Decades of investment in cybersecurity software, hardware, and training haven’t prevented breaches, with many incidents stemming from human error like clicking malicious links or using weak passwords. The National Institute of Standards and Technology (NIST) has observed this pattern and is now prioritizing a shift toward recognizing that people are not simply vulnerabilities but also essential defenders.
Julie Haney and Jody Jacobs explain in a NIST blog post that frustrating cybersecurity processes often lead to workarounds and increased risk, asking, “When was the last time a cybersecurity process at work made you want to scream?” NIST released a concept paper to solicit public input and develop practical guidelines for building security programs that prioritize the needs and limitations of people.
NIST recently released a “Human-Centered Cybersecurity Guidelines and Resources Concept Paper” and is actively soliciting public input to shape future guidelines, acknowledging that awareness training alone is insufficient to prevent breaches. The agency notes that overreliance on training creates unrealistic expectations without tackling underlying issues like poorly designed security processes or a lack of organizational security culture. These experiences contribute to burnout and poor judgment, particularly for professionals who are potential defenders, reporters, and problem-solvers.
This perspective acknowledges the high stakes of neglecting human factors, including professional burnout, employee frustration, and potential harm to businesses through lost productivity and damaged reputations. The agency’s plan involves developing practical guidelines complementing existing NIST cybersecurity publications, grounded in input from hundreds of cybersecurity practitioners and researchers gathered through surveys, interviews, and workshops.
The authors state that, like NIST’s other open and transparent stakeholder-informed cybersecurity efforts, their approach is itself human-centered, developed with the community, not handed down to them. Input is being accepted through gov until September 30, 2026, with the goal of creating guidelines valuable to organizations of all sizes.
Existing cybersecurity frameworks, while comprehensive, often lack specific guidance on integrating human factors beyond general training recommendations, a gap NIST intends to address. The agency observed a common frustration among cybersecurity professionals, who often grapple with “a half dozen disconnected dashboards,” all flagged as urgent. This overload, according to NIST, contributes to burnout and impaired judgment, especially when coupled with tools not designed for realistic workflows. The agency’s plan focuses on addressing the root causes of issues like disruptive security processes and a lack of organizational security culture, rather than simply adding more training.
See today’s quantum computing news on Quantum Zeitgeist for the latest breakthroughs in qubits, hardware, algorithms, and industry deals.
