Ivan Flechais

Professor Ivan Flechais
Interests
My research focuses on human-centred cybersecurity and the design of secure socio-technical systems. I am interested in how security and privacy can be engineered to work effectively in the real-world contexts in which technologies are designed, deployed, and used. This means looking beyond technical security mechanisms to understand the human, organisational, social, and cultural factors that shape security outcomes.
A longstanding strand of my work has explored how usability, security, and software engineering can be brought together in the design process. More recently, my research has increasingly moved beyond the individual user to examine how security and privacy are experienced and negotiated collectively. This includes work on smart homes, communal and bystander privacy, ultra-large systems, remote and shadow security practices, data protection, and AI-enabled threats. Across these areas, I am interested in how responsibility, trust, power, and control are distributed between individuals, groups, organisations, and the technologies they rely on.
My current interests increasingly concern security as a collective and relational phenomenon: how security practices emerge from interactions between people, technologies, organisational structures, and wider social contexts. I am particularly interested in situations where different actors have competing needs, unequal levels of power, or shared responsibility for security, and in how these tensions can be recognised and addressed through better design. As digital systems become more interconnected and increasingly mediated by AI, I am interested in developing approaches to cybersecurity that account for these wider relationships rather than treating security primarily as a problem of individual behaviour.
Biography
I am an Associate Professor of Computer Science at the University of Oxford, where my research focuses on human-centred cybersecurity and the design of secure socio-technical systems. Over more than 25 years, my work has explored how security and privacy can be designed to reflect the needs, behaviours, and constraints of the people and organisations who use, develop, and operate digital technologies.
My research has contributed to the development of usable security as a socio-technical engineering discipline, spanning secure systems design, security requirements, human-computer interaction, software engineering, privacy, smart technologies, and organisational security practices. This work has attracted more than £2.5 million in external funding from organisations including EPSRC, the Information Commissioner’s Office, DCMS/Innovate UK, and CyBOK, and has been published in leading venues including CHI, CSCW, USENIX Security, SOUPS, and the International Journal of Human–Computer Studies. It has also received a USENIX Security Distinguished Paper Award and a CSCW Impact Recognition Award.
More recent work has increasingly moved beyond the individual user to examine how security and privacy are shaped by relationships between people, technologies, and organisations. This includes research on privacy and power in smart homes, the user experience of data protection, remote and shadow security practices, AI-enabled deception, and the wider human and organisational consequences of cybersecurity work. Across these areas, I am particularly interested in how responsibility, trust, power, and security practices are distributed across groups, organisations, and increasingly complex socio-technical environments.
Selected Publications
-
Beyond the Office Walls: Understanding Security and Shadow Security Behaviours in a Remote Work Context
Sarah Alromaih‚ Ivan Flechais and George Chalhoub
In Twentieth Symposium on Usable Privacy and Security (SOUPS 2024). 2024.
Details about Beyond the Office Walls: Understanding Security and Shadow Security Behaviours in a Remote Work Context | BibTeX data for Beyond the Office Walls: Understanding Security and Shadow Security Behaviours in a Remote Work Context | Download (pdf) of Beyond the Office Walls: Understanding Security and Shadow Security Behaviours in a Remote Work Context | DOI (10.5555/3696899.3696926)
-
"It Becomes More of an Abstract Idea‚ this Privacy" − Informing the Design for Communal Privacy Experiences in Smart Homes.
Martin Kraemer‚ Helena Webb‚ George Chalhoub and Ivan Flechais.
In International Journal of Human−Computer Studies (IJHCS 2023). December, 2023.
Details about "It Becomes More of an Abstract Idea‚ this Privacy" − Informing the Design for Communal Privacy Experiences in Smart Homes. | BibTeX data for "It Becomes More of an Abstract Idea‚ this Privacy" − Informing the Design for Communal Privacy Experiences in Smart Homes. | Download (pdf) of "It Becomes More of an Abstract Idea‚ this Privacy" − Informing the Design for Communal Privacy Experiences in Smart Homes. | DOI (10.1016/j.ijhcs.2023.103138) | Link to "It Becomes More of an Abstract Idea‚ this Privacy" − Informing the Design for Communal Privacy Experiences in Smart Homes.
-
Data Protection at a Discount: Investigating the UX of Data Protection from User‚ Designer‚ and Business Leader Perspectives
George Chalhoub and Ivan Flechais
In The 25th ACM Conference On Computer−Supported Cooperative Work And Social Computing (CSCW 2022). ACM. November, 2022.
Details about Data Protection at a Discount: Investigating the UX of Data Protection from User‚ Designer‚ and Business Leader Perspectives | BibTeX data for Data Protection at a Discount: Investigating the UX of Data Protection from User‚ Designer‚ and Business Leader Perspectives | Download (pdf) of Data Protection at a Discount: Investigating the UX of Data Protection from User‚ Designer‚ and Business Leader Perspectives | DOI (10.1145/3555537)