Log in or create a free Rosenverse account to watch this video.
Log in Create free account100s of community videos are available to free members. Conference talks are generally available to Gold members.
To Protect People, You Have to Protect Information: A Human-Centered Design Approach to Cybersecurity
Summary
If you design digital products, you’re already influencing the security user experience—even if you don’t realize it. Your design choices impact how users handle security and privacy decisions. We live in an ecosystem where everything increasingly relies on the security of systems: from hospitals, to our water supply, to cars and robots. So the stakes are high: disruptions to these systems mean people can get hurt. Further, technology like AI agents—services that will know nearly everything about us and will take actions on our behalf—mean security and privacy are more important than ever. As a UX designer, you understand your product better than your users ever will. This gives you the power to protect users by developing safer systems. By the end of this talk, you’ll learn how to: Apply human-centered design principles to security: human-centered security. Identify key areas where security impacts users most. Understand the dynamics of the security ecosystem. Collaborate with your security UX allies. Ask better questions to balance security and usability. You’ll leave with a human-centered security framework that you and your team can use immediately. Start asking the right questions to improve security outcomes and keep people and systems safer.
Key Insights
-
•
Security means different things to different roles, making cross-disciplinary collaboration essential.
-
•
Users (Alice) often do not think about security until it directly interrupts their tasks.
-
•
Charlie personifies the security systems and communications users interact with; their unhelpfulness harms user trust.
-
•
Improving the relationship between Alice and Charlie is critical to enhancing security behaviors and outcomes.
-
•
Threat actors understand users and security systems better than many security teams do, exploiting weak points.
-
•
Onboarding and signup are crucial moments to influence secure user behaviors because users are motivated and captive.
-
•
Security messaging must balance clarity and avoiding fatigue caused by false positives or jargon.
-
•
AI-driven social engineering and deepfakes will make future attacks more convincing and harder to detect.
-
•
Designers should anticipate user objections and behaviors when creating security flows.
-
•
Clear standard protocols for unusual financial requests reduce vulnerability to phishing scams.
Notable Quotes
"Security means protecting business, productivity, safety."
"The user is the weakest link is an unhelpful and harmful perspective."
"You cannot improve security outcomes until you improve the relationship between Alice and Charlie."
"Threat actors can masquerade as Charlie to trick users like Alice."
"Most security work happens below the surface where users don’t need to think about it."
"If users have to look things up, they often won’t, so policies must be easy and fast to respond to."
"Onboarding is often fleeting, so influencing security behavior there has an outsized impact."
"With AI, phishing will get worse; attackers will craft messages users are more likely to believe."
"We need to get really good at strategy board games to outsmart threat actors."
"Clear outcomes and defined secure behaviors are better than vague goals like 'be more secure'."
Or choose a question:
More Videos
"Everyone wants to see themselves reflected in the research questions and findings."
Jerome “Axle” BrownHow to Use Self-Directed Learning to Ensure Your Research Insights are Heard and Acted Upon
March 11, 2021
"Our design language gives broad ditches on either side of the road with some nuance, but no rigid libraries at first."
Phil GilbertA Consistent Culture of Design
May 14, 2015
"Building ecosystems of interconnected tools that work seamlessly is crucial for modern, fast-moving organizations."
Kate Towsey Basel Fakhoury Oren Friedman Graham GardnerParticipant Recruitment and Management Tools
March 12, 2026
"We consider machine learning as the third leg of mixed methods research, alongside data science and user research."
Sohit KarolDesigning Delightful Listening Experiences: Mixed Methods Research in the Age of Machine Learning
March 31, 2020
"Seeing the dots connected so clearly reminded me why I was doing what I was doing."
Christopher Taylor Edwards Valerie RoskeDesign as a Team Practice, A Practical Guide to Cross-functional Collaboration
September 30, 2021
"Evaluating interventions must loop back to expand understanding of consequences and radiating effects."
Sheryl CababaExpanding Your Design Lens with Systems Thinking
February 23, 2023
"We had to push back on the idea that we could just use existing models without understanding our team’s needs."
Francesca Barrientos, PhDYou Need Your Own Definition of Design Maturity
June 8, 2022
"It’s important to create space outside work for people to connect to meaningful activities and communities."
Allison SandersOperating with Purpose
January 8, 2024
"Before we started this process, we banned words like designer and prototype."
Saara Kamppari-Miller"Prototype" vs "Prototype"--Breaking Down and Rebuilding Our Understanding of What We Do
October 24, 2019
Latest Books All books
Dig deeper with the Rosenbot
How should a vision be documented and communicated for maximum organizational buy-in?
What are the challenges of self-assessment in work behaviors and how can they be mitigated?
What are the core UX research tools essential for managing participant recruitment and study logistics in large companies?