Rosenverse

Log in or create a free Rosenverse account to watch this video.

Log in Create free account

100s of community videos are available to free members. Conference talks are generally available to Gold members.

To Protect People, You Have to Protect Information: A Human-Centered Design Approach to Cybersecurity
Thursday, January 23, 2025 • Rosenfeld Community
Share the love for this talk
To Protect People, You Have to Protect Information: A Human-Centered Design Approach to Cybersecurity
Speakers: Heidi Trost
Link:

Summary

If you design digital products, you’re already influencing the security user experience—even if you don’t realize it. Your design choices impact how users handle security and privacy decisions. We live in an ecosystem where everything increasingly relies on the security of systems: from hospitals, to our water supply, to cars and robots. So the stakes are high: disruptions to these systems mean people can get hurt. Further, technology like AI agents—services that will know nearly everything about us and will take actions on our behalf—mean security and privacy are more important than ever. As a UX designer, you understand your product better than your users ever will. This gives you the power to protect users by developing safer systems. By the end of this talk, you’ll learn how to: Apply human-centered design principles to security: human-centered security. Identify key areas where security impacts users most. Understand the dynamics of the security ecosystem. Collaborate with your security UX allies. Ask better questions to balance security and usability. You’ll leave with a human-centered security framework that you and your team can use immediately. Start asking the right questions to improve security outcomes and keep people and systems safer.

Key Insights

  • Security user experience is hindered by conflicting priorities among UX, security, engineering, compliance, and product teams.

  • Users (Alice) generally focus on their goals, not security, so security often only surfaces as friction during critical moments.

  • Charlie represents the frustrating and jargon-heavy security communications that users encounter, impacting their trust and compliance.

  • Building a positive relationship between Alice (user) and Charlie (security systems) is essential to improve security outcomes.

  • Threat actors exploit gaps in the security user experience by understanding user behavior and system vulnerabilities better than designers do.

  • Signup and onboarding are critical moments to influence lasting security behavior since users have a captive and motivated audience.

  • Clear, jargon-free communication across disciplines helps unify disparate security languages into a shared understanding.

  • AI and sophisticated social engineering attacks will intensify the challenges in user trust and security communications.

  • Cross-disciplinary collaboration involving UX, security, product, and legal teams is key to designing effective human-centered security.

  • Security solutions should anticipate user stress, confusion, and typical user behaviors to design helpful, context-aware interactions.

Notable Quotes

"The stakes are really high, from disrupting critical infrastructure to AI acting on our behalf."

"If Alice no longer believes Charlie, she’s going to resent him and change how she responds next time."

"Charlie is like the worst coworker you’ve ever had: well intentioned but painful to interact with."

"Threat actors often understand Alice and Charlie better than we do and use that to their advantage."

"Users literally swat security warnings away because the flows are so overwhelming and confusing."

"We all speak different security languages, but at some point, they have to come together."

"We can’t improve security outcomes until we improve the relationship between Alice and Charlie."

"Threat actors try to convince Alice that they are Charlie to trick her into giving up access."

"Signup and onboarding offer a fleeting but critical opportunity to influence user security behaviors."

"The user is the weakest link is an unhelpful mindset; understanding dynamics helps design better security UX."

Ask the Rosenbot
Abbey Smalley
Scaling UX Past the Size of Your Team
2024 • Enterprise Experience 2020
Gold
Nora Tejeda
Scaling Design Capabilities at BBVA Through a Self-service Design Model
2021 • Design at Scale 2021
Gold
Sheri Byrne-Haber
Accessibility at Scale
2021 • Design at Scale 2021
Gold
Lija Hogan
Practical Principles of Inclusive Research
2023 • Advancing Research 2023
Gold
Ron Bronson
Design, Consequences & Everyday Life
2022 • Civic Design 2022
Gold
Bria Alexander
Opening Remarks Day 2
2024 • Advancing Research 2024
Gold
Chris Geison
Theme Two Intro
2023 • Advancing Research 2023
Gold
Sam Proulx
Designing For Screen Readers: Understanding the Mental Models and Techniques of Real Users
2021 • Civic Design 2021
Gold
Alla Weinberg
People Are Sick of Change: Psychological Safety is the Cure (Videoconference)
2023 • DesignOps Community
Steve Portigal
War Stories LIVE! Steve Portigal
2020 • Advancing Research 2020
Gold
Sheryl Cababa
Expanding Your Design Lens with Systems Thinking (Videoconference)
2023 • Enterprise Community
Mackenzie Guinon
M.C. Escher’s UX Research Career Ladder
2022 • Advancing Research 2022
Gold
Prayag Narula
Dialing for Research: How to Reach the Unreachable
2022 • Advancing Research 2022
Gold
Sohit Karol
Designing Delightful Listening Experiences: Mixed Methods Research in the Age of Machine Learning
2020 • Advancing Research 2020
Gold
Ignacio Martinez
Fair and Effective Designer Evaluation
2024 • DesignOps 2024
Gold
Chris Govias
Perspectives on Civic Design (Videoconference)
2021 • Civic Design Community

More Videos

Angelos Arnis

"There is no such thing as a single issue struggle because we do not live single issue lives — bell hooks."

Angelos Arnis

Navigating the Rapid Shifts in Tech's Turbulent Terrain

October 2, 2023

John Calhoun

"Prioritizing design ops work is tough amid competing priorities and limited time and budget."

John Calhoun Rachel Posman

Bring your DesignOps Story to Life! The Definitive DesignOps Book Jam

October 3, 2023

Alfred Kahn

"If design is not viewed as a player moving the needle on business strategy, designers feel disempowered and frustrated."

Alfred Kahn

A Seat at the Table: Making Your Team a Strategic Partner

November 29, 2023

Dan Willis

"I should have brought you along on this journey instead of scheduling a big meeting — I was wrong."

Dan Willis

Enterprise Storytelling Sessions

June 3, 2019

John Maeda

"Designers still love Adobe Photoshop even though the tooling hasn’t moved as quickly as other fields."

John Maeda Alison Rand

About Design Organizations (Videoconference)

May 13, 2019

Anat Fintzi

"We consolidated over 10 configurable tools into one holistic supply chain management tool this year."

Anat Fintzi Rachel Minnicks

Delivering at Scale: Making Traction with Resistant Partners

June 9, 2022

Uday Gajendar

"Nobody wants to buy or use a sloppy product, especially when enterprise users engage daily for hours."

Uday Gajendar

The Wicked Craft of Enterprise UX

May 13, 2015

Kristin Skinner

"There was a need around definition but also understanding the value our teammates would find in this role."

Kristin Skinner

Theme 1 Intro

September 29, 2021

Maish Nichani

"Design is a rendering of intent, and at the national level, this intent shapes everything from innovation to being a lovable city by 2025."

Maish Nichani

Sparking a Service Excellence Mindset at a Government Agency

December 9, 2021