April 20, 2026
Est 10 min
Cyber security is no longer something that works away unobtrusively in the background of IT departments.
From logging into workplace systems to verifying our identities on banking apps, it has become an integral part of how our society works and lives online.
Yet, as the need to protect our personal data increases, and security tools become embedded in our daily routines, inclusion is often still missing from the important conversations.
Read on as we explore the practical steps we can take to change that harmful narrative, ensuring everyone stays safe online.
People are as important as systems
What do you think when you hear the words cyber security?
For some, they think ‘complicated’ and ‘technical’.
Something that the IT person sorts out for them.
Something they don’t have to worry about or know anything about.
To an extent, they are right.
Most organisations have someone or something keeping people safe behind the scenes, but cyber security is no longer a small risk that you can let someone else worry about.
People are the most important defence in the face of cyber threats.
If you can spot a cyber threat, for example, a phishing email, you can help keep yourself and others safe online.
If you know how to update your device regularly, you can keep your devices protected at home and at work.
These are two simple examples where an individual keeps people, systems and organisations safe online.
When security bypasses accessibility
Most common security measures rely on users carrying out specific actions to be effective:
- Complex passwords ask users to memorise and enter long strings of mixed-case letters, numbers and symbols
- CAPTCHA often depends on identifying distorted text, selecting particular images or solving puzzles
Many users complete these actions with little fuss, but for others, like our neurodivergent colleague, they create unnecessary anxiety, make completing tasks laborious, and often result in people avoiding digital services altogether:
“I find it really frustrating when password fields don’t provide an option to reveal what you have already typed, or when they conceal the whole password. You can’t check what you have entered to see if it is correct.”
Experiences like these are more common than you’d think and highlight an undeniable fact: cyber security features can only be effective when everyone can use them confidently and consistently.
Shifting the dial on accessibility and inclusion
Truly considering diversity in cyber security starts with recognising that not everyone interacts with technology and digital environments in the same way.
Users may rely on assistive technologies, have alternative ways of processing information, or experience digital spaces differently due to neurodivergence or disability.
Yet many security systems are still designed around limited assumptions of how the ‘typical’ user behaves and interacts.
Rather than protecting users and reducing organisational risk, they often unintentionally create new threats.
With around 22% of the UK’s population identifying as disabled, and an estimated 15% being neurodivergent, understanding that cyber security and inclusion are inextricably linked is more important than ever.
Following on from that point, another persistent challenge in cyber security design is the way accessibility continues to be viewed by many in the industry. It is too often seen as an optional extra or an afterthought, diminishing its efficacy significantly.
Security tools prioritise technical resilience foremost, while the experiences of different user groups are only considered when problems come to light.
Designing security with users, not for them
Embracing diversity in cyber security means finding the balance between strength and respecting the diverse needs of real users.
Taking an inclusive design-first approach, for example, encourages teams to challenge each other’s assumptions and ask broader questions during development:
- How will this authentication process work for someone using voice control?
- Could the process result in cognitive overload for someone managing multiple prompts or time limits?
This leads to stronger collaboration across departments and more intentional decision-making.
Organisations also need to ensure that disabled and neurodiverse users are included in the design and testing of security tools or systems from day one.
Manual accessibility testing, for example, involves people performing tasks on tools, using assistive technologies such as screen readers or text-to-speech software.
These technologies identify barriers that automated testing alone could never pick up.
At the end of the day, accessibility is a human issue, and only people with lived experience of access barriers and exclusion can truly understand other users’ needs.
They apply judgment and flexibility in real-world scenarios, helping organisations identify issues or design flaws before they impact large groups of users.
Cyber learning
Individuals should be our focus, as we have already said and for them to be the best line of defence against cyber threats, they need to know the basics. People deserve to feel safe and protected online, at home or at work. Often, this means increasing their own cyber confidence and knowledge through cyber learning.
Cyber learning can be done in many ways. It can be done independently, taking online courses. It could be through a trusted friend, carer or support worker who is safe to share cyber learning or advice with. It can be done casually through social media posts, catching people’s eyes as they are scrolling, or it can be done through a group training session at a workplace or in the community.
Not everyone learns best the same way. That’s why it’s important that there is a diverse range of opportunities to learn about being safe and confident online. Equally, not every learning opportunity is suitable for specific scenarios or environments.
One thing that is common across any cyber learning opportunity is accessibility. Whether it is a webinar, e-learning course, blog or in-person session – accessibility always needs to be considered.
Making learning accessible
Passion4Social has already demonstrated the importance of an inclusive design-first approach. Designing with users, not for them, ensures accessibility is practical. Accessibility isn’t an add-on, it’s something to be considered at every stage of design. It makes the systems designed to keep us safe online actually work for us.
We can take the same approach when designing inclusive cyber learning opportunities. Passion4Social have already given great advice:
- Consider disabled people and neurodivergent users
- Challenge assumptions about how people interact with learning and digital environments
- Use lived experience to influence design (look to trusted organisations or carry out your own research and testing)
Additionally, where appropriate, make accessibility features opt-out, not opt-in or on request. Not everyone has the confidence to request an accessibility feature, especially if it isn’t offered. Not everyone knows they might benefit from an accessibility feature.
Some accessibility can be built in naturally, for example, using Sans-Serif fonts. Sans-Serif fonts are inclusive for visually impaired and dyslexic people. Others can be provided alongside – for example, a BSL interpreter. A BSL interpreter makes a session inclusive for Deaf people as well as hearing people.
Where features are opt-in, make these obvious. For example, a button that opens an accessibility overlay should be clear and move with the page. If participants can keep their cameras off in a webinar, make sure they know that. Don’t assume people will know to ask for an accessibility feature, or have the confidence to.
Neurodiversity as a cyber security strength
Conversations about digital accessibility often focus on barriers, so let’s turn the debate on its head.
Diversity in cyber security is, and should be viewed as an opportunity.
In a recent study of neurodivergent professionals, 73% said cyber security work aligns with their strengths: pattern recognition, sustained analytical focus, lateral thinking and unconventional problem-solving, to name just a few.
These skills can be particularly valuable for anticipating cyberattacks and outwitting hackers.
Increasing the presence of both disabled and neurodivergent professionals in cyber security roles, product development, and decision-making positions also ensures accessibility is baked into design processes from day one.
As the sector continues to face well-documented skills shortages, organisations need to recognise the importance of broadening their talent pipelines and embracing different ways of contributing.
All too often, neurodivergent professionals do not reach their potential in this sector because of a lack of psychological safety and support systems.
Now, as organisations race to keep up with ever-evolving threats, they must see neurodiversity as the strength it undoubtedly is.
Practical tips for creating an inclusion-first culture in your organisation and beyond
Creating more inclusive cyber security does not necessarily mean organisations should redesign their entire operation overnight; however, it does require a change in workplace culture and policies.
As we have already said, the first step on the journey to inclusive security is recognising that accessibility and cyber resilience are inextricably linked, but here are some practical strategies to support sustainable change:
- Create a culture where people feel safe disclosing accessibility challenges without fear of judgment (employees, service users and stakeholders alike). Security should empower users, not intimidate them.
- Training and awareness also have an important role to play across organisations. Everyone should understand the harmful impact of excluding millions of users through poor accessibility. However, security departments, above all, need to understand how barriers can emerge within authentication processes and how they relate to legally binding accessibility standards.
- Strengthen collaboration between accessibility and cyber security teams to build solutions that strike the right balance between robustness and inclusion.
- Embed diversity into procurement decisions and risk assessments to ensure inclusion becomes part of an organisation’s resilience strategy rather than an afterthought.
- Simplify language in security policies and avoid unnecessary jargon. What is the use of these documents if employees and service users cannot understand them?
- Involve employees with diverse needs in user testing and feedback sessions, alongside accessibility testers and diverse user groups. Their lived experience of both cyber security and accessibility barriers is invaluable.
Delivering accessible cyber learning
Lead Scotland delivers a Cyber and Accessibility Project.
They offer free online safety resources and learning opportunities.
They run online webinars and create accessible resources like Easy Read and BSL videos.
They are part of CyberScotland and work to meet the outcomes of the Cyber Resilient Scotland 2025 to 2030 strategic framework.
Their aim is to make sure everyone in Scotland is safe and secure online.
For them, this means providing inclusive, accessible opportunities to learn.
People are the most important line of defence in online safety, let’s make sure that means everyone.
Security that works for everyone
At Passion4Social, we want to build on Lead Scotland’s foundations.
If the tools designed to safeguard digital environments hinder disabled and neurodivergent users, the end goal of ensuring everyone’s safety online can never be achieved.
Recognising diversity in cyber security is imperative to creating the accessible tools of tomorrow because it encourages organisations to look beyond technical design and consider the real experiences of the people using them.
By involving a wider range of voices in the design and development of security tools, organisations can build protections that are not only stronger but also provide a better user experience for everyone.