NIST wants your take on building better security for people

Decades of investment in cybersecurity software, hardware, and training haven’t prevented breaches, with many incidents stemming from human error like clicking malicious links or using weak passwords. The National Institute of Standards and Technology (NIST) has observed this pattern and is now prioritizing a shift toward recognizing that people are not simply vulnerabilities but also essential defenders.

Julie Haney and Jody Jacobs explain in a NIST blog post that frustrating cybersecurity processes often lead to workarounds and increased risk, asking, “When was the last time a cybersecurity process at work made you want to scream?” NIST released a concept paper to solicit public input and develop practical guidelines for building security programs that prioritize the needs and limitations of people.

NIST recently released a “Human-Centered Cybersecurity Guidelines and Resources Concept Paper” and is actively soliciting public input to shape future guidelines, acknowledging that awareness training alone is insufficient to prevent breaches. The agency notes that overreliance on training creates unrealistic expectations without tackling underlying issues like poorly designed security processes or a lack of organizational security culture. These experiences contribute to burnout and poor judgment, particularly for professionals who are potential defenders, reporters, and problem-solvers.

This perspective acknowledges the high stakes of neglecting human factors, including professional burnout, employee frustration, and potential harm to businesses through lost productivity and damaged reputations. The agency’s plan involves developing practical guidelines complementing existing NIST cybersecurity publications, grounded in input from hundreds of cybersecurity practitioners and researchers gathered through surveys, interviews, and workshops.

The authors state that, like NIST’s other open and transparent stakeholder-informed cybersecurity efforts, their approach is itself human-centered, developed with the community, not handed down to them. Input is being accepted through gov until September 30, 2026, with the goal of creating guidelines valuable to organizations of all sizes.

Existing cybersecurity frameworks, while comprehensive, often lack specific guidance on integrating human factors beyond general training recommendations, a gap NIST intends to address. The agency observed a common frustration among cybersecurity professionals, who often grapple with “a half dozen disconnected dashboards,” all flagged as urgent. This overload, according to NIST, contributes to burnout and impaired judgment, especially when coupled with tools not designed for realistic workflows. The agency’s plan focuses on addressing the root causes of issues like disruptive security processes and a lack of organizational security culture, rather than simply adding more training.

Stay current

See today’s quantum computing news on Quantum Zeitgeist for the latest breakthroughs in qubits, hardware, algorithms, and industry deals.

Avatar of Ivy Delaney

Ivy Delaney

Ivy Delaney has been working with neural networks and machine learning since the mid-nineties, back when a couple of hidden layers and a long afternoon of training counted as ambitious. She has watched the field go from academic curiosity to the thing quietly running underneath everything, and she brings that long view to quantum computing. For Quantum Zeitgeist she covers the ground where the two fields meet. That means quantum machine learning and the variational algorithms it leans on, and it also means the less glamorous but more interesting story of classical machine learning already doing real work inside quantum machines, decoding error-correcting codes, calibrating noisy hardware and learning the error models that simulators depend on. She writes about the hardware those algorithms have to run on too, and about the post-quantum cryptography scramble that the same hardware has set off. Her stories typically start with the paper, whether that is peer-reviewed work, conference proceedings or an arXiv preprint, with the source linked so you can hold a claim up against the research it came from. She is unimpressed by benchmarks that will not say what they beat, and by demonstrations that only work in the press release.

Latest Posts by Ivy Delaney: