Retrieving Dossier…
Abdul Wahab
September 2026 Information Security 5 min read

The quiet information-security problem nobody puts in the policy memo

Formal security frameworks tend to describe systems. The actual risk usually lives in the informal workarounds staff build around them.

#Information Security #Public Sector #Data Governance

When senior leadership reviews an information security baseline, they see architecture diagrams, identity management policies, and encryption tiers. Everything is rationalized into controls.

Yet when you sit inside an operational branch handling sensitive taxpayer records or protected intelligence, the real threat vectors rarely look like brute-force intrusions. They look like informal workarounds invented by well-intentioned staff trying to meet statutory performance deadlines.

The friction of security controls

Security controls that introduce high friction without understanding operational workflows inevitably generate underground procedures. When transferring an encrypted file between secure enclaves takes forty minutes due to multi-hop authentication gates, officers find ways to summarize or re-key information into less restrictive zones.

Security policy that ignores administrative friction is an unfunded mandate for non-compliance.

Information hygiene as administrative practice

Addressing this gap requires moving beyond compliance audits toward ethnographic workflow analysis. Information security in the public sector cannot merely be an IT governance checklist; it must be taught as an organic craft of administrative justice.

In my doctoral investigations, I study how institutional memory and local peer training mitigate security decay far more effectively than punitive compliance sanctions.

By Roby A. Wahab • UWM SOIS & CRA Appeals