NIST Calls for Comment on Human-Centered Security

NIST Seeks Public Input on Human-Centered Cybersecurity

INFORMATIONAL
August 18, 2026
4m read
Policy and ComplianceRegulatory

Full Report

Executive Summary

The U.S. National Institute of Standards and Technology (NIST) is calling for public comment on a new concept paper that proposes a 'human-centered' approach to cybersecurity. Announced on August 18, 2026, the initiative signals a strategic shift away from solely blaming users for security failures and towards addressing the systemic issues that lead to them. Recognizing the limitations of traditional security awareness training, NIST aims to develop guidance that considers factors like security culture, usability of security tools, and human cognition. The goal is to treat people not as the weakest link, but as a vital part of an organization's defense. The public comment period is open until September 30, 2026.

Regulatory Details

The concept paper is not a new regulation but a request for information that will inform future NIST guidance, potentially leading to new Special Publications (SPs) or updates to existing frameworks like the NIST Cybersecurity Framework (CSF). The core of the proposal is to reframe the 'human element' in cybersecurity.

Instead of focusing narrowly on user error, the human-centered cybersecurity (HCC) approach encourages organizations to examine:

  • Organizational Culture: How does the organization's culture promote or hinder secure behaviors? Is security seen as a shared responsibility or just an IT problem?
  • Human-System Interaction: Are security tools and processes intuitive and easy to use, or do they create friction that encourages insecure workarounds?
  • Communication: How are security policies and incidents communicated? Is the communication clear, timely, and actionable?
  • Cognitive and Behavioral Science: How can an understanding of human psychology be used to design more effective security controls and training programs?

Affected Organizations

While the call for comment is open to everyone, the resulting guidance will affect a wide range of organizations, particularly:

  • U.S. Federal Agencies: Who are often required to follow NIST guidance.
  • Critical Infrastructure Operators: Who increasingly align with NIST frameworks for their security programs.
  • Private Sector Companies: Many private companies, both in the U.S. and globally, voluntarily adopt NIST standards as a benchmark for best practices.
  • Cybersecurity Vendors: Who will need to consider these human-centered design principles in their products.

Compliance Requirements

There are no immediate compliance requirements. However, organizations should anticipate that future NIST frameworks and guidelines will likely incorporate principles of human-centered design. This could eventually translate into expectations for organizations to demonstrate that they are not just 'training' their users but are actively working to create a more secure environment by improving processes and tools. This might involve conducting usability testing for security tools or assessing the organization's security culture.

Implementation Timeline

  • August 18, 2026: NIST releases the concept paper and opens the public comment period.
  • September 30, 2026: Deadline for public comments.
  • Post-September 2026: NIST will analyze the feedback and begin the process of drafting new guidance or updating existing publications. The timeline for this can range from several months to over a year.

Impact Assessment

A shift towards human-centered cybersecurity could have a significant positive impact. By focusing on the root causes of human error, organizations may see a real reduction in incidents caused by phishing, misconfigurations, and other common user-related mistakes. However, it also requires a shift in mindset and investment. Organizations will need to budget for activities like usability studies and security culture assessments. IT and security teams will need to develop new skills, collaborating more closely with HR, communications, and user experience (UX) design teams. For cybersecurity vendors, it creates pressure to build products that are not just powerful but also intuitive and easy for non-experts to use correctly.

Enforcement & Penalties

As this is a pre-guidance initiative, there are no enforcement actions or penalties. However, once the principles are integrated into established frameworks, regulators and auditors may begin to look for evidence of a human-centered approach during their assessments.

Compliance Guidance

Organizations can begin preparing for this shift now by:

  1. Reviewing the Concept Paper: Download and read the paper from the NIST website to understand the proposed direction.
  2. Submitting Comments: If your organization has insights or concerns, contribute to the public comment process.
  3. Conducting Internal Reviews: Start asking human-centered questions about your own security program. Why do users click on phishing links? Is it because they are careless, or is the email client's warning system ineffective? Why do developers use weak passwords? Is it because the password policy is too complex and encourages writing them down?
  4. Building Cross-Functional Teams: Create a working group with representatives from IT, security, HR, legal, and key business units to discuss security culture and process improvement.

Timeline of Events

1
August 18, 2026
NIST releases its concept paper on human-centered cybersecurity and opens the public comment period.
2
August 18, 2026
This article was published
3
September 30, 2026
Deadline for public comments on the NIST concept paper.

MITRE ATT&CK Mitigations

This NIST initiative aims to evolve the concept of user training to be more effective and holistic.

A human-centered approach would advocate for software with secure-by-default configurations that are also intuitive for users.

Timeline of Events

1
August 18, 2026

NIST releases its concept paper on human-centered cybersecurity and opens the public comment period.

2
September 30, 2026

Deadline for public comments on the NIST concept paper.

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

NISTCybersecurity FrameworkHuman FactorPolicyRegulation

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.