengaged.
NIST's research into security fatigue identified feelings including resignation, loss of control, fatalism and decision avoidance. The researchers also highlighted three practical principles to implement:
- reduce the number of security decisions users need to make,
- make the correct action easier and,
- support consistent decision-making.
This provides an important distinction enterprise security teams should consider: More security prompts don’t necessarily mean more security.
An ignored warning isn’t providing the same protection as a warning that changes behaviour. The goal should therefore be to reduce unnecessary cognitive load while making genuinely important interventions harder to miss.
How Does Optimism Bias Change How Employees Perceive Risk?
Inside High-Impact Cyber Attacks
Break down malware, DDoS, phishing and zero-day campaigns behind major incidents to stress-test your security architecture.
There is another factor at play: optimism bias. This means people tend to believe that negative events are less likely to happen to them than to other people.
When applied to cybersecurity, that optimism bias can produce thoughts such as:
- “I've never been hacked before.”
- “I've opened emails like this hundreds of times.”
- “Why would anyone target me?”
- “The security team would probably block it anyway.”
- “It’s probably just another false alarm.”
None of these thoughts necessarily reflect deliberate disregard for security but they do reflect the way people assess personal risk.
Research examining non-IT employees in organisational settings found that optimism bias can contribute to risky cybersecurity behaviour and foster a less favourable attitude towards cybersecurity. The same researchers also found that providing more awareness around security helped alter the relationship between cybersecurity attitudes and risky behaviour.
Additional phishing-related research has found that optimism bias can weaken the relationship between perceived risk and attitudes towards adopting preventive measures.
This matters because security teams frequently communicate risk in terms of what could happen. But employees may also weigh that risk against what they believe is likely to happen to them personally. When the perceived likelihood of something happening feels low, a warning may have less influence on behaviour, even when it’s known the potential consequences are significant.
A warning that says “Attackers could steal your credentials” is technically accurate but if an employee believes the likelihood of that happening to them is very slim, the warning may not pay off and change their behaviour.
People’s Struggle With Evaluating Risk That’s Invisible
Cybersecurity faces another psychological disadvantage: when security is successful, it’s largely invisible.
If an employee follows a warning and avoids a malicious attachment, nothing happens. If they ignore the warning and the attachment happens to be harmless, nothing happens.
Ticketmaster’s Data Liability Shock
A half-billion customer leak raises questions on cyber due diligence, incident response readiness and the long-term cost of eroded digital trust.
From the employee's perspective, both decisions can produce the same immediate result. That makes it difficult to build an intuitive connection between engaging in secure behaviour and positive outcomes.
Another issue is that the consequences of a poor security decision may also be delayed.
Say an employee enters their credentials into a convincing phishing page today and the consequences to this are only discovered days later. By that point, the connection between the original unsafe decision and the eventual incident is difficult to recognise and reconcile.
This creates an uneven trade-off for employees. The inconvenience of following the correct steps in a security process is immediate and tangible, while its benefits are often invisible. Meanwhile, the consequences of ignoring a security warning can feel uncertain, distant or unlikely to affect them personally.
This doesn’t mean employees are incapable of making rational security-related decisions. It means organisations should recognise that asking individuals to repeatedly perform high-quality risk assessments while they’re busy with their day-to-day work isn’t a strong security architecture to implement.
When Security Fights With Productivity
Being productive at work and security are often presented as competing priorities. It may seem understandable to frame it as such, but it can create an undesirable outcome.
If a security control repeatedly prevents employees from completing legitimate work, employees may start looking for ways to circumvent it.
NIST has highlighted the relationship between poor usability, employee frustration, mistakes and noncompliance. Its recent work on human-centred cybersecurity argues that providing awareness-related training alone can’t address the problems created by disruptive or difficult security processes.
In modern enterprise environments, employees may work across multiple SaaS platforms, cloud applications, identity providers, collaboration platforms, customer portals, AI tools, remote-access systems and third-party applications.
Every additional system can potentially introduce another authentication step, notification, permission request or security decision that needs to be interacted with. The cumulative experience this creates matters.
When Fans Become Attack Surface
How World Cup ticketing, travel and streaming ecosystems widen the attack surface – and why slowing user decisions is now core to cyber strategy.
So, the IT team may see ten separate security controls but all the employee experiences is ten interruptions that frustrate them.
So Should Enterprises Stop Warning Employees?
Obviously not. Warnings remain an important layer of defence, particularly when they are designed around specific risks.
Ultimately, the problem isn’t the fact that organisations issue warnings in the first place, but more so that sometimes warnings are treated like the solution to the problem of risk.
A better approach would be to ask what should happen before, during and after the warning.
Before the warning: Remove unnecessary decisions
Where a security-related decision can be automated safely and technology can handle it behind the scenes, then that should be implemented.
Endpoint protection, phishing detection, access controls, MFA, sandboxing, email filtering and other technical controls can reduce the number of instances where an employee has to manually make a security decision.
Both the US Cybersecurity and Infrastructure Security Agency (CISA) and the UK's National Cyber Security Centre (NCSC) emphasise the importance of using layered cybersecurity measures. This means combining technical controls with employee awareness and a clear process for reporting suspicious activity.
During the warning: Make the decision obvious
A warning should answer three questions quickly:
- What is happening?
- Why does it matter?
- What should I do?
If a warning says “Potentially dangerous content detected”, it’s technically accurate. But the problem is it places the burden of interpretation on the user.
A more useful intervention in the moment would be something that explains what the problem is and the potential consequence as well as gives the employee a clear next action to take.
The objective isn’t to make the warning more frightening. It’s to make it more useful.
After the warning: Make reporting easy
It’s inevitable that employees will make mistakes so it’s important to develop a security architecture that makes the process of recovery and reporting after-the-fact straightforward.
CISA recommends creating a no-blame culture in which employees can safely report phishing attempts, including situations where they inadvertently downloaded malware or shared data.
This is important because a warning is only one link in the incident chain. Organisations still need clear processes set up for reporting, containing and responding to an incident when an employee does interact with something suspicious.
Awareness Needs to Account for Human Behaviour
Traditional security awareness often focuses on rules telling employees what not to do: don't click suspicious links, don't reuse passwords, don't open unexpected attachments. Unfortunately, real-world security decisions don’t come explicitly labelled as “suspicious”.
An employee might recognise an obvious phishing email thanks to training and past experiences but might still hesitate when a known supplier sends an unusual payment request or a legitimate-looking login prompt appears but just at the wrong time.
With phishing attacks becoming more sophisticated, including those that use AI and gathering information from previous communications to mimic familiar language, people and business relationships, the distinction is becoming harder. CISA warns that as attackers continue to evolve their techniques, traditional warning signs can become less reliable.
To negate this, security awareness needs to go beyond teaching employees what to avoid. It needs to help them recognise when something feels different from the normal context. That could mean showing employees that they should pause when:
- A familiar supplier suddenly changes payment details.
- A senior executive makes an unusual request that doesn’t follow their usual pattern of behaviour.
- A message has a sense of urgency that prompts them to complete an action.
- A familiar process suddenly has a new step included that requires an unfamiliar action to be taken.
- A login request appears without an obvious reason for it to be there.
- A message looks superficially convincing but the context doesn’t make sense.
The goal isn’t to turn employees into security analysts. It’s to give them enough background to recognise when they should be uncertain and know what to do when something does not feel right.
Fewer, Better Security Decisions
This leads to one of the clearest lessons from the psychology of security warnings: people shouldn’t have to make every security decision themselves.
Where technology can safely make the decision, it should. Where human judgement is necessary, the employee should have enough context to make that judgement quickly. And when a warning genuinely matters, it needs to stand out from the humdrum, routine notifications employees encounter every day.
This responsibility shift should also change how organisations think about mistakes. An employee who hurriedly clicks a malicious link should be able to report it quickly without worrying that admitting the mistake will get them into trouble. At the end of the day, the faster the security team is notified of a problem, the faster a cyber incident response plan can be set in motion.
This takes the spotlight away from blaming employees and treating them as the “weakest link” in the process. The perspective should be that employees don’t operate outside the security architecture but inside it.
When all is said and done, employee behaviour is shaped by the interfaces they use, the processes they follow, the workload they carry and the number of security decisions they are expected to make on a daily basis.
If employees routinely ignore security warnings, there shouldn’t be an autopilot response of starting another awareness campaign but it may be time to examine what about the environment that’s producing these warnings and how it can be improved.
Cybersecurity Equals a Behavioural Design Problem
Cybersecurity is often treated primarily as a technology problem with a human element. But the psychology of security warnings suggests that the relationship works both ways: the technology shapes human behaviour just as much as the human behaviour shapes security.
Technology, through interface design, determines what employees see, when they see it and what decisions they are asked to make. Those design choices, in turn, influence how people respond to security.
The human element comes in when:
- Habituation makes familiar warnings disappear into the background.
- Warning fatigue makes repeated security decisions feel like an unavoidable part of getting work done.
- Optimism bias makes a threat feel less relevant to the person receiving the warning.
When secure behaviour creates an immediate inconvenience and, on top of that, the benefits of acting appropriately are invisible, employees may be more inclined to prioritise their work instead of the warning.
These shouldn’t be reasons to remove human accountability but they should make enterprises recognise that employee behaviour, when it comes to cybersecurity warnings, is partly shaped by the systems surrounding it.
The strongest enterprise security environment is therefore unlikely to be the one that produces the most warnings. It’s the one that understands when technology should make the decision, when humans need to make it, and when a warning is important enough to interrupt important work.
If every warning demands immediate attention, employees eventually learn that most warnings can wait. For more insights into the technologies and behaviours shaping enterprise security, explore EM360Tech’s cybersecurity coverage.
Comments ( 0 )