> Markdown version of [/events/world-congress-2026-north-america/sessions/1725-secure-by-inclusion](https://www.wearedevelopers.com/events/world-congress-2026-north-america/sessions/1725-secure-by-inclusion). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Secure-by-Inclusion: Preventing Accessibility Barriers from Becoming Security Vulnerabilities - **Event:** World Congress 2026 North America ## Description What happens when security measures cannot be used by everyone? Any security control that is not accessible becomes a barrier, and barriers trigger unsafe workarounds that create security risks. We face a paradox, security mechanisms designed to protect users can systematically exclude the most vulnerable populations, including people with disabilities and older adults, and this exclusion can become an exploitable vulnerability. Users facing accessibility barriers adopt insecure coping mechanisms: sharing passwords, delegating authentication to others, storing credentials insecurely, relying on weaker fallback paths, or abandoning security measures altogether. Each workaround is a predictable security failure caused not by user negligence, but by design choices that made the secure path inaccessible. This presentation introduces Secure-by-Inclusion, a new practical approach that ensures that security controls actually function for all intended users across diverse abilities, devices, and assistive technologies. We will walk through common patterns where security and accessibility collide, including CAPTCHAs, multi-factor authentication, biometric authentication, time-limited one-time codes, brittle account recovery flows, and inaccessible verification steps. For each pattern, we connect the accessibility failure to concrete security outcomes, then show safer, more inclusive alternatives. We will also look into the European Accessibility Act (EAA) and the WCAG 2.2 Accessible Authentication requirements, examining their implications for security design and testing. We will learn practical techniques for incorporating inclusive evaluation into security testing practices and identify accessibility gaps as security vulnerabilities. Accessibility and security might seem like separate disciplines, but they share common goals: protecting users and ensuring inclusive, trustworthy digital experiences. ## Speaker ### [Radostina (Ina) Tsvetkova](https://www.wearedevelopers.com/@radostina-ina-tsvetkova) Norwegian Directorate of Labour and Welfare (NAV), Senior Advisor in Digital Accessibility and Inclusive Design ## Related talks at this congress - [The Things Your AI Isn't Telling You](https://www.wearedevelopers.com/events/world-congress-2026-north-america/sessions/1710-the-things-your-ai) — Desmond Lamptey - [Don’t kill my Vibes - Simple Steps to Stay Secure when Vibe Coding](https://www.wearedevelopers.com/events/world-congress-2026-north-america/sessions/1413-don-t-kill-my-vibes) — Isaac Evans - [SecurePrompt: Building a Pre-Flight Security Layer for Agentic AI](https://www.wearedevelopers.com/events/world-congress-2026-north-america/sessions/1431-secureprompt) — Ravi Sastry Kadali - [Vibe Coding Accessibility](https://www.wearedevelopers.com/events/world-congress-2026-north-america/sessions/1438-vibe-coding) — Karl Groves ## Watch remotely Can’t make it to San José? Watch this session live with Pro. You also get: - All full videos, bookmarks, and playlists - World Congress livestreams [See pricing](https://www.wearedevelopers.com/pricing) ## Links - [Get tickets](https://www.wearedevelopers.com/world-congress-north-america/tickets)