World Congress 2026 North America

Secure-by-Inclusion: Preventing Accessibility Barriers from Becoming Security Vulnerabilities

September 25, 2026 09:40 – 10:10 Β· 30 min Stage 5

What this session covers

What happens when security measures cannot be used by everyone? Any security control that is not accessible becomes a barrier, and barriers trigger unsafe workarounds that create security risks.

We face a paradox, security mechanisms designed to protect users can systematically exclude the most vulnerable populations, including people with disabilities and older adults, and this exclusion can become an exploitable vulnerability. Users facing accessibility barriers adopt insecure coping mechanisms: sharing passwords, delegating authentication to others, storing credentials insecurely, relying on weaker fallback paths, or abandoning security measures altogether. Each workaround is a predictable security failure caused not by user negligence, but by design choices that made the secure path inaccessible.

This presentation introduces Secure-by-Inclusion, a new practical approach that ensures that security controls actually function for all intended users across diverse abilities, devices, and assistive technologies.

We will walk through common patterns where security and accessibility collide, including CAPTCHAs, multi-factor authentication, biometric authentication, time-limited one-time codes, brittle account recovery flows, and inaccessible verification steps. For each pattern, we connect the accessibility failure to concrete security outcomes, then show safer, more inclusive alternatives. We will also look into the European Accessibility Act (EAA) and the WCAG 2.2 Accessible Authentication requirements, examining their implications for security design and testing.

We will learn practical techniques for incorporating inclusive evaluation into security testing practices and identify accessibility gaps as security vulnerabilities. Accessibility and security might seem like separate disciplines, but they share common goals: protecting users and ensuring inclusive, trustworthy digital experiences.

Related talks at this congress

Open session

World Congress 2026 North America

September 24, 2026 Β· 14:50–15:20

Stage 1

The Era of Machine-Driven Defense is Here: Headless Security

Loris Degioanni

Founder & CTO of Sysdig

Loris Degioanni
Open session

World Congress 2026 North America

September 25, 2026 Β· 16:50–17:20

Stage 5

The Things Your AI Isn't Telling You

Desmond Lamptey

Lead Software Engineer at Capital One

Desmond Lamptey
Open session

World Congress 2026 North America

September 25, 2026 Β· 09:00–09:30

Stage 4

Don’t kill my Vibes - Simple Steps to Stay Secure when Vibe Coding

Isaac Evans

Founder & CEO of Semgrep

Isaac Evans
Open session

World Congress 2026 North America

September 25, 2026 Β· 11:00–11:30

Outdoor Stage

Vibe Coding Accessibility

Karl Groves

Focused on actively fixing accessibility

Karl Groves
All sessions at this congress