Gesia All articles
Business & Operations

Locked Out of Productivity: When Your Security Stack Becomes the Biggest Threat in the Room

Gesia
Locked Out of Productivity: When Your Security Stack Becomes the Biggest Threat in the Room

Let's play a quick game. Picture your average Monday morning. A sales rep sits down, opens her laptop, and needs to pull a client contract before a 9 a.m. call. She logs into her SSO portal, gets bounced to an MFA prompt, grabs her phone, approves the push notification, gets redirected to the document management system — which requires a separate login — enters those credentials, triggers another MFA challenge because she's on a new IP address, and finally lands on a screen telling her she doesn't have permission to view the file without submitting an access request.

The client call starts in four minutes.

This isn't a hypothetical. It's Tuesday for a lot of American workers right now. And the uncomfortable truth that most security vendors won't put in their pitch decks is this: the authentication overhead you've built to protect your organization may be generating more risk than it's eliminating.

The Compliance Theater Problem

There's a meaningful difference between being secure and looking secure. A lot of what passes for enterprise security today falls firmly in the second category — a performance designed to satisfy auditors, check regulatory boxes, and give leadership something reassuring to say during board meetings.

The result is what some security researchers have started calling "compliance theater": policies and tooling that create the appearance of rigorous protection without actually reducing the attack surface in any meaningful way. Mandatory 90-day password resets that lead employees to cycle through "Password1" to "Password2." MFA requirements that apply equally to the marketing intern and the database administrator with root access. VPN mandates that slow down remote workers so much that they just... stop using the VPN.

Each of these policies was probably born from a legitimate concern. But layered on top of each other, without a coherent risk model underneath, they produce a security environment that's simultaneously burdensome and porous.

MFA Fatigue Is a Real Attack Vector — And You're Creating It

Here's something worth sitting with: MFA fatigue isn't just an employee morale problem. It's an actual, documented attack technique. Bad actors will flood a target's authentication app with approval requests until the user — exhausted, distracted, or just trying to get on with their day — hits "approve" on something they shouldn't.

The Uber breach in 2022 is the case study everyone in security circles references. A contractor approved a fraudulent MFA push after being bombarded with requests. The attacker then reached out via WhatsApp pretending to be IT support, and the rest is an uncomfortable headline.

When employees are conditioned to tap "approve" dozens of times a day as a reflexive habit, you've effectively trained them to lower their guard at the exact moment it needs to be raised. More prompts don't equal more security. They equal more noise — and noise is where attackers love to hide.

The Workaround Economy

Here's where the operational cost really starts compounding. When legitimate work becomes harder than it should be, people find ways around the friction. Not because they're careless or malicious, but because they have deadlines, managers, and jobs to protect.

So the sales team starts emailing contracts to personal Gmail accounts so they can access them from their phones. The engineering lead shares credentials with a junior dev because the access request queue takes three days. The remote worker disables the VPN because it cuts their upload speed in half and they have a product demo in an hour.

Every one of these workarounds is a genuine vulnerability — arguably worse than the ones your security stack was built to prevent, because they're invisible to your monitoring tools and born directly from the friction you created. You've essentially outsourced your risk to human desperation.

Disconnected Tools Make It Worse

A lot of security stacks in mid-market and enterprise companies right now are basically a collection of point solutions that don't talk to each other. You've got an identity provider over here, a CASB over there, an endpoint detection tool that logs to a completely separate SIEM, and a compliance platform that was bolted on after the last audit panic.

The operational overhead of managing all of this is significant — but the security gap it creates is worse. When your tools aren't integrated, your visibility is fragmented. Anomalous behavior that would trigger an alert if any single system could see the full picture gets lost in the seams between platforms. Attackers increasingly understand this and deliberately operate in those blind spots.

Meanwhile, your IT team is spending half their week managing access requests, resetting locked accounts, and troubleshooting authentication failures — time that could be spent on proactive threat hunting or actually hardening the infrastructure.

What a Risk-Based Approach Actually Looks Like

The alternative isn't to throw your hands up and go password-optional. It's to apply security controls proportionally — matching the friction to the actual risk profile of the action being taken.

Accessing a shared marketing calendar? Low risk. Streamline it. Exporting your customer database to an external location? High risk. Layer on every control you've got and make the user justify it in writing.

This is the core idea behind adaptive authentication and zero-trust architecture done right: not treating every login as equally dangerous, but continuously evaluating context — who's logging in, from where, on what device, to access what — and calibrating the response accordingly. A known device, on the corporate network, accessing a low-sensitivity resource should be nearly frictionless. An unknown device, logging in from a new country, trying to access your financial systems should hit every gate you have.

Some platforms are starting to get this right. Behavioral analytics tools that establish a baseline for each user and flag deviations — without interrupting normal workflows — are a step in a smarter direction. Passwordless authentication, when implemented thoughtfully, removes the weakest link (the password) while often reducing friction compared to traditional MFA.

The Conversation You Need to Have

If you're a CTO, a CISO, or a founder who's also wearing the security hat, the question worth asking isn't "are we secure?" It's "what is our security posture actually costing us in productivity, and is that cost buying us proportional protection?"

Because here's the uncomfortable math: if your security overhead is driving employees toward shadow IT and workarounds at scale, you may be spending significant money to make yourself more vulnerable while also making your team less productive. That's not a trade-off. That's just a loss.

Smart security isn't about maximum friction. It's about friction in the right places, applied intelligently, in a way that your tools can actually enforce consistently. The goal is a workforce that doesn't have to choose between getting their job done and following the rules — because when those two things are in conflict, the job usually wins.

And the attacker on the other end of that MFA fatigue campaign is counting on exactly that.

All Articles

Related Articles

Too Many Cooks: How Approval Culture Is Quietly Neutering Your Engineering Team

Too Many Cooks: How Approval Culture Is Quietly Neutering Your Engineering Team

What Your AI Investment Is Actually Buying You (Hint: Probably Not What You Think)

What Your AI Investment Is Actually Buying You (Hint: Probably Not What You Think)

The Hidden Tax on Your Tech Stack: What Broken API Integrations Are Really Costing You