Program JavaZone

Foredrag Onsdag 2. september

Secure-by-Inclusion: Preventing Accessibility Barriers from Becoming Security Vulnerabilities

Room 4

Engelsk 45 min accessibility security testing inclusion secure-by-inclusion

Radostina (Ina) Tsvetkova

Radostina (Ina) Tsvetkova is a Senior Advisor in Digital Accessibility and Inclusive Design at the Norwegian Directorate of Labour and Welfare (NAV). Ina was recognized as one of Norway’s top 50 women in Tech in 2026. She is also an Invited Expert in the W3C Accessibility Guidelines Working Group, a Certified Professional in Web Accessibility (CPWA), a DHS Trusted Tester, and an ISTQB Advanced Level Test Manager and Test Analyst.

Ina provides guidance on digital accessibility throughout the product development lifecycle, from early planning and design through development, testing, and procurement. She has participated in the development of two Norwegian standards on accessibility in procurement and accessibility in the workplace, as well as the European standard “Accessible Systems for Living Independently.”

Ina is a passionate advocate for an accessible and inclusive world for all, regardless of ability.

What happens when security measures cannot be used by everyone? Any security control that is not accessible becomes a barrier, and barriers trigger unsafe workarounds that create security risks.

We face a paradox, security mechanisms designed to protect users can systematically exclude the most vulnerable populations, including people with disabilities and older adults, and this exclusion can become an exploitable vulnerability. Users facing accessibility barriers often adopt insecure coping mechanisms: they share passwords, delegate authentication to others, store credentials insecurely, rely on weaker fallback paths, or abandon security measures altogether. Each workaround is a predictable security failure caused not by user negligence, but by design choices that made the secure path inaccessible.

This presentation introduces Secure-by-Inclusion, a new practical approach that ensures security controls actually function for all intended users across diverse abilities, devices, and assistive technologies. We will walk through common patterns where security and accessibility collide, including CAPTCHAs, multi-factor authentication, biometric authentication, time-limited one-time codes, brittle account recovery flows, and inaccessible verification steps. We will also look into the European Accessibility Act (EAA) and the WCAG 2.2 Accessible Authentication requirements, examining their implications for security design and testing.

Accessibility and security might seem like separate disciplines, but they share common goals: protecting users and ensuring inclusive, trustworthy digital experiences.

Security and QA engineers, Developers, Test Managers, Security testers, Accessibility testers, Test managers, Technical leads and architects

  1. Hacking i "gamle" dager - røverhistorier fra 80- og 90-tallet Room 1
  2. Snake in 10 Lines: Learning More by Coding Less Room 2
  3. How Are We Doing? Practical Metrics that Matter Room 3
  4. Let's Dance! - Teaching your Robot some Moves with Reinforcement Learning Room 5