Loading the Elevenlabs Text to Speech AudioNative Player...

Online Safety and Privacy

|

4

4

Min Read

People Should Be at the Heart of Security: The Human-Centered Cybersecurity Approach

Cybersecurity works better when it works for people. That’s the idea behind human-centered cybersecurity (HCC), an approach that puts people’s needs, abilities, and, yes, even their limitations at the forefront of cybersecurity decisions.

The Annual Cybersecurity Attitudes and Behaviors Report

The National Institute of Standards and Technology (NIST) is exploring how organizations can put this approach into practice. In its new Human-Centered Cybersecurity Guidelines and Resources Concept Paper, NIST outlines potential guidance and resources and is asking the cybersecurity community for input through September 30, 2026. 

The National Cybersecurity Alliance supports this effort and has long beat the drum for more HCC. We believe HCC can move security beyond the idea that people are simply a vulnerability to manage and toward a model where people actively participate in creating stronger security. 

What is human-centered cybersecurity? 

NIST defines human-centered cybersecurity as an approach that focuses on people and their needs, abilities, and limitations when organizations design, implement, and decide on cybersecurity policies, processes, technologies, and services.  

A human-centered approach considers everyone who influences or is influenced by cybersecurity, including employees, security professionals, IT teams, developers, system designers, executives, vendors, human resources professionals, operations teams, and others. 

This broader perspective matters today because cybersecurity is not just a technical problem, but an ecosystem involving people, processes, and technology. Organizations need to consider the relationships between all three.

Security should work with people, not against them 

Security teams often respond to unwanted behavior by layering in more training. Training and awareness are important (we co-founded Cybersecurity Awareness Month, for crying out loud!), but more training cannot solve every security problem.

If employees repeatedly struggle with a security process, the process itself may be unnecessarily complicated, disruptive, confusing, or poorly suited to the way people work. A focus on HCC brings a holistic eye to organizations.

Today, we overrely on annual awareness training and assume a lack of knowledge is the primary reason people don't behave securely. But what if we asked a different question, like what conditions led to an unwanted outcome?

And this question will lead to even more questions! Your security team can ask whether people had the information they needed, whether the secure option was easy to use, whether the technology supported the workflow, and whether organizational policies created unnecessary friction.

Yes, sometimes the solution will be education. Other times, it may require a change in process, technology, policy, communication, or culture.

Making HCC everyone’s job 

HCC should not be an initiative a security team considers in isolation. Security teams understand risk. HR understands workforce needs and organizational culture. Operations teams understand how processes work in practice. IT and engineering teams understand technical constraints. Crucially, employees can explain where security requirements create friction in their day-to-day work.

Bringing these perspectives together produces better security decisions. We also think it benefits the business. When workplaces consider people earlier in the design of security processes and projects, they can identify unnecessary friction and inefficiency before those problems become expensive to fix. You can create a virtuous cycle where HCC supports productivity, employee satisfaction, risk management, and resilience while reducing cybersecurity friction and burnout.

Start practicing HCC now 

Organizations can begin applying a human-centered mindset to security decisions today. Before implementing a new control, policy, technology, or training program, think about: 

  • Who will this decision affect? 

  • What will people need to do differently?

  • Is the secure behavior clear and achievable? 

  • Where might this create friction? Is the friction necessary? 

  • Have the people who will use or manage it been involved in its design? 

  • How will we know whether it is improving security? 

These questions can help organizations identify problems before they become workarounds, frustration, noncompliance, or, in the worst-case scenario, security incidents. 

NIST wants your input! 

NIST is developing its HCC guidance with input from cybersecurity practitioners, researchers, government, industry, and other stakeholders. The concept paper identifies several areas where NIST is seeking feedback, including which aspects of HCC matter most, how HCC should align with existing NIST frameworks, what resources organizations need, and what evidence should inform future guidance. 

The National Cybersecurity Alliance encourages cybersecurity professionals and other stakeholders to participate in the process! Download the white paper here. Comments on NIST’s Human-Centered Cybersecurity Guidelines and Resources Concept Paper are due September 30, 2026. You can submit comments to human-cybersec@nist.gov

And for more resources that support a human-centered cybersecurity approach, sign up for our free newsletter!  

Featured Articles

sextortion

Sextortion: What It Is, How It Works, and What to Do If It Happens to You

Sextortion is a heinous crime that takes place over the internet and can target anyone, including children. Here’s what to know.

Convene Boston

How Awareness Practitioners Are Crushing It: Takeaways from Convene: Boston's Share & Brag

We asked real cybersecurity professionals to share what is working for them – learn free tips from the Convene: Boston 2026 Share & Brag session!