News / June 2026

New Paper Highlights the Need for Usable Cybersecurity

Sarah Powazek
Sarah Powazek

In a new paper in Cyber Security: A Peer-Reviewed Journal, Sarah Powazek, Director of CLTC’s Public Interest Cybersecurity Program, addresses the challenge of “usability” in cybersecurity, particularly for nonprofits, city governments, schools, hospitals, and other public interest organizations. Powazek’s article, “Usable technology for non-experts: Bridging the cyber security expertise gap for low resource organisations,” argues that new, more accessible solutions are needed to help organizations with limited resources more easily use cybersecurity products.

“Cyber security has a complexity problem; most products require a baseline level of knowledge about cyber security controls to be used effectively, but many small organisations, such as non-profits, rural hospitals, utilities, cooperatives and cities, lack the staff to adequately protect themselves from common cyber incidents,” Powazek writes. “Similarly, these small organisations cannot afford to hire or contract managed services, as human expertise is expensive and difficult to scale.”

The Expertise Burden

The paper first outlines the “expertise burden” of cybersecurity on small- and medium-sized organizations, highlighting that many products widely used in the private sector, such as CrowdStrike Falcon, can be overwhelming for non-experts to navigate. “To learn how to use Falcon, CrowdStrike has an entire online educational platform called ‘CrowdStrike University’, which includes 75 courses, both available self-paced and instructor-led, as well as six certifications of product knowledge, including for the basic ability to be an administrator of the product,” Powakek notes, adding that products sold by SentinelOne and Microsoft are similarly designed for large corporations with extensive budgets for cybersecurity.

“Small and medium-sized organisations cannot afford mainstream cyber security products, and even if they could, they often lack the in-house expertise to implement and maintain them,” she writes.

Powazek explains that there are existing solutions to the “cyber poverty” problem, including managed services (which enable organizations to outsource cybersecurity services), cyber insurance (which helps organizations manage and track cyber risk), and cyber volunteering (when students or cyber professionals provide low-cost or pro bono services to low-resource organizations). Yet “no single programme, or even all three together, is enough to extend a basic layer of cyber defence across all small and medium-sized organisations in the US,” she writes.

Cyber volunteering programs, for example, “provide critical services and are widespread enough to support a growing number of organisations in need,” but they do not “have the resources to protect every organisation in need across the country. They must, within limits, prioritise delivering free services to those organisations in their direct region that are most in need and have a focus on the public interest.”

Training on cybersecurity is also too difficult for most low-resource organizations to access, Powazek writes, and awareness training programs for employees “have been shown across multiple studies to be ineffective at reducing successful phishing attacks. Training and education function best as a supplement, not a replacement, to in-house expertise and cyber security tools.”

A Call for Investment in Usable Cybersecurity

To help close the “expertise gap” in cybersecurity, Powazek argues that “a new generation of cyber security technology is needed to serve the small and medium-sized marketplace — one that treats users as non-experts and uses automation and machine learning (ML) to scale basic cyber capability without scaling hiring…. These products could fill a gap in a currently underserved marketplace. Rather than replacing high-complexity tools…, usable technology products can provide an onramp and pipeline for organisations as they continue to grow into more traditional products and services.

Powazek points to products like Zip Security, a product that “could enable organisations without a full-time IT staff to configure their software for security, even without knowing the exact cyber security best practices or where to locate them.” Another example is Coro, which provides “a primary product of endpoint detection, along with additional services including e-mail security, cloud security and security awareness trainings” and “has a strong focus on ease of use and a product targeted at small and medium-sized organisations.” 

Such products “emphasise usability and lean on automation to create efficiencies” and are “light on buzzwords and cyber lingo,” Powazek notes, which makes it “easy for small IT teams or companies without dedicated IT to understand the product’s use cases.

“The most high-impact intervention for usable technology is expanded investment,” Powazek concludes. “Venture capitalists and investors can help grow the usable technology field by increasing their cyber security investments in companies that serve small and medium-sized organisations and design their products around their needs. Only with ‘people, processes and usable technology’ can the organisations that keep US communities afloat continue to deliver their critical services.