Security Fatigue: What It Is and Why More Training Backfires
Security fatigue explained: the NIST-documented exhaustion behind risky clicks, MFA approvals, and password reuse, and how to actually reduce it.
Security fatigue explained: the NIST-documented exhaustion behind risky clicks, MFA approvals, and password reuse, and how to actually reduce it.
Security fatigue is the mental exhaustion and growing indifference employees feel after repeated exposure to security demands: password resets, MFA prompts, phishing warnings, and mandatory training. First documented by researchers at the National Institute of Standards and Technology (NIST) in 2016, it explains why well-trained employees still click, reuse passwords, and approve requests they shouldn’t, not from ignorance, but from depletion.
Table of Contents
ToggleNIST researchers Brian Stanton and Mary Theofanos weren’t looking for fatigue when they interviewed 40 computer users about their security habits and beliefs in 2016. It showed up anyway, consistently, across nearly every interview. Their study defined security fatigue as a weariness or reluctance to deal with computer security, and found it drove people toward the path of least resistance: reusing an old password because it’s easier to remember, dismissing a certificate warning without reading it, or deciding a decision isn’t worth the mental effort it demands.
Theofanos later summarized the underlying shift in plain terms: security used to mean remembering one password at work. Now employees are expected to manage dozens of passwords, MFA prompts, and security decisions across every tool they touch, with no corresponding reduction in how much attention each one demands.
Security fatigue isn’t laziness. It’s a predictable response to cognitive overload, and it shows up in a few recognizable patterns:
A concrete, well-documented example of security fatigue being weaponized directly is the MFA fatigue attack: an attacker who already has a stolen password sends repeated MFA push notifications until an exhausted employee approves one just to make the prompts stop. The 2022 Uber breach followed exactly this pattern. The attacker didn’t need to break MFA. They needed an employee tired enough to tap “approve.”
Discover how Threatcop protects your workforce from modern cyber threats.
The instinctive response to a security failure is often more training, more warnings, more reminders. Against security fatigue, that instinct backfires. Adding more security decisions to an already-overloaded employee doesn’t build resilience; it accelerates the exhaustion that caused the problem in the first place.
NIST’s own researchers proposed three design principles instead of more volume:
This is also why role-based security awareness training tends to outperform one-size-fits-all annual modules: it cuts the volume of irrelevant decisions a given employee has to process, rather than adding another generic layer on top of what’s already overwhelming them. Programs built on strong security awareness training fundamentals apply the same logic at the platform level, sequencing content instead of dumping it all at once.
There’s a direct link between security fatigue and how an organization responds when someone makes a mistake. Insider incidents are rarely malicious; far more often they’re a tired, overloaded employee who made a reasonable-sounding call and got it wrong. An employee who fears blame for reporting a mistake late learns to avoid reporting altogether, which is learned helplessness with an audience.
Organizations that treat a reported near-miss as useful data, not a disciplinary event, get two things in return: earlier warning when something does go wrong, and a workforce that hasn’t concluded that staying quiet is safer than raising a hand. That shift costs nothing to implement and directly counters the “why bother” resignation NIST’s research identified as security fatigue’s most damaging symptom.
A few concrete changes lower the cognitive load without lowering the bar:
Nearly a decade after NIST first named it, security fatigue remains one of the most underestimated risks inside organizations, precisely because it looks like carelessness from the outside and feels like exhaustion from the inside. Treating every lapse as a training gap misses what the research actually found: the fix is reducing unnecessary friction and decision load, not adding more of both.
Programs that measure human risk rather than just tracking training completion are better positioned to catch fatigue before it shows up as a breach, because the warning signs (declining report rates, rising dismissal of warnings, growing password reuse) are visible well before the incident is.
Security fatigue is the mental exhaustion and growing indifference employees develop after repeated exposure to security demands like password rules, MFA prompts, and warnings, first documented by NIST researchers in a 2016 study of everyday computer users.
NIST’s research identifies decision fatigue from too many security choices, desensitization from repeated warnings that often turn out to be false alarms, and learned helplessness after employees conclude their caution doesn’t change outcomes.
Alert fatigue specifically describes desensitization to security warnings and pop-ups. Security fatigue is the broader condition, including alert fatigue alongside password fatigue, MFA fatigue, and general weariness toward security decisions of any kind.
An MFA fatigue attack, also called MFA bombing, is when an attacker who already has a stolen password sends repeated multi-factor authentication push notifications until an exhausted employee approves one just to stop the prompts, as happened in the 2022 Uber breach.
Not automatically, and it can worsen it. NIST’s research points toward reducing the number of security decisions employees face and making the right action the easiest one, rather than simply adding more training volume on top of an already-overloaded workforce.
Dinesh Varma is the Director of Business Growth & Strategy, MEA at Threatcop, with experience in cybersecurity consulting, business strategy, account management, and growth. He focuses on helping organizations understand evolving cyber threats and strengthen their security posture. His areas of interest include cybersecurity awareness, human risk management, phishing, social engineering, email security, and People Security Management, with a focus on building stronger organizational resilience against emerging threats.
Dinesh Varma is the Director of Business Growth & Strategy, MEA at Threatcop, with experience in cybersecurity consulting, business strategy, account management, and growth. He focuses on helping organizations understand evolving cyber threats and strengthen their security posture. His areas of interest include cybersecurity awareness, human risk management, phishing, social engineering, email security, and People Security Management, with a focus on building stronger organizational resilience against emerging threats.
Vibe coding security risks explained: 7 real threats, why AI-generated code fails on security, and a checklist to catch...
What is OSINT in cyber security: how attackers use public social media data to research and target employees, and...
Average time to detect a data breach: 241 days per IBM 2025 data, versus the 60 seconds it takes...
Table of Contents
×