Patch Me If You Can by Kandji

Episode 001 - Balancing Security vs. User Experience with Richard Hiralal, Grammarly

Written by Kandji Team | May 8, 2025 7:44:25 PM

In this episode of Patch Me If You Can, Arek Dreyer welcomes Richard Hiralal, a Systems Engineer at Grammarly, for a revealing conversation about the realities of maintaining secure systems without sacrificing user experience. Dreyer introduces Richard as someone who not only understands the technical demands of endpoint security but also has a keen sense for how organizational friction arises between users, IT, and security teams. Richard’s background in keeping critical systems protected while ensuring productivity sets the stage for an exploration of what it takes to design and uphold modern, user-friendly security practices.

A central theme of the discussion is the delicate balance between enforcing strong security measures and enabling a smooth user experience. Richard shares detailed examples, such as the challenges of Chrome patching at Grammarly—where repeated urgent updates threatened to frustrate users. He highlights how transparent communication about “the why,” collaboration across teams, and thoughtful rollout strategies (including deferral mechanisms and pilot user groups) led to higher compliance and greater trust between IT, security, and end users. They also unpack the dangers of working in silos, recounting past missteps where the lack of cross-team input resulted in cumbersome processes and negative user feedback, particularly during the implementation of privilege access management tools.

Throughout the episode, Richard emphasizes the vital role of empathy, communication, and collaboration in IT. By involving help desks in policy formulation, demystifying the rationale behind controls for end users, and designing documentation with the non-technical employee in mind, organizations can ensure both security and usability. The conversation ends on a big-picture note, with Richard advocating for a shift in how companies perceive IT—not just as a cost center, but as an enabler of productivity, trust, and business success, underscoring the strategic value that proactive, user-centric IT teams bring to the table.