Author: Braulio Holguin
On a quiet Tuesday morning, a global manufacturing company discovered something unsettling. A single user account had been transferring gigabytes of data to an external server at 3:17 a.m. There were no malware alerts, no privilege escalation warnings, and no red flags from the intrusion detection system. Just a steady stream of intellectual property slipping away.
The company had monitoring tools, but they were configured unevenly. Some departments were watched closely, others barely at all. Policies were vague. Employees were confused. When leadership asked whether the monitoring was ethical, defensible, and aligned with frameworks like NIST 800 53 or ISO 27001, the security team hesitated. They could not confidently say yes.
This is the moment many organizations face. They need visibility to protect their systems, yet they also need trust to protect their culture. The question is not whether monitoring should exist. The real question is how to design monitoring that strengthens security without weakening the relationship between an organization and its people.
The answer begins with understanding the boundary between security and surveillance.
Where Security Ends and Surveillance Begins

A helpful analogy is airport security. People accept bag scans because they understand the purpose, the scope, and the limits. If airport staff began reading personal journals or tracking passengers outside the airport, trust would collapse instantly. Workplace monitoring follows the same logic.
A financial services company once debated deploying keystroke logging to detect insider threats. The security team argued it would help catch data exfiltration. HR warned it would destroy trust. Legal raised concerns about state privacy laws. When the idea was mapped to NIST 800 53 controls, specifically AU 2, AU 6, and AC 6, the team realized keystroke logging was not required to meet any control objective. Network monitoring and access logging already addressed the risk. The proposal was dropped.
The lesson was simple. If a monitoring activity cannot be tied to a specific control requirement or risk scenario, it is surveillance, not security.
Transparency: The Foundation of Trust
Transparency is the first principle of ethical monitoring. According to Gartner, organizations that communicate monitoring practices clearly see trust scores rise by about 30 percent compared to those that do not. This statistic comes from the Gartner Workplace Trust Survey published in 2023.
Transparency is not a vague statement like “We monitor for security.” It is a clear explanation of what data is collected, why it is collected, how long it is retained, who can access it, and when it may be escalated.
A global retailer learned this the hard way. They deployed a new analytics tool without explaining it. Employees assumed the company was reading their messages. Trust scores dropped. Productivity dipped. Only after publishing a detailed monitoring policy and hosting open Q&A sessions did trust recover.
Transparency is not a courtesy. It is a control.
Necessity: Collect Only What You Need
The second principle is necessity. ISO 27001 emphasizes data minimization in controls such as A.5.1 and A.8.2. Necessity means every monitoring capability must map to a defined risk.
A healthcare organization once collected full packet captures simply because the tool allowed it. After a privacy impact assessment, they discovered that most of the captured data was irrelevant. Storage costs were rising. Sensitive patient information was being retained unnecessarily. They shifted to metadata-only monitoring and reduced storage costs by 40 percent while maintaining detection effectiveness.
Necessity protects both systems and people.
Proportionality: Match the Tool to the Threat
Proportionality asks whether the intrusiveness of a monitoring measure is justified by the severity of the risk it addresses.
Monitoring aggregated network anomalies is proportionate to everyday security operations. Recording employees’ screens is proportionate only during an active investigation.

Proportionality is not about limiting security. It is about choosing the right tool for the right threat.
Governance: The Guardrails That Prevent Surveillance Creep
Monitoring tools tend to expand over time. This pattern is often called surveillance creep. Strong governance prevents it.
Effective organizations use written monitoring policies, defined retention limits, access controls for monitoring data, and annual privacy impact assessments. They also ensure oversight is not limited to the security team. NIST 800 53 controls PL 2 and AR 4 emphasize that monitoring must be governed, reviewed, and justified.
One multinational company implemented quarterly monitoring reviews. Within a year, they reduced unnecessary data collection by 27 percent and improved compliance audit outcomes.
Governance is the difference between ethical monitoring and accidental surveillance.
Culture and Law: Why One Size Never Fits All
Monitoring expectations vary globally. In the European Union, GDPR requires strict justification for employee monitoring and often explicit consent. In the United States, monitoring is more permissible but still governed by state privacy laws. In parts of Asia, monitoring is culturally expected as part of workplace security.
A global organization once tried to deploy a uniform monitoring policy across fourteen countries. It failed. Employees in Germany objected. Employees in Singapore did not. Legal teams scrambled. The company eventually adopted a regional model aligned with local laws and cultural expectations. Trust improved and compliance strengthened.
Monitoring is not just technical. It is cultural.
A Practical Model for Ethical Monitoring

They communicate everything. They review quarterly. They retire unnecessary monitoring. They update risk scenarios. This model aligns with NIST, ISO, SOC 2, and global privacy expectations. It protects systems without sacrificing trust.
The Human Side of Security
Research from the University of British Columbia found that intensive monitoring increases stress and reduces trust, which leads to lower productivity and higher turnover. This study was published in 2022 and examined the relationship between workplace surveillance and employee well-being.
Security is not just about preventing breaches. It is about creating an environment where people feel respected, protected, and valued. Bruce Schneier captured this idea well when he wrote, “Security is not a product. It is a process.” This quote appears in his book Secrets and Lies published in 2000.
Ethical monitoring is part of that process.
The Take Away
Monitoring is essential, but surveillance is harmful. Ethical monitoring is built on transparency, necessity, and proportionality. Control frameworks provide structure and guardrails. Strong governance prevents surveillance creep. Cultural and legal context matter as much as technology. Ethical monitoring improves trust, reduces risk, and strengthens compliance.
When organizations get this right, they protect both their systems and their people. And that is the kind of security culture leaders want to build.


