Security Fatigue
Security fatigue is the weariness that builds when security demands too many decisions — leading people to reuse passwords, dismiss warnings, and take shortcuts.
Security fatigue is the weariness and resignation people develop when security asks too much of them: too many passwords, too many warnings, too many rules that interrupt the actual job. A fatigued employee is not ignorant or careless — they are depleted. They know reusing a password is risky and do it anyway, because the alternative is one more demand on an attention budget that ran out hours ago. NIST researchers documented the phenomenon in interview studies years ago, and every security team has watched it since: beyond a certain point, each added control produces less compliance, not more.
How it works
Security decisions are costly in a currency people have little of — attention. Every rotation prompt, policy exception, warning banner, and training reminder draws from the same pool, and when the pool empties, people default to the easiest available action: pick the familiar password, click accept, skip the reporting step. Fatigue also compounds socially; when colleagues visibly treat controls as noise, treating them as noise becomes the norm. The result is a workforce that passes every compliance checkbox while drifting into exactly the behaviors — reuse, reflexive approval, unreported incidents — that attacks like credential stuffing and MFA fatigue bombing are designed to harvest. Its cousin, alert fatigue, does the same damage to the people watching the dashboards.
How to defend
Treat employee attention as a finite resource and spend it deliberately. Remove the demands that produce no security — forced password rotation and composition rules are the classic offenders, now explicitly rejected by NIST guidance — and automate what a tool can do better, starting with a password manager that takes dozens of daily credential decisions off the human entirely (our credential hygiene guide covers the rollout). Make the remaining asks few, clear, and well-timed: a security nudge at the moment of risk beats a policy document nobody rereads, and short, spaced training beats marathon sessions — the evidence is in our training frequency guide. The goal is a simple trade: fewer demands, honored more often.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo