Have you lost the count of the security policies you have written, reviewed or “inherited” over the years?
You know the type: an 80-page Information Security Policy, full of numbered sections, cross-references, and words nobody would ever say out loud. It lives in a shared folder or an intranet page. Once a year, everyone gets an email reminder: “Please confirm you have read and understood the Information Security Policy.”
Everyone scrolls to the bottom. Everyone clicks “I Agree”. Nobody changes a single thing about how they actually work.
At some point, you have to ask yourself: Are we genuinely protecting the company, or are we just writing PDFs for auditors?
Accept the uncomfortable truth: most people don’t care about your policy
Lets be blunt here, most employees don’t card about security policies. They care mostly about:
- Meeting deadlines
- Keeping their bosses happy
- Having their favorite tools available
- Getting home on time
If following security policies fits into this reality, then great! If it doesn’t, the policy loses.
You can find countless cases where there’s a document for everything: access controls, incident management, backups, encryption, remote work, etc… Each policy could be even longer than most books people read for pleasure. Even though this doesn’t happen anymore in our time.
Walk around, talk to colleagues, ask them simple questions:
- What do you do if you think you clicked on a bad link?
- Who do you call if a system goes down?
- Are you allowed to use your personal email to send work files?
- How do you request access to a new system?
More times than not, the real answers don’t match the policy at all. People describe “how we do things here”, which is often completely different from “how the policy says we do things”.
This uncovers the ugly truth: the policy is not guiding behaviour. The policy is paperwork…
How did we end up with 80-page monsters?
I don’t think anyone wakes up and says, “Let’s write something nobody will ever read.”
Most of these huge policies grow over time:
- A new regulation appears → we copy phrases into the policy
- An auditor asks for more detail → we add another section
- A new standard (ISO, NIS2, GDPR, DORA, you name it) → we bolt on more text
- A security incident happens → we patch the policy with extra lines so it “covers” that scenario
No one ever has time to remove anything. We just keep adding.
Eventually, the policy becomes this Frankenstein document, stitched together from:
- Old templates
- Legal wording
- Best practice checklists
- Things we added to “please the auditor”
And almost none of it is written in normal human language.
“But we need it for compliance”
This is the most common defense I hear.
“We know no one reads it, but the auditor wants to see it.” “We need it for ISO certification.” “The regulator expects detailed documentation.”
I get it. Compliance is real. Audits are real. Certifications can open doors with clients. But here’s the problem:
Having a policy is not the same as having control over risk.
You can have:
- A perfect-looking document
- Signed by management
- Stored in the right folder
- Version controlled, watermarked, and beautifully formatted
…and still have staff sharing passwords on WhatsApp, sensitive data sitting in personal Dropbox accounts, and contractors walking around the office with unencrypted laptops.
On paper, you’re “compliant”. In reality, you’re exposed.
I don’t believe regulators or auditors really want us to write novels. What they want is evidence that:
- Risks are understood
- Controls are in place
- People know what to do
- Things actually happen, not just get written down
Somewhere along the way, we turned that into: “Write more pages.”
Are we lying to ourselves?
There’s a deeper, slightly uncomfortable question here.
When we proudly show policies to auditors, while secretly knowing nobody reads or follows them… are we being completely honest?
We claim:
- “Employees are aware of the security policy.”
- “Processes are defined and documented.”
- “The organisation follows a risk-based approach.”
But if you walk into certain departments, the reality is:
- People share accounts because individual logins are a hassle
- Sensitive spreadsheets get emailed to external Gmail addresses
- USB sticks float around without encryption
- Incident reporting is “talk to IT if it’s really bad”
On the surface, the organisation looks mature. Underneath, it’s fragile.
I’m not saying we should throw away policies or fight auditors. Not at all. I’m saying we should stop pretending that writing more pages equals better security.
Real security is messy, human, and sometimes inconvenient. Real policies should live in that mess, not hover above it in a PDF.
Are we just writing PDFs for auditors?
Sometimes, yes.
You can catch yourself polishing wording in policies that nobody outside an audit team will ever care about. When that happens, stop and ask:
- “Will this sentence change how anyone behaves?”
- “If we removed this entire section, would anything bad actually happen?”
- “Are we spending more time writing about security than actually doing security?”
If the honest answer is “no, it won’t change anything”, then you know you are drifting back into document “theatre”.
Security policies can be powerful. They can set expectations, protect people, and give structure to how we manage risk. But only if they are:
- Readable
- Realistic
- Embedded in daily work
- Backed by training and leadership
Otherwise, they’re just long PDFs that satisfy an auditor, sit on a virtual shelf, and quietly gather digital dust. Did you get into security just to become a PDF author?
