Every company has security policies. Passwordless and multi-factor authentication on every account. Conditional access based on device compliance. No personal devices on the corporate network without management enrollment.
And almost every company has someone who gets an exception.
It is usually an executive. Sometimes a founder or a family member. The request sounds reasonable: a preferred phone that does not meet device compliance requirements, or a personal laptop that cannot be enrolled in management because it is also used for personal business, or a workflow that requires bypassing conditional access for convenience.
The IT team pushes back. The executive pushes harder. Someone decides the relationship is not worth the fight. The exception is granted.
We have worked through the aftermath of incidents that started exactly this way. In one case that our industry still references by first name, a senior executive's device preference required a security exception. The exception was found and exploited by an attacker. The breach expanded from that single entry point into a company-wide incident.
Why exceptions are more dangerous than gaps
A security gap is something you do not know about. It is a misconfiguration, an oversight, an unpatched system. Gaps are fixable once you find them.
An exception is something you chose. It is a deliberate hole in your defenses, documented or not, that exists because someone with authority decided the rules should not apply to them. Exceptions are harder to fix because the political dynamics that created them do not change just because the risk is theoretical.
Until it is not theoretical.
The policy that works
At CTP, we help clients establish a simple rule: no exceptions. Not for the CEO. Not for family members. Not for the IT team. Not for board members. The same security controls apply to every person and every device, period.
This is harder to implement than it sounds. The technical configuration is straightforward. The organizational commitment is the real work. You need buy-in from the top. You need leadership who will hold the line when a senior person pushes for special treatment. You need someone who can explain, in business terms, why the exception is not worth the risk.
We play that role for our clients. When the pressure comes (and it always does), having an external technology partner who can say "this is a serious risk and here is why" carries weight that an internal IT person often cannot muster. The external advisor does not report to the person asking for the exception.
What this looks like in practice
Every account gets passwordless and multi-factor authentication. Every device is enrolled in compliance management. Conditional access policies apply to every login, regardless of who is logging in. If a device does not meet security requirements, it does not connect. If a login attempt comes from an unusual location or device, additional verification is required.
The people who resist this most are often the people who present the highest-value targets to attackers. Executive accounts with access to financial systems, strategic documents, and sensitive communications are exactly what a motivated attacker is looking for. And they look for the person with the exception, because that is the weakest link.
The conversation nobody wants to have
The hardest part of implementing a no-exception policy is the conversation with the executive who believes the rules should not apply to them. We have been in that meeting many times. The arguments are always similar: "I need my personal phone for business." "I travel too much for conditional access to work." "My assistant needs my login credentials to manage my calendar."
Each of these has a technical solution that does not require an exception. Personal phones can be enrolled in device management with a work profile that separates business and personal data. Conditional access policies can be tuned for travel patterns. Calendar delegation does not require sharing credentials.
The real question is whether leadership is willing to hear that. As an external technology partner, CTP can have that conversation with a credibility and directness that an internal IT person often cannot. We do not report to the person requesting the exception. We report to the security posture of the organization.
We have also seen what happens when leadership gets it right. One of our clients had an executive team that fully committed to the no-exception policy. When a new board member requested a workaround for their device, the CEO shut it down personally, citing an incident the company had experienced years earlier. The organization now refers to exceptions by the first name of the person whose exception caused that incident. There is no faster way to end the conversation.
Building the culture
The technical controls are the easy part. The culture is what makes them stick. That means communicating why the policy exists in business terms, not just security terms. Not "our conditional access policy requires device compliance" but "if your phone gets stolen in an airport, we need to make sure nobody can use it to access our financial systems."
When people understand the why, compliance goes from resentful to willing. And that shift makes the entire security posture stronger, because people who understand the risks are less likely to create new ones.
What to do if you already have exceptions
If you are reading this and realizing that your organization has existing exceptions in place, you are not alone. Most companies do. The question is what to do about it.
Start by inventorying every exception. Who has one? What does it allow? Why was it granted? Document them all.
Then work through each one with the question: "Is there a technical solution that achieves what this person needs without bypassing the security control?" In our experience, the answer is almost always yes. A preferred device can usually be enrolled in management. A workflow requirement can usually be met with a different configuration. A convenience issue can usually be resolved with training.
For any exception that genuinely cannot be eliminated (this is rare, but it happens), document the risk, require executive sign-off with a written acknowledgment of the risk, set a review date, and implement compensating controls. Treat it like what it is: a known vulnerability that is being monitored.
The goal is zero exceptions. The path to zero may take a few weeks. That is fine. What matters is the commitment to get there and the organizational will to hold the line once you do.
Our guidance to every client: the moment you grant your first exception, every other security control becomes less effective. Hold the line. It is the single most important security decision you will make.

