Writing · Human Layer
Breaking the standard: human-centric thinking from architecture to security
By Mahmoud Lotfy · Jul 2026 · 6 min read
An architect on Tencast said something that applies to security more than to buildings. Nouf Al-Khubaizi, who has spent 19 years designing spaces in Dubai, argues that engineering standards are just rules written by people, and that she breaks them when they stop serving the human inside the space. That sounds like a rejection of rigor. It is the opposite. It is a demand that rigor serve the person, not the checklist. Security awareness fails for exactly the reason bad architecture does: when it serves the standard instead of the human, it produces something that passes inspection and does not work.
I work on the human layer of security, the part of every organisation that is most exploited and least designed for. So I pay attention when someone from a completely different discipline describes the same disease. Nouf is not talking about compliance frameworks. She is talking about buildings. But the diagnosis transfers cleanly, because both fields have the same temptation: to treat the standard as the goal rather than the means.
Nouf: the standard is a starting point, not a cage
Her distinction between architecture and architectural engineering is really a distinction about who the work serves. The art can look finished on a screen while ignoring how a person actually lives in the space. She makes the point sharply about AI: it can give you a look, but it cannot tell you that the morning sun will hit your face in the bedroom. A tool can produce something that photographs well and fails the human who has to live there. The standard, in her telling, is where you start thinking, not where you stop.
"The standards of engineering were written by people. They are not sacred, and they can be broken."
Where security copies bad architecture
Now look at how most organisations run security awareness. A framework requires training, so training is assigned. A module is bought, completion is recorded, a certificate is issued, and the control is marked satisfied. The standard has been met. And almost nothing about how people actually behave under pressure has changed. This is the architectural sin Nouf describes, applied to security: a design that serves the checklist and forgets the human inside it.
The tell is that the training is generic. The same module goes to the finance director and the new joiner, in the same language, with the same examples, describing threats as if they happen to someone else. It passes the audit. It does not change the moment that matters, which is a real person, under time pressure, deciding whether to trust a message that arrived at exactly the wrong time. Compliance theatre is not a failure of rigor. It is rigor pointed at the wrong target.
Designing for the person who has to say yes or no
Human-centric security starts from the person the control actually lands on. It asks what this specific individual can authorise, what they are actually exposed to, and what a realistic attack against them looks like, and it designs the intervention around that. This is the idea behind Excera: briefings scoped to a person's role and authority, delivered in their own language, English and Arabic, so the message reaches them as a human being rather than a compliance record. Break the standard where it stops serving that person, exactly as Nouf breaks an engineering rule when it stops serving the resident.
None of this means abandoning frameworks. A framework is a good starting point, the same way building codes are. The failure is treating the code as the finished design. A control that satisfies an auditor but leaves the human unprepared is a beautiful render of a house nobody can live in.
How to pressure-test a control against the human it targets
Take any security control you rely on and run it through three questions. Who is the human at the sharp end of this control, and what does the world look like from their seat? What decision are we actually asking them to make, and have we prepared them for that decision specifically or for a generic one? And if this control were tested by a real, well-timed attack tomorrow, would it change what the person does, or only what the audit shows? If a control only serves the standard, break it and design one that serves the person. That is not a lowering of rigor. It is the point of it.