Backbase

A read on how people actually decide something is safe, and why "secure" is a feeling a culture negotiates, not a fact a system proves.

METHODS

12 remote motivational interviews, journey mapping, card sorting, empathy maps, benchmark

DELIVERABLES

  • A set of 9 security motivations, the north-star for a "feels secure" experience

  • Four motivational archetypes, each with a defining quality, authentication expectations, and crucial touch-points

  • A map of how the motivations and archetypes interact

  • Key touch-points, where security and authentication matter most, by archetype

  • Empathy maps per participant, and a set of universal patterns

  • An insight-to-action workshop and a prioritised solution set (us and now, other team and now, backlog)

THE SHIFT

Started with a new passwordless authentication product that needed to prioritise its MVP features and settle its design direction, and a broad question: what does a trustworthy, secure banking experience look like for American users. Landed on a reframe of the problem itself, from "how strong is the authentication" to "what makes people feel secure," plus a north-star the team could design against, nine motivations and four archetypes, and a prioritised set of solutions built around them.

MARKETS

UNITED STATES

THE SIGNAL

Security has quietly stopped meaning safety and started meaning trust. In a market where breaches are so common they read as normal, people no longer expect to be protected from risk, so "secure" becomes a feeling built on relationship, control and reputation rather than on the strength of the lock. And the same protective behaviour, a workaround, a password ritual, comes from opposite emotional places in different people. What looks like a technical question is really a cultural one: who and what a person has decided to trust.


The Stakes.
Trust in banks is fragile and getting stranger. Traditional institutions read as old, corporate and distant, fraud is widespread enough to feel routine, and a new wave of digital-first banks is rewriting what a banking relationship even feels like. Into that, a passwordless product had to decide how to make people feel safe. The real stakes weren't the authentication mechanics, they were reading how trust and safety are being redefined by people who have learned to expect breaches, so the product could meet that shift honestly rather than out-engineer it.

The Tension.
The intuitive way to build secure authentication is to maximise it: more factors, more checks, more friction equals more secure. The research held a harder truth. Perceived security and actual security are not the same thing, and in a US market with a long fraud history, people decide whether something feels secure on trust and control, not on cryptographic strength. There was a second trap underneath it: grouping people by what they do hides why they do it. The same behaviour, a workaround, a password habit, came from opposite motivations, so designing for the behaviour would have missed the person.


The Phases.

→ Align

A stakeholder session with Product and Design to agree the features in question, the business objective, and the questions the research would answer.

→ Benchmark

Desk research on the best-in-class players in online authentication, to set the experience baseline and the known pain points.

→ Go deep

Twelve remote motivational interviews with people who had switched from major American banks to neobanks and authentication leaders, using journey mapping and a prompting exercise, so both the traditional and best-in-industry journeys surfaced.

→ Make sense, together

The team sat in on interviews, with a mid-point sharing session to catch what was striking and what was still missing. Empathy maps per person, then archetypes grouped by shared motivation rather than shared behaviour.

→ Make it stick

Insights shared and discussed, then a research-led workshop that ideated a secure experience for one archetype at each touch-point, and prioritised the solutions.


The Turn.
Security is a feeling before it is a fact. People call an experience secure when it meets their underlying motivation and gives them a sense of control, not when it is objectively strongest, and breaches are so normalised that trust is built on relationship rather than on the absence of risk. The wider signal, and why it matters beyond this project: as breaches become background noise, safety turns into an emotional and cultural judgment, decided by trust, reputation and control rather than by the lock itself. Reading how people are quietly redrawing the line between safe and unsafe is what lets you design for trust rather than just for security.