Conference Description
Key Takeaways
- Academic conference exploring the intersection of human-computer interaction and cybersecurity
- Addresses authentication, biometrics, cryptography, artificial intelligence security, and cyber psychology
- Designed for researchers, cybersecurity professionals, HCI specialists, and policy makers
- Examines usability challenges in security technologies and human factors in threat mitigation
- Features paper presentations, workshops, courses, and a student design competition
- Takes place 26–31 July 2026 at the Montreal Convention Centre, Canada
Introduction
The 8th International Conference on HCI for Cybersecurity, Privacy, and Trust (HCI-CPT) convenes researchers, academics, and practitioners working at the intersection of human-computer interaction and information security. Scheduled for late July 2026 in Montreal, the conference addresses a fundamental tension in modern cybersecurity: security measures are only effective when people can actually use them. As organisations deploy increasingly sophisticated defences against cyber threats, the human element remains both the greatest vulnerability and the key to sustainable protection.
This timing proves particularly relevant as artificial intelligence reshapes both attack vectors and defensive capabilities. Large language models have introduced new categories of social engineering threats while simultaneously offering novel approaches to security awareness and threat detection. The conference provides a forum for examining these developments through the lens of human factors research, recognising that technical solutions alone cannot address the full spectrum of contemporary cybersecurity challenges.
About This Event
HCI-CPT 2026 represents the eighth iteration of this specialised academic forum, which has established itself as a venue for multidisciplinary dialogue on security usability and human-centred privacy protection. The conference format combines traditional academic paper and poster presentations with hands-on workshops, educational courses, and a student design competition intended to cultivate emerging talent in the field.
The event takes place at the Montreal Convention Centre from 26 to 31 July 2026, offering an extended programme that allows for deep engagement with complex subject matter. This in-person format facilitates the kind of collaborative discussion and networking that drives research partnerships and cross-sector knowledge transfer.
Human Factors in Security Technology Design
A central premise of the conference is that cybersecurity failures frequently stem from misalignment between security mechanisms and human behaviour. Authentication systems that frustrate users lead to workarounds that compromise security. Privacy controls that require technical expertise exclude the majority of users from meaningful data protection. Threat warnings that generate excessive false positives train users to ignore genuine alerts.
The conference examines how HCI principles, methods, and tools can address these challenges. This includes research into authentication and identification systems that balance security requirements with usability, biometric technologies that account for diverse user populations and environmental conditions, and cryptographic applications designed for non-specialist users. The goal is not merely to make security more convenient but to design systems where secure behaviour becomes the path of least resistance.
Cybersecurity Across Computing Environments
The conference programme reflects the reality that cybersecurity challenges manifest differently across computing contexts. Web applications, mobile devices, cloud infrastructure, Internet of Things deployments, smart city systems, and healthcare technologies each present distinct threat landscapes and user interaction patterns. A security approach effective in one environment may prove inadequate or counterproductive in another.
Healthcare cybersecurity, for instance, must contend with clinical workflows where security friction can directly impact patient care. Smart city infrastructure introduces questions of public trust and civic participation alongside technical security requirements. IoT devices often lack the interface capabilities for traditional security interactions, demanding entirely new paradigms for user authentication and consent. The conference provides a venue for examining these domain-specific challenges while identifying transferable insights across sectors.
Artificial Intelligence, Misinformation, and Cyber Psychology
The programme addresses emerging concerns around artificial intelligence in cybersecurity, including both the security of AI systems themselves and the use of AI in attacks and defences. Large language models have dramatically lowered the barrier to sophisticated social engineering, enabling personalised phishing at scale and convincing impersonation attacks. Understanding how users perceive and respond to AI-generated content has become a pressing research priority.
Related discussions encompass fake news, social media manipulation, and the broader field of cyber psychology. These topics recognise that cybersecurity extends beyond technical system protection to encompass the integrity of information environments and the psychological wellbeing of users navigating increasingly hostile digital spaces. Gaming also features in the programme, both as a domain with its own security challenges and as a potential vehicle for security awareness education.
Legal, Ethical, and Regulatory Dimensions
Technical security measures operate within legal and ethical frameworks that shape their permissible scope and implementation. The conference addresses these dimensions, recognising that privacy protection involves not only technical controls but also compliance with evolving regulatory requirements across jurisdictions. Practitioners must navigate tensions between security monitoring and privacy rights, between data collection for threat intelligence and data minimisation principles.
Ethical considerations extend to questions of equitable access to security protections, the potential for security technologies to enable surveillance or discrimination, and the responsibilities of researchers and practitioners in disclosing vulnerabilities. These discussions benefit from the multidisciplinary attendance the conference attracts, bringing legal scholars and policy makers into dialogue with technologists and behavioural researchers.
Who Should Attend
HCI-CPT 2026 serves a diverse professional community united by interest in human-centred approaches to cybersecurity. Academic researchers in human-computer interaction, usable security, and privacy will find opportunities to present findings and engage with peers across disciplinary boundaries. Cybersecurity professionals seeking to improve the effectiveness of security programmes through better user experience design can gain research-informed insights applicable to organisational practice.
The conference also addresses the needs of policy makers grappling with regulatory approaches to privacy and security, IT managers responsible for security implementations that must work for real users, and technology strategists evaluating emerging security technologies. Attendees typically come from academia, technology companies, government agencies, healthcare organisations, financial institutions, and operators of critical infrastructure.
The Case for Multidisciplinary Collaboration
The conference reflects a growing recognition that effective cybersecurity requires collaboration across traditional disciplinary boundaries. Technical expertise in cryptography or network security, while essential, proves insufficient when security systems fail due to human factors that technologists alone cannot address. Conversely, HCI researchers benefit from deep engagement with the specific constraints and threat models that security practitioners navigate daily.
This multidisciplinary approach becomes increasingly important as cyber threats grow in sophistication and as society’s dependence on interconnected technologies deepens. The protection of individuals, organisations, and critical infrastructures demands integrated strategies that account for technical vulnerabilities, human behaviour, organisational dynamics, and regulatory environments. HCI-CPT 2026 provides a forum for developing such strategies through sustained dialogue among the diverse communities whose expertise must be combined to address contemporary cybersecurity challenges.

