← Studies

Supports · 1999

Users are not the enemy

Anne Adams, Martina Angela Sasse

Key finding

Insecure password practices (e.g., writing passwords down, linking passwords) stemmed from memory overload and poorly designed policies, not user carelessness. Security departments that withheld information and treated users as a threat worsened motivation and compliance.

Why it matters

Landmark evidence that blaming users misdiagnoses the problem and that communication and design, not control, drive secure behavior.

Informs Cite
Adams, A., & Sasse, M. A. (1999). Users are not the enemy. Communications of the ACM, 42(12). https://doi.org/10.1145/322796.322806