Security controls fail for more reasons than missing technology. Sometimes the control is technically correct but so disruptive that people route around it.
Security is a system, not a checkbox
A useful control has to account for threat, likelihood, impact, user behaviour and the real workflow around the asset. That is why secure design benefits from talking to the people who actually perform the process.
Friction has a security cost
Unnecessary friction can create shadow processes: copied files, reused passwords, unofficial tools and informal exceptions. Good security does not mean removing all friction; it means putting friction where it meaningfully reduces risk.
A better question
Instead of asking only “Is this secure?”, ask: Will the secure path remain the easiest realistic path under pressure?