Latest
Anthropic Bans Cruelty Toward Claude: What It Means for WritersWork-for-Hire Contracts: What the Asimov’s Cover Fight Teaches FreelancersGenre Fiction vs Literary Fiction: Don’t Confuse Taste With SkillFlorida Hurricane Prep Rituals: The Grocery Run, the Water Pallet and the Generator in the BoxThe Most Insulting Line of Dialogue Ever Written for the ScreenLoki Through the Ages: From Norse Myth to Marvel, The Mask and Dogma“You Are Utterly Disgusting”: A Book Festival, an AI Cover Ban and a Pile-OnWho Rewrote the Sligachan Legend: AI or the Tour Buses?Why I Don’t Like Reedsy for Ghostwriting: The NDA ProblemLayers: How I Ride Out Florida Power Outages in My ApartmentThe Enshittification of AmazonPublishers Cancel Books Over AI While Using It in SecretI Was Getting 100 Spam Emails a Day. $4.50 a Month Fixed It.World Mental Health Day: Nothing Was Wrong With MeKessler Syndrome: How Space Debris Could Close Earth’s OrbitAmazon Is Blocking Real Readers From Book ReviewsShould a Novella Get a Paperback, or Go Ebook Only?BookFunnel Download Problems: Fixes, Scams and AlternativesSir Sean Connery: A TributeHow to Find Plot Holes in Your Novel (Most Are Character Holes)Reshoring: The Factory Is the Easy PartMost of the Books I Was Forced to Read in High School Were CrapPlot Armor: Signs Your Hero Is Too Safe, and How to Fix ItShould You Sell Lifetime Rights to Your Self-Published Book for a Modest Advance?Shame Doesn’t Stop Artists From Using AI. It Stops Them From Telling You.AI Labels on TikTok and Meta Are Flagging Human WorkAuthor Richard Lowe Completes Peacekeeper, a Four-Book Science Fiction Series He Started at Age 14Sir Sam Neill: A TributeFan Art Copied by AI: Glass Houses, Copyright and the Pile-OnReal Names in a Book: Who Gets Sued, the Author, the Publisher or the Ghostwriter?When Characters Take Over the Plot, Let ThemDoes Human Writing Have a Soul?“You’re Not a Real Author”: The Pile-On Over AI-Assisted BooksDoes AI Have a Soul? Wrong QuestionHumor in Book Marketing: Getting Attention Without BeggingHow Long Should a Chapter Be? Manuscript Habits That Save You LaterThe Business Novel and the Companion Workbook: Two Formats Business Authors OverlookThe Back of the Book: Index, About the Author, Acknowledgments and Back Cover CopyI Build My Own Software Tools With Claude, and Some of Them Bit MeWhat Years of Buying From IT Vendors Taught MeI Write Books for a Living. I Barely Read Them Anymore.Three Management Habits That Waste Good PeopleThe Coach and the Webinar That Sold Me NothingThe Work I’d Cringe At Now, and Why I’m Glad I DoWho Is Your Book For? Build a Reader Avatar Before Chapter OnePreface, Prologue, Foreword or Introduction: What Goes WhereWhy I Won’t Build a Ghostwriting Business That ScalesHow I Hire a Virtual Assistant: Do It, Script It, Hand It OffThe Mail Carrier Who Thought Flipping Houses Was EasyWhat Wedding Photography Taught Me About Pricing Creative Work
The Writing King Your Ethical Ghostwriter. Your Story, Done Right.

The People Getting Attacked Are the Ones Nobody Writes For

TL;DR: Security writing is written by defenders for defenders. The households and small businesses taking most of the losses get warnings they can’t act on and jargon that makes them feel stupid. Writing for them is a different job, and the main difference is assuming the reader is capable and busy.

Hydrologists write most flood advice for other hydrologists. The people whose kitchens fill with water get a leaflet. Security writing has the same shape. It’s produced by defenders, for defenders, in the vocabulary of an industry that’s been talking to itself for thirty years. It’s frequently excellent and it’s aimed at somebody with a budget, a team and a job title.

Meanwhile the losses land on a household or a small business with no security team, reading a warning written for somebody who has one. They can’t act on it, and the jargon makes them feel stupid for asking.

The priorities here are upside down. The industry spends fortunes defending companies that can absorb a breach, and then leaves a retired couple to puzzle out a phishing text by themselves. They’re the ones who lose the savings, and they’re the ones nobody writes for.

I watched it almost happen at a Walgreens. A family at the counter was buying gift cards, three of them at $500 each. I walked up and told them they didn’t want to do that. They asked why. A man on the phone had told them they needed the cards to pay for something. I told them it was a scam, and the cashier, who’d overheard by then, told them the same thing. They kept their $1,500. That family is exactly who security writing should be for.

Why does most security writing miss its audience?

Why most security writing misses the people who need itWriters describe their own working world. Somebody who spends their days on enterprise defence writes naturally about frameworks, threat models and posture, all real and useful concepts, and none of them means anything to a person trying to work out whether their router matters. The second failure is scale: advice built for an organisation assumes somebody whose job includes this, and a household has nobody whose job includes it, so any recommendation requiring sustained attention gets abandoned within a fortnight and the writer concludes that people do not care. They care. They have twenty minutes and no vocabulary.Why security writing misses the householdThey care. They have twenty minutes and no vocabulary.1The writer describes their worldFrameworks. Threat models. Posture.All real, all useful, all professional.2The reader has a routerAnd no way to connect any of itto the question they actually have3The advice assumes a jobSomebody whose work includes thisA household has nobody4So it gets abandonedWithin a fortnight, and the writerdecides people do not careAdvice requiring sustained attention fails in a house where nobody is paid to pay attention.
Why most security writing misses the people who need itWriters describe their own working world. Somebody who spends their days on enterprise defence writes naturally about frameworks, threat models and posture, all real and useful concepts, and none of them means anything to a person trying to work out whether their router matters. The second failure is scale: advice built for an organisation assumes somebody whose job includes this, and a household has nobody whose job includes it, so any recommendation requiring sustained attention gets abandoned within a fortnight and the writer concludes that people do not care. They care. They have twenty minutes and no vocabulary.Why security writing missesthe householdThey care. They have twenty minutes and novocabulary.1The writer describes their worldFrameworks. Threat models. Posture.All real, all useful, all professional.2The reader has a routerAnd no way to connect any of itto the question they actually have3The advice assumes a jobSomebody whose work includes thisA household has nobody4So it gets abandonedWithin a fortnight, and the writerdecides people do not careAdvice requiring sustained attention fails in ahouse where nobody is paid to pay attention.

Because the writers are describing their own working world. Somebody who spends their days on enterprise defense writes naturally about structures, threat models and posture. Every one of those is a real and useful concept. None of them means anything to a person trying to work out whether their router matters.

The second failure is scale. Advice built for an organization assumes somebody whose job includes this. A household has nobody whose job includes it, so any recommendation requiring sustained attention will be abandoned within a fortnight, and the writer will conclude that people don’t care.

They care. They have twenty minutes and no vocabulary. I get impatient with security people who call that apathy, because the label lets them off the hook for writing advice nobody could follow.

The book on this: Family Cybersecurity is 231 pages written for the household taking the losses, in plain words, with the reasoning attached.

What does writing cybersecurity for ordinary people require?

Assuming the reader is capable and busy. That’s different from assuming they’re ignorant.

The condescending tone is the most common failure, and I think it’s worse than jargon. A reader who feels talked down to stops reading immediately and doesn’t come back, and the next security message they pay attention to may be a scam text that sounds friendlier.

The person reading Family Cybersecurity runs a life. They handle insurance, mortgages, schools, ageing parents. They’re entirely capable of understanding what a router does. Nobody has ever explained it to them without either simplifying it into uselessness or burying it in terms.

What they need is an ordered list of what matters most, in plain words, with the reasoning attached so they can adapt it when their situation differs.

The book on this: The Day Your Website Died does the same job for a different audience: the mechanism explained plainly enough to reason from.

Why does the reasoning matter in cybersecurity writing?

Because instructions without reasons don’t survive contact with a real household. Tell somebody to enable two-factor authentication and they will, on the accounts they think of, once. Explain what an attacker does with a password and which accounts are the ones that unlock everything else, and they’ll work out the rest themselves, including the case you didn’t anticipate.

This is also what makes the writing durable. Specific instructions go stale as products change. The reasoning doesn’t, and a reader who has it can handle the next thing without a new book.

The best example I have is device inventory, and it’s the chapter of Family Cybersecurity people mention most. Nobody needs telling to count their devices. What changes behavior is finding out that a two-year-old microwave attached itself to a neighbor’s unsecured network and was contacting the manufacturer nightly, because that reframes the whole category from theory into something in their kitchen.

Does fear work in cybersecurity writing?

Briefly, and then it makes things worse.

Fear produces a burst of action followed by avoidance. A reader who’s frightened and doesn’t know what to do first concludes the situation is hopeless, and hopeless is considerably less useful than uninformed. Security marketing built on fear is a cheat. It scares people into buying a product, the fear fades within a week, and the household is left with a subscription and the same weak password on the bank account.

What works is a small ordered list with the reason attached and a plain statement of what each step is worth. Some things matter enormously and some barely matter.

Almost nobody tells people which is which, because everything in the field gets presented as essential, and I think that habit does real harm. When everything is urgent, a busy family can’t choose, so they do nothing.

A reader who does three things properly is safer than one who was told about thirty and did none.

The book on this: Real World Survival applies the same twenty years of disaster recovery to a household instead of a company.

Why write about cybersecurity as a book?

Because the audience doesn’t read security content and will read one thing about their family.

Nobody in this group subscribes to security newsletters. They’re not going to find a well-written blog post, because they’re not looking. What they’ll do is read something recommended to them once, after an incident or a scare, and act on it that week.

That’s an argument for a single durable artifact instead of a stream. It also means the framing outweighs the content list. A book about protecting your family gets read. A book about home network security doesn’t, and the material inside can be identical.

What should technical experts write about?

The gap you can fill is the one between your competence and everybody else’s. Technical people underrate what they know because everybody around them knows it too. Thirty years of enterprise work produces judgment that seems ordinary in the office and is rare outside it, and the translation is worth more than the expertise.

That’s true well beyond security. It’s true of anybody whose field has a public that keeps getting hurt by things the field considers obvious. I think experts who keep that knowledge inside the office are letting down the people who pay for the field’s blind spots, and the people things break on deserve a plain account of how they break.

The neighboring pieces are home computer security, where security breaks, and why most tools are theater. The Cybersecurity Hub collects them, and my cybersecurity ghostwriting work exists because the people who understand this best are usually too busy defending things to write it down.

Frequently Asked Questions

Why does most cybersecurity writing fail ordinary readers?
Because it’s written by defenders describing their own working world, in a vocabulary aimed at somebody with a budget and a team. Advice built for organizations assumes a person whose job includes this, and a household has nobody like that.
What does security writing for non-experts need to do?
Assume the reader is capable and busy. Give an ordered list of what matters most, in plain words, with the reasoning attached so they can adapt it when their situation differs from the example.
Why include reasoning instead of just instructions?
Because instructions without reasons don’t survive a real household, and they go stale as products change. A reader who understands what an attacker does with a password will handle the case you didn’t anticipate.
Does scaring people improve security behavior?
Briefly, then it backfires. A frightened reader who doesn’t know what to do first concludes the situation is hopeless, and that’s less useful than being uninformed. Three things done properly beats thirty things listed.
Why write a security book instead of articles?
Because this audience doesn’t read security content and isn’t looking for it. They’ll read one recommended thing after a scare and act on it that week. That argues for a single durable artifact instead of a stream.

About the Author
Richard Lowe, professional ghostwriter

Richard Lowe is a professional ghostwriter and author with 113+ books authored and 54+ ghostwritten. Before writing full time he spent 33 years in enterprise technology, including 20 years as Director of Computer Operations and Technical Services at Trader Joe's. He writes nonfiction, fiction and memoir, and works with executives and experts on books that build authority.

More about Richard Lowe →

Disclaimer

The views and opinions expressed in this blog post are solely those of Richard Lowe and are based on personal experience and research. This content is for informational purposes only and should not be construed as professional legal, financial, accounting, or business advice. Always consult with qualified professionals before making important business or legal decisions. Richard Lowe is not a lawyer, accountant, or licensed professional advisor, and this content does not establish any professional relationship.

0 comments

No comments yet. Yours can be the first.

Was this useful?

Leave a comment