Join our Newsletter — 33% off our NHI Course
Home› Glossary› Foundations & NHI Taxonomy› Design Thinking
Foundations & NHI Taxonomy

Design Thinking

← Back to Glossary
By NHI Mgmt Group Updated September 24, 2026 Domain: Foundations & NHI Taxonomy

Design thinking is a problem-solving approach that starts with the customer’s needs, behaviours, and constraints before selecting a solution. In banking, it helps teams build services around real user journeys rather than internal process structures, reducing friction and improving adoption, trust, and usability across digital and physical channels.

What Design Thinking Means in Security and Product Work

Design thinking is a user-centred problem-solving method that starts with real needs, behaviours, and constraints before a solution is chosen. In security and banking, that means resisting the urge to optimise around internal workflows first.

The value of the approach is not creativity for its own sake. It is disciplined problem framing, where teams separate the underlying user problem from the current process, policy, or channel that happens to exist today.

How Design Thinking Changes Solution Discovery

Design thinking shifts the first question from “what can we build?” to “what problem are we actually solving?” That matters when organisations are designing authentication journeys, approval flows, onboarding steps, case handling, or customer support paths that can fail simply because they were built around internal convenience.

Good design thinking surfaces hidden friction, such as unnecessary handoffs, duplicated verification, or confusing language that pushes users toward unsafe workarounds. It also helps teams identify where a control is necessary but poorly placed, so the security outcome can be preserved without making the experience brittle.

The approach is iterative. Teams observe behaviour, prototype alternatives, test assumptions, and refine based on evidence rather than stakeholder preference alone. That makes it especially useful where adoption, usability, and trust all affect whether a control is followed in practice.

Why It Matters for Trust, Adoption, and Usability

In regulated and security-sensitive environments, poor usability often becomes a security problem. When legitimate users struggle to complete a process, they may delay actions, contact support, reuse steps, or seek informal shortcuts that weaken control integrity.

Design thinking helps teams understand where trust is built or lost. A process that feels opaque, inconsistent, or disconnected from the user’s goal can reduce adoption even if it is technically correct. A process that is clear, respectful of context, and aligned to real journeys is more likely to be used as intended.

That is why design thinking is useful for services that span digital and physical channels. The strongest outcome is often not the flashiest interface, but a simpler end-to-end journey that preserves the needed safeguards while reducing avoidable friction.

Where Design Thinking Sits in Delivery and Governance

Design thinking is best treated as a cross-functional method, not a standalone deliverable. It works when product, operations, risk, compliance, security, and service teams share a common view of the user journey and the control intent behind it.

It is also a strong complement to secure-by-design practices when the goal is to make the secure path the easiest path. For product and platform teams, resources such as the CISA Secure by Design principles help anchor that mindset in concrete product choices. For programs that need to align user experience with privacy and security obligations, the EU Cyber Resilience Act and EU General Data Protection Regulation (GDPR) provide a useful external reference point for secure and privacy-aware design expectations.

Risk and Threat Considerations

Poorly applied design thinking can create the opposite of its intent: attractive experiences that hide weak controls, skip user validation, or over-simplify a journey until important safeguards are bypassed. The risk is not the method itself, but the assumption that better UX automatically means better security or better outcomes.

Failure mechanism: Teams optimise for visible convenience while ignoring user abuse paths, exception handling, or the operational reality of how people complete work under time pressure. That can produce processes that are easy to start but hard to govern, especially when edge cases and control exceptions were not tested early.

Impact: Organisations can end up with lower control effectiveness, inconsistent adoption, and more workarounds, which in turn increases error rates and weakens trust in the service. In security-sensitive journeys, those failures can also make unsafe steps feel normal to users.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-16 — Application Software SecurityDesign thinking helps shape secure user journeys and safer application flows.
Recommendation — Embed security review into user-journey design to reduce unsafe workarounds and control friction.
NIST CSF 2.0GV.OC-01 — Organizational ContextDesign thinking starts by understanding the user and business context before solution choice.
Recommendation — Define the user and business context before selecting controls or service designs.
ISO/IEC 27001:2022A.5.15 — Access controlDesign-led journeys often determine how access steps are experienced and followed.
Recommendation — Design access processes so control intent remains clear and usable in practice.

Practitioner Guidance

Common misunderstanding: Design thinking is not a branding exercise or a workshop label. Its value comes from disciplined problem discovery, explicit trade-off handling, and repeated testing against actual user behaviour, not from producing a polished journey map.

Practitioner note: The most useful question is often whether the proposed experience still works when users are stressed, distracted, or forced off the ideal path. If it does not, the design is not yet ready for operational reality.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 24, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org