Learning outcomes
- Design usable decisions, support paths, and recovery without relying on exceptional vigilance.
- Distinguish phishing, social engineering, insider, biometric, warning-fatigue, and workflow threats.
- Analyze who controls, pays for, benefits from, and bears the failure of a security decision.
- Build role-specific practice and measures that improve both behavior and the technical system.
Scenario
An organization protects production and customer-support tools with strong authentication, but attackers target help desks, users approve repeated prompts, emergency access persists, application teams keep direct paths, and annual training reports high completion without reducing incidents.
Ordered learning units
Usable Security
Make the secure action effective, efficient, understandable, accessible, recoverable, and compatible with the person's real task.
Design access controls that people can use
Use open design, clear choices, safe defaults, and observable recovery so people can operate security correctly.
Social Engineering
Model deception and influence that cause a person or process to disclose information, change identity state, or perform an unauthorized action.
Phishing
Distinguish deceptive delivery from verifier impersonation, credential relay, malware, payment fraud, and session theft, then use protocol controls.
Warning Fatigue and Habituation
Prevent repeated low-value prompts and alerts from training people to approve, dismiss, mute, or bypass security decisions.
Biometric Authentication
Use noisy, non-secret human characteristics only within a bounded authenticator, sensor, matching, privacy, fallback, and recovery design.
Account Recovery
Restore account access without giving attackers an easier path than the normal authentication and enrollment process.
Security Support and Recovery Workflow
Treat support, enrollment, authenticator replacement, policy exception, impersonation, and emergency recovery as high-authority security controls.
Secure Support and Recovery Workflows
Constrain help-desk, authenticator reset, impersonation, exception, federation, and emergency actions as one privileged control plane.
Insider Threat
Reduce harmful action by people or partners who hold legitimate access, knowledge, proximity, or influence, whether intentional or accidental.
Threat-Model a Human Security Workflow
Model the real people, pressures, interfaces, support paths, incentives, and technical controls around one high-impact security task.
Security Incentives and Externalities
Find when the party able to reduce risk does not receive the benefit or bear the loss, then realign cost, authority, and feedback.
Principal-Agent Security Problem
Control delegated security work when the actor has different goals, information, incentives, and accountability from the owner.
Analyze Security Incentives
Map cost, benefit, authority, information, liability, and feedback so a control works after teams and vendors optimize their own goals.
Security Awareness and Behavior Change
Build role-specific learning around real tasks, safe alternatives, practice, feedback, and measured behavior instead of annual completion.
Build a Security Behavior Learning Program
Turn role-specific risks into practiced tasks, usable tools, behavior measures, feedback, and control improvements.
Evaluation questions
- Can the intended person finish normal, denied, urgent, accessible, support, and recovery work without a hidden bypass?
- Which social, insider, prompt, biometric, or support path can transfer authority despite correct primary authentication?
- Who can reduce each risk, who pays control cost, who receives benefit, and who bears failure?
- Do measures show safer tasks and lower harm rather than completion, clicks, or other gameable proxies?
Completion conditions
- Observe and threat-model one real high-impact human workflow with representative people and realistic pressure.
- Remove one vigilance-dependent step, one broad support action, and one persistent unsafe workaround.
- Produce an incentive map and change one default, owner, budget, feedback loop, or exception rule.
- Run one role-specific practice cycle and show both a control improvement and a measured behavior improvement.
