Physical risks are inherently defined by the physical environment. Cyber security risks are similarly defined by the combined physical and electronic environment. However, unlike the increased risk from speed in the rain on the highway at night, the dimensions of both the combined environment and the nature of the underlying risks are not so obvious. Physical risks are often transparent, and inherently aligned with human information processing capacity: contextual, often visual, and at a pace that fits well within a human narrative. In contrast, cyber risks are ill-suited for human risk perception: either they are literally invisible or identified in a decontextualized manner. There is a critical need in computer security to communicate risks and thereby enable informed decisions by average, non-expert computer users.

Thus the design of the current research prototype includes four lines of development:

Risk Context Analysis- Creating the ability to identify a user risk context from intrinsic (user activity, history, and known network entities) and extrinsic (system configuration, location, network details) factors.

Automatic Context Response- Automatically adapt system actions and configuration to the changing context, to reduce cognitive overload on the user by taking non-controversial actions without involving the human.

Metaphorical Risk Communication- Ability to convey risk factors of a particular context to the user in narrative form consistent with the users' mental model that will be quickly and effectively understood.

Intelligent Communication- Engaging the user effectively and infrequently, appropriately, and only for the time necessary to communicate.

