Skip to main content

Design Security for Real Human Systems

Build security that survives deception, pressure, support, recovery, insider authority, poor incentives, and daily work.

Learning outcomes

  • Design usable decisions, support paths, and recovery without relying on exceptional vigilance.
  • Distinguish phishing, social engineering, insider, biometric, warning-fatigue, and workflow threats.
  • Analyze who controls, pays for, benefits from, and bears the failure of a security decision.
  • Build role-specific practice and measures that improve both behavior and the technical system.

Scenario

An organization protects production and customer-support tools with strong authentication, but attackers target help desks, users approve repeated prompts, emergency access persists, application teams keep direct paths, and annual training reports high completion without reducing incidents.

Ordered learning units

  1. Concept

    Usable Security

    Make the secure action effective, efficient, understandable, accessible, recoverable, and compatible with the person's real task.

  2. Concept

    Social Engineering

    Model deception and influence that cause a person or process to disclose information, change identity state, or perform an unauthorized action.

  3. Concept

    Phishing

    Distinguish deceptive delivery from verifier impersonation, credential relay, malware, payment fraud, and session theft, then use protocol controls.

  4. Concept

    Warning Fatigue and Habituation

    Prevent repeated low-value prompts and alerts from training people to approve, dismiss, mute, or bypass security decisions.

  5. Concept

    Biometric Authentication

    Use noisy, non-secret human characteristics only within a bounded authenticator, sensor, matching, privacy, fallback, and recovery design.

  6. Concept

    Account Recovery

    Restore account access without giving attackers an easier path than the normal authentication and enrollment process.

  7. Concept

    Security Support and Recovery Workflow

    Treat support, enrollment, authenticator replacement, policy exception, impersonation, and emergency recovery as high-authority security controls.

  8. Concept

    Insider Threat

    Reduce harmful action by people or partners who hold legitimate access, knowledge, proximity, or influence, whether intentional or accidental.

  9. Concept

    Principal-Agent Security Problem

    Control delegated security work when the actor has different goals, information, incentives, and accountability from the owner.

  10. Guide

    Analyze Security Incentives

    Map cost, benefit, authority, information, liability, and feedback so a control works after teams and vendors optimize their own goals.

Evaluation questions

  • Can the intended person finish normal, denied, urgent, accessible, support, and recovery work without a hidden bypass?
  • Which social, insider, prompt, biometric, or support path can transfer authority despite correct primary authentication?
  • Who can reduce each risk, who pays control cost, who receives benefit, and who bears failure?
  • Do measures show safer tasks and lower harm rather than completion, clicks, or other gameable proxies?

Completion conditions

  • Observe and threat-model one real high-impact human workflow with representative people and realistic pressure.
  • Remove one vigilance-dependent step, one broad support action, and one persistent unsafe workaround.
  • Produce an incentive map and change one default, owner, budget, feedback loop, or exception rule.
  • Run one role-specific practice cycle and show both a control improvement and a measured behavior improvement.

Sources and further reading

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo