design thinking in ict security - business aspect · delivering business value from a fresh...

18
Design Thinking in ICT security Delivering business value from a fresh approach

Upload: others

Post on 21-Sep-2020

0 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Design Thinking in ICT security - Business Aspect · Delivering business value from a fresh approach. Difficulties for security Afterthought Fixing a problem, not designing a feature

Design Thinking in ICT security

Delivering business value

from a fresh approach

Page 2: Design Thinking in ICT security - Business Aspect · Delivering business value from a fresh approach. Difficulties for security Afterthought Fixing a problem, not designing a feature

Difficulties for security Afterthought

Fixing a problem, not

designing a feature

Overhead, Hindrance,

Inconvenience

Jarring for users

Not part of product

design

Can Design Thinking

help?

Page 3: Design Thinking in ICT security - Business Aspect · Delivering business value from a fresh approach. Difficulties for security Afterthought Fixing a problem, not designing a feature

What is design thinking?

‘the collaborative process by which the

designer’s sensibilities and methods are

employed to match people’s needs with

what is technically feasible and a

viable business strategy.’ – Tim Brown

Ideo.

Reliability Intuition

Design

Thinking

Science Art

Page 4: Design Thinking in ICT security - Business Aspect · Delivering business value from a fresh approach. Difficulties for security Afterthought Fixing a problem, not designing a feature

Build rapid prototypes

of ideas, focused on a

particular area.

‘Lo-fidelity’ to show

potential - not

problems.

Design thinking approach

Gain basic knowledge

to ask the right

questions.

Empathy with target

users. Watch what

they do, not what

they say. Ask “why?”

Develop a point of

view statement.

User + need + insight

Based on POV,

generate as many

ideas as possible.

Take findings from

prototypes back to

assumptions and

validate.

http://www.slideshare.net/mikeyk/intro-to-design-thinking

Understand Observe Synthesise Ideate Prototype Iterate

Inspiration Ideation Implementation

Page 5: Design Thinking in ICT security - Business Aspect · Delivering business value from a fresh approach. Difficulties for security Afterthought Fixing a problem, not designing a feature

Design thinking works

http://ns-design.com/sherwinwilliams.php

Page 6: Design Thinking in ICT security - Business Aspect · Delivering business value from a fresh approach. Difficulties for security Afterthought Fixing a problem, not designing a feature

Education Insight

http://moraveji.org/projects_med.html

User

+

Need

+

Insight

Page 7: Design Thinking in ICT security - Business Aspect · Delivering business value from a fresh approach. Difficulties for security Afterthought Fixing a problem, not designing a feature

Can Design

Thinking be

applied to ICT

security?

Hint – the traffic cop

approach is not the

best answer...

Page 8: Design Thinking in ICT security - Business Aspect · Delivering business value from a fresh approach. Difficulties for security Afterthought Fixing a problem, not designing a feature

Consumer

Choice

Employee

Rule (ouch)

Page 9: Design Thinking in ICT security - Business Aspect · Delivering business value from a fresh approach. Difficulties for security Afterthought Fixing a problem, not designing a feature

Tactical

security models

hurt users

Benefits are

invisible

Security as

strategy?

Page 10: Design Thinking in ICT security - Business Aspect · Delivering business value from a fresh approach. Difficulties for security Afterthought Fixing a problem, not designing a feature

Behaviour on unseen risks

http://www.youtube.com/watch?v=h-8PBx7isoM

Page 11: Design Thinking in ICT security - Business Aspect · Delivering business value from a fresh approach. Difficulties for security Afterthought Fixing a problem, not designing a feature

ANZ Security

http://www.youtube.com/watch?v=Fqr7-9dT17E

Page 12: Design Thinking in ICT security - Business Aspect · Delivering business value from a fresh approach. Difficulties for security Afterthought Fixing a problem, not designing a feature

Checkin security

User

+

Need

+

Insight

Page 13: Design Thinking in ICT security - Business Aspect · Delivering business value from a fresh approach. Difficulties for security Afterthought Fixing a problem, not designing a feature

Conditions for design thinking

• Needs different kind of

leadership

– Promote exploitation and

exploration

– Move away from reliability and

onto validity

• If you’re not the CEO

– Become a design champion

– Stance, tools, experiences

Page 14: Design Thinking in ICT security - Business Aspect · Delivering business value from a fresh approach. Difficulties for security Afterthought Fixing a problem, not designing a feature

How can You become a

design thinker? • Stance

– Step away from reliability model

– Priority on seeking validity and

advances in knowledge

• Tools

– Noticing, analysing, synthesising

• Experiences

– Mastery of local domain

– Continuous improvement

– External models which can help

Page 15: Design Thinking in ICT security - Business Aspect · Delivering business value from a fresh approach. Difficulties for security Afterthought Fixing a problem, not designing a feature

Flow Stance - who am

I and what am I

trying to achieve?

Tools – what do I use to

organise my thinking

and understand the

world?

Experiences – what

can I use to build

my selection of

sensitivities and

skill?

Guide

Inform

Guide

Inform

Page 16: Design Thinking in ICT security - Business Aspect · Delivering business value from a fresh approach. Difficulties for security Afterthought Fixing a problem, not designing a feature

Takeaways

• Design thinking promotes

divergent approaches in business

• Involves thinkers from across the

business

• Creates conditions for revolution,

gets out of evolution.

• Security needs to play in the

business to get the benefits

• Security projects become change

projects too!

Page 17: Design Thinking in ICT security - Business Aspect · Delivering business value from a fresh approach. Difficulties for security Afterthought Fixing a problem, not designing a feature

Some reading

Page 18: Design Thinking in ICT security - Business Aspect · Delivering business value from a fresh approach. Difficulties for security Afterthought Fixing a problem, not designing a feature

Thank You

Gil Carter

[email protected]