The Writing King Your Ethical Ghostwriter. Your Story, Done Right.

The People Getting Attacked Are the Ones Nobody Writes For

This entry is part 21 of 21 in the series Technology
TL;DR: Security writing is written by defenders for defenders. The households and small businesses taking most of the losses get warnings they cannot act on and jargon that makes them feel stupid. Writing for them is a different job, and the main difference is assuming the reader is capable and busy, not ignorant.

Most flood advice is written by hydrologists for other hydrologists. The people whose kitchens fill with water get a leaflet.

Security writing has the same shape. It is produced by defenders, for defenders, in the vocabulary of an industry that has been talking to itself for thirty years. It is frequently excellent and it is aimed at somebody with a budget, a team and a job title.

Meanwhile the losses land on households and small businesses, who receive warnings they cannot act on and terminology that makes them feel stupid for asking.

Why does most security writing miss its audience?

Because the writers are describing their own working world.

Somebody who spends their days on enterprise defense writes naturally about frameworks, threat models and posture. Every one of those is a real and useful concept. None of them means anything to a person trying to work out whether their router matters.

The second failure is scale. Advice built for an organization assumes somebody whose job includes this. A household has nobody whose job includes it, so any recommendation requiring sustained attention will be abandoned within a fortnight, and the writer will conclude that people do not care.

They care. They have twenty minutes and no vocabulary.

The book on this: Family Cybersecurity is 231 pages written for the household taking the losses, in plain words, with the reasoning attached.

What does writing for them require?

Assuming the reader is capable and busy, which is different from assuming they are ignorant.

The condescending register is the most common failure and it is worse than jargon, because a reader who feels talked down to stops reading immediately and does not come back.

The person reading Family Cybersecurity runs a life. They handle insurance, mortgages, schools, ageing parents. They are entirely capable of understanding what a router does. Nobody has ever explained it to them without either simplifying it into uselessness or burying it in terms.

What they need is an ordered list of what matters most, in plain words, with the reasoning attached so they can adapt it when their situation differs.

The book on this: The Day Your Website Died does the same job for a different audience: the mechanism explained plainly enough to reason from.

Why does the reasoning matter?

Because instructions without reasons do not survive contact with a real household.

Tell somebody to enable two-factor authentication and they will, on the accounts they think of, once. Explain what an attacker does with a password and which accounts are the ones that unlock everything else, and they will work out the rest themselves, including the case you did not anticipate.

This is also what makes the writing durable. Specific instructions go stale as products change. The reasoning does not, and a reader who has it can handle the next thing without a new book.

The best example I have is device inventory, and it is the chapter of Family Cybersecurity people mention most. Nobody needs telling to count their devices. What changes behavior is finding out that a two-year-old microwave attached itself to a neighbour’s unsecured network and was contacting the manufacturer nightly, because that reframes the whole category from theory into something in their kitchen.

Does fear work?

Briefly, and then it makes things worse.

Fear produces a burst of action followed by avoidance. A reader who is frightened and does not know what to do first concludes the situation is hopeless, and hopeless is considerably less useful than uninformed.

What works is a small ordered list with the reason attached and an honest statement of what each step is worth. Some things matter enormously and some barely matter, and telling people which is which is the part almost nobody does, because everything in the field is presented as essential.

A reader who does three things properly is safer than one who was told about thirty and did none.

The book on this: Real World Survival applies the same twenty years of disaster recovery to a household instead of a company.

Why write it as a book?

Because the audience does not read security content and will read one thing about their family.

Nobody in this group subscribes to security newsletters. They are not going to find a well-written blog post, because they are not looking. What they will do is read something recommended to them once, after an incident or a scare, and act on it that week.

That is an argument for a single durable artifact instead of a stream. It also means the framing matters more than the content list. A book about protecting your family gets read. A book about home network security does not, and the material inside can be identical.

What does this mean for anybody in a technical field?

The gap you can fill is the one between your competence and everybody else’s.

Technical people underrate what they know because everybody around them knows it too. Thirty years of enterprise work produces judgment that seems ordinary in the office and is genuinely rare outside it, and the translation is worth more than the expertise.

That is true well beyond security. It is true of anybody whose field has a public that keeps getting hurt by things the field considers obvious.

The neighbouring pieces are home computer security, where security breaks, and why most tools are theatre. The Cybersecurity Hub collects them, and my cybersecurity ghostwriting work exists because the people who understand this best are usually too busy defending things to write it down.

The Guides That Get Your Book Written, Published, and Sold

Four short, practical guides on writing, publishing, and selling your book, plus the occasional note when there's something worth your time. No fluff, no daily inbox clutter. Drop your email and they're yours.

We use MailerLite to manage our list and send these emails. Your address is used only to send you what you signed up for. We will not sell it, share it, or use it for anything else, and you can unsubscribe anytime.

Frequently Asked Questions

Why does most cybersecurity writing fail ordinary readers?
Because it is written by defenders describing their own working world, in a vocabulary aimed at somebody with a budget and a team. Advice built for organizations assumes a person whose job includes this, and a household has nobody like that.
What does security writing for non-experts need to do?
Assume the reader is capable and busy, not ignorant. Give an ordered list of what matters most, in plain words, with the reasoning attached so they can adapt it when their situation differs from the example.
Why include reasoning instead of just instructions?
Because instructions without reasons do not survive a real household, and they go stale as products change. A reader who understands what an attacker does with a password will handle the case you did not anticipate.
Does scaring people improve security behavior?
Briefly, then it backfires. A frightened reader who does not know what to do first concludes the situation is hopeless, which is less useful than being uninformed. Three things done properly beats thirty things listed.
Why write a security book instead of articles?
Because this audience does not read security content and is not looking for it. They will read one recommended thing after a scare and act on it that week, which argues for a single durable artifact instead of a stream.


📁︎ Cybersecurity📁︎ Technology📁︎ Writing

🏷︎ Book Writing🏷︎ Cybersecurity🏷︎ Security

📝 Disclaimer

The views and opinions expressed in this blog post are solely those of Richard Lowe and are based on personal experience and research. This content is for informational purposes only and should not be construed as professional legal, financial, accounting, or business advice. Always consult with qualified professionals before making important business or legal decisions. Richard Lowe is not a lawyer, accountant, or licensed professional advisor, and this content does not establish any professional relationship.

Leave a Reply

Your email address will not be published. Required fields are marked *