The shortcut becomes the norm long before the incident

Césped de un parque de oficinas atravesado en diagonal por un sendero de tierra pisada que la gente abrió a fuerza de caminarlo, con la vereda de baldosas intacta a un costado, bajo la luz cálida del atardecer

The shortcut becomes the norm long before the incident

The shortcut becomes the norm long before the incident

In 2021, a social psychology research team put one of the most cited findings on social norms back to the test, across two preregistered field experiments and one online experiment, with 1,798 participants in total. It confirmed the simplest thing. People litter less in a clean place than in one already covered in trash.

Nobody read a sign. What moved the decision was the state of the place, which quietly indicated what most people did there. Something similar happens with an unsafe practice that repeats inside an organization. Long before that practice shows up in an incident report, it has already worked for months as the way things get done, and that way is learned by watching what everyone else does rather than by reading the policy.

When the incident arrives, the usual reaction points at whoever was holding it that day. The sanction lands on the last link of a practice the organization had been producing, and leaves what produced it untouched. In human risk in cybersecurity I argued why that risk is systemic. What interests me here is what happens in the group, a level that reading case by case never reaches.

Why does an unsafe practice stop looking that way?

When unsafe behaviour repeats without visible consequences, it changes how the risk is perceived and makes the deviation look acceptable.

The best documented case is the Challenger shuttle, which broke apart shortly after lift-off in January 1986. The problem that destroyed it was no surprise. The seals joining the rocket segments had been taking damage flight after flight, and the engineering team had warned that below 53 degrees Fahrenheit the seal was not reliable. On the day of the launch it was 36.

Sociologist Diane Vaughan reconstructed that decision in The Challenger Launch Decision, published in 1996, and showed that nobody had overridden an alarm that was going off. Each time the damage was repaired and the shuttle came back whole, the problem sat a little closer to tolerable, until the agency ended up treating it as an acceptable risk. What shifted in that process was the standard the organization used to measure risk. Vaughan called that shift normalization of deviance, and made clear that it does not consist of an accumulation of breaches, because what sustains it is production pressure, poor communication and workplace culture.

Inside an organization it looks like this. Nobody decided the shortcut was fine. It repeated once a week for a year with nothing happening, and every repetition made the risk it carried a little less visible, until the reference for judging it stopped being the written procedure and became whatever was done last month.

What does a new hire learn in their first two weeks?

They learn by watching, and they learn fast. Before onboarding is over they already know what actually gets done in their team in three concrete situations:

  1. Whether the urgent request coming from the sales floor gets verified through another channel or gets executed so as not to hold anything up.
  2. Whether the shared credential is read out loud in front of the whole team or someone asks for one of their own.
  3. Whether the person who asks “is this normal here?” gets an answer or a look of irritation.

None of that is in the document they signed on day one, and yet it is what they will do. What they learned has a name in research on social norms.

Robert Cialdini, Carl Kallgren and Raymond Reno separated, in a review of their own research programme, two meanings of the word norm that until then were used interchangeably. The injunctive norm is what is expected of us, what the group approves or disapproves of. The descriptive norm is what people actually do, with nobody authorising it. They called them the norms of ought and the norms of is.

Their conclusion is that both operate, and that in any given decision the one in focus at that moment is the one that guides it. That is where policy is at a disadvantage, because it lives in a document and you have to go looking for it. The descriptive norm needs no looking for, since it is on display every day.

The curious part is that this norm almost never has private support. Each person who thinks the team’s shortcut is wrong assumes everyone else is fine with it, and settles into the silence. Social psychology calls it pluralistic ignorance, believing yourself the lone critic inside a group that in fact thinks the same, because we read the visible behaviour of everyone around us rather than the opinions nobody says out loud. Deborah Prentice and Dale Miller documented it in 1993, and recorded something more uncomfortable. Over time, private attitudes can drift toward the position each person mistakenly attributes to the group.

Why doesn’t the sanction move the norm that produced the case?

The sanction acts on one episode, and takes that episode out of circulation. The norm rests on something else, on the practice the team keeps seeing, and the sanction never touches that practice.

The first thing the sanction takes away is the report, and I have already written about the concealment a punitive culture trains. What the collective layer adds is a second effect, on the descriptive norm. The team reads the punished episode as proof that the practice still works until someone sees it, and that message speaks to the risk of getting caught far more than to the practice itself.

So the sanction does not merely leave the existing norm untouched. It also manufactures a new one, silent, about what is worth reporting and what is better solved without a trace.

None of this makes every case equivalent or leaves the organization without a response. An honest slip, a sustained negligence and a deliberate act call for different interventions, and in another article I set out what fits each type. What none of the three resolves is this. A practice that became the team’s norm does not get corrected case by case, because its cause is not there.

Why can a campaign make the problem it addresses worse?

A message carries a descriptive norm of its own, and sometimes that norm contradicts what the message asks for.

To show it, Cialdini used the most remembered anti-litter ad on American television. A man paddles a canoe up a river carrying industrial waste, comes ashore beside a highway and watches someone throw a bag of garbage from a moving car, splitting open on the asphalt. The camera pans slowly up to his face and a tear appears.

The ad asks people not to litter, and that is an injunctive norm. But to ask it, it shows an entire country littered, and that image conveys something else, that littering is what people do. That is a descriptive norm. In his experiments people littered more precisely where there was already litter, even though nobody approves of littering.

The corporate version is the campaign that opens with the percentage of people who clicked on the last simulation. The number reports a result and at the same time signals that clicking is what happens here.

The practical consequence is that the portrait of the problem cannot be the centre of the message. If justifying the campaign takes putting on display how many people fail, then the campaign may be teaching people to fail.

Three decisions that move a norm

None of the three runs through the case.

The first is making the safe behaviour the visible one. Communicating how many people reported the email, naming the team rather than the person, produces a descriptive norm in your favour with the same effort it takes to produce the opposite one.

The second is making the practice visible without exposing whoever was holding it. The deviation gets named, the person does not. A team can discuss with reasonable honesty that verification of urgent payments gets skipped whenever the request lands after six in the evening, and that is the level at which the norm can be touched.

The third is lowering the cost of saying it out loud, which is the only thing that breaks pluralistic ignorance. When the person who asks gets an answer, everyone else discovers they were not the only one who felt uncomfortable, and the norm loses the imagined backing that held it up.

At SMARTFENSE we work on that plane with two pieces of the programme. Teachable moments step in right after the action and without a punitive tone, so the episode stays as information rather than as a file. And the report button makes flagging faster than sitting with the doubt, which starts producing the number that is actually worth showing the team. The platform also lets you design the campaign around that reading instead of repeating the reminder that no longer describes anything.

Policy says what the organization approves of. The norm says what the organization lets you see. A programme moves the second, and only then does the first begin to describe something that happens.

Tatiana Stacul

Psicóloga cognitivo-conductual enfocada en comportamiento humano en entornos digitales: estudia cómo la atención, la carga cognitiva y la respuesta emocional al riesgo condicionan la toma de decisiones frente a la pantalla. Colabora con SMARTFENSE en el diseño de contenidos de concienciación en ciberseguridad y divulga sobre ciberpsicología y bienestar digital en Código Calma. Forma parte de Women4Cyber Sweden y Cibervoluntarios.

Leave a Reply