The Annual Ritual of Blaming the User
Cybersecurity Awareness Month has become a familiar corporate ritual. Led by well-meaning IT departments, employees are subjected to phishing simulations, webinars, and reminders about security best practices. The core message, often unspoken, is that
people are the weakest link in the security chain. The problem with this approach is not just that it’s often ineffective—some studies show that typical training barely reduces the likelihood of someone clicking a malicious link—but that it places the entire burden of security on the end-user. We are essentially asking ordinary people to become cybersecurity experts to compensate for systems that are not inherently safe. This strategy is proving to be a failing one, as human error continues to be a factor in the majority of security breaches.
When Bad Design Makes Us Vulnerable
The truth is, many security incidents don't happen because users are careless, but because products are designed in ways that make mistakes easy. Think about confusing privacy settings that require a dozen clicks to secure your profile, or authentication prompts that are so frequent and intrusive that users learn to dismiss them without reading. When security features are complex or add significant friction to a user's workflow, people will naturally find ways to bypass them. This isn't malicious behavior; it's a predictable human response to poor user experience (UX). A well-designed product makes the secure option the easiest and most intuitive one. When a product fails to do this, it's a design failure, not just a user failure. The responsibility for that failure lies with the creators of the product, not the person trying to use it.
The 'Secure by Design' Philosophy
There is a better way. It’s a philosophy known as “Secure by Design.” The core idea is simple: security should be a fundamental requirement built into a product from the very beginning, not a feature that gets bolted on at the end. This approach, sometimes called “shifting left,” moves security considerations into the earliest stages of the development lifecycle. Instead of expecting users to become security experts, products are engineered to be secure by default. This means shipping with the safest settings already enabled, designing interfaces that guide users toward secure actions, and building systems that are resilient to common attacks out of the box. The evolution of the CAPTCHA from unreadable text to a nearly invisible background check is a perfect example of this principle in action. The most secure action for the user became doing nothing at all.
Whose Job Is It, Anyway?
Shifting to a “Secure by Design” model requires a cultural change within technology companies. This isn't just an IT or security team's responsibility; it's a core business and product strategy. Product managers, designers, and engineers must treat security as a critical feature, on par with usability and functionality. Company leadership must invest the resources to make this happen, understanding that building safer products reduces long-term costs and protects brand reputation. For too long, the tech industry has tacitly accepted a model where it produces potentially insecure products and then tasks its customers—and their IT departments—with the responsibility of using them safely. This is like an automaker selling a car with known brake issues and then running an awareness campaign on how to be a better driver.













