Skip to content
As Written, As Enforced

Home / When broken

The Workaround, Which Is Most of Them

The largest category of policy breach by a wide margin, and the one where treating it as misconduct guarantees a repeat.

When broken · Analysis

Use of approved systems

Never enforced

As written

Company information must be processed only using approved systems and routes.

What happens

Breached whenever the approved route fails, which is often enough that nobody treats the clause as binding.

Not enforced, because enforcing it would require fixing the routes first and nobody has connected those two things.

The operative rule is: get it done, do not spend money, do not use customer data.

Most substantiated breaches are somebody working around something broken. Recognising the pattern changes both the response and the remedy.

The boundary discussed in “The Workaround, Which Is Most of Them” is also a practical test for workforce technology. Teams researching this workplace technology guide for employee monitoring data security should choose the least intrusive settings, explain when collection begins and ends, and keep personal or out-of-hours activity outside the programme unless a specific, disclosed need has been approved.

What it looks like

A file sent to a personal address because the transfer limit is smaller than the file.

For a separate benchmark relevant to “The Workaround, Which Is Most of Them”, consult the SCCE compliance resources. Use it to test purpose, notice, permissions, retention and response procedures against the proposed operating model rather than treating a generic checklist as proof that the rule works.

A login shared because one person has the access and they are on leave.

A tool installed because the approved one cannot open the format a client sent.

A spreadsheet exported because the system cannot produce the report somebody above asked for this morning.

Each produces a clear policy breach and each is somebody solving a problem the organisation created.

How to tell quickly

Ask what they were trying to achieve.

Somebody working around a broken process answers immediately, specifically, and usually with visible irritation about the process. The answer is checkable within the hour.

Somebody doing something else does not have that answer ready.

Why treating it as misconduct fails

The behaviour continues, because the underlying problem is unchanged and the work still has to be done.

What changes is that nobody mentions it. The next workaround is invisible, and the organisation has traded a known problem for an unknown one.

What the breach is actually reporting

A defect: a limit set too low, a licence not bought, a permission process too slow, a report the system cannot produce.

An organisation that closes the case has discarded the finding. One that routes it to whoever owns the process has converted a policy matter into an operational repair and removed the cause.

Most policy owners have no route for doing that, which is why the same workaround generates the same breach every month.

The response that works

Address the behaviour where it needs addressing — credential sharing is a real risk whatever the motive, and the person should be told so.

And fix the thing, with a date and an owner.

Doing only the first guarantees a repeat. Doing only the second tells everybody the rule is optional.

The count worth keeping

Breaches closed as workarounds, by cause, per quarter.

It is the most useful output the policy produces, it goes to operations rather than to HR, and it is the figure that justifies the policy owner's existence to people who otherwise regard the document as overhead.

One question, thirty seconds

What were you trying to achieve. Somebody working around a broken process answers immediately and specifically; the answer is checkable within the hour and ends most cases.

Doing both halves

Fixing the process without addressing the behaviour tells everybody the rule is optional. Addressing the behaviour without fixing the process guarantees a repeat. Neither alone is a response.

What the breach is reporting

A defect: a limit set too low, a licence not bought, a permission process too slow, a report the system cannot produce. Closing the case discards the finding.

How to tell within the hour

Ask what they were trying to achieve. The answer is immediate, specific, usually irritated about the process, and checkable. Somebody doing something else does not have it ready.

What the quarterly count is for

Breaches closed as workarounds, by cause. It goes to operations rather than to HR, it identifies the processes that are generating the rule-breaking, and it is the output that justifies the policy owner's existence to people who regard the document as overhead.

Most owners have no route for producing it, which means the same workaround generates the same breach every month and nobody connects the instances.