On August 12, 2026, NIST released a concept paper on human-centered cybersecurity. The paper lays out a plan to build practical guidelines that treat people as central to security. NIST now wants public feedback before it decides what to build next.
The comment window runs through September 30, 2026. Anyone can weigh in by email. The agency frames this as a chance to shape the guidelines from the ground up.
What Human-Centered Cybersecurity Means
NIST uses the term human-centered cybersecurity, or HCC, for a people-first approach. It aims to improve outcomes by putting people’s needs, abilities, and limits at the forefront of security decisions. That covers everyone who affects or is affected by cybersecurity.
The paper reframes how organizations view people. Too often, security treats humans as the weak link. NIST pushes back on that view. It describes people as defenders, reporters, and problem-solvers to be empowered.
Why It Matters
Breaches keep happening despite decades of security spending. Many trace back to the human element, not to broken technology. Examples include clicking a malicious link, reusing a weak password, or taking a risky shortcut to finish work.
The cost of ignoring people runs high. NIST points to burnout among security staff, employee frustration and mistakes, and lost productivity and money. In its blog announcing the paper, NIST argues that a people-first approach is central to modern security programs.
The How-To Gap
NIST sees a clear gap between recognition and practice. Most frameworks address the human element only through awareness training. Yet the concept paper argues that awareness training alone is not cutting it.
Training assumes employees will memorize lessons and always choose correctly. That assumption ignores root causes, such as hard-to-use security tools and weak security culture. As a result, organizations stay unsure how to take a human-centered approach.
What the Research Shows
The concept paper draws on years of stakeholder input, not just NIST opinion. It synthesizes surveys, interviews, and workshops with hundreds of practitioners and researchers. One participant summed up the stakes.
According to the paper, a NIST interview subject said the tools and outcomes of cybersecurity depend entirely on people and teams. The document also shares real-world stories in sidebars. One security leader dropped a punitive phishing program and instead used exercises to test support, not to punish staff.
NIST’s Plan and Guiding Principles
NIST plans an initial, foundational publication first. It will define HCC’s scope, goals, and value to organizations. Later guidelines and resources will show how to apply the approach.
The agency wants these outputs to be community-informed and evidence-based. It also wants them to complement existing NIST publications rather than replace them. Possible formats include quick-start guides, videos, checklists, case studies, and training modules.
The Human-in-the-Loop Stays
NIST stresses that AI will not remove people from security. Emerging tools can cut burden and boost efficiency. Even so, the paper argues people remain the linchpin of a strong security strategy. It also warns that AI can help or hurt how people interact with security.
How to Give Feedback
NIST invites comments on scope, value, evidence, and format. Interested parties can email human-cybersec@nist.gov with the subject line “HCC Concept Paper.” The deadline is September 30, 2026.
Comments fall under the Freedom of Information Act. NIST says any AI used to summarize feedback will not train on the comments. Public reporting will stay in aggregate, with no attribution to individuals or organizations. For teams tired of security processes that frustrate staff, this is a direct line to help shape better guidance.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.