Rosenverse

Log in or create a free Rosenverse account to watch this video.

Log in Create free account

100s of community videos are available to free members. Conference talks are generally available to Gold members.

To Protect People, You Have to Protect Information: A Human-Centered Design Approach to Cybersecurity
Thursday, January 23, 2025 • Rosenfeld Community
Share the love for this talk
To Protect People, You Have to Protect Information: A Human-Centered Design Approach to Cybersecurity
Speakers: Heidi Trost
Link:

Summary

If you design digital products, you’re already influencing the security user experience—even if you don’t realize it. Your design choices impact how users handle security and privacy decisions. We live in an ecosystem where everything increasingly relies on the security of systems: from hospitals, to our water supply, to cars and robots. So the stakes are high: disruptions to these systems mean people can get hurt. Further, technology like AI agents—services that will know nearly everything about us and will take actions on our behalf—mean security and privacy are more important than ever. As a UX designer, you understand your product better than your users ever will. This gives you the power to protect users by developing safer systems. By the end of this talk, you’ll learn how to: Apply human-centered design principles to security: human-centered security. Identify key areas where security impacts users most. Understand the dynamics of the security ecosystem. Collaborate with your security UX allies. Ask better questions to balance security and usability. You’ll leave with a human-centered security framework that you and your team can use immediately. Start asking the right questions to improve security outcomes and keep people and systems safer.

Key Insights

  • Security means different things to different roles, making cross-disciplinary collaboration essential.

  • Users (Alice) often do not think about security until it directly interrupts their tasks.

  • Charlie personifies the security systems and communications users interact with; their unhelpfulness harms user trust.

  • Improving the relationship between Alice and Charlie is critical to enhancing security behaviors and outcomes.

  • Threat actors understand users and security systems better than many security teams do, exploiting weak points.

  • Onboarding and signup are crucial moments to influence secure user behaviors because users are motivated and captive.

  • Security messaging must balance clarity and avoiding fatigue caused by false positives or jargon.

  • AI-driven social engineering and deepfakes will make future attacks more convincing and harder to detect.

  • Designers should anticipate user objections and behaviors when creating security flows.

  • Clear standard protocols for unusual financial requests reduce vulnerability to phishing scams.

Notable Quotes

"Security means protecting business, productivity, safety."

"The user is the weakest link is an unhelpful and harmful perspective."

"You cannot improve security outcomes until you improve the relationship between Alice and Charlie."

"Threat actors can masquerade as Charlie to trick users like Alice."

"Most security work happens below the surface where users don’t need to think about it."

"If users have to look things up, they often won’t, so policies must be easy and fast to respond to."

"Onboarding is often fleeting, so influencing security behavior there has an outsized impact."

"With AI, phishing will get worse; attackers will craft messages users are more likely to believe."

"We need to get really good at strategy board games to outsmart threat actors."

"Clear outcomes and defined secure behaviors are better than vague goals like 'be more secure'."

Ask the Rosenbot
Mark Interrante
Collaboration Flows in Product Development
2017 • Enterprise Experience 2017
Gold
Kim Holt
A Salesforce Panel Discussion on Values-Driven DesignOps
2022 • DesignOps Summit 2022
Gold
Christopher Geison
Theme 1 Intro
2024 • Advancing Research 2024
Gold
Sheryl Cababa
Expanding your Design Lens with Systems Thinking
2023 • Advancing Research 2023
Gold
Louis Rosenfeld
Coffee with Lou #3: What Makes for a Successful UX Conference Presentation?
2024 • Rosenfeld Community
Gretchen Anderson
Scaling the Human Center
2017 • Enterprise Experience 2017
Gold
Prerna Makanawala
Achieving Balanced Design Consistency
2021 • Design at Scale 2021
Gold
Jane Davis
Strategic Shifts and Innovations in User Research: Navigating Challenges and Opportunities
2025 • Advancing Research 2025
Gold
Ellie Krysl
Planned Right. Managed Right. Designed Right.
2023 • Enterprise UX 2023
Gold
Lisa Spitz
Building Trust Through Equitable Research Practices
2022 • Civic Design 2022
Gold
Natalia Radywyl
Co-Designing New Power in Australia's Public Sector
2022 • Civic Design 2022
Gold
Yalenka Mariën
Designing for Digital Inclusion in the Belgian Government
2021 • Civic Design 2021
Gold
Victor Udoewa
Research in the Pluriverse
2023 • Advancing Research 2023
Gold
Kim Lenox
Leading Distributed Global Teams
2019 • Enterprise Community
Frances Yllana
Theme 2 Intro
2024 • DesignOps Summit 2024
Gold
Kristin Skinner
Group Activity: A Deep Dive Into Value and Outcomes
2019 • DesignOps Summit 2019
Gold

More Videos

Neema Mahdavi

"By understanding our systems and being intentional about tools and processes, everyone benefits."

Neema Mahdavi

Operationalizing DesignOps

November 7, 2018

Sean McKay

"Balancing risk and confidence helps teams move at the right speed for the right decisions."

Sean McKay

Coexisting with non-researchers: Practical strategies for a democratized research future

March 11, 2025

Jack Behar

"UXPin is a full-stack platform that bridges the gap between design and development disciplines."

Jack Behar

How to Build Prototypes that Behave like an End-Product

December 6, 2022

Lena Shenkarenko

"The future of urban living depends on our commitment to environmental justice."

Lena Shenkarenko

Collaborative Wireframing for Creating Team Alignment and Shipping Better Products

October 21, 2020

Aurobinda Pradhan

"Our Jira integration will be two-way so you can link design activities to epics, user stories, or tasks."

Aurobinda Pradhan Shashank Deshpande

Introduction to Collaborative DesignOps using Cubyts

September 9, 2022

Matt Bernius

"Being trauma-informed means caring for yourself, forgiving your mistakes, and moving forward with humility."

Matt Bernius Sarah Fathallah Hera Hussain Jessica Zéroual-Kara

Trauma-informed Research: A Panel Discussion

October 7, 2021

Maria Giudice

"The best future leaders will embody the qualities, skills and traits of a DEO, a Design Executive Officer."

Maria Giudice

Empowering change: Reigniting purpose, passion and impact in research

March 13, 2025

Marc Majers

"The timing is key—you want to interrupt them when they are in that flow state."

Marc Majers Tony Turner

Interrupted UX - Add A Dose of Reality To Usability Testing

March 11, 2022

Jennifer Strickland

"Academia pressures us to share research for academic audiences, but public communication is key to impact."

Jennifer Strickland Lesley-Ann Noel

Fireside Chat: How Design Addresses a World on Fire

March 18, 2022