Happy Birthday HIPAA. The Health Insurance Portability and Accountability Act became law on August 21, 2026, thirty years ago yesterday. Check out this interesting LinkedIn post.
From the Project Glasswing front,
- The Wall Street Journal reports,
- “OpenAI took a break from training new artificial intelligence models over the past two weeks, saying it needed time to revamp security measures for risky trial runs.
- The move followed nearly half a dozen similar incidents across top AI developers in which frontier models escaped virtual testing containers, known as sandboxes, and accessed external data sources. In some cases, this involved hacking third-party companies.
- “As models become more capable, the risks associated with developing and testing them internally also grow,” OpenAI said in an online post Tuesday [August 18, 2026]. “Our standards for monitoring, alignment, and security must stay ahead of those risks,” the company said. Its largest planned model training remains on hold, for now, the company said.”
- Beckers Health IT points out,
- “Epic used its Users Group Meeting executive address this week to confirm publicly for the first time that it’s participating in Project Glasswing, Anthropic’s effort to test its most capable — and still unreleased — AI model against critical software before that capability spreads to attackers.
- “Anthropic launched Project Glasswing in April after deciding not to publicly release Claude Mythos, an AI model capable of autonomously finding and exploiting decades-old cybersecurity vulnerabilities.
- “The program initially included about 50 partners, mostly major tech and cybersecurity firms, before expanding in June to roughly 150 more organizations spanning industries including healthcare. Anthropic has not disclosed the identities of most participants, citing security concerns, though it has said organizations are free to share their own involvement.”
- Security Week relates,
- “Anthropic has published new research showing that Claude-based AI agents, when placed in situations with competing objectives, deployed self-replicating malware against one another.
- “The finding comes from an experiment designed to mirror behavior Anthropic says it has already observed in real-world deployments.
- “Researchers spun up three instances of the same Claude model, each running on its own virtual machine and tasked with migrating a shared Python backend to a different programming language — Rust, Go, or TypeScript — without initial knowledge that the other agents existed. Left to run for four hours, every model concluded that the other agents were deliberately blocking its progress and responded by trying to disable or outlast them.
- “The interference escalated quickly. Agents disabled each other’s system accounts, wrote scripts that repeatedly hunted down and killed rival processes, and planted malicious code camouflaged as legitimate work from another agent. In some cases, one agent seized control outright by revoking the others’ access. In others, agents simply gave up rather than continue the conflict.
- “Not every run ended in stalemate or hostile takeover. A meaningful share of cases resolved when agents recognized that the conflict stemmed from contradictory instructions rather than malicious intent. At this point, they de-escalated, documented what they’d done, and in some cases requested human intervention.
- “Anthropic’s Mythos 5 model reached a negotiated truce in 98% of its runs, while older models like Sonnet 4.6 and Opus 4.6 more often ended conflicts by force or failed to resolve them at all.”
- Startup Fortune adds today,
- “Anthropic has put Claude Mythos 5, its restricted cyber model, inside Claude Security for Enterprise customers. The bet is simple: give defenders the results without handing everyone the raw model.
- “Anthropic made the move on August 21, 2026, and the details matter if you run security inside a company that already pays for Claude Enterprise. Claude Security can scan a repository, trace data flows across files, and return vulnerability findings with a CWE category, confidence and severity ratings, and a suggested fix for human review. According to Anthropic’s launch post, those Mythos 5 scans are billed as standard token usage under the existing Enterprise plan. No separate add-on.
- “That’s the commercial hook.
- “Security tooling usually lives in its own budget fight, with its own vendor review and renewal cycle. Anthropic is trying to make AI vulnerability scanning feel less like a new platform purchase and more like turning on a capability customers already have access to. For security teams, that distinction isn’t cosmetic. It can be the difference between testing a tool this quarter and waiting for procurement to catch up next year.”
- sdx central informs us,
- “Palo Alto Networks followed in the footsteps of Nvidia and Anthropic by assembling an all-star group focused on AI-powered cybersecurity.
- “The Frontier AI Critical Defense Program builds on Palo Alto Network’s existing collaborations with IBM, Red Hat, Microsoft, Siemens, and Idaho National Laboratory, welcoming Anthropic, OpenAI, and Mitsubishi into the fold.
- “The initiative is targeted at shielding critical infrastructure across operational technology (OT), health care, commercial software, and open-source from AI-driven exploits. Members coordinate with Palo Alto Networks in applying network-level “virtual patches” to neutralize security flaws prior to exploitation.
- “The security giant claimed its work with compute-heavy frontier AI models has already uncovered more than 14,000 previously unknown vulnerabilities in open source software. As a comparison, Anthropic claimed at one point to have used its vaunted Claude Mythos Preview Model to fing more than 23,000 flaws across more than 1,000 open-source projects.
- “IBM and Red Hat’s similar Project Lightwell venture has not yet disclosed any findings, but it’s worth remembering that project is still in its infancy.”
From the cybersecurity policy and law enforcement front,
- Cyberscoop reports,
- “Artificial intelligence has never been more important to the federal government.
- “Under the Trump administration, AI has been adopted rapidly across the private sector and federal agencies. Software developers now use large language models to generate much of their code. Frontier AI models are escaping testing sandboxes to hack live internet infrastructure. Foreign governments are conducting cyber and kinetic attacks targeting data centers and other AI-related infrastructure.
- “The AI industry’s lightning-fast evolution since 2022 and growing importance to U.S. economic and national security have prompted calls for stronger federal oversight in order to better manage emerging threats.
- “A new report published Thursday [August 20, 2026] from the nonprofit Americans for Responsible Innovation, shared exclusively with CyberScoop, calls for the federal government to declare key AI models, companies and its supporting industries as critical infrastructure. It also calls for naming the Cybersecurity and Infrastructure Security Agency as the lead agency managing cyberthreats for the sector.
- and
- “A pair of lawmakers wants a watchdog agency to probe how the federal government hacks Americans, including with the use of spyware, and deliver a report to the public.
- “Sen. Ron Wyden, D-Ore., and Rep. Greg Casar, D-Texas, wrote to the Government Accountability Office on Friday to request the review.
- “While federal law enforcement agencies have used hacking and spyware as an investigative tool for more than 25 years, there exists little public information regarding its scope, frequency, or operational safeguards,” they wrote. “Unlike traditional surveillance authorities, such as wiretaps or pen registers, the government does not publish annual reports for hacking operations.”
- Cybersecurity Dive relates,
- “Defense contractors are struggling to meet the requirements of the U.S. military’s Cybersecurity Maturity Model Certification (CMMC) program, even as the Pentagon tries to accommodate their complaints about compliance burdens.
- “Only two-thirds of contractors that have submitted CMMC self-assessment scores to the military in 2026 are extremely or very confident that those scores accurately reflect their cybersecurity posture, and the median contractor believes it is only 70% ready to undergo a CMMC certification review, the consulting firm CyberSheath said in a report published on Thursday [August 20, 2026].
- “The report — which also finds that defense contractors want a wider range of firms to be subject to cybersecurity requirements — underscores the difficulty of protecting the defense industry at a time of increasing nation-state hacking threats.”
- and
- “The Trump administration says a new AI-enhanced clearinghouse will dramatically speed up the process of analyzing and fixing software vulnerabilities before hackers can exploit them. But one month after its launch, it’s still unclear how much value the program will create.
- “The U.S. government’s Gold Eagle clearinghouse, which launched in mid-July, is intended to analyze an AI-fueled tidal wave of bug reports, identify and help patch the most dangerous vulnerabilities and raise awareness about those fixes. But Gold Eagle’s limited scale and voluntary nature raise serious doubts about its ability to corral a vast universe of vulnerability analysis, according to cybersecurity experts. These experts also questioned the Treasury Department’s oversight of the clearinghouse, the funding for its central technology system and the way it will integrate with private-sector vulnerability coordination hubs.”
- Federal News Network tells us,
- “Agencies are getting some help to improve how they log cybersecurity data. A new logging architecture from the Cybersecurity and Infrastructure Security Agency, the Office of Management and Budget and the Chief Information Security Officer Council aims to assist agencies in taking a practical, risk-based, prioritized logging approach that improves agency network monitoring. The guidance, released yesterday [August 20, 2026] helps agencies implement the changes OMB outlined in a May memo. CISA said agencies will be able to achieve priority logging capabilities that support continuous event monitoring, threat hunting, incident response and forensics. Through this guidance, agencies will be able to update their enterprise logging strategies by applying CISA’s operational checklists. CISA said it will continually update the guidance as cybersecurity threats and agency capabilities evolve.”
- Cybersecurity Dive informs us,
- “The U.S. Department of Justice today announced indictments against 17 members of the Mabna Institute, an Iranian organization alleged to be behind a coordinated cyberattack campaign on behalf of the Islamic Revolutionary Guard Corps.
- “Federal prosecutors said the group allegedly hacked into 144 U.S.-based universities, 42 U.S.-based private sector companies and at least five federal and state agencies, as well as a large number of foreign universities and companies, since 2013.
- “The charges reveal a broader effort behind a “sweeping state-sponsored campaign to steal research and intellectual property from American universities, businesses and government institutions,” Jamie McDonald, U.S. Attorney for the Southern District of New York, said in a statement.
- “Prosecutors allege more than 100,000 accounts of professors were targeted by the alleged hackers, and 8,000 of those accounts were successfully compromised.”
From the cybersecurity breaches and vulnerabilities front,
- HIPAA Journal reports,
- “Baylor Genetics, a clinical diagnostic genomics company, has recently disclosed a cybersecurity incident that has exposed patient and employee data. The incident was first announced in June; however, the extent of the data breach was unclear at the time.
- “Baylor Genetics provides genetic testing services to hospitals and is headquartered at the Texas Medical Center in Houston. The company identified suspicious activity within its computer network on or around June 15, 2026. Immediate action was taken to secure its systems, and an investigation was launched to determine the cause of the activity. The investigation determined that an unauthorized third party accessed a portion of its information technology network between June 11 and June 17, 2026, and viewed or obtained data stored on the network.
- “Assisted by third-party cybersecurity specialists, Baylor Genetics conducted a detailed and time-intensive review of all potentially impacted files. The review was completed on July 30, 2026, when it was confirmed that the personal information of certain patients and employees was involved. The types of data involved varied from individual to individual and may have included names plus one or more of the following: date of birth, medical testing information, lab test results, health insurance information, and for a limited subset of patients, Social Security numbers.
- “Employee data was also exposed in the incident, including personally identifying information such as Social Security numbers, government-issued identification numbers, and financial account information. While data was exposed and potentially exfiltrated, Baylor Genetics is unaware of any actual or attempted identity theft, fraud, or other misuses of the impacted data.”
- and
- “When we last reported on the CareCloud data breach in early August, it was starting to become clear from breach notifications to state attorneys general that the cybersecurity incident involved a major breach of patient data. The scale of the breach was difficult to determine, as many state attorneys general do not make data breaches affecting state residents public, and of those that do, only a few state how many individuals have been affected.
- “The data breach has now been added to the HHS’ Office for Civil Rights breach portal, showing that this was one of the largest healthcare data breaches of the year, involving unauthorized access to the electronic protected health information of 3,756,469 individuals.\
- While CareCloud has confirmed that a threat actor claimed to have stolen sensitive data, no threat group appears to have publicly claimed responsibility for the attack. This often means that ransom payment has been negotiated, although CareCloud has not confirmed whether that is the case.”
- Cybersecurity Dive explains “what we know so far about the hacking campaign against US water systems
- “Support is growing for stricter oversight and increased financial resources for utilities in the wake of a cyberattack spree, suspected to be the work of Iran-linked threat groups.”
- Cyberscoop relates,
- “Apollo Global Management confirmed it was among several financial institutions impacted by a string of social engineering attacks that hit the sector last month, the company said Friday [August 21, 2026].
- “Attackers gained unauthorized access to some of the private equity firm’s cloud platforms between July 6 and July 10, the company said in a data breach notificationfiled in California. Apollo did not say when or how it became aware of the intrusion and did not respond to a request for comment.
- “Apollo is the first victim to formally disclose that sensitive personal data under its care was compromised by a wave of attacks that have hit large private equity firms, law firms, financial rating agencies and medical technology companies.
- “The company did not name the group responsible for the attack. Yet, Google earlier this month attributed the ongoing campaign to BlackFile, a threat group affiliated with The Com, that recently split its extortion operations across four brands with shared infrastructure: Redact, Pink, Helix and Falcon.”
- The American Hospital Association News tells us,
- “The National Security Agency and other federal agencies released a joint advisory Aug. 18 warning of active cyber threats to Siemens S7 Series programmable logic controllers, which are industrial computers used to monitor essential equipment. Healthcare applications operated by PLCs include climate control, access control and many other systems.
- “The agencies said threat actors are targeting PLCs using artificial intelligence-generated exploitation scripts disguised as legitimate monitoring tools. The actors are using internet scanning services to find PLCs that are using outdated software or are poorly protected. The agencies urge all owners and operators of Siemens S7 Series and other PLCs to proactively check their systems and adopt mitigation actions recommended in the advisory, including applying critical security patches as soon as possible.
- “This latest warning about PLCs specifically focuses on active attacks against one type, but the warning applies more broadly,” said Scott Gee, AHA deputy national advisor for cybersecurity and risk. “Hospitals and healthcare systems should ensure that they have an accurate inventory of PLCs in their environments and prioritize protecting them in collaboration with cybersecurity teams. It is strongly recommended that vulnerable PLCs be disconnected from the internet or placed on isolated networks.”
- The Cybersecurity and Infrastructure Security Agency (CISA) added nine known exploited vulnerabilities to its catalog this week.
- August 17, 2026
- CVE-2025-62593 Ray-Project Ray Code Injection Vulnerability
- The Hacker News discusses this KVE here.
- CVE-2025-62593 Ray-Project Ray Code Injection Vulnerability
- August 18, 2026
- CVE-2026-33824 Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability
- CVE-2026-55040 Microsoft SharePoint Weak Authentication Vulnerability
- CVE-2026-59310 Broadcom VMware vCenter Path Traversal Vulnerability
- CVE-2026-65400 Apple macOS Improper Authentication Vulnerability
- SecNews discusses these KVEs here.
- August 19, 2026
- CVE-2026-64849 MLflow Server-Side Request Forgery Vulnerability
- Bleeping Computer discusses this KVE here.
- CVE-2026-64849 MLflow Server-Side Request Forgery Vulnerability
- August 20, 2026
- CVE-2026-72529 TrueConf Server Missing Authentication for Critical Function Vulnerability
- CVE-2026-72530 TrueConf Server Code Injection Vulnerability
- Bleeping Computer discusses these KVEs here.
- August 21, 2026
- CVE-2026-73570 Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
- Security Affairs discusses this KVE here.
- CVE-2026-73570 Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
- August 17, 2026
- Cybersecurity Dive adds,
- “Microsoft issued a patch for a critical remote-code execution vulnerability in Entra ID has been discovered by its own security researchers.
- “The vulnerability, tracked as CVE-2026-69836, is related to deserialization of untrusted data and has a severity score of 10 out of 10, the highest score possible.
- “In a bulletin from the Microsoft Security Response Center, Microsoft said the vulnerability has been fully mitigated and no additional action is required of customers. The company added that it disclosed the vulnerability in an effort to provide greater transparency.”
- and
- “Security researchers are raising concerns after GitLab on Monday [August 17, 2026] issued an out-of-band patch for a critical code injection vulnerability.
- “The vulnerability, tracked as CVE-2026-19478, could enable an attacker to remotely modify or delete a public project as well as user data through a Graph QL directive. The flaw has a severity score of 9.4 out of 10.
- “The flaw was reported through the HackerOne bug bounty program.
- “Threat intelligence firm watchTowr warned Tuesday that it was able to reproduce the vulnerability within minutes of the public disclosure. Researchers said an attacker could do significant damage by exploiting this particular flaw.”
- Bleeping Computer points out,
- “Citrix urges admins to patch new NetScaler flaws as soon as possible.” (August 20, 2026)
- and
- “New SynkLoader malware pushed in Microsoft Teams phishing campaign.” (August 21, 2026)
- Dark Reading notes,
- “A successful multi-agent AI attack on a government’s agencies in the Asia-Pacific region by a Chinese-language operator has put nations and businesses on notice that near- and fully-autonomous AI-enabled attacks are now a reality.
- “The attack used as many as eight simultaneously-operated AI agents to conduct reconnaissance, find and evaluate vulnerabilities, attack networks and systems, and then evaluate and improve successive attacks, according to research from sovereign AI firm Dream published on Aug. 12. The company did not attribute the attack to a specific actor or group, but researchers did point to strong evidence that the attackers spoke simplified Chinese — typically a sign of speakers from mainland China.
- While the company also limited the identification of the targets to “government entities in Asia,” Taiwan’s Ministry of Digital Affairs (MODA) issued a statement the following day, giving details of its response to an attack matching much of Dream’s description, including that it used “AI agents like OpenClaw.”
- “Overall, the incident should be a warning that fully autonomous attacks could be used against major targets, says Amir Becker, chief business and strategy officer at Dream and a former commander of the cyber operation division of Israel’s 8200 Unit, more formally known as the Central Collection Unit of the Intelligence Corps.”
From the ransomware front,
- The American Hospital Association News reports,
- “A joint advisory released Aug. 19 by the FBI, Cybersecurity and Infrastructure Security Agency, and the Department of Health and Human Services provides updates on activity by Medusa, a foreign ransomware-as-a-service variant first identified in 2021. Healthcare has been a frequent victim of Medusa operations, which have also impacted organizations in education, legal, insurance, technology and manufacturing. The ransomware has affected more than 500 victims in total and has been identified through FBI investigations as recently as April. Its developers and affiliates use a double-extortion model to encrypt victim data and threaten to publicly release the stolen data if a ransom is not paid. The FBI said Medusa ransomware is unrelated to the MedusaLocker variant and the Medusa mobile malware variant. The advisory includes more information about Medusa’s affiliate model, payment ranges for initial access brokers and a broader list of exploited vulnerabilities, among other new information.
- “Medusa ransomware has been used by threat actors to conduct malicious activity against U.S. hospitals and health systems over the last several years,” said John Riggi, AHA national advisor for cybersecurity and risk. “This year, Medusa claimed responsibility for a high-impact attack against a regionally important Level 1 trauma center, disrupting care delivery and posing a risk to patient and community safety. Once again, these attacks highlight the need for hospitals and health systems to strengthen cyber resiliency through enhanced defensive measures and clinical continuity procedures.”
- HIPAA Journal adds,
- Medusa attacks typically start with phishing or the exploitation of unpatched vulnerabilities. The group incorporates exploits for recently announced vulnerabilities into it arsenal. For instance, the CVE-2026-1731 BeyondTrust vulnerability started to be exploited soon after it was announced in February 2026, and the CVE-2025-10035 Fortra GoAnywhere vulnerability was also rapidly exploited. The authoring agencies have observed the group incorporating new exploits within 24 hours of a vulnerability being announced and, in some cases, has started exploiting vulnerabilities in the week prior to an announcement. No evidence has been found to indicate that the group develops its own exploits; rather, the group is believed to obtain exploits from unknown sources, potentially IABs, exploiting them before victims have the time to patch.
- Medusa actors use living-of-the-land techniques, hiding their malicious activities by using legitimate tools to support credential access, data exfiltration, and ransomware deployment. Remote monitoring and management software and remote access services such as Remote Desktop Protocol are also used.
- The key actions that HPH sector organizations should take to prevent attacks are to mitigate known vulnerabilities rapidly, ensuring all software, firmware, and operating systems are kept patched and up to date. Networks should be segmented to restrict lateral movement within the network, and network traffic should be filtered to prevent unknown or untrusted origins from accessing remote services on internal systems.
- Cyberscoop tells us,
- “A notorious cybercrime group has once again exploited a critical zero-day vulnerability on a large scale, claiming it stole data from dozens of organizations, including some of the world’s largest publicly traded companies.
- Clop, a prolific but calculated data theft extortion group that’s been active since 2020, began sending threatening emails to its alleged victims in mid-July, according to researchers.
- The fallout from the attack spree, which followed a familiar pattern for Clop and its targeted pool of victims, is still evolving as companies hunt for potential signs of compromise.
- The vulnerability at the center of Clop’s latest campaign affects a pair of software products from PTC — Windchill and FlexPLM — which manufacturers and retailers, particularly in the manufacturing, aerospace, and automotive industries, use to automate supply chain systems and manage product lifecycles.”
- Bleeping Computer notes,
- “A suspected ransomware affiliate is posing as a ransomware recovery service called “Ransom Busters,” contacting victims before the attacks become public and claiming it can provide decryption keys and delete stolen data for a fee.
- “GuidePoint Security’s Research and Intelligence Team (GRIT) disclosed this activity after responding to several recent ransomware attacks in which victims received emails from Ransom Busters offering to help recover from the attack.
- “The messages were suspicious because they were sent to victims before the attacks became public, raising questions about how they knew about the cyberattacks in the first place.”
- and
- “The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April.
- “Task Host is a core Windows system component that allows DLL-based processes to run in the background and prevents data corruption by ensuring they close properly during shutdown.
- “Tracked as CVE-2025-60710, this Windows privilege escalation security flaw was patched by Microsoft in November 2025 and stems from a link following weakness that affects Windows 11 and Windows Server 2025 devices.”
- Cybersecurity Dive relates,
- “Medium-sized businesses accounted for roughly three-quarters (73%) of ransomware incidents between 2023 and the first half of 2026, according to the risk management firm Black Kite.
- “Manufacturing was the most targeted industry (accounting for more than 25% of those victims), and nearly 30% of mid-market organizations had at least one known exploited vulnerability, the firm said in a report published on Tuesday.
- “The findings add to the challenges facing mid-market firms, which include large customers demanding accountability and a vast array of suppliers that the mid-market firms lack the personnel to hold accountable.”
From the cybersecurity business and defenses front,
- The Wall Street Journal reports,
- “OpenAI told investors its revenue grew 18% to $6.7 billion in the second quarter, disappointing some shareholders as losses deepened.
- “The company’s operating loss widened to $12.3 billion in the second quarter from $9.3 billion in the first quarter.
- “Anthropic more than doubled its revenue to $11.6 billion in the same period, surpassing OpenAI’s sales for the first time.”
- Tech Crunch relates,
- “As AI models have become more powerful, the potential for those models to be misused has grown — as has a clamor for safety guardrails that can stop such abuse from happening. AI companies must now walk a delicate tight rope between respecting their enterprise customers’ privacy while also watching usage for possible issues.
- “Sensing an opportunity to one-up its rival Anthropic, OpenAI just announced [August 19, 2026] a privacy-centric safety approach to monitoring for misuse. The company is previewing a new service to select customers that it calls Private Safety Processing. This is an automated system that watches for potential abuse while simultaneously retaining none of the customer’s data.
- “This system clearly runs counter to Anthropic’s recently announced data-retention policy. The policy, which has aggravated some customers, enables the AI lab to keep user data (all of their sessions — and the conversations therein) for a period of 30 days, when it comes to “covered models.” Those models include all Mythos-class models and “future models with similar capabilities,” the company says.”
- Reuters adds,
- “Anthropic plans to let enterprise customers exercise greater control over their data when using its advanced AI models, a source familiar with the matter said on Thursday [August 20, 2026], marking a shift in the Claude chatbot maker’s data retention policy.
- The company is expected to roll out a new safety system later this year, the person said.
- Cybersecurity Dive shares how “Fitch explains how water, healthcare organizations can keep strong credit ratings despite cyberattacks
- “Resilience, not prevention, is key, analysts at the credit-rating agency said in a pair of new reports.”
- Per National Institute of Standards and Technology news releases,
- “NIST announces the release of Special Publication (SP) 1353 ipd (Initial Public Draft), QuickStart Guide for Using Artificial Intelligence (AI) for Cybersecurity Framework (CSF) Analysis and Reporting. This new quick-start guide illustrates practical and actionable ways AI could be used for analyzing, planning, implementing, and monitoring an organization’s progress toward achieving CSF 2.0 outcomes.
- “The document’s purpose is to:
- Provide structured AI prompts as tools for practitioners to begin creating CSF-related artifacts in support of achieving CSF outcomes
- Identify current state of practice for AI prompt engineering in CSF implementation and analysis
- “The comment period for NIST SP 1353 ipd is open through October 15, 2026, at 11:59 PM. Email comments to: csf@nist.gov.”
- and
- “Cybersecurity works best when it works with people, not against them — and that’s exactly what human-centered cybersecurity (HCC) is all about. The Human-Centered Technologies team at NIST is releasing a concept paper on HCC, and we want your input. Our goal is to build a shared understanding of what HCC really means, then chart a path toward practical guidelines and resources that organizations can actually use to make meaningful change by:
- “Clarifying whether HCC is primarily an approach—measured by indicators of adoption and maturity—or an outcome—requiring other measures of success such as culture, trust, usability, or resilience
- “Communicating the relationship between HCC and existing NIST cybersecurity guidelines and frameworks
- “Assisting organizations in implementing and enhancing HCC within their cybersecurity programs.
- “But we can’t do that without you. We invite you to read the blog introducing our “Human-Centered Cybersecurity Guidelines and Resources Concept Paper” and submit your feedback via human-cybersec@nist.gov by September 30, 2026.”
- Here is a link to Dark Reading’s CISO Corner.
