Cyber Risk
Putting People First: The Shift Toward Human-Centered Cybersecurity
FORTSECURE GLOBAL· 2026-08-17🛰 NIST Cybersecurity Insights
#NIST#Cybersecurity Strategy#Human Factors#User Experience#Security Awareness
NIST is seeking industry feedback on a human-centered approach to cybersecurity to reduce user friction and combat security fatigue.
The Human Element in Modern Security\n\nIn the evolving landscape of information security, technical controls are no longer sufficient on their own. The National Institute of Standards and Technology (NIST) has recently emphasized that stronger cybersecurity programs must start with people. A new initiative, 'Human-Centered Cybersecurity,' seeks to address the friction often caused by security protocols. For years, employees have faced overly complex password requirements, confusing security warnings, and phishing simulations that feel more like traps than educational opportunities. These frustrations lead to 'security fatigue,' a state of weariness where users become less likely to follow security procedures correctly. This fatigue can result in users bypassing controls or making errors that lead to significant data breaches. NIST is now calling for public input through a Request for Information (RFI) to reshape how organizations approach security from a user-perspective, ensuring that protection does not come at the cost of productivity.\n\n## Why Feedback Matters in Security Design\n\nThe primary goal of this initiative is to move away from a 'blame the user' mentality that has plagued the industry for decades. Instead, NIST wants to understand the professional challenges faced by both end-users and cybersecurity staff. Security professionals themselves are not immune to these issues; they are often overwhelmed by dozens of disconnected dashboards and a constant stream of alerts, leading to professional burnout and missed threats. By collecting feedback from the global community, NIST plans to develop a path forward that integrates human factors into the design and implementation of security systems. This involves creating tools that are more intuitive and warnings that are clearer, ultimately reducing the cognitive load on staff while maintaining high security standards. This human-centric approach is vital for building a resilient culture where security is seen as a collective responsibility rather than a burden.\n\n## Practical Recommendations for Organizations\n\n1. Implement Phishing-Resistant MFA: Transition from SMS-based codes or push notifications to biometrics or hardware keys like FIDO2 to reduce user friction and increase security levels.\n2. Audit Security Policies for Friction: Periodically review current policies to see if they are causing 'shadow IT' behaviors where employees use unauthorized tools just to get their work done.\n3. Focus on Positive Reinforcement: In security awareness training, reward users for reporting suspicious emails rather than solely penalizing those who fail simulations. This builds trust and encourages proactive participation.
แหล่งที่มา: NIST Cybersecurity Insights เผยแพร่ครั้งแรก: Mon, 17 Aug 2026 12:00:00 +0000 บทความต้นฉบับ: อ่านต้นฉบับ
Source Attribution
แหล่งที่มา: NIST Cybersecurity Insights
เผยแพร่ครั้งแรก: Mon, 17 Aug 2026 12:00:00 +0000
บทความต้นฉบับ: https://www.nist.gov/blogs/cybersecurity-insights/stronger-cybersecurity-programs-start-people-nist-wants-your-input-path
* Facebook / LinkedIn ไม่อนุญาตให้ใส่ข้อความให้ล่วงหน้า — กดปุ่มจะคัดลอกข้อความให้ก่อน เปิดหน้าแชร์แล้ววาง (paste) ได้เลย พรีวิวการ์ดจะแสดงอัตโนมัติเมื่อวางลิงก์
