<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=8635850&amp;fmt=gif">

If Your Security is “Best-In-Class”, Why Are Your Staff Using WhatsApp?

July 7, 2026

Let me start with a confession.

 

If you’re a CISO, CTO, or IT Director, and you say you have zero Shadow IT in your organisation, I probably won’t believe you. Not because you’re bad at your job, but because you’re human - and so are the people you support.

 

You’ve likely invested heavily in security. Identity controls, data protection, conditional access, monitoring, alerts. On paper, your workplace is locked down. Bulletproof, even.

 

And yet, deep down, you know sensitive conversations are happening on WhatsApp. Files are being forwarded to personal email. Someone, somewhere, is using a workaround you’d never approve; because it’s quicker, easier, or just less faff.

 

This isn’t a failure of security tooling. It’s a failure of user experience.

 

If Your Security is Best-In-Class, Why Are Your Staff Using WhatsApp

 

Shadow IT Isn’t Rebellion. It’s Feedback.

Shadow IT is often framed as a discipline problem. Users breaking the rules. Ignoring policy. Going rogue.

In reality, it’s usually a symptom.

 

When sharing a document securely becomes a multi-step process - approvals, warnings, and delays - and a personal account takes seconds, the path of least resistance usually wins. Especially at 4:55pm on a Friday.

 

That doesn’t make them reckless. It makes them human.

 

The truth is this: every unnecessary step you introduce creates friction, and friction creates risk.

 

 

The Illusion of “Unusable Security”

There’s a dangerous illusion in enterprise IT that says: if it’s locked down, it must be safe.

 

But security that people can’t or won’t use doesn’t eliminate risk. It just moves it out of sight.

 

We see this all the time. Organisations build a blanket of controls across everything, rather than focusing on what actually matters. The result is a workplace where:

 

  • Simple tasks feel clunky and slow
  • Warnings appear so often they’re ignored
  • Policies are technically correct but practically useless
  • Users find ways around the system

The irony is painful. The more restrictive the environment becomes, the more incentive there is to bypass it. That’s how “secure” workplaces end up leaking data through the least visible channels.

 

 

Security Should Wrap Around the User, Not Restrain Them

Our philosophy is simple: security should be a wrapper, not a straitjacket.

 

It shouldn’t sit on top of the Modern Workplace as a bolt-on layer that users constantly collide with. It should be woven into the experience - invisible where possible, intuitive where it isn’t.

 

When we look at a workplace environment, we don’t just ask: “Is this locked down?”

 

We also ask: “Will a tired employee actually use this the way it’s intended?”

 

That second question is where many security strategies fall down.

 

 

Protect the Crown Jewels, Not Everything Equally

Not all data is equal. Not all actions carry the same risk.

 

One of the biggest sources of low-value friction is treating every file, conversation, and workflow as if it’s mission-critical. When everything is “high risk”, users stop paying attention.

 

A more effective approach is to be deliberate:

 

  • Identify the crown jewels; genuinely sensitive data and systems
  • Apply strong, visible controls where the risk is real
  • Reduce friction everywhere else so secure behaviour is the easiest behaviour

This isn’t about lowering your risk appetite. It’s about deploying controls where they actually make a difference.

 

 

Sit With End Users. Ask Uncomfortable Questions.

One of the most valuable things an IT or security team can do is sit with users and ask a simple question:

“Where do you use workarounds, and why?”

 

The answers are rarely malicious. They’re usually practical:

 

  • “It’s faster.”
  • “I don’t know which tool I’m meant to use.”
  • “It works fine until I’m working remotely or on my mobile.”
  • “I’m not sure what’s allowed, so I just get it done.”

These conversations are gold dust. They show you exactly where friction lives; and where risk is being created unintentionally.

 

The goal isn’t to tell people off. It’s to replace unsafe shortcuts with IT-sanctioned tools that are genuinely better than the consumer alternatives.

 

 

Smarter Security, Not Less Security

Let’s be clear: this is not an argument for weakening controls. It’s an argument for designing security around real working patterns.

 

That means:

 

  • Identity and access that reflect how people collaborate, not just job titles
  • Secure sharing that feels easier than personal workarounds
  • Consistent experiences across devices and locations
  • Clear guidance that people can actually remember

When security is usable, adoption improves. When adoption improves, risk drops.

 

That’s how you stop being seen as the “Department of No”; not by saying yes to everything, but by designing environments where the right thing is also the easy thing.

 

A Better Place to Start

Building a secure workplace shouldn’t feel like building a digital prison.

It starts with understanding where friction exists today — and what that friction is really telling you about risk.

 

That’s exactly what our Cyber Assessments are designed to uncover. We help you find the workaround hotspots in your environment and replace them with secure, IT-sanctioned solutions your teams actually want to use.

 

Smarter security. Better experience. Less risk.

 

If that sounds like a conversation worth having, let’s start there.

 

Oliver Smith
About the Author

Oliver Smith
Oliver Smith is TIEVA’s Microsoft Modern Work Go-To-Market Lead. Drawing on his previous experience as a Customer Success Manager at Ingram Micro, Oliver helps clients understand how Microsoft’s modern workplace technologies can support their goals, improve collaboration and deliver lasting business value.

Email icon oliver.keeling-smith@tieva.co.uk