What a trip to the supermarket can teach you about writing security tickets that engineers actually…
This is a story about connecting threads and combining ideas from different experiences, as much as it is about engineering, security, or…
What a trip to the supermarket can teach you about writing security tickets that engineers actually fix.

This is a story about connecting threads and combining ideas from different experiences, as much as it is about engineering, security, or human biases and behavior. I’ve spoken on this topic at re:Inforce in Philadelphia and re:Inforce reCap in London in 2025, and there were many questions, so I thought I’d put pen to paper, so to speak, and share it with a wider audience.
Around 2006, I was buried in a case study on product placement, the physical kind of product in the real world, which just happened to be a jam and jelly company. The case study centered on slotting fees that would need to be paid to secure favorable shelf space for a regional company on the US West Coast, which was considering expanding further into the Midwest. I knew the case was about money, it always is right; I think the formula in this case is Payback months ≈ slotting $ ÷ (monthly incremental units × gross margin/unit × expected retention%). I had never heard of this, is what we see at eye level in stores really intentionally planned. The answer is yes, of course it is, and so are so many other things that you may not notice. It turns out that most people do take the easiest path, and that path often does not include reaching for the top or the bottom of the supermarket shelves, so companies will pay to be on the easy path.
At around the same time, Thaler and Sunstein were about to publish their book, Nudge, in 2008, offering a different perspective on the conventional theory that all humans make perfectly rational choices. There were two main takeaways for me. First, the concept of choice architecture and choice architects (spoiler: we are all choice architects) was introduced, and second, the examination of human biases that influence choice architecture was presented.
Choice architecture involves designing experiences or environments that make it easier for users or individuals to choose the option you prefer them to take. You may also see this described as context. In Nudge theory, individuals always retain the freedom to choose any path; architects design the environment to make the path aligning with their goals easier to select. Slotting fees, where companies pay to be at eye level, influence sales; however, individuals still have the option to choose items from both the bottom and top shelves.
Question: What represents eye level for your specific business problem?
Product placement on shelves is not the only aspect of your trip to the supermarket that has been carefully thought out and intentionally designed. Perhaps if you have small children or a fondness for candy and toys, you have encountered product placement at the checkout lane, where items are deliberately positioned at the eye level of typical children’s height.
Lesson: Meet your customers where they are.
You might have noticed yourself walking a bit further to pick up milk or eggs, as many perishable items, such as dairy and meats, are usually placed at the far edges of the store. This setup naturally leads you to explore more of the aisles in your shopping trip. Even the placement of produce near the front entrance in most stores is intentional; research indicates that after choosing healthy options, you’re more likely to indulge when passing through the snack aisles on your way to pick up a dozen eggs.
Placement matters; however, this represents an antipattern for your use case. Your customers should not have to explore the store.
Ok, so we’ve discussed making things easier for the customer. Now, let’s explore human biases before we tie all of this together and apply it to security teams crafting messages for engineers.
In traditional economic theory, it’s assumed that people act rationally, possess all the necessary information to make decisions, have the computational power to process this information, and always choose the optimal option to maximize their happiness. We know that’s not the case; we make irrational choices all the time, mainly because we’re influenced by framing and context, use shortcuts, have biases, and, honestly, who has all the time in the world, not to mention perfect information?
Let’s discuss biases and framing. Biases are mental shortcuts we all use to save time and make quick decisions when information is limited. We have trouble with probabilities and struggle to weigh options accurately; combine that with making mistakes and misjudging time, and it’s clear that messaging plays a key role in how effectively you can convert customers. We can categorize common biases into three main areas: how we perceive time, numbers, and our behavior in groups. When it comes to security communications, we want them to be broadly appealing, prompt immediate action, and provide information that nudges recipients toward the desired response, leading to quicker resolution and saving the recipient’s time.
With that in mind, we’ll only cover a few biases here, and you can certainly explore many more.
We can classify common biases into three categories: perceptions of time, perceptions of numbers, and perceptions of group behavior. In security communications, our goal is to make messages widely appealing, encourage quick responses, and include information that gently steers recipients toward the intended action, leading to faster fixes and saving their time. We will focus on only a few biases here, but there are many more you can explore.
About numbers and probability.
Some biases we have related to numbers and probability that influence our judgment of value include anchoring, loss aversion, and framing.
Loss aversion is a bias where people feel a loss about twice as strongly as an equivalent gain. You notice this at the supermarket with signs like “Sale Ends: save $5 on coffee through Saturday,” “Last Chance,” or “Limit 5.” You might not have needed coffee, but suddenly you feel you have to buy it now or you’ll miss the discount.
Anchoring is a bias where the first number we see becomes our starting point. Have you ever been to the store and noticed the signs that say “Was $9.99, Now $4.99,” or maybe eye-level displays with a row of higher-priced products and just below eye level a similar but lower-priced option, like the cover image of this post? You’ve just encountered anchoring, and all of a sudden $4.99 seems like a steal when compared to the old price.
Framing is when the same object or idea feels different depending on how it is described. Imagine, close your eyes and imagine that I describe ground beef as 90% lean, this sounds familiar, it’s the middle price point in most US supermarkets between the 85% and 95% options. Now, let me reframe that. Let’s describe it as 10% fat. Same product, different feel.
About time.
Hyperbolic discounting describes how humans prioritize short-term gains over future rewards, even if the short-term benefit is smaller or could cause long-term harm. This is probably the main reason for procrastination.
About how we perceive ourselves in groups.
Social proof is the idea that we observe what others are doing and assume they are making the right choice. There’s another aspect to this: we rely more heavily on this bias when we are unsure about the decision or choice we are about to make. Think about your last few tough decisions. Did you survey the situation, consult with others, seek expert advice, or rationalize your decision because you felt most people do it this way? In practice, at the store, you might see “Bestseller” labels, or, to be honest, have you looked for a product and noticed one brand with a shelf that’s emptier than the others and thought, “That’s the one!”; if most people choose it, it must be better in some way.
Now, let’s consider slotting fees, product placement, and some human biases, and apply these principles to make your security tickets easier to understand and more actionable for engineering teams. This leads to shorter remediation times, reduced overall risk, and less engineering time spent on tasks unrelated to product development.
A common question after discussing this topic is, “How do I get started?” The answer is simple: review your communication to find ways to improve context and simplify the language, while being aware of human biases and how they might affect the ticket closure rate. We used to think this would take months of planning, involve the marketing department, maybe some experts in human behavior, and subject-matter experts before you even start iterating. You can cut both time and complexity by leveraging AI.
I’ll outline a simple plan below, but keep in mind that you need all the steps to ensure you’re adding value to the business and not just making changes for the sake of it.
First, you’ll need to assess your current state and identify the behaviors you want to change. In the example above, we discuss ticket closure rates because the behavior we want to target is the speed at which the action is performed in the ticket and our hypothesis is that clear language and well defined steps will increase this so we’ll target choice arcitecture changes first, but just like you learned in science class we need to measure where we are now before we test our hypothesis, so we measure the current speed of ticket closure to establish the current baseline.
Next, you can utilize large language models (LLMs) to create a text auditor. This tool is designed to pinpoint areas for improvement in communication. Because the concepts are familiar, similar to the 4Cs: customer, cost to satisfy, convenience, and communication, these foundational models, which are rich in context, can support your efforts. Consider employing tools like Partrock or other AI platforms, but be cautious about the information you share and formulate a clear prompt. Here’s an example prompt:
Prompt: Quick Communication Auditor (Clarity + Choice Architecture)
You are a Quick Communication Auditor and Choice Architect.
Your job is to review the technical communication below and rewrite it so the recipient clearly understands:
- What they need to do
- How to do it (step-by-step)
- By when
- Why it matters (briefly)
While rewriting, apply the fundamentals of choice architecture to help the recipient follow through without confusion or extra effort.
Choice Architecture Fundamentals To Use. When you audit/rewrite, explicitly improve these:
1) Simplify & cut friction
- Remove jargon or define it once, simply.
- Reduce steps.
- Put the smallest possible “next action” first.
2) Make the desired action salient (obvious)
- Highlight the single most important action.
- Use headings, bullets, or numbering to surface priorities.
- Avoid burying key requirements mid-paragraph.
3) Use good defaults / recommended paths
- If there’s a preferred approach, label it clearly: “Recommended path.”
- If there are multiple options, provide a default suggestion and when to use alternatives.
4) Sequence tasks in the order people actually do them
- Put steps in real execution order.
- One action per step.
- Include inputs/tools needed right where they’re used.
5) Be timely & concrete
- Replace vague timing (“soon,” “ASAP”) with exact deadlines.
- If urgency matters, explain it in one line.
6) Support confidence & completion
- Add a short “success check” (“You’re done when…”)
- Add “If stuck, do X / contact Y.”
What to Produce
Return your answer in this exact structure:
A) One-sentence plain-English summary
- What this message is really saying.
B) Recipient action checklist (bullets)
- What to do (most important first)
- How to do it
- Tools/links/inputs needed
- Deadline(s)
- Who to contact if stuck
- “Done when…” success check
C) Where it’s unclear or too technical
For each issue:
- Quote the confusing phrase
- Why it may confuse a busy non-expert
- A simpler replacement
D) Rewritten version (simple, direct, choice-architected)
- 7th–9th grade reading level
- Short
- Numbered steps
- Preferred/default path labeled
- Key action stated in the first 2 lines
- Concrete deadlines
- “Done when…” line at the end
Ok, now you should have an idea of what changes you need to make and how far your current communication is from the principles of choice architecture.
Finally, send out your new text. Wait. Measure. Wait. Measure. Iterate.
What about the biases that were discussed? Once you have a simple, clear, actionable message that doesn’t confuse the recipient with jargon and unclear language, you can perform the same steps using prompts to audit for bias or ask that the text use them where appropriate.
Here’s an example of loss aversion in communication: imagine you have an automated system that prevents engineers from doing manual work but requires time to onboard. You might rewrite the message to highlight how much time a team loses by not using an automated system, framing security automation as a time saver compared to the cost of automation.
I hope this helps you to start thinking about where you can simplify and make communication easier. Additionally, if you start thinking about processes and communication that need improvement by starting with the measurable change you would like to see, you can leverage AI tools to do things that were not possible without a large team just 5 years ago.
By Joshua McDonald on November 20, 2025.
Exported from Medium on August 26, 2026.
Reader discussion