Nobody files a ticket that says “logging in took ninety seconds instead of ten.” They just sigh and get on with it. That is why tech friction is invisible on every report you look at, and also why it is probably one of the largest recurring costs in your business. It does not show up as a line item. It shows up as everything taking slightly longer than it should, all day, for everyone.

We call it a productivity tax because that is how it behaves. A small percentage skimmed off every task, collected automatically, paid by your most experienced people as often as your newest ones. Unlike an actual tax, this one is optional. Most of it comes from a handful of fixable causes, and the fixes mostly involve removing steps rather than adding tools.

Where the Friction Actually Hides

When we walk through a small business and watch people work, the same five things come up almost every time:

  • Logging in over and over. Separate credentials for email, accounting, payroll, the scheduling tool, the customer database, and the vendor portal. Each one has its own rules and its own expiration date. Nobody planned this. It accumulated one purchase at a time.
  • Remote access gymnastics. Connect to the VPN, which is the encrypted tunnel used to reach the office network, wait for it, get dropped, reconnect, then find that the thing you needed is in a cloud app that never required the VPN.
  • Files nobody can find. Three storage locations, two naming conventions, and one person who knows where the current version lives. When that person is on vacation, work stops or gets redone.
  • Approval chains built for a company you no longer are. A purchase process designed for forty employees, still in place at twelve, requiring signatures from people who never say no.
  • Printers and scanners. Yes, still. The device that works from one desk and not another eats real minutes and generates real tickets.

Notice what these have in common. None of them are broken, exactly. Everything technically works, which is precisely why nobody escalates it and why it persists for years.

How to Audit It Without Buying Anything

You do not need a consultant to find your friction. You need to ask your staff a better question than “is everything working?” Everything is always working. Ask these instead, and write down the answers verbatim:

  1. What part of your day makes you sigh? People answer this honestly because it is about feeling, not about blame. The sigh is a reliable indicator.
  2. What have you built a workaround for? Every workaround is a map to a broken process. The sticky note, the spreadsheet, the personal cloud account. Ask without judgment or you will not hear the truth.
  3. What do you avoid doing because it is a hassle? This is the expensive one. Avoided work does not disappear. It piles up somewhere with interest.
  4. If I could fix one computer thing tomorrow, what is it? Ask everyone. When three people name the same thing independently, you have found your first project.

In a 2023 NIST article on common cybersecurity pitfalls, computer scientist Julie Haney notes that time pressured users become vulnerabilities when systems are overly complex, and recommends surveys, focus groups, and help desk analytics to reveal user pain points. Your version of help desk analytics is a notebook and five conversations.

Why Fewer Passwords Pays Back Faster Than Anything Else

Password friction is the biggest single source of daily drag in most small businesses. In a 2016 NIST study on security fatigue published in IEEE’s IT Professional, researcher Mary Theofanos observed that where people once had one password to keep up with at work, they are now asked to remember 25 or 30. That study defined security fatigue as weariness or reluctance to engage with security measures, and found it leads people to avoid decisions, choose the easiest available option, act impulsively, and reuse passwords.

Two changes attack this directly. The first is single sign-on, where staff log in once and that identity carries them into the other business applications instead of each one demanding a separate password. CISA released guidance in 2024 on single sign-on adoption for small and medium-sized businesses specifically to address how it can improve an SMB’s level of security. It also urged software manufacturers to consider how their business practices may inadvertently reduce the security posture of their customers, a polite reference to vendors charging extra for the secure option.

The second is a password manager, which stores and fills credentials so that people remember one strong password rather than thirty weak variations. Do the arithmetic for your own shop. Count the logins a typical employee performs in a day, estimate the seconds each one costs including failed attempts and resets, and multiply by your headcount and your working days. Most owners who run that calculation stop asking whether the software is worth the per user fee. This is the same logic we applied when we argued that saving time outranks saving money.

Some Rules Cost You Time and Buy Nothing

A fair amount of the friction in small businesses comes from password rules everyone assumes are required, which the standards body itself no longer recommends. In its Digital Identity Guidelines, Special Publication 800-63B, NIST states that verifiers shall not require subscribers to change passwords periodically, and shall not impose composition rules such as requiring mixtures of different character types. It also states that verifiers shall allow the use of password managers and autofill. Length is what carries the weight: NIST requires a minimum of 15 characters for a password used as a single factor.

Read that list against your own environment. If you force a change every 90 days and demand a capital letter, a number, and a symbol, you are collecting a productivity tax that current federal guidance says you should stop collecting. You are also, predictably, generating a workforce of passwords ending in an exclamation point and a number that increments quarterly.

Fix It in This Order

  1. Remove the rules that current guidance no longer supports. Free, fast, and immediately popular.
  2. Deploy a password manager and set it up for people. Do not just buy licenses and send a link. Sit with each person for ten minutes. Adoption is the entire value.
  3. Consolidate logins where single sign-on is available. Start with the applications people open every single day.
  4. Kill the VPN requirement for things that do not need it. If an application is in the cloud and properly secured, routing people through a tunnel adds steps without adding protection.
  5. Pick one file location and move everything there. Painful for a week, permanent afterward.
  6. Re-examine approvals. If a step has never produced a rejection, it is theater. Remove it or lower the threshold.

Friction is also the leading cause of shadow IT, the unapproved tools staff adopt on their own. People do not go around the system to be difficult. They go around it because the official path is slow and they have work to finish.

The Bottom Line

Friction is a cost you are already paying, silently, in the currency of your team’s attention. Ask five people what makes them sigh, remove the password rules that current federal guidance says are unnecessary, get everyone on a password manager, and consolidate logins where you can. The pleasant surprise is that the convenient version is usually the more secure version too, because security that fits into the workday actually gets followed.

If you would like an outside set of eyes on where your team is losing time, we do this walkthrough regularly for businesses across Denton County and will tell you plainly what to fix first. Contact us today.


Sources:

Comments are closed

This website uses cookies and asks your personal data to enhance your browsing experience. We are committed to protecting your privacy and ensuring your data is handled in compliance with the General Data Protection Regulation (GDPR).