Most flood advice is written by hydrologists for other hydrologists. The people whose kitchens fill with water get a leaflet.
Security writing has the same shape. It is produced by defenders, for defenders, in the vocabulary of an industry that has been talking to itself for thirty years. It is frequently excellent and it is aimed at somebody with a budget, a team and a job title.
Meanwhile the losses land on households and small businesses, who receive warnings they cannot act on and terminology that makes them feel stupid for asking.
Why does most security writing miss its audience?
Because the writers are describing their own working world.
Somebody who spends their days on enterprise defense writes naturally about frameworks, threat models and posture. Every one of those is a real and useful concept. None of them means anything to a person trying to work out whether their router matters.
The second failure is scale. Advice built for an organization assumes somebody whose job includes this. A household has nobody whose job includes it, so any recommendation requiring sustained attention will be abandoned within a fortnight, and the writer will conclude that people do not care.
They care. They have twenty minutes and no vocabulary.
The book on this: Family Cybersecurity is 231 pages written for the household taking the losses, in plain words, with the reasoning attached.
What does writing for them require?
Assuming the reader is capable and busy, which is different from assuming they are ignorant.
The condescending register is the most common failure and it is worse than jargon, because a reader who feels talked down to stops reading immediately and does not come back.
The person reading Family Cybersecurity runs a life. They handle insurance, mortgages, schools, ageing parents. They are entirely capable of understanding what a router does. Nobody has ever explained it to them without either simplifying it into uselessness or burying it in terms.
What they need is an ordered list of what matters most, in plain words, with the reasoning attached so they can adapt it when their situation differs.
The book on this: The Day Your Website Died does the same job for a different audience: the mechanism explained plainly enough to reason from.
Why does the reasoning matter?
Because instructions without reasons do not survive contact with a real household.
Tell somebody to enable two-factor authentication and they will, on the accounts they think of, once. Explain what an attacker does with a password and which accounts are the ones that unlock everything else, and they will work out the rest themselves, including the case you did not anticipate.
This is also what makes the writing durable. Specific instructions go stale as products change. The reasoning does not, and a reader who has it can handle the next thing without a new book.
The best example I have is device inventory, and it is the chapter of Family Cybersecurity people mention most. Nobody needs telling to count their devices. What changes behavior is finding out that a two-year-old microwave attached itself to a neighbour’s unsecured network and was contacting the manufacturer nightly, because that reframes the whole category from theory into something in their kitchen.
Does fear work?
Briefly, and then it makes things worse.
Fear produces a burst of action followed by avoidance. A reader who is frightened and does not know what to do first concludes the situation is hopeless, and hopeless is considerably less useful than uninformed.
What works is a small ordered list with the reason attached and an honest statement of what each step is worth. Some things matter enormously and some barely matter, and telling people which is which is the part almost nobody does, because everything in the field is presented as essential.
A reader who does three things properly is safer than one who was told about thirty and did none.
The book on this: Real World Survival applies the same twenty years of disaster recovery to a household instead of a company.
Why write it as a book?
Because the audience does not read security content and will read one thing about their family.
Nobody in this group subscribes to security newsletters. They are not going to find a well-written blog post, because they are not looking. What they will do is read something recommended to them once, after an incident or a scare, and act on it that week.
That is an argument for a single durable artifact instead of a stream. It also means the framing matters more than the content list. A book about protecting your family gets read. A book about home network security does not, and the material inside can be identical.
What does this mean for anybody in a technical field?
The gap you can fill is the one between your competence and everybody else’s.
Technical people underrate what they know because everybody around them knows it too. Thirty years of enterprise work produces judgment that seems ordinary in the office and is genuinely rare outside it, and the translation is worth more than the expertise.
That is true well beyond security. It is true of anybody whose field has a public that keeps getting hurt by things the field considers obvious.
The neighbouring pieces are home computer security, where security breaks, and why most tools are theatre. The Cybersecurity Hub collects them, and my cybersecurity ghostwriting work exists because the people who understand this best are usually too busy defending things to write it down.
The Guides That Get Your Book Written, Published, and Sold
Four short, practical guides on writing, publishing, and selling your book, plus the occasional note when there's something worth your time. No fluff, no daily inbox clutter. Drop your email and they're yours.
We use MailerLite to manage our list and send these emails. Your address is used only to send you what you signed up for. We will not sell it, share it, or use it for anything else, and you can unsubscribe anytime.
Frequently Asked Questions
