Hydrologists write most flood advice for other hydrologists. The people whose kitchens fill with water get a leaflet. Security writing has the same shape. It’s produced by defenders, for defenders, in the vocabulary of an industry that’s been talking to itself for thirty years. It’s frequently excellent and it’s aimed at somebody with a budget, a team and a job title.
Meanwhile the losses land on a household or a small business with no security team, reading a warning written for somebody who has one. They can’t act on it, and the jargon makes them feel stupid for asking.
The priorities here are upside down. The industry spends fortunes defending companies that can absorb a breach, and then leaves a retired couple to puzzle out a phishing text by themselves. They’re the ones who lose the savings, and they’re the ones nobody writes for.
I watched it almost happen at a Walgreens. A family at the counter was buying gift cards, three of them at $500 each. I walked up and told them they didn’t want to do that. They asked why. A man on the phone had told them they needed the cards to pay for something. I told them it was a scam, and the cashier, who’d overheard by then, told them the same thing. They kept their $1,500. That family is exactly who security writing should be for.
Why does most security writing miss its audience?
Because the writers are describing their own working world. Somebody who spends their days on enterprise defense writes naturally about structures, threat models and posture. Every one of those is a real and useful concept. None of them means anything to a person trying to work out whether their router matters.
The second failure is scale. Advice built for an organization assumes somebody whose job includes this. A household has nobody whose job includes it, so any recommendation requiring sustained attention will be abandoned within a fortnight, and the writer will conclude that people don’t care.
They care. They have twenty minutes and no vocabulary. I get impatient with security people who call that apathy, because the label lets them off the hook for writing advice nobody could follow.
The book on this: Family Cybersecurity is 231 pages written for the household taking the losses, in plain words, with the reasoning attached.
What does writing cybersecurity for ordinary people require?
Assuming the reader is capable and busy. That’s different from assuming they’re ignorant.
The condescending tone is the most common failure, and I think it’s worse than jargon. A reader who feels talked down to stops reading immediately and doesn’t come back, and the next security message they pay attention to may be a scam text that sounds friendlier.
The person reading Family Cybersecurity runs a life. They handle insurance, mortgages, schools, ageing parents. They’re entirely capable of understanding what a router does. Nobody has ever explained it to them without either simplifying it into uselessness or burying it in terms.
What they need is an ordered list of what matters most, in plain words, with the reasoning attached so they can adapt it when their situation differs.
The book on this: The Day Your Website Died does the same job for a different audience: the mechanism explained plainly enough to reason from.
Why does the reasoning matter in cybersecurity writing?
Because instructions without reasons don’t survive contact with a real household. Tell somebody to enable two-factor authentication and they will, on the accounts they think of, once. Explain what an attacker does with a password and which accounts are the ones that unlock everything else, and they’ll work out the rest themselves, including the case you didn’t anticipate.
This is also what makes the writing durable. Specific instructions go stale as products change. The reasoning doesn’t, and a reader who has it can handle the next thing without a new book.
The best example I have is device inventory, and it’s the chapter of Family Cybersecurity people mention most. Nobody needs telling to count their devices. What changes behavior is finding out that a two-year-old microwave attached itself to a neighbor’s unsecured network and was contacting the manufacturer nightly, because that reframes the whole category from theory into something in their kitchen.
Does fear work in cybersecurity writing?
Briefly, and then it makes things worse.
Fear produces a burst of action followed by avoidance. A reader who’s frightened and doesn’t know what to do first concludes the situation is hopeless, and hopeless is considerably less useful than uninformed. Security marketing built on fear is a cheat. It scares people into buying a product, the fear fades within a week, and the household is left with a subscription and the same weak password on the bank account.
What works is a small ordered list with the reason attached and a plain statement of what each step is worth. Some things matter enormously and some barely matter.
Almost nobody tells people which is which, because everything in the field gets presented as essential, and I think that habit does real harm. When everything is urgent, a busy family can’t choose, so they do nothing.
A reader who does three things properly is safer than one who was told about thirty and did none.
The book on this: Real World Survival applies the same twenty years of disaster recovery to a household instead of a company.
Why write about cybersecurity as a book?
Because the audience doesn’t read security content and will read one thing about their family.
Nobody in this group subscribes to security newsletters. They’re not going to find a well-written blog post, because they’re not looking. What they’ll do is read something recommended to them once, after an incident or a scare, and act on it that week.
That’s an argument for a single durable artifact instead of a stream. It also means the framing outweighs the content list. A book about protecting your family gets read. A book about home network security doesn’t, and the material inside can be identical.
What should technical experts write about?
The gap you can fill is the one between your competence and everybody else’s. Technical people underrate what they know because everybody around them knows it too. Thirty years of enterprise work produces judgment that seems ordinary in the office and is rare outside it, and the translation is worth more than the expertise.
That’s true well beyond security. It’s true of anybody whose field has a public that keeps getting hurt by things the field considers obvious. I think experts who keep that knowledge inside the office are letting down the people who pay for the field’s blind spots, and the people things break on deserve a plain account of how they break.
The neighboring pieces are home computer security, where security breaks, and why most tools are theater. The Cybersecurity Hub collects them, and my cybersecurity ghostwriting work exists because the people who understand this best are usually too busy defending things to write it down.
