Session
Your Warning Is Technically Correct and Completely Useless
Security teams spend enormous effort detecting threats, then hand the final decision to a frightened user through a banner, modal, push notification, or block page.
“Suspicious activity detected.”
“Do you want to continue?”
“This connection may not be secure.”
The warning may be technically accurate and still fail completely.
Attackers manufacture urgency, authority, fear, secrecy, and cognitive overload. Under those conditions, users do not read security messages the way designers expect. They dismiss warnings, follow the attacker’s instructions, work around controls, or interpret friction as proof that the attacker’s story is real.
This session examines security warnings as part of an adversarial system. We will dissect common warning patterns, map how attackers neutralize them, and trace where responsibility shifts from detection logic to interface design, timing, escalation, and recovery.
The talk introduces the Adversarial Warning Model, a framework for evaluating whether a security control can interrupt action when the user is already under pressure. Attendees will learn how to test warnings against attacker narratives, reduce dangerous ambiguity, design safer defaults, create trusted escalation paths, and measure whether a warning changes behavior rather than merely appears on screen.
A warning that the user ignores is not a completed control. It is an unhandled detection.
Session Format
1-hour technical talk
Topics
Security Usability
Human Factors
Social Engineering
Blue Team
Threat Modeling
Security Architecture
Application Security
Security Awareness
What will attendees walk away with?
• A framework for evaluating warnings under urgency, fear, authority, and attacker coaching
• Practical methods for testing whether security controls interrupt harmful action rather than merely display information
• Design patterns for safer defaults, escalation, recovery, and high-risk decision points
Level
Intermediate
Can we record your talk?
Yes. The session may be recorded and published.
First-Time Speaker?
No.
Catherine (Cat) Karow
Cat Karow built security for Apple, the White House, and Fortune 100s. Then her mom got scammed, and she discovered the next cybersecurity frontier wasn't infrastructure. It was human beings.
Jacksonville, Florida, United States
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top