Author: Braulio Holguin

On a quiet Tuesday morning, a global manufacturing company discovered something unsettling. A single user account had been transferring gigabytes of data to an external server at 3:17 a.m. There were no malware alerts, no privilege escalation warnings, and no red flags from the intrusion detection system. Just a steady stream of intellectual property slipping away.

The company had monitoring tools, but they were configured unevenly. Some departments were watched closely, others barely at all. Policies were vague. Employees were confused. When leadership asked whether the monitoring was ethical, defensible, and aligned with frameworks like NIST 800 53 or ISO 27001, the security team hesitated. They could not confidently say yes.

This is the moment many organizations face. They need visibility to protect their systems, yet they also need trust to protect their culture. The question is not whether monitoring should exist. The real question is how to design monitoring that strengthens security without weakening the relationship between an organization and its people.

The answer begins with understanding the boundary between security and surveillance.

Where Security Ends and Surveillance Begins

Surveillance TextSecurity monitoring is essential. Surveillance is harmful. The line between them is not drawn by technology. It is drawn by choices.

A helpful analogy is airport security. People accept bag scans because they understand the purpose, the scope, and the limits. If airport staff began reading personal journals or tracking passengers outside the airport, trust would collapse instantly. Workplace monitoring follows the same logic.

A financial services company once debated deploying keystroke logging to detect insider threats. The security team argued it would help catch data exfiltration. HR warned it would destroy trust. Legal raised concerns about state privacy laws. When the idea was mapped to NIST 800 53 controls, specifically AU 2, AU 6, and AC 6, the team realized keystroke logging was not required to meet any control objective. Network monitoring and access logging already addressed the risk. The proposal was dropped.

The lesson was simple. If a monitoring activity cannot be tied to a specific control requirement or risk scenario, it is surveillance, not security.

Transparency: The Foundation of Trust

Transparency is the first principle of ethical monitoring. According to Gartner, organizations that communicate monitoring practices clearly see trust scores rise by about 30 percent compared to those that do not. This statistic comes from the Gartner Workplace Trust Survey published in 2023.

Transparency is not a vague statement like “We monitor for security.” It is a clear explanation of what data is collected, why it is collected, how long it is retained, who can access it, and when it may be escalated.

A global retailer learned this the hard way. They deployed a new analytics tool without explaining it. Employees assumed the company was reading their messages. Trust scores dropped. Productivity dipped. Only after publishing a detailed monitoring policy and hosting open Q&A sessions did trust recover.

Transparency is not a courtesy. It is a control.

Necessity: Collect Only What You Need

The second principle is necessity. ISO 27001 emphasizes data minimization in controls such as A.5.1 and A.8.2. Necessity means every monitoring capability must map to a defined risk.

A healthcare organization once collected full packet captures simply because the tool allowed it. After a privacy impact assessment, they discovered that most of the captured data was irrelevant. Storage costs were rising. Sensitive patient information was being retained unnecessarily. They shifted to metadata-only monitoring and reduced storage costs by 40 percent while maintaining detection effectiveness.

Necessity protects both systems and people.

Proportionality: Match the Tool to the Threat

Proportionality asks whether the intrusiveness of a monitoring measure is justified by the severity of the risk it addresses.

Monitoring aggregated network anomalies is proportionate to everyday security operations. Recording employees’ screens is proportionate only during an active investigation.

Ethical OversightA technology company once considered screen recording to prevent code theft. After mapping the idea to SOC 2 Privacy criteria and conducting a risk assessment, they realized the intrusion outweighed the benefit. They implemented role-based access controls, repository monitoring, and behavioral analytics instead. Security incidents dropped by 18 percent and employee satisfaction rose by 12 percent.

Proportionality is not about limiting security. It is about choosing the right tool for the right threat.

Governance: The Guardrails That Prevent Surveillance Creep

Monitoring tools tend to expand over time. This pattern is often called surveillance creep. Strong governance prevents it.

Effective organizations use written monitoring policies, defined retention limits, access controls for monitoring data, and annual privacy impact assessments. They also ensure oversight is not limited to the security team. NIST 800 53 controls PL 2 and AR 4 emphasize that monitoring must be governed, reviewed, and justified.

One multinational company implemented quarterly monitoring reviews. Within a year, they reduced unnecessary data collection by 27 percent and improved compliance audit outcomes.

Governance is the difference between ethical monitoring and accidental surveillance.

Culture and Law: Why One Size Never Fits All

Monitoring expectations vary globally. In the European Union, GDPR requires strict justification for employee monitoring and often explicit consent. In the United States, monitoring is more permissible but still governed by state privacy laws. In parts of Asia, monitoring is culturally expected as part of workplace security.

A global organization once tried to deploy a uniform monitoring policy across fourteen countries. It failed. Employees in Germany objected. Employees in Singapore did not. Legal teams scrambled. The company eventually adopted a regional model aligned with local laws and cultural expectations. Trust improved and compliance strengthened.

Monitoring is not just technical. It is cultural.

A Practical Model for Ethical Monitoring

LegalImagine a company that wants to detect insider threats without harming trust. They begin by monitoring systems rather than people. They focus on network anomalies, access logs, and file transfer patterns. They use aggregated analytics to identify unusual login times or abnormal data movement across the population. Individual monitoring is triggered only when a documented risk exists, such as an active investigation or legal authorization.

They communicate everything. They review quarterly. They retire unnecessary monitoring. They update risk scenarios. This model aligns with NIST, ISO, SOC 2, and global privacy expectations. It protects systems without sacrificing trust.

The Human Side of Security

Research from the University of British Columbia found that intensive monitoring increases stress and reduces trust, which leads to lower productivity and higher turnover. This study was published in 2022 and examined the relationship between workplace surveillance and employee well-being.

Security is not just about preventing breaches. It is about creating an environment where people feel respected, protected, and valued. Bruce Schneier captured this idea well when he wrote, “Security is not a product. It is a process.” This quote appears in his book Secrets and Lies published in 2000.

Ethical monitoring is part of that process.

The Take Away

Monitoring is essential, but surveillance is harmful. Ethical monitoring is built on transparency, necessity, and proportionality. Control frameworks provide structure and guardrails. Strong governance prevents surveillance creep. Cultural and legal context matter as much as technology. Ethical monitoring improves trust, reduces risk, and strengthens compliance.

When organizations get this right, they protect both their systems and their people. And that is the kind of security culture leaders want to build.