A senior information security leader rewrote his organization’s policies using a different approach to language and structure. Within a few months, policies were reduced to two pages, approvals accelerated, and employees became more willing to come forward and ask for help.
What changed
He made a deliberate shift in how policies were written and structured:
-
replaced command-and-control wording with clear, declarative language
-
separated policy from procedure, removing operational detail from policy documents
-
reframed policies as communication tools rather than instruments of control
What happened
Within a few months, several changes in organizational behaviour became evident:
-
policies were reduced to two pages
-
approvals were obtained more quickly, with minimal legal revision
-
resistance to policy decreased
-
employees became more willing to come forward and report issues
As one example, legal review—previously a potential bottleneck—became straightforward. In the case of his principle policy, the legal team returned it for only a single round of revisions. “Legal sent it back once… and that was it… it was done.”
More notably, employees began to say: “I may have made a mistake. Can you come and help me?”
What this shows
The most significant outcome was not procedural but relational.
The shift in policy language altered how employees responded—not just to the policies themselves, but to the people responsible for them. As the tone of the policies changed, the security function began to be seen less as an enforcer and more as a partner.
That kind of change is a strong signal that the relationship between management and employees is becoming more collaborative.
Download the case report
This two-page case report outlines the approach taken and the outcomes observed in a real organizational setting.
It provides a practical example of how changes in policy wording and structure can influence behaviour, accelerate approval, and reduce resistance.