Dropbox Germany’s Andrea Pfundmeier argues that security strategies collapse not because the technology is weak, but because employees quietly route around tools that slow them down — and calls for security to be built into everyday workflows rather than bolted on top.
There is an unwritten rule in most organizations: if a system makes work harder, employees will eventually find a way around it. According to Andrea Pfundmeier, Managing Director and Senior Group Product Manager at Dropbox, this holds true for CRM platforms, document approvals and expense policies alike — and IT security, where the stakes are highest, is no exception. In a guest contribution, she writes that many companies still design security strategies as though this dynamic did not exist, pouring millions into technology that looks secure on paper but is ignored or circumvented in daily practice.
Security decided in the wrong place
Pfundmeier contends that most security strategies are built for a single audience: the CISO or CTO. They are sold on features, certifications and controls, and often look excellent on paper. The people who use these systems every day, however, are rarely consulted — and that, she argues, is where the trouble starts: security is not what gets implemented, but what actually gets absorbed into daily work. If sharing a file requires five extra steps, employees find a shortcut; if a collaboration tool is too restrictive, work migrates to outside platforms. The result, she says, is a false sense of security — formal controls on paper, growing risk in practice — while IT and security teams lose the visibility needed to meet governance and customer expectations.
The real risk sits in everyday behavior
Companies tend to picture security threats as external: ransomware, phishing, targeted attacks. Pfundmeier does not dispute these risks, but says they obscure a quieter vulnerability — how people handle technology day to day. Gaps rarely stem from dramatic external attacks, she argues; more often they come from small decisions under time pressure, such as sharing a file through a private link or routing a process outside approved systems “just this once.” She singles out contract approvals and signatures as especially exposed: when documents move through email, local PDFs or unofficial tools, organizations lose traceability and integrated safeguards. Such shortcuts are rarely malicious — employees are usually chasing efficiency — which is exactly why tools that slow the process down become counterproductive. Pitting security against productivity, she warns, risks losing both.
More friction, more workarounds
A common corporate reflex is to tighten controls as risk rises: more rules, more approval loops, more steps. Short term, that raises formal security, Pfundmeier acknowledges. Over time, it can backfire: the gap between official process and actual behavior widens, and employees build workarounds and shadow processes. These “shadow workflows,” she says, are where the biggest risks now concentrate — without transparency or oversight. The pattern is playing out visibly around AI today, though the dynamic is not new: shadow IT becomes shadow AI.
Usability as a security feature
For Pfundmeier, the question is no longer how to tighten control over employees, but how to design secure workflows people will actually use without unnecessary friction. That means treating security not as a layer bolted onto the end of a process, but as something embedded in design from the start. Usability, in this view, becomes a security factor: complicated or slow systems push employees toward simpler — and often less secure — alternatives. She cites document-based processes such as approvals and signing, pointing to tools like Dropbox Sign, which builds authentication, access controls and audit trails directly into the signing process — simple for employees, while preserving the transparency companies need for governance and accountability. Security, in short, becomes a natural part of the workflow rather than an extra step.
From gatekeeper to growth driver
Security has historically been seen as a blocker — a function that slows projects down. Pfundmeier argues that in a world of fast decisions and digital-first processes, it instead needs to become core to operational infrastructure. Products that treat security as an added layer rather than embedding it from the outset, she predicts, will find shrinking acceptance — and when employees bypass them, companies lose oversight and risk falling short of standards customers, partners and regulators increasingly expect. Her alternative framing: security not as a guard standing outside the workflow, but as an integrated enabler — not less security, but security woven seamlessly into how people actually work.
Looking ahead, Pfundmeier expects a widening split between companies that try to minimize risk through control, slowing themselves down, and those that embed security into workflows in ways that enable innovation without undermining leadership. The deciding factor, she says, will not be the technology itself but how organizations understand security: not the most restrictive architecture wins, but the one so seamlessly integrated into daily work that there is no reason to circumvent it.
About the author: Andrea Pfundmeier is Senior Group Product Manager at Dropbox and Managing Director of Dropbox Germany, shaping product strategy with a focus on secure, collaborative B2B solutions. Before Dropbox, she founded and led Boxcryptor, an encryption software company built over 15-plus years before its 2022 acquisition by Dropbox, where she directed innovation, security and growth strategy. She is a recognized expert on IT security, enterprise software and secure digital collaboration.

Dr. Jakob Jung is Editor-in-Chief of Security Storage and Channel Germany. He has been working in IT journalism for more than 20 years. His career includes Computer Reseller News, Heise Resale, Informationweek, Techtarget (storage and data center) and ChannelBiz. He also freelances for numerous IT publications, including Computerwoche, Channelpartner, IT-Business, Storage-Insider and ZDnet. His main topics are channel, storage, security, data center, ERP and CRM.
Contact via Mail: jakob.jung@security-storage-und-channel-germany.de
