a NIST blog
When was the last time a cybersecurity process at work made you want to scream? Maybe it was a password requirement so complicated you had to write it down (defeating the purpose), a phishing simulation test that felt more like a trap than a lesson, or a confusing security warning pop-up that interrupted your work. Or maybe you’re on the other side of the equation, working as a cybersecurity professional who is wrangling a half dozen disconnected dashboards, drowning in alerts (all flagged "urgent"), or struggling to make a sound judgment call at midnight because you’re tired and your tools weren't built with your actual workflow in mind. If any of that sounds familiar, you're not alone — and it’s a bigger deal than you might think.
Despite decades of investment in cybersecurity software, hardware, and training, cyber breaches keep happening. Many of those breaches trace back not to technology failures, but to the so-called “human element,” for example, someone clicking a malicious link, reusing or setting an easy-to-guess password, configuring the wrong setting, or resorting to a less-secure workaround just to get their work done [1]. At NIST, we’ve taken notice. To address the human element, we just released a concept paper about what we call human-centered cybersecurity and want to hear from you to help us decide what comes next.
Human-Centered Cybersecurity and Why You Should Care
Human-centered cybersecurity (HCC for short) is an approach that focuses on improving cybersecurity outcomes by putting people (everyone who impacts or is impacted by cybersecurity) and their needs, abilities, and limitations at the forefront when designing, implementing, and making decisions about cybersecurity. Above all, we see people not just as vulnerabilities to be contained; they’re also defenders, reporters, and problem-solvers to be empowered.
HCC matters because the stakes of not doing it are high: burnout among security professionals [2][3]; employee frustration, mistakes, and noncompliance [4][5]; and harm to the business through lost productivity, money, and reputation [3][6]. HCC isn’t just a fringe idea—major industry, research, and government voices have flagged the human element as central to modern cybersecurity programs [7][8][9].
The “How-To” Gap and NIST’s Plan to Close It
Despite increasing recognition, existing authoritative cybersecurity publications and frameworks do not always include or incorporate HCC considerations beyond recommendations to train employees. But, awareness training alone (while still helpful) isn’t cutting it. Overreliance on training creates unrealistic expectations that employees will commit the knowledge to memory, understand the concepts, and always make the “right” decisions, without addressing the root causes of many cybersecurity issues, like hard-to-use and disruptive security processes or an uninformed organizational security culture.
NIST wants to fill this advice gap. The concept paper describes our intention to develop practical guidelines and resources—complementing existing NIST cybersecurity publications—that can help organizations implement HCC. We summarize HCC themes we’ve observed over the past few years and suggest possible approaches and formats. Importantly, we didn’t just come up with these points on our own; our effort is grounded in input we’ve received from hundreds of cybersecurity practitioners and researchers via surveys, interviews, workshops, and other conversations. Like NIST’s other open and transparent stakeholder-informed cybersecurity efforts, you could say our approach is itself human-centered — developed with the community, not handed down to them.
Let’s Build This Together!
Ultimately, we want our HCC guidelines and resources to be valuable to organizations of all types and sizes… so, we need your feedback! We invite you to review our “Human-Centered Cybersecurity Guidelines and Resources Concept Paper” and weigh in by September 30, 2026, by emailing us at human-cybersec [at] nist.gov (human-cybersec[at]nist[dot]gov).
This is a unique opportunity to help shape new NIST human-centered cybersecurity guidelines from the ground up. We hope you join us on this journey!
To stay involved and informed of what comes next, join our mailing list and HCC Community of Interest by following the links on the NIST Human-Centered Cybersecurity website.
References:
[1] Verizon. (2025). 2025 Data Breach Investigations Report. https://www.verizon.com/business/resources/reports/dbir/
[2] Gupta, V., Rangarajan, A., & Nobles, C. (2024). Burnout in the Cybersecurity Profession: A Scoping Review. In Proceedings of the 19th Midwest Association for Information Systems Conference. 2024. https://aisel.aisnet.org/mwais2024/20
[3] Nobles, C. (2025, March). Exploring mitigative strategies to prevent burnout in cybersecurity. In Proceedings of the 19th International Conference on Cyber Warfare and Security. https://doi.org/10.34190/iccws.20.1.3347
[4] Stanton, B., Theofanos, M.F., Prettyman, S.S., & Furman, S. Security Fatigue. (2016). IT Professional, 18(5), 26-32. https://ieeexplore.ieee.org/stamp/stamp.jsp?arnumber=7579112
[5] Von Preuschen, A., Schuhmacher, M. C., & Zimmermann, V. (2024). Beyond fear and frustration: Towards a holistic understanding of emotions in cybersecurity. In Proceedings of the Twentieth Symposium on Usable Privacy and Security (SOUPS 2024) (pp. 623-642). https://www.usenix.org/system/files/soups2024-von-preuschen.pdf
[6] Mizrak, F., Demirel, H.G., Yaşar, O., & Karakaya, T. (2025). Digital detox: exploring the impact of cybersecurity fatigue on employee productivity and mental health. Discover Mental Health, 5(1), 25. https://doi.org/10.1007/s44192-025-00149-x
[7] Gartner. (2023). Gartner identifies the top cybersecurity trends for 2023: Security leaders must pivot to a human-centric focus to establish an effective cybersecurity program. https://www.gartner.com/en/newsroom/press-releases/04-12-2023-gartner-identifies-the-top-cybersecurity-trends-for-2023
[8] Networking and Information Technology Research and Development Subcommittee of the National Science and Technology Council. (2023, December). Federal Cybersecurity Research and Development Strategic Plan. https://www.nitrd.gov/pubs/Federal-Cybersecurity-RD-Strategic-Plan-2023.pdf
[9] National Academies of Sciences, Engineering, and Medicine. (2025). Cyber Hard Problems. https://nap.nationalacademies.org/resource/29056/CyberHardProblems-2025.pdf
As a Doctor of Health Informatics candidate, machine learning developer, and Clinical Laboratory Scientist with more than two decades of frontline healthcare experience, I strongly support NIST’s shift toward human-centered cybersecurity (HCC).
Working in high-volume diagnostic laboratory environments has shown me firsthand that poorly integrated software can create cognitive burden at exactly the moment people need to make careful decisions. Confusing warnings, disruptive authentication workflows, fragmented dashboards, and security processes that do not reflect the realities of frontline work can contribute to fatigue and workarounds rather than better security outcomes.
That experience has also influenced how I design AI systems. In developing projects such as DiagNosticEHR, a malaria-detection application, and my Product Safety Recall Intelligence Agent at productsafety.bryerstone.com, I have tried to keep the human operator at the center of the architecture. The Product Safety Agent, for example, uses CPSC recall evidence to produce explainable safety prioritization while preserving the underlying source evidence, reasoning path, governance state, and audit trail for human review. The objective is not to replace professional judgment, but to make that judgment better supported and easier to verify.
I see a strong parallel in cybersecurity. Relying primarily on awareness training to compensate for difficult systems can push systemic design problems onto the end user. It is similar to deploying an inadequately designed analytical model and expecting frontline personnel to continually compensate for its weaknesses.
Human-centered cybersecurity instead recognizes that people are not merely vulnerabilities to be controlled. They are defenders, reporters, decision-makers, and problem-solvers who should be supported by systems designed around their actual capabilities, limitations, and workflows.
By treating the human operator as an active component of the security architecture rather than a problem to be patched, NIST’s HCC initiative can help close an important gap between cybersecurity policy and operational reality.
Glenford Robinson
Clinical Laboratory Scientist | 23 years of frontline clinical laboratory experience
Doctor of Health Informatics Candidate, Rutgers University | AI/ML Developer
Founder & Developer, DiagNosticEHR
There’s a book called Human-Centered Security, by Heidi Trost. I only just started reading it.