SecretCon 2026

Desire paths: The most secure option is the one you actually use

Emily Spotts

Abstract:

Consider the analogy of the different face masks worn during the start of the COVID19 pandemic outbreak. There were different styles with varying degrees of efficacy (handmade cloth masks, masks with ventilation valves, surgical, N95 respirators), but that efficacy is a moot issue if you never wear a better mask due to it being uncomfortable. The most effective mask was the one you actually used and wore (such as comfortable cloth), even if it provided less actual protection than the standard best practice (i.e. N95/KN95).
To this extent I propose the equivalent in our industry, that security tools and policies often introduce perceived friction to the end user, making them feel like it’s hard to do their job within these systems. The best security program is one that’s actually being used. This talk will discuss why it’s important to talk with users and know what these pain points are before they become security events, that are often created by end users seeking alternative, easier solutions to meet their work load inside a bureaucracy. This talk includes real world examples of problematic desire paths to hunt for in your own environment, and how you can use this framework to improve even a mature security program (and incidentally, customer satisfaction). I have met a lot of well meaning people just trying to stay on their boss’ good side by emailing a spreadsheet to their yahoo address to finish on the weekend. These damaging events aren’t always intentionally malicious, but when the InfoSec department is seen as a strict BigBrother and “The ‘no’ Police” many people become afraid to ask questions, look stupid, or even challenge the status quo when individual contributors are often coached to solve their own problems first before asking for help. A similar framing to “solving for the latent error,” we must make the easiest path forward for the ‘lazy employee’, the most secure option by default.

Emily Spotts

Email wizard

Emily is a Senior Security Engineer at a law firm. A once and former email administrator,  their work now primarily focuses on securing cloud systems, with a particular interest in confidentiality, data security, and insider risks. Over the past 15 years, they have dedicated their efforts to understanding how human behavior impacts an organization’s cyber security strategy, with particular experience in highly regulated environments such as healthcare and academic research. Emily is a staunch supporter for solving XY problems: “The XY problem is _asking about your attempted solution_ rather than your actual problem.” Emily hopes by focusing on the behavioral aspects of information security, organizations will understand how to mitigate risks that humans introduce: both the errors, intentional harm, and mischief. Emily holds a Master of Science in Information Assurance, as well as a Bachelor of Business Administration, and holds a CISSP certification. In addition to their work, they give back to the community by volunteering and are an active member in different groups and committees. They are based in Texas, where they enjoy reading, traveling, and the theatre when offline.