Why a Good Security Strategy Requires More Than Just Control
Andrea Pfundmeier, Managing Director of Dropbox Germany explains why a strong security strategy for digital workflows depends on usability, secure-by-design processes, and tools employees will actually use.
©metamorworks | istockphoto.com
There’s an unspoken rule in companies: If a system makes work more complicated, people will usually find a way around it. This applies to CRM tools, document approvals, travel expense policies – and IT security is no exception. In fact, it is where the stakes are highest. Yet many companies still develop their products and security strategies as if that weren’t the case. The result: Companies invest millions in technologies that are secure on paper but are ignored or actively circumvented in everyday use. This isn’t a minor issue. It’s the central reason why security so often fails.
Security decisions are being made in the wrong place
Most security strategies and solutions are developed with a clear target audience in mind: the CISO or CTO. They impress with features, certifications, and control options. On paper, they often look excellent. But here’s the thing: the people who have to work with these systems and tools every day rarely have a say in the process. And that’s exactly where the problem lies: security isn’t what gets implemented. Security is what’s actually integrated into everyday work.
If an employee needs to take five extra steps to share a file, they will find a way to bypass those steps. If a collaboration solution is too restrictive, collaboration will migrate to external tools. And if core processes cannot be efficiently mapped, alternatives will emerge outside the intended systems.
The result is a false sense of security: formal control accompanied by growing real-world risk. At the same time, IT and security teams are left with less visibility and oversight, making it harder to meet internal governance requirements, regulatory obligations, and the security standards customers increasingly expect.
The real threat lies in everyday user behavior
When it comes to security risks, companies often think first of external threats such as ransomware, phishing, or targeted cyberattacks. While these dangers are real, they overshadow another significant vulnerability: the day-to-day use of technology within the organization. Security breaches do not always result from spectacular external attacks but can also result from seemingly innocuous decisions made in the course of daily work. For example, when a file is quickly shared via a private link, a document is copied into an external tool, or a process is handled “as an exception” outside the designated systems.
This behavior also becomes particularly risky in business-critical processes such as contract approvals or signings. When documents are exchanged via email, as locally stored PDFs, or through unofficial tools, blind spots emerge – without clear traceability, without central control, and without integrated security mechanisms.
Such actions are rarely malicious; they usually pursue a legitimate goal, namely working efficiently. This is precisely why tools that add friction fall short here. Those who pit security against productivity risk losing both in the end.
When security creates friction, risk follows
A common reflex in companies is clear: when risks rise, controls must be tightened. More rules. More approval loops, more steps to follow. More friction.
In the short term, this can increase formal security. In the long term, however, it has the opposite effect: the gap between official processes and actual behavior widens. Employees develop workarounds, set up shadow processes, and use tools outside the controlled environment. “Shadow workflows” emerge – and that is precisely where the greatest risks arise: without transparency, without governance, without control. This pattern is currently particularly evident in the context of AI. But it is by no means new. Shadow IT is becoming shadow AI – and shadow processes along core business workflows.
Security is not achieved through control, but through use
The key question today is no longer how to increase control over employees, but how to design secure products and workflows that people will actually use, without creating unnecessary friction. This is precisely why a fundamental shift in perspective is needed. Security should not be treated as a control layer added at the end of a process. It needs to be built into the design of products, processes, and ways of working from the outset.
In practice, this means one thing above all: user-friendliness becomes a security factor. Systems that are complicated, slow, or difficult to understand almost inevitably lead employees to seek out simpler alternatives – even if those alternatives are insecure. It is equally important to embed security directly into existing workflows rather than adding it as an extra step. The most effective security solution is often the one that operates in the background and is barely noticed by the user.
This principle is increasingly applicable to document-based business processes such as approvals and contract signings. Modern eSignature and workflow solutions like Dropbox Sign integrate security directly into the signing process through features such as authentication, access controls, and comprehensive audit trails. For employees, the process remains simple and intuitive, while organizations retain the visibility and control needed to support governance, compliance, and accountability. Security is therefore not experienced as an additional step, but as a natural part of the way work gets done.
From the categorical “No” to a new driver of growth
Historically, security has been perceived in many companies as an obstacle – an entity that slows down projects and minimizes risks.
In a work environment characterized by rapid decision-making, distributed teams, and digital processes, security needs to become an integral part of the operational infrastructure. That requires a different approach to product design.
Products that position security as an additional layer, rather than embedding it into the user experience from the outset, are increasingly unlikely to be adopted in fast-moving environments. When employees work around them, organizations lose visibility and control, while also risking falling short of the security and privacy standards that customers, partners, and regulators increasingly expect.
The alternative is a new understanding of security: not as a gatekeeper that sits outside the workflow, but as an enabler built directly into it. Not in the sense of less security, but of security that is seamlessly integrated into the way people work.
The decisive competitive advantage
In the coming years, a clear distinction will emerge between companies: on the one hand, organizations that try to minimize risks through control – and in doing so slow themselves down. On the other hand, there will be companies that adopt technology with security built into the way people work, enabling innovation without sacrificing governance. The difference will not lie in the technology itself, but in the understanding of security. Ultimately, it is not the most restrictive security architecture that prevails – but the one that is embedded so seamlessly into everyday work that people have no reason to work around it.
📚 Citation:
Andrea Pfundmeier. (September 2026). Why a Good Security Strategy Requires More Than Just Control. dotmagazine. https://www.dotmagazine.online/issues/security-compliance-digital-sovereignty/security-strategy-digital-workflows
Andrea Pfundmeier is Senior Group Product Manager at Dropbox and serves as Managing Director for Dropbox Germany, helping shape the company's product strategy with a particular focus on secure, collaborative B2B solutions. Before joining Dropbox, Andrea was the founder and CEO of Boxcryptor, the encryption software company she built over more than 15 years before it was acquired by Dropbox in 2022. During that time, she led the company's innovation, security, and growth strategy.
With deep expertise in IT security, enterprise software, and product leadership, Andrea is a recognized voice on the future of secure digital collaboration and AI-powered work.
FAQ
Why can strict security controls increase risk in everyday workflows?
Security controls can increase risk when they make routine tasks unnecessarily difficult, prompting employees to create workarounds or use unauthorized tools. In this dotmagazine article, Andrea Pfundmeier of Dropbox explains why effective security depends on secure processes that people will actually use; dotmagazine is published by eco – Association of the Internet Industry.
How does usability contribute to an effective security strategy?
Usability helps keep employees within approved systems and reduces the incentive to create shadow workflows. Andrea Pfundmeier of Dropbox argues in this dotmagazine article, published by eco – Association of the Internet Industry, that security is most effective when it is integrated into products and workflows rather than added as an extra step.
What are shadow workflows, and why are they a security risk?
Shadow workflows emerge when employees bypass official processes or use tools outside the controlled environment to complete their work more efficiently. In dotmagazine, published by eco – Association of the Internet Industry, Andrea Pfundmeier of Dropbox explains that these workarounds can reduce visibility, governance, and control.
How can organizations secure document approvals and contract signing without adding unnecessary friction?
Organizations can embed measures such as authentication, access controls, and audit trails directly into digital approval and signing workflows, allowing security to operate as part of the process rather than as an additional hurdle. Andrea Pfundmeier of Dropbox discusses this secure-by-design approach in her dotmagazine article, published by eco – Association of the Internet Industry.