Back to Insights

FIELD NOTE

Good security is usable security

ABRI Systems ·

A security control has to work during an ordinary working day: when someone loses a phone, a supplier needs access, or a staff member is rushing to complete a task. If the approved route is confusing or impossible, the pressure to improvise grows.

Usable security means designing a safe path people can follow under those conditions. It does not mean removing checks whenever they are inconvenient. It means putting effective checks in a workflow that has an owner, a recovery route and enough support to function.

The help desk is part of the security boundary

The July 29, 2025 joint Scattered Spider advisory describes attackers gathering information and calling help desks to obtain password resets or transfer multifactor-authentication tokens. The agencies also document impersonation, push-notification abuse and data theft. Source: international joint advisory, published by the Australian Cyber Security Centre.

That is evidence of attacker behaviour, not proof that a particular company’s interface caused its breach. ABRI’s lesson is narrower: a recovery process can become an alternative route around the protections used at login. A strong sign-in method offers limited benefit if an impostor can persuade support to replace it.

Consider a hypothetical employee whose phone fails while travelling. “Never reset MFA” leaves a legitimate person stranded. “Reset it for anyone who knows the employee’s details” gives an attacker an opportunity. A usable process offers an independent verification route, explains which evidence is acceptable and escalates exceptions to someone with authority to decide.

Reduce the burden of defending every prompt

The same joint advisory recommends phishing-resistant authentication such as FIDO/WebAuthn. These methods can reduce reliance on users identifying a fraudulent login page or rejecting repeated approval prompts. Recovery and enrolment still need protection. Source: joint advisory, mitigation guidance.

Make approved tools available before banning the alternatives. Provide a managed password manager, a way to request limited access and a reporting button that reaches a monitored queue. Offer accessible instructions and a fallback for users who cannot use the primary method. “Ask IT” is incomplete if nobody knows how to reach IT after hours.

Make least privilege practical for software identities too

Microsoft’s September 25, 2026 Storm-3168 analysis describes compromised service principals used in destructive Azure activity. A roughly seven-minute sequence included more than 100 storage-account deletion attempts. Some protections blocked deletions despite the identities’ permissions. Microsoft also found a previously public secret, but could not confirm it caused the compromise. Source: Microsoft Security Research, Storm-3168 analysis.

A service principal is an identity for software. ABRI’s analysis: least privilege becomes usable when the application owner can request the specific access needed, understand what was granted and remove it without breaking unrelated work. A permanent administrator credential is convenient to start with, but difficult to contain later.

For example, a hypothetical reporting job needs to read a defined dataset. Give it that capability rather than broad subscription access. If a deployment needs temporary write permissions, provide a documented, time-limited route. Protect backup administration separately so the routine application identity cannot erase its own recovery path.

Measure the workflow, not just the policy

Walk through a lost-device recovery, an urgent access request, a suspected phishing report and an exposed application secret. Observe where people hesitate, which channels they use and how long a responsible person takes to respond. Test exceptions as carefully as the normal route.

Useful measures include successful recovery time, how quickly reports reach a responder, unresolved access requests and whether exposed credentials can actually be revoked. A growing pile of exceptions is a reason to inspect the design, rather than simply repeat the training.

Good security gives people a workable next step while maintaining the boundary that matters. The test is whether the safe route holds up when real work becomes messy.

Sources checked October 1, 2026. Incident facts are attributed inline; hypothetical examples and practical analysis are ABRI’s.

Share