Building a safer digital future, together: a community for professionals who care about cyber security
Cyber security hub
Featured content
In this CYBERUK Online video, Ollie Whitehouse (CTO, NCSC) and Pelin Demir (UX Designer, Hippo Digital/NHS Login) discuss the successful integration of passkeys into the NHS Login system. The conversation highlights how shifting from traditional passwords to biometric-based passkeys significantly improved accessibility for millions of users while simultaneously creating a "phishing-resistant" environment that protects the UK’s critical health infrastructure.
Latest cyber security articles and news from Hippo

Customer Identity and Access Management (CIAM)
Discover what’s next in our new eBook

Putting users at the heart of financial services
Putting users at the heart of financial services can protect customers, prevent fraud and build better experiences through design and data.

Digital wallets
How to build for an emerging identity landscape
Play
Digital Identity: Seamless and Secure
Secure by design
James Odom, Director for Cyber Security, explains how his team utilises a user-centred, “secure by design” approach to help public sector and healthcare clients improve their security maturity. He highlights the importance of bridging the gap between technical security requirements and business leadership to ensure effective threat monitoring and service integration.
Latest news from the sector
Ask an expert
Hippo is a proud member of the cyber security community. Our aim is support our partners, educate those with an interest and provide insights at every level.
Q: How are leaders effectively moving from “verify then trust” towards a Zero Trust model?
A: The shift to Zero Trust is a journey of cultural and technical change. The community is seeing the most success when focusing on “never trust, always verify” as a foundational principle rather than just a toolset. This involves prioritising continuous identity verification, enforcing least-privilege access, and implementing micro-segmentation. By integrating these from the very start of a service’s lifecycle, we minimise the blast radius of any potential breach and move away from the fragile “castle and moat” mentality.
Q: In the face of AI-driven risks and quadruple extortion ransomware, how can we realistically stay ahead of the 2025 threat landscape?
A: Staying ahead requires moving from reactive to adaptive security. The most resilient organisations are leveraging machine learning-enhanced SIEM to process massive event volumes while providing predictive analytics. Furthermore, addressing the “quadruple extortion” threat—which targets your entire partner ecosystem—requires a community-minded approach to software supply chain risk. We must treat our partners’ security as an extension of our own.
Q: What is the collective experience regarding the ROI of “Secure by Design” versus retrospective auditing?
A: The consensus is that retrospective auditing is increasingly unsustainable. Retiring “security debt” late in the delivery cycle is exponentially more expensive and introduces operational friction. “Secure by Design” isn’t just a compliance check; it’s a cost-saving measure. By embedding threat modelling at the inception of a project, services become resilient by default, reducing the need for emergency remediations and protecting the organisation’s reputation from day one.
Q: How can we integrate threat modelling into early design without obstructing Agile delivery?
A: Threat modelling should be an iterative, collaborative conversation rather than a “gate” at the end of a process. Security specialists and engineers find the most success when they work together during discovery phases to identify potential attack vectors. This “Built-in Observability” ensures that security is part of the Minimum Viable Product (MVP), allowing teams to move fast while knowing the foundations are sound.
Q: We often hear that “humans are the weakest link.” How can User-Centred Design change this narrative?
A: It is time to shift the perspective: if a user bypasses a security measure, the design has failed, not the user. When security is overly complex, people find workarounds, creating “shadow” security risks. UCD reduces risk by making the secure path the easiest path. By researching user behaviours and pain points, we can design authentication journeys—like modern Digital Identity solutions—that are intuitive. This drives higher compliance and ensures that security protocols are adopted, not circumvented.
Q: Can “User Experience” (UX) truly coexist with high-assurance security in sensitive sectors like Health or Government?
A: Not only can they coexist, they must. In critical sectors, high-assurance security only works if the people on the front lines can navigate it quickly and accurately. Industry examples show that applying UCD to complex verification journeys can significantly reduce completion times while maintaining—or even strengthening—security. A seamless user experience reduces the cognitive load on staff, allowing them to focus on their primary tasks without being hindered by security friction.
Q: How do we account for adversarial behaviour within a user-centred framework?
A: Effective UCD isn’t just about the “happy path” for legitimate users; it involves rigorous research into “adversary personas.” By thinking like a bad actor and understanding how they might exploit a service’s flow, we can design defensive features that intercept malicious behaviour. This approach turns user research into a proactive security tool.
Q: How do we best ensure alignment with international frameworks like NIST or MITRE ATT&CK as we scale?
A: These frameworks provide a vital shared language. The most effective approach is to use them as benchmarks for our defences rather than just “check-box” exercises. By mapping security rules and workflows directly to these standards, we ensure that as an organisation grows, its security governance remains consistent, transparent, and defensible to stakeholders and regulators.
Q: How can human-centric security scale across a complex ecosystem of legacy and cloud-native applications?
A: Scaling requires a focus on holistic monitoring and SIEM enablement that bridges the gap between cyber operations and business functions. Using clear language, consistent visual cues, and standardised patterns across your entire digital estate helps build a unified security culture. This reduces confusion for employees and ensures that security awareness is embedded into every interaction, regardless of whether the underlying technology is a legacy system or a modern cloud app.
Q: How can we move away from “blame culture” when security incidents occur?
A: Resilience is built on psychological safety. When we treat security incidents as learning opportunities rather than disciplinary triggers, we encourage honest reporting. A community-minded CISO focuses on “blame-free post-mortems.” By understanding the systemic reasons why a design allowed a mistake to happen, we can improve the service for everyone, rather than just penalising the individual.
Q: What is the most effective way to communicate security risk to non-technical board members?
A: Speak in terms of mission and service continuity rather than vulnerabilities and patches. Boards respond to risks that threaten the organisation’s ability to deliver its core services. By framing security as an enabler of digital transformation—one that protects trust and reduces long-term operational costs—we position security as a strategic partner rather than a cost centre.
Q: How do we manage third-party risk without becoming a bottleneck for procurement?
A: We should move towards a “collaborative assurance” model. Instead of lengthy, static spreadsheets, many leaders are moving towards dynamic assessments and sharing security expectations early in the tender process. By being transparent about our security standards and helping our suppliers meet them, we uplift the security of the entire ecosystem, which in turn protects us.
Q: With the move to cloud-native, how do we handle the “Shared Responsibility” model effectively?
A: Clarity is key. Often, vulnerabilities arise in the gaps between what the provider manages and what the customer manages. The best practice is to create a clear matrix of responsibilities that is understood by both the technical teams and the legal/procurement teams. Regularly testing these boundaries through joint simulations ensures that everyone knows their role when an incident occurs.
Key contacts
We have a team of over 50 specialist consultants that cover cyber security and identity, supported by over 600 technology professionals. Our team work alongside and within clients in the largest public and private sector organisations.
Cyber security is a specialism
50+
Hippos with deep cyber security and identity expertise
Part of a
600
strong team of technology professionals





















