The U.S. National Institute of Standards and Technology (NIST) is calling for public comment on a new concept paper that proposes a 'human-centered' approach to cybersecurity. Announced on August 18, 2026, the initiative signals a strategic shift away from solely blaming users for security failures and towards addressing the systemic issues that lead to them. Recognizing the limitations of traditional security awareness training, NIST aims to develop guidance that considers factors like security culture, usability of security tools, and human cognition. The goal is to treat people not as the weakest link, but as a vital part of an organization's defense. The public comment period is open until September 30, 2026.
The concept paper is not a new regulation but a request for information that will inform future NIST guidance, potentially leading to new Special Publications (SPs) or updates to existing frameworks like the NIST Cybersecurity Framework (CSF). The core of the proposal is to reframe the 'human element' in cybersecurity.
Instead of focusing narrowly on user error, the human-centered cybersecurity (HCC) approach encourages organizations to examine:
While the call for comment is open to everyone, the resulting guidance will affect a wide range of organizations, particularly:
There are no immediate compliance requirements. However, organizations should anticipate that future NIST frameworks and guidelines will likely incorporate principles of human-centered design. This could eventually translate into expectations for organizations to demonstrate that they are not just 'training' their users but are actively working to create a more secure environment by improving processes and tools. This might involve conducting usability testing for security tools or assessing the organization's security culture.
A shift towards human-centered cybersecurity could have a significant positive impact. By focusing on the root causes of human error, organizations may see a real reduction in incidents caused by phishing, misconfigurations, and other common user-related mistakes. However, it also requires a shift in mindset and investment. Organizations will need to budget for activities like usability studies and security culture assessments. IT and security teams will need to develop new skills, collaborating more closely with HR, communications, and user experience (UX) design teams. For cybersecurity vendors, it creates pressure to build products that are not just powerful but also intuitive and easy for non-experts to use correctly.
As this is a pre-guidance initiative, there are no enforcement actions or penalties. However, once the principles are integrated into established frameworks, regulators and auditors may begin to look for evidence of a human-centered approach during their assessments.
Organizations can begin preparing for this shift now by:
This NIST initiative aims to evolve the concept of user training to be more effective and holistic.
A human-centered approach would advocate for software with secure-by-default configurations that are also intuitive for users.
NIST releases its concept paper on human-centered cybersecurity and opens the public comment period.
Deadline for public comments on the NIST concept paper.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.