Stronger Cybersecurity Programs Start with People: NIST Wants Your Input on the Path Forward for Human-Centered Cybersecurity | NIST
Skip to main content
Official websites use .gov
A .gov website belongs to an official government organization in the United States
Secure .gov websites use HTTPS
A lock (
) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites
Stronger Cybersecurity Programs Start with People: NIST Wants Your Input on the Path Forward for Human-Centered Cybersecurity
August 17, 2026
By:Julie Haney and Jody Jacobs

Credit:
Shutterstock
When was the last time a cybersecurity process at work made you want to scream? Maybe it was a password requirement so complicated you had to write it down (defeating the purpose), a phishing simulation test that felt more like a trap than a lesson, or a confusing security warning pop-up that interrupted your work. Or maybe you’re on the other side of the equation, working as a cybersecurity professional who is wrangling a half dozen disconnected dashboards, drowning in alerts (all flagged “urgent”), or struggling to make a sound judgment call at midnight because you’re tired and your tools weren’t built with your actual workflow in mind. If any of that sounds familiar, you’re not alone — and it’s a bigger deal than you might think.
Despite decades of investment in cybersecurity software, hardware, and training, cyber breaches keep happening. Many of those breaches trace back not to technology failures, but to the so-called “human element,” for example, someone clicking a malicious link, reusing or setting an easy-to-guess password, configuring the wrong setting, or resorting to a less-secure workaround just to get their work done [1]. At NIST, we’ve taken notice. To address the human element, we just released a concept paper about what we call human-centered cybersecurity and want to hear from you to help us decide what comes next.
Human-Centered Cybersecurity and Why You Should Care
Human-centered cybersecurity (HCC for short) is an approach that focuses on improving cybersecurity outcomes by putting people (everyone who impacts or is impacted by cybersecurity) and their needs, abilities, and limitations at the forefront when designing, implementing, and making decisions about cybersecurity. Above all, we see people not just as vulnerabilities to be contained; they’re also defenders, reporters, and problem-solvers to be empowered
HCC matters because the stakes of not doing it are high: burnout among security professionals [2][3]; employee frustration, mistakes, and noncompliance [4][5]; and harm to the business through lost productivity, money, and reputation [3][6]. HCC isn’t just a fringe idea—major industry, research, and government voices have flagged the human element as central to modern cybersecurity programs [7][8][9]
The “How-To” Gap and NIST’s Plan to Close It
Despite increasing recognition, existing authoritative cybersecurity publications and frameworks do not always include or incorporate HCC considerations beyond recommendations to train employees. But, awareness training alone (while still helpful) isn’t cutting it. Overreliance on training creates unrealistic expectations that employees will commit the knowledge to memory, understand the concepts, and always make the “right” decisions, without addressing the root causes of many cybersecurity issues, like hard-to-use and disruptive security processes or an uninformed organizational security culture.
NIST wants to fill this advice gap. The concept paper describes our intention to develop practical guidelines and resources—complementing existing NIST cybersecurity publications—that can help organizations implement HCC. We summarize HCC themes we’ve observed over the past few years and suggest possible approaches and formats. Importantly, we didn’t just come up with these points on our own; our effort is grounded in input we’ve received from hundreds of cybersecurity practitioners and researchers via surveys, interviews, workshops, and other conversations. Like NIST’s other open and transparent stakeholder-informed cybersecurity efforts, you could say our approach is itself human-centered — developed with the community, not handed down to them.
Let’s Build This Together!
Ultimately, we want our HCC guidelines and re, we need your feedback! We invite you to review our “Human-Centered Cybersecurity Guidelines and Reling us at human-cybersec [at] nist.gov(human-cybersec[at]nist[dot]gov)
This is a unique opportunity to help shape new NIST human-centered cybersecurity guidelines from the ground up. We hope you join us on this journey!
To stay involved and informed of what comes next, join our mailing list and HCC Community of Interest by following the links on the NIST Human-Centered Cybersecurity website
References:[1] Verizon. (2025). 2025 Data Breach Investigations Report. https://www.verizon.com/business/re
[2] Gupta, V., Rangarajan, A., & Nobles, C. (2024). Burnout in the Cybersecurity Profession: A Scoping Review. In Proceedings of the 19th Midwest Association for Information Systems Conference. 2024. https://aisel.aisnet.org/mwais2024/20
[3] Nobles, C. (2025, March). Exploring mitigative strategies to prevent burnout in cybersecurity. In Proceedings of the 19th International Conference on Cyber Warfare and Security. https://doi.org/10.34190/iccws.20.1.3347
[4] Stanton, B., Theofanos, M.F., Prettyman, S.S., & Furman, S. Security Fatigue. (2016). IT Professional, 18(5), 26-32. https://ieeexplore.ieee.org/stamp/stamp.jsp?arnumber=7579112
[5] Von Preuschen, A., Schuhmacher, M. C., & Zimmermann, V. (2024). Beyond fear and frustration: Towards a holistic understanding of emotions in cybersecurity. In Proceedings of the Twentieth Symposium on Usable Privacy and Security (SOUPS 2024) (pp. 623-642). https://www.usenix.org/system/files/soups2024-von-preuschen.pdf
[6] Mizrak, F., Demirel, H.G., Yaşar, O., & Karakaya, T. (2025). Digital detox: exploring the impact of cybersecurity fatigue on employee productivity and mental health. Discover Mental Health, 5(1), 25. https://doi.org/10.1007/s44192-025-00149-x
[7] Gartner. (2023).Gartner identifies the top cybersecurity trends for 2023: Security leaders must pivot to a human-centric focus to establish an effective cybersecurity program. https://www.gartner.com/en/newsroom/press-releases/04-12-2023-gartner-identifies-the-top-cybersecurity-trends-for-2023
[8] Networking and Information Technology Research and Development Subcommittee of the National Science and Technology Council. (2023, December). Federal Cybersecurity Research and Development Strategic Plan. https://www.nitrd.gov/pubs/Federal-Cybersecurity-RD-Strategic-Plan-2023.pdf
[9] National Academies of Sciences, Engineering, and Medicine. (2025). Cyber Hard Problems. https://nap.nationalacademies.org/re
About the author

Julie Haney is a Computer Scientist in the Visualization and Usability Group at the National Institute of Standards and Technology. She leads the NIST Human-Centered Cybersecurity Program and conducts research about the human element of cybersecurity and privacy. Previously she spent over 20 years working at Department of Defense as a cybersecurity professional and technical leader. She earned a Ph.D. in Human-Centered Computing from University of Maryland, Baltimore County. She has a B.S. in Computer Science from Loyola University Maryland and an M.S. in Computer Science from University of Maryland.
Jody Jacobs is a Computer Scientist in the Visualization and Usability Group at the National Institute of Standards and Technology. Her research interests include user susceptibility to phishing attacks, security adoption, and security awareness. Previously she spent over 20 years working in the private sector in security networking, network and systems operations, and business continuity. She was a member of the NIST FISMA team, which produces security standards and guidelines required by Congressional legislation. She has a B.S. in Environmental Science from the University of Rochester and an M.S. in Information Systems from Strayer University.
Comments
Add new comment
Was this page helpful?

