Uploaded February 2025 | Updated September 2026, 4 days ago
The sixth annual Wheeler lecture was given at the Computer Laboratory on Wednesday 24th May, 2017. The speaker was M. Angela Sasse who spoke on some of the usability considerations in designing security mechanisms.
In many organisations today, IT security is a battleground: to manage the risks the organisation faces, security specialists devise policies and deploy security mechanisms that they expect staff and customers to comply with. But most of time, staff and customers don’t comply, and attempts to change that by “raising awareness” and “educating” them generally fail. The talk will use the examples of security warnings, access control, and sandboxing to explain the different perspectives and values that security specialists and ‘the rest of us’ apply to security. In conclusion, I will argue that a value-centred design approach is the only way to develop security solutions people want to use.
The sixth annual Wheeler lecture was given at the Computer Laboratory on Wednesday 24th May, 2017. The speaker was M. Angela Sasse who spoke on some of the usability considerations in designing security mechanisms.
In many organisations today, IT security is a battleground: to manage the risks the organisation faces, security specialists devise policies and deploy security mechanisms that they expect staff and customers to comply with. But most of time, staff and customers don’t comply, and attempts to change that by “raising awareness” and “educating” them generally fail. The talk will use the examples of security warnings, access control, and sandboxing to explain the different perspectives and values that security specialists and ‘the rest of us’ apply to security. In conclusion, I will argue that a value-centred design approach is the only way to develop security solutions people want to use.






