It looks like the child directories are inheriting the permissions of the parent directory. If the parent directory has stronger restrictions than the child directories, then the child directories are subject to those limitations.
Here's another approach for configuring User
A- ERGASIWN [Read/Write]
- ERGASIWN > EMPLOKES [Deny Access or Read]
- ERGASIWN > OFFICER [Deny Access or Read]
- ERGASIWN > RISK [Deny Access or Read]
- ERGASIWN > PEP [Deny Access or Read]
This is more work since every time you add a new directory under ERGASIWIN, you'll need to add the "Deny Access" or "Read" permission to all users depending on what they are entitled to do/see.