a NIST blog
When was the last time a cybersecurity process at work made you want to scream? Maybe it was a password requirement so complicated you had to write it down (defeating the purpose), a phishing simulation test that felt more like a trap than a lesson, or a confusing security warning pop-up that interrupted your work. Or maybe you’re on the other side of the equation, working as a cybersecurity professional who is wrangling a half dozen disconnected dashboards, drowning in alerts (all flagged "urgent"), or struggling to make a sound judgment call at midnight because you’re tired and your tools weren't built with your actual workflow in mind. If any of that sounds familiar, you're not alone — and it’s a bigger deal than you might think.
Despite decades of investment in cybersecurity software, hardware, and training, cyber breaches keep happening. Many of those breaches trace back not to technology failures, but to the so-called “human element,” for example, someone clicking a malicious link, reusing or setting an easy-to-guess password, configuring the wrong setting, or resorting to a less-secure workaround just to get their work done [1]. At NIST, we’ve taken notice. To address the human element, we just released a concept paper about what we call human-centered cybersecurity and want to hear from you to help us decide what comes next.
Human-Centered Cybersecurity and Why You Should Care
Human-centered cybersecurity (HCC for short) is an approach that focuses on improving cybersecurity outcomes by putting people (everyone who impacts or is impacted by cybersecurity) and their needs, abilities, and limitations at the forefront when designing, implementing, and making decisions about cybersecurity. Above all, we see people not just as vulnerabilities to be contained; they’re also defenders, reporters, and problem-solvers to be empowered.
HCC matters because the stakes of not doing it are high: burnout among security professionals [2][3]; employee frustration, mistakes, and noncompliance [4][5]; and harm to the business through lost productivity, money, and reputation [3][6]. HCC isn’t just a fringe idea—major industry, research, and government voices have flagged the human element as central to modern cybersecurity programs [7][8][9].
The “How-To” Gap and NIST’s Plan to Close It
Despite increasing recognition, existing authoritative cybersecurity publications and frameworks do not always include or incorporate HCC considerations beyond recommendations to train employees. But, awareness training alone (while still helpful) isn’t cutting it. Overreliance on training creates unrealistic expectations that employees will commit the knowledge to memory, understand the concepts, and always make the “right” decisions, without addressing the root causes of many cybersecurity issues, like hard-to-use and disruptive security processes or an uninformed organizational security culture.
NIST wants to fill this advice gap. The concept paper describes our intention to develop practical guidelines and resources—complementing existing NIST cybersecurity publications—that can help organizations implement HCC. We summarize HCC themes we’ve observed over the past few years and suggest possible approaches and formats. Importantly, we didn’t just come up with these points on our own; our effort is grounded in input we’ve received from hundreds of cybersecurity practitioners and researchers via surveys, interviews, workshops, and other conversations. Like NIST’s other open and transparent stakeholder-informed cybersecurity efforts, you could say our approach is itself human-centered — developed with the community, not handed down to them.
Let’s Build This Together!
Ultimately, we want our HCC guidelines and resources to be valuable to organizations of all types and sizes… so, we need your feedback! We invite you to review our “Human-Centered Cybersecurity Guidelines and Resources Concept Paper” and weigh in by September 30, 2026, by emailing us at human-cybersec [at] nist.gov (human-cybersec[at]nist[dot]gov).
This is a unique opportunity to help shape new NIST human-centered cybersecurity guidelines from the ground up. We hope you join us on this journey!
To stay involved and informed of what comes next, join our mailing list and HCC Community of Interest by following the links on the NIST Human-Centered Cybersecurity website.
References:
[1] Verizon. (2025). 2025 Data Breach Investigations Report. https://www.verizon.com/business/resources/reports/dbir/
[2] Gupta, V., Rangarajan, A., & Nobles, C. (2024). Burnout in the Cybersecurity Profession: A Scoping Review. In Proceedings of the 19th Midwest Association for Information Systems Conference. 2024. https://aisel.aisnet.org/mwais2024/20
[3] Nobles, C. (2025, March). Exploring mitigative strategies to prevent burnout in cybersecurity. In Proceedings of the 19th International Conference on Cyber Warfare and Security. https://doi.org/10.34190/iccws.20.1.3347
[4] Stanton, B., Theofanos, M.F., Prettyman, S.S., & Furman, S. Security Fatigue. (2016). IT Professional, 18(5), 26-32. https://ieeexplore.ieee.org/stamp/stamp.jsp?arnumber=7579112
[5] Von Preuschen, A., Schuhmacher, M. C., & Zimmermann, V. (2024). Beyond fear and frustration: Towards a holistic understanding of emotions in cybersecurity. In Proceedings of the Twentieth Symposium on Usable Privacy and Security (SOUPS 2024) (pp. 623-642). https://www.usenix.org/system/files/soups2024-von-preuschen.pdf
[6] Mizrak, F., Demirel, H.G., Yaşar, O., & Karakaya, T. (2025). Digital detox: exploring the impact of cybersecurity fatigue on employee productivity and mental health. Discover Mental Health, 5(1), 25. https://doi.org/10.1007/s44192-025-00149-x
[7] Gartner. (2023). Gartner identifies the top cybersecurity trends for 2023: Security leaders must pivot to a human-centric focus to establish an effective cybersecurity program. https://www.gartner.com/en/newsroom/press-releases/04-12-2023-gartner-identifies-the-top-cybersecurity-trends-for-2023
[8] Networking and Information Technology Research and Development Subcommittee of the National Science and Technology Council. (2023, December). Federal Cybersecurity Research and Development Strategic Plan. https://www.nitrd.gov/pubs/Federal-Cybersecurity-RD-Strategic-Plan-2023.pdf
[9] National Academies of Sciences, Engineering, and Medicine. (2025). Cyber Hard Problems. https://nap.nationalacademies.org/resource/29056/CyberHardProblems-2025.pdf