Effective cyber security practices are critical for organisations to protect their users, data and assets in a digital-first world—where evolving threats and risk grow evermore prevalent.
Though a multitude of cyber security technologies exist to combat these threats – and many of them do a great job – truly holistic cyber security relies on people. Whether that’s citizens or employees using software and services, or cyber security and data professionals directly monitoring the systems—and everyone else in between.
It’s this critical element of people that makes a user-centred approach so important to building secure infrastructure and services. Harnessing a user-centred lens to cyber projects goes hand in hand with secure by design thinking, where security measures and threat modelling are embedded at the beginning of the design phase and throughout the delivery and operation of services.
In this blog post, we explore core strategies for how secure by design can be achieved and how user-centred principles are key to this process, offering a host of benefits to your organisation and your users.
Humans can be the strongest link
It’s a common opinion in the world of cyber security that humans are the weakest link of any system. This is largely down to their susceptibility to error and manipulation – with cyber criminals exploiting vulnerability through multiple bad actor tactics such as phishing or social engineering. However, by taking user-centered approach, and focusing on supporting and working with people, we can change that perception and make humans the strongest link.
The threat landscape is constantly evolving but the human factor remains consistent for organisations, who often take action primarily through policies and educational programmes. Whilst this is a key element of any cyber security strategy, how do you break down barriers and bridge the gap between the user and the technology?
Bridging the gap between users and technology – why it’s all about empathy
It takes humans to understand humans. Overly complex or technical security measures can confuse or frustrate users, often leading to measures that could undermine safety. This friction can be caused by managing multiple passwords and deciphering multi-factor authentication procedures. If the system is unintuitive or inconsistent, that gap between the user and the tech gets larger, leaving you wide open to risk.
This is why it’s crucial to design security solutions that align with human behaviour from the outset, using empathy and context to anticipate any stages in the process where the user may be vulnerable to error or tempted to cut corners. A user-centred interface with clear guidance can help to empower users when engaging with security measures—building a platform for cooperation rather than resistance. But there’s so much more to embedding a secure-by-approach into your systems.
The principles of a user-centred secure-by-design approach
Building the thing right and building the right thing
User-centred design (UCD) principles require an understanding of user needs in order to build digital products that are understandable and usable by intended users. By taking a similar approach to designing services with an understanding of nefarious users and adversaries, organisations can ensure digital products are built to be secure/protected from the outset.
Agile is about building the thing right. UCD is about building the right thing. Where these approaches are blended, products, services and systems become easy-to and attractive-to use. Applying these principles to the cyber security elements of projects allows for building in usable security features and understanding the context of use to identify and build out security flaws before they are rolled-out at scale.
Threat modelling and observability from the outset
Proactive threat modelling during the development stage is also a key principle of the secure-by-design approach. This helps to mitigate vulnerabilities early on and anticipate potential attack vectors. Engineers can then create safeguards driven by that threat modelling before such risks become exploitable weaknesses.
This modelling also extends to understanding human behaviour. Where customers and employees experience a cyber security incident, shame or fear of punishment can delay them in reporting what has happened. Understanding this human reaction and addressing fears directly by creating solutions for identifying and reporting threats, as well as supporting users to assess threats accurately, will reduce risk within organisations and for their end customers.
Feedback loops for continuous improvement
A key principle of agile and UCD is iteration. Even the best-designed technical cyber security systems require adaptation over time as threats evolve and features change. Incorporating feedback loops ensures continuous improvement and allows user experiences and incident analysis to enhance your security measures.
This iterative process, grounded in prevention and adaptation ensures that secure-by-design systems are effective and user-focused as the cybersecurity landscape evolves.
How to implement secure-by-design using user-centric principles
Understand your users (and adversaries)
It may seem obvious, but time and time again user research is overlooked in the design and development of systems, leading to cyber security issues down the line. User research is key to identifying the needs, behaviours and pain points of the users interacting with your service. A key goal of secure-by-design is to make secure behaviour the easiest and most natural choice for your users. Embedding user research early on ensures that you can predict interactions and tailor security features to align with the user’s capability and preferences.
Simplifying security
If a digital platform is simple to understand you’ll have a much better chance of ensuring compliance with security measures. Complex systems are confusing and this can lead to user friction and larger risk of error. Clear language, consistency, familiar visual cues and UX design best practices can help to guide users through security actions – or responding to threats. This helps remove obstacles, drive adoption and build confidence.
Building awareness
User-centred principles help you build trust across your organisation and drive cultural shifts and change. Creating accessible and engaging awareness methods helps users to understand cyber security concepts, threats and the roles that play negating them.
Collaboration is key
Integral to the success of a secure-by-design approach and implementation is collaboration across teams and expertise. This means user researchers, UX designers, service designers, data engineers and cyber security engineers all collaborating to find that balance between usability and robust practices. By taking this holistic approach and mindset, you can address both the technical and human factors of your service.
A human solution for a human challenge
Though today’s interconnected digital world may be powered by technology – it’s governed and harnessed by people. A secure-by-design approach, underpinned by user-centred principles, ensures that you bridge the gap between technology and the people who use it. Understanding user needs, applying empathy, iteration and collaboration are all key ways to reduce cyber security risks and embed resilience without creating barriers.
James Odom
James Odom is a Service Line Director for Cyber at Hippo, bringing over a decade of experience in cyber security, product management and data analytics. James' focus is on driving and enhancing the Hippo cyber security capability, supporting client's cyber needs, and helping our teams deliver world-class solutions.
