Cybersecurity and usability are often perceived as competing objectives. The literature contains numerous examples of cybersecurity solutions that have been criticized for poor usability and user experience. Several studies highlight several conflicts between security and usability during both system design and use. From a design perspective, security is frequently treated as an afterthought and integrated late in the development process, often resulting in complex and difficult-to-use solutions. From a user perspective, security mechanisms can interrupt users’ primary tasks and workflows, whereas usability aims to support users in achieving their goals efficiently and effectively. However, rather than viewing security and usability as mutually exclusive, both are essential and should be considered jointly throughout the design process in an iterative and integrated manner.
Similarly, some studies emphasize the importance of usable cybersecurity by examining the limited visibility of security functionalities within end-user applications. Common shortcomings include security settings scattered across multiple menus and sub-menus, security-related features hidden within advanced configuration options, and interfaces that fail to clearly communicate security status or available protections. Such design issues can reduce user awareness, hinder the effective use of security features, and ultimately weaken the overall security posture of the system [1].
These findings highlight the importance of adopting user-centred approaches when designing cybersecurity solutions, ensuring that security mechanisms are not only effective but also understandable, accessible, and usable by their intended users.
CyberAId Practices: User needs & Requirements collection
In the CyberAId project, requirements engineering and user-centred design play a central role in ensuring that the developed tools address actual cybersecurity needs within finance organisations and ensure effectives system’s usability. The CyberAId requirements engineering process follows a structured methodology that combines multiple sources of information, including:
- Financial sector cybersecurity challenges
- Pilot stakeholder needs
- Project technical objectives
- Regulatory frameworks such as DORA, NIS2, GDPR, PSD2, and the EU AI Act
- International cybersecurity standards and best practices
- Partner expertise and operational experience
By combining these perspectives, CyberAId ensures that requirements are not only technically feasible but also aligned with real-world financial-sector environments.
The requirements collected during the project are classified, reviewed, prioritised, and validated through an iterative process involving technical partners, pilot organisations, cybersecurity experts, and financial-sector stakeholders [2].
Why User stories Matter
While requirements describe what the CyberAId platform must achieve, user stories explain why specific capabilities are needed and how they deliver value to end users. They provide a user-centred perspective that helps translate technical requirements into practical functionalities aligned with real operational needs.
CyberAId adopts user stories as a means of bridging the gap between technical development and the day-to-day realities of financial-sector organizations. By capturing requirements from the perspective of the individuals who will interact with the platform, user stories help development teams better understand user goals, expectations, and challenges.
By developing structured user stories based on the needs of actual stakeholders, CyberAId ensures that the resulting solutions are not only technically robust and compliant with regulatory requirements, but also relevant, usable, and effective in addressing real-world cybersecurity challenges. This approach supports the design of solutions that enhance user experience, facilitate adoption, and ultimately contribute to stronger cybersecurity resilience across the financial sector.
Continuous Validation Through Pilot Activities
Within CyberAId, requirements and user stories are not treated as static project outputs but as living artifacts that evolve throughout the project lifecycle. As technical development progresses and pilot activities unfold, stakeholders continuously review, validate, and refine the identified requirements to ensure they remain aligned with emerging cybersecurity challenges, regulatory developments, and operational needs.
The project’s pilot environments play a crucial role in this process by providing realistic financial-sector settings in which CyberAId technologies can be evaluated and improved. Through ongoing feedback from cybersecurity professionals, operational teams, and financial-sector stakeholders, the consortium can assess whether the proposed functionalities effectively address real-world challenges related to threat detection, incident response, operational resilience, regulatory compliance, and cyber risk management.
This iterative validation approach ensures that CyberAId remains grounded in practical needs while delivering solutions that are both technically robust and operationally relevant.
Looking Ahead
The requirements baseline established in CyberAId marks the beginning of a structured journey towards a more resilient, trustworthy, and intelligent cybersecurity ecosystem for the financial sector. By translating stakeholder needs into clear requirements and user-centred functionalities, the project creates a solid foundation for the design, development, and validation of its AI-driven cybersecurity framework.
As the project advances, these requirements will continue to guide the evolution of CyberAId’s core capabilities, supporting the development of innovative solutions for proactive cyber defense, continuous monitoring, threat intelligence, incident management, and regulatory reporting.
By combining advanced cybersecurity technologies, artificial intelligence, regulatory compliance, and continuous stakeholder engagement, CyberAId aims to deliver solutions that not only strengthen the security posture of financial organizations but also enhance their operational resilience in an increasingly complex threat landscape.
References
[1] Nurse, J. R. C., Creese, S., Goldsmith, M., & Lamberts, K. (2011). Guidelines for Usable Cybersecurity: Past and Present. Proceedings of the 2011 International Conference on Cyber Security and Protection of Digital Services. Available at: https://kar.kent.ac.uk/67535/1/CSS2011_NCGL_authors_final.pdf
[2] CyberAId Consortium, D2.1 – Financial Sector Cybersecurity Requirements Analysis, Deliverable D2.1, CyberAId Project, 2026.



