Online Safety and Privacy
|
Min Read
People Should Be at the Heart of Security: The Human-Centered Cybersecurity Approach
Cybersecurity works better when it works for people. That’s the idea behind human-centered cybersecurity (HCC), an approach that puts people’s needs, abilities, and, yes, even their limitations at the forefront of cybersecurity decisions.

The National Institute of Standards and Technology (NIST) is exploring how organizations can put this approach into practice. In its new Human-Centered Cybersecurity Guidelines and Resources Concept Paper, NIST outlines potential guidance and resources and is asking the cybersecurity community for input through September 30, 2026.
The National Cybersecurity Alliance supports this effort and has long beat the drum for more HCC. We believe HCC can move security beyond the idea that people are simply a vulnerability to manage and toward a model where people actively participate in creating stronger security.
What is human-centered cybersecurity?
NIST defines human-centered cybersecurity as an approach that focuses on people and their needs, abilities, and limitations when organizations design, implement, and decide on cybersecurity policies, processes, technologies, and services.
A human-centered approach considers everyone who influences or is influenced by cybersecurity, including employees, security professionals, IT teams, developers, system designers, executives, vendors, human resources professionals, operations teams, and others.
This broader perspective matters today because cybersecurity is not just a technical problem, but an ecosystem involving people, processes, and technology. Organizations need to consider the relationships between all three.
Security should work with people, not against them
Security teams often respond to unwanted behavior by layering in more training. Training and awareness are important (we co-founded Cybersecurity Awareness Month, for crying out loud!), but more training cannot solve every security problem.
If employees repeatedly struggle with a security process, the process itself may be unnecessarily complicated, disruptive, confusing, or poorly suited to the way people work. A focus on HCC brings a holistic eye to organizations.
Today, we overrely on annual awareness training and assume a lack of knowledge is the primary reason people don't behave securely. But what if we asked a different question, like what conditions led to an unwanted outcome?
And this question will lead to even more questions! Your security team can ask whether people had the information they needed, whether the secure option was easy to use, whether the technology supported the workflow, and whether organizational policies created unnecessary friction.
Yes, sometimes the solution will be education. Other times, it may require a change in process, technology, policy, communication, or culture.
Making HCC everyone’s job
HCC should not be an initiative a security team considers in isolation. Security teams understand risk. HR understands workforce needs and organizational culture. Operations teams understand how processes work in practice. IT and engineering teams understand technical constraints. Crucially, employees can explain where security requirements create friction in their day-to-day work.
Bringing these perspectives together produces better security decisions. We also think it benefits the business. When workplaces consider people earlier in the design of security processes and projects, they can identify unnecessary friction and inefficiency before those problems become expensive to fix. You can create a virtuous cycle where HCC supports productivity, employee satisfaction, risk management, and resilience while reducing cybersecurity friction and burnout.
Start practicing HCC now
Organizations can begin applying a human-centered mindset to security decisions today. Before implementing a new control, policy, technology, or training program, think about:
Who will this decision affect?
What will people need to do differently?
Is the secure behavior clear and achievable?
Where might this create friction? Is the friction necessary?
Have the people who will use or manage it been involved in its design?
How will we know whether it is improving security?
These questions can help organizations identify problems before they become workarounds, frustration, noncompliance, or, in the worst-case scenario, security incidents.
NIST wants your input!
NIST is developing its HCC guidance with input from cybersecurity practitioners, researchers, government, industry, and other stakeholders. The concept paper identifies several areas where NIST is seeking feedback, including which aspects of HCC matter most, how HCC should align with existing NIST frameworks, what resources organizations need, and what evidence should inform future guidance.
The National Cybersecurity Alliance encourages cybersecurity professionals and other stakeholders to participate in the process! Download the white paper here. Comments on NIST’s Human-Centered Cybersecurity Guidelines and Resources Concept Paper are due September 30, 2026. You can submit comments to human-cybersec@nist.gov.
And for more resources that support a human-centered cybersecurity approach, sign up for our free newsletter!

