Supports · 1999
Users are not the enemy
Anne Adams, Martina Angela Sasse
Key finding
Insecure password practices (e.g., writing passwords down, linking passwords) stemmed from memory overload and poorly designed policies, not user carelessness. Security departments that withheld information and treated users as a threat worsened motivation and compliance.
Why it mattersLandmark evidence that blaming users misdiagnoses the problem and that communication and design, not control, drive secure behavior.
Informs CiteAdams, A., & Sasse, M. A. (1999). Users are not the enemy. Communications of the ACM, 42(12). https://doi.org/10.1145/322796.322806