Bas Hoorn: 'A good password manager makes safe behavior a matter of course'

About
Nieuws
identify
Bas Hoorn: 'A good password manager makes safe behavior a matter of course'
According to Bas Hoorn, founder of Timension, user-friendliness is not a “nice to have” in security, but a prerequisite for maintaining safe behavior. But how do you properly incorporate that into a password manager?
Merijn de Jonge
Founder & CEO
Nieuws
identify
Bas Hoorn: 'A good password manager makes safe behavior a matter of course'
According to Bas Hoorn, founder of Timension, user-friendliness is not a “nice to have” in security, but a prerequisite for maintaining safe behavior. But how do you properly incorporate that into a password manager?
Merijn de Jonge
Founder & CEO

Start making vulnerable passwords impossible today

Thank you for your request! We will contact you within 1 business day.
Please fill in all fields before submitting the form

Password managers are a special category of software. In contrast to regular applications, users always work on two tracks at the same time: on the one hand, there is the password manager, and on the other, the application in which they want to log in. The fact that applications vary a lot from each other, and look visually different from a password manager, makes things even more complex.

UX as a response to unnecessary complexity

Bas became involved with MindYourPass when the product was still in its early stages. Initially, he was hired to develop training courses. Early on, however, he noticed that many user questions, errors, and frustrations came not so much from a lack of explanation, but from the user experience of the product itself. Because Bas had also designed user interfaces at an earlier stage in his career, he was asked to look at the product from that combined perspective, trainer and UX designer.

The product worked technically well at the time, but the user experience was unnecessarily complex. For example, too many functionalities were offered at the same time and actions were not always logically positioned in the flow. Because the use of a password manager is already complex by definition, it is important that the password manager interface does not add extra cognitive load and guides users through the right steps at the right time. The UX approach therefore initially focused not on making the interface intuitive, but on removing everything that was not intuitive in the flow as much as possible, Bas explains.

Competence as key to safe behavior

The failure of security is rarely due to user reluctance, says Bas. In most organizations, people want to work safely, but are stuck on complexity, time pressure and unclear tooling. Password managers are often technically functional, but do not match how people actually work. Especially when the mental burden is already high, users are confronted with extra steps, choices and warnings. This does not lead to safer behavior, but to frustration and ultimately to workarounds: exactly the risk that is removed by MindYourPass.

A central factor in safe behavior is the sense of competence, says Bas. “People need to feel that they know what they're doing and that they can't make mistakes at the expense of safety.” As soon as that feeling is missing, uncertainty occurs. Uncertainty leads to avoidance, half understanding and the search for faster but more unsafe solutions. “I see this every day in training and user research. When people feel stupid about a security solution, they drop out demotivated, and that's risky when using a password manager. Maintaining safe behavior is only possible if users experience that they have the situation under control.”

User-friendliness is a fundamental prerequisite

Many organizations invest in explanations, training and awareness campaigns. That is useful, but it is not enough. People forget instructions and make mistakes under pressure, and a good password manager should anticipate that, says Bas. “You can't expect all users to understand security. This is where solutions designed so that safe behavior is the easiest and only option. User-friendliness is not an extra layer on top of security, but a fundamental prerequisite for policy to work in practice.”

In addition, secure password use within organizations should ultimately be made mandatory, says Bas. That sounds strict, but enforcement does not have to lead to frustration. On the contrary, if the tooling is properly arranged, it actually gives users peace of mind. They no longer have to think about what is allowed or what is not allowed. The system must serve this purpose. The prerequisite is that the solution is reliable, predictable and learnable.

In addition to technology and design, the organizational context also plays a major role. That's why MindYourPass works with ambassadors within organizations: superusers who help colleagues, answer questions and identify where people get stuck. The success of adoption depends heavily on this role. Remarkably, these are not always the people with the toughest IT background, says Bas. They are often pragmatic, curious users who don't give up easily, like to figure out how something works and communicate easily in the workplace. They form the bridge between technology and daily practice.

Safe behavior should feel effortless

The core of Bas's vision is that security only works when people don't have to think about it all the time. A good password manager makes safe behavior natural by removing uncertainty, preventing errors and serving the end user and the organization. User-friendliness and enforceability are not opposites, but reinforce each other. If you want security to work in practice, you need to design for the human brain, taking into account a variety of user scenarios and personas.

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

“Juist de collega’s die in het begin sceptisch waren, werden later de grootste ambassadeurs,”- addsadasd

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

Get in touch with us.

Let MindYourPass make your organization safe.

Thank you for your request! We will contact you within 1 business day.
Please fill in all fields before submitting the form
Want to read more?
See other articles
More articles
The MindYourPass Solution

Log in securely with ease.
At home and at work.

Triple-i™ improvement method

Wachtwoordveiligheid meten om doelgericht te verbeteren

Elke verandering begint met het verkrijgen van volledig inzicht in de huidige situatie. Om vanuit daar met behulp van een concreet en praktisch plan toe te werken naar de gewenste situatie: het gebruik van kwetsbare wachtwoorden binnen jouw organisatie onmogelijk maken.

Learn more about Triple-i™

Learn more about cybersecurity

See all articles
Resource
A year of innovations: this is what we built for you in 2025
Hulpartikel
What is a good password manager? Bitwarden, 1Password, Keeper, and MindYourPass compared
Customer Story
How the Kempen municipalities are taking password security to a higher level with MindYourPass
Nieuws
Peter Bronkhorst: “Cybercrime also affects small companies - are you prepared?”