Hack.lu 2026

Hostile Tools Aren't a Badge of Honour: UX for Security Engineers

Why is poor user experience (UX) in security tools so common? From expensive enterprise systems to home-grown vibe coded disposable applications to CLI tools, it's rare to find security tools where data and controls are laid out the same way our brain works. As security analysts, we often don't have the design vocabulary to explain why something isn't working the way we'd like, but on an emotional level there's something we know is not quite right.

Why is that? In this talk, we'll look at why UX is often undervalued in security tooling, but that it doesn't have to be this way. We'll also discuss some foundational design concepts and patterns to help everyone improve the way you think about user experience in your own projects.


What’s the essential security tool you use every day but subconsciously grind your teeth at? Data-rich but cluttered interfaces, subconscious analyst workarounds for sharp UI edges, and steep learning curves are far too common. We're talking about everything from the most expensive enterprise platforms to open source, home grown, vibe coded, web, or CLI for analysis, logging, and automation.

So why is bad user experience (UX) in security tools so common? A few suspects:

  • UX is undervalued as a "soft" discipline in tools built by or for security teams.
  • Mastery of a hostile UI is even seen as a badge of honour or job security.
  • Analysts deeply understand the flow of their daily operations, but they lack the design language to build the best interface for it.
  • Sometimes, analysts struggle to describe how their brain works when they are analysing a topic, case, or dataset, but they have a strong subconscious feeling for what good and bad for UX.
  • Vibe coding quickly gets you a UI, but not always one that understands the subtleties of cybersecurity investigations.
  • A "maximalist" mindset assumes more data and more features always equal a better tool.

Why is good UX so important? Bad UX in tools wastes time and creates frustration but worse, it leads to missed analysis, detection, and insight. Good interface design is the bridge between the human-in-the-loop and making the best decisions quickly, whether using AI or not.

If you're a security practitioner who writes software, "vibe codes" software, or has input into an internal software dev team, in this presentation you'll learn:

  • Why good UX is a technical requirement, not just attractive window dressing.
  • That analysts’ mental models, not underlying data models, should drive UI design.
  • Guerrilla usability testing methods that cost zero dollars
  • A 'Security UX Manifesto': 6 UI patterns like Progressive Disclosure that reduce cognitive load when you’re under pressure.

We’ll use concrete examples and classic ideas from the UX discipline to get you on the road to much improved cybersecurity tooling.

Chris Horsley

Chris Horsley is the CTO and co-founder at Cosive, a consultancy specialising in cyber threat intelligence and security operations. At Cosive, Chris leads the company's threat intelligence sharing and MISP initiatives and is a frequent speaker and trainer at industry conferences and meetups on these topics. Prior to co-founding Cosive, Chris spent many years in the international CSIRT community including working as an incident responder for both AusCERT and JPCERT/CC, the Japanese national CSIRT.