Skip to main content

Ivan Flechais

Personal photo - Ivan Flechais

Professor Ivan Flechais

Associate Professor of Computer Science

Interests

My research focuses on human-centred cybersecurity and the design of secure socio-technical systems. I am interested in how security and privacy can be engineered to work effectively in the real-world contexts in which technologies are designed, deployed, and used. This means looking beyond technical security mechanisms to understand the human, organisational, social, and cultural factors that shape security outcomes.

A longstanding strand of my work has explored how usability, security, and software engineering can be brought together in the design process. More recently, my research has increasingly moved beyond the individual user to examine how security and privacy are experienced and negotiated collectively. This includes work on smart homes, communal and bystander privacy, ultra-large systems, remote and shadow security practices, data protection, and AI-enabled threats. Across these areas, I am interested in how responsibility, trust, power, and control are distributed between individuals, groups, organisations, and the technologies they rely on.

My current interests increasingly concern security as a collective and relational phenomenon: how security practices emerge from interactions between people, technologies, organisational structures, and wider social contexts. I am particularly interested in situations where different actors have competing needs, unequal levels of power, or shared responsibility for security, and in how these tensions can be recognised and addressed through better design. As digital systems become more interconnected and increasingly mediated by AI, I am interested in developing approaches to cybersecurity that account for these wider relationships rather than treating security primarily as a problem of individual behaviour.

Biography

I am an Associate Professor of Computer Science at the University of Oxford, where my research focuses on human-centred cybersecurity and the design of secure socio-technical systems. Over more than 25 years, my work has explored how security and privacy can be designed to reflect the needs, behaviours, and constraints of the people and organisations who use, develop, and operate digital technologies.

My research has contributed to the development of usable security as a socio-technical engineering discipline, spanning secure systems design, security requirements, human-computer interaction, software engineering, privacy, smart technologies, and organisational security practices. This work has attracted more than £2.5 million in external funding from organisations including EPSRC, the Information Commissioner’s Office, DCMS/Innovate UK, and CyBOK, and has been published in leading venues including CHI, CSCW, USENIX Security, SOUPS, and the International Journal of Human–Computer Studies. It has also received a USENIX Security Distinguished Paper Award and a CSCW Impact Recognition Award.

More recent work has increasingly moved beyond the individual user to examine how security and privacy are shaped by relationships between people, technologies, and organisations. This includes research on privacy and power in smart homes, the user experience of data protection, remote and shadow security practices, AI-enabled deception, and the wider human and organisational consequences of cybersecurity work. Across these areas, I am particularly interested in how responsibility, trust, power, and security practices are distributed across groups, organisations, and increasingly complex socio-technical environments.

Selected Publications

View AllManage publications

Activities

Projects

Completed Projects

Current Students

Yara Alsiyat
(King Abdulaziz City for Science and Technology (KACST))
Varad Vishwarupe
(Trinity College, University of Cambridge)

Past Students

Deena Alghamdi
Selina Cho
Paula Fiddi
Martin J. Kraemer
Joe Loughry
Russel Magaya
Norbert Nthala