Design Security for Real Human Systems
Build security that survives deception, pressure, support, recovery, insider authority, poor incentives, and daily work.
Topic index
Learn how usable controls, social engineering, incentives, insiders, support, recovery, biometrics, and behavior shape real security.
Topic index
Pomerium can provide a consistent identity-aware access path and visible route policy. Organizations still own identity-provider ceremonies, application actions, help-desk recovery, administrator workflow, training, incentives, insider controls, and the consequences imposed on users and operators.
1 learning path
Build security that survives deception, pressure, support, recovery, insider authority, poor incentives, and daily work.
4 related guides
Map cost, benefit, authority, information, liability, and feedback so a control works after teams and vendors optimize their own goals.
Turn role-specific risks into practiced tasks, usable tools, behavior measures, feedback, and control improvements.
Constrain help-desk, authenticator reset, impersonation, exception, federation, and emergency actions as one privileged control plane.
Model the real people, pressures, interfaces, support paths, incentives, and technical controls around one high-impact security task.
10 related terms
Use noisy, non-secret human characteristics only within a bounded authenticator, sensor, matching, privacy, fallback, and recovery design.
Reduce harmful action by people or partners who hold legitimate access, knowledge, proximity, or influence, whether intentional or accidental.
Distinguish deceptive delivery from verifier impersonation, credential relay, malware, payment fraud, and session theft, then use protocol controls.
Control delegated security work when the actor has different goals, information, incentives, and accountability from the owner.
Build role-specific learning around real tasks, safe alternatives, practice, feedback, and measured behavior instead of annual completion.
Find when the party able to reduce risk does not receive the benefit or bear the loss, then realign cost, authority, and feedback.
Treat support, enrollment, authenticator replacement, policy exception, impersonation, and emergency recovery as high-authority security controls.
Model deception and influence that cause a person or process to disclose information, change identity state, or perform an unauthorized action.
Make the secure action effective, efficient, understandable, accessible, recoverable, and compatible with the person's real task.
Prevent repeated low-value prompts and alerts from training people to approve, dismiss, mute, or bypass security decisions.