NIST Says Cybersecurity Programs Fail When They Treat People as the Problem

Table of Contents

A password policy so painful people write the password on a sticky note. A phishing drill that feels like a gotcha. A warning dialog that pops over the one task that has to go out before noon. On the other side of the wall: analysts staring at six dashboards, every alert marked urgent, making a call at midnight on tools that were never designed around a real shift.

NIST researchers Julie Haney and Jody Jacobs opened their August 17 Cybersecurity Insights post with that scene for a reason. After decades of spend on software, hardware, and awareness training, breaches keep happening. A large share still traces to what industry shorthand calls the human element — a reused password, a malicious link, a bad configuration, a workaround invented because the official path made work impossible.

NIST’s response is not another training module. It is a concept paper on human-centered cybersecurity, and the agency wants comments by September 30, 2026, at human-cybersec@nist.gov.

People as Defenders, Not Just Weak Links

Human-centered cybersecurity, as NIST frames it, puts the people who affect or are affected by security — their needs, abilities, and limits — at the front of design and decision-making. The shift in posture matters. Employees are not only a residual risk to be contained. They are also the people who notice odd behavior, report incidents, and invent fixes when official process fails.

The costs of ignoring that are familiar: security-team burnout; staff frustration, error, and quiet noncompliance; lost time, money, and reputation. Gartner, federal R&D strategy documents, and the National Academies have all flagged the human layer as central to modern programs. Verizon’s breach reports keep putting people in the causal chain. The diagnosis is not new. The implementation guidance is thin.

Training Alone Is the Wrong Primary Control

Authoritative frameworks still treat “train the workforce” as the main answer to human risk. Training helps. It does not fix a login flow that forces people to defeat the control, a ticket system that rewards speed over verification, or a culture that punishes reporting. Overreliance on awareness assumes staff will memorize policy, understand the threat model, and choose the secure option under time pressure. Many incidents start because the secure option was the slowest or the least usable option.

NIST’s concept paper is meant to close that how-to gap. The agency plans practical guidelines and resources that sit alongside existing NIST cybersecurity publications rather than replacing them. Themes in the paper come from surveys, interviews, workshops, and conversations with hundreds of practitioners and researchers — not from a closed drafting room.

That process is itself the point. Guidelines that tell organizations to “consider users” without showing what that looks like in a 40-person firm or a 40,000-person SOC will join the pile of unread PDFs.

What Better Looks Like in Practice

Human-centered design in security is not softer security. It is security that survives contact with a real workday.

That can mean authentication that people can complete without storing secrets in the clear. Alerts ranked by actual consequence instead of a single “urgent” flag. Security reviews that fit the deployment path instead of arriving after the vendor is already live. Phishing programs that teach and measure improvement rather than humiliating the person who clicked. On-call tooling that matches how analysts actually triage, not how a product manager imagined they triage.

It also means treating workarounds as diagnostic data. When staff route around a control, the control has already failed part of its job. Punishing the workaround without fixing the friction produces the next incident with a different name on the ticket.

Why Comment Periods Matter Here

NIST is asking organizations of every size to review the concept paper and say what would actually help: formats, examples, sector-specific pain, where existing CSF and SP 800-series documents already cover the ground and where they do not. Comments close September 30, 2026.

People who want to stay in the loop can join the mailing list and Human-Centered Cybersecurity Community of Interest from NIST’s HCC program site.

The invitation is unusual only if you still think cybersecurity guidance is something handed down after the lab work is finished. Haney and Jacobs are arguing the opposite. If the last twenty years of tooling did not stop the same classes of failure, the next publication should start from the people who live inside those failures — including the ones who have been screaming at the password prompt.

Written by: 

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.