There was a time when the security manager's problem was getting people's attention. Today, the problem may be having too much of it.

Every week brings another reason to be concerned. A new vulnerability. A phishing campaign. A regulatory change. A third-party incident. An AI risk. An insider threat. A new privacy requirement. A warning about deepfakes. Another mandatory training module.

Security has become almost impossible to escape, and that creates an uncomfortable paradox: the more we tell people that everything is a security issue, the harder it becomes for them to recognise what is actually important.

This is not simply "security fatigue"; at its core, it is an attention problem.

Human beings have a limited capacity to evaluate warnings, make decisions and remain vigilant. For security leaders, this means that security consciousness cannot simply be measured by how much security people are expected to process. The volume of warnings, policies, training, controls and decisions can itself become a problem when people are expected to remain equally attentive to all of them.

When Everything Is Important, Nothing Is

That is where security leadership starts to look less like policing and more like executive leadership.

A good CEO does not tell the organisation that every opportunity deserves maximum investment; they allocate scarce resources. Security leaders should do the same with attention.

Imagine an employee receiving:

  • a suspicious-email warning,
  • a mandatory security training,
  • an MFA prompt,
  • an AI-use policy,
  • a privacy notice,
  • a third-party risk questionnaire,
  • a new password rule,
  • and a dozen other “important” security messages.

This goes beyond a communications problem; it becomes a security problem.

Research on security fatigue, including work by NIST, has found that repeated security demands can lead to a loss of control, fatalism, risk minimisation and decision avoidance. The practical lesson is strikingly simple: reduce the number of security decisions people have to make and make the correct action easier.

A security control has a cost even when it costs no money. It consumes someone's time, interrupts someone's workflow, and creates another thing they have to remember. And, most importantly, it competes with every other thing demanding their attention.

That means security has an overlooked form of technical debt: attention debt.

Each approval, warning, exception, popup, policy and manual check adds to it. Eventually people find ways around the system, not because they are careless, but because the system has made secure behaviour psychologically expensive.

When Security Becomes Background Noise

That is where social engineers have an advantage: they only need to create one convincing moment of urgency. The organisation, meanwhile, may have trained its employees to respond to a constant stream of security demands: “Your account will be disabled.” “Respond immediately.” “Security alert.”

When everything sounds urgent, urgency itself loses its power.