How to Make Cybersecurity Language Clearer

TL;DR
Replace intimidating security jargon with familiar, inclusive language that helps users understand, care, and act. Calling security “protection,” defining unavoidable technical terms before using them, and creating a small organizational glossary can build shared understanding among practitioners, users, decision-makers, vendors, customers, and policymakers.
Transcript
Thank you very much. So good morning. So yesterday, I had the good fortune of attending, uh, Taylor Wilson's keynote. Now, Taylor is a nineteen-year-old nuclear scientist, who at the age of fourteen created a nuclear fusion device. I was enthralled listening to him describe his accomplishments, describe his plans for commercialization, and describe... Read More
Key Insights
- Words influence both thought and feeling, so effective communication must produce intellectual understanding as well as an emotional response. People need to understand and believe the message before they are likely to care about it, support it, or take the requested action.
- Security communication is often harsh, overwhelming, chaotic, and negative. Language framed around threats and intimidating technical concepts can alienate users instead of inviting them to participate, weakening initiatives that otherwise have strong intentions, useful technology, sound architecture, and carefully written policies.
- The term “security” can suggest black vehicles, armed guards, cages, jails, locks, and static restrictions. These associations encourage people to view responsibility as belonging to a security officer or guard, rather than recognizing that they personally contribute to protecting an organization.
- The word “protection” is a positive and relatable alternative to “security.” People already understand protecting their children, homes, and country, so the term describes an accessible action and can help communities and decision-makers see themselves as active contributors rather than passive users.
- Technical jargon intimidates people as well as confusing them. Users who do not understand terms such as DDoS, SQL injection, cross-site scripting, or hash may avoid asking questions because they do not want to feel embarrassed or appear uninformed in front of others.
- Common language supports action because audiences can connect unfamiliar issues to concepts they already understand. Doctors and pharmacists may use specialized terminology with professional peers, but they use “common cold” with patients, illustrating why practitioners should adapt vocabulary to their audience.
- Unavoidable technical terms should be explained proactively at the beginning of a conversation. Waiting for audience members to admit confusion is unreliable, and unexplained language can cause users or decision-makers to make choices without sharing the practitioner’s understanding of the issue.
- An organizational glossary can establish consistent meanings for five to ten frequently used terms. The definitions do not need to duplicate those of external bodies, but they must be shared across the organization, published, distributed, attached to relevant documents, and used consistently.
Install to Summarize YouTube Videos and Get Transcripts
Explore YouTube Video Summarizer or Get YouTube Transcript Extractor
Questions & Answers
Q: Why does cybersecurity language affect security initiatives?
Cybersecurity language affects whether users and decision-makers understand an initiative, care about it, and act on it. Words produce both intellectual and emotional responses. When communication is harsh, chaotic, negative, or filled with unfamiliar terms, it alienates the people whose participation is needed. Clear, compelling language creates common understanding and can turn users into active partners in building safer environments.
Q: Why replace the word security with protection?
The word “security” may evoke armed guards, black vehicles, cages, jails, locks, and restrictions. It can also imply that responsibility belongs to a security officer rather than ordinary users. “Protection” describes a familiar and positive action associated with children, homes, and country. Using it can help people relate to the goal and recognize that they have a role in achieving it.
Q: How does technical jargon discourage user participation?
Technical jargon prevents users from understanding what practitioners want them to know or do. It can also intimidate or embarrass people, making them reluctant to admit that a term is unfamiliar. As a result, they may remain silent, disengage from the discussion, or make decisions without a shared understanding of concepts such as DDoS, SQL injection, cross-site scripting, or hash.
Q: How should security practitioners explain technical terms?
Security practitioners should use common, everyday words whenever an accurate alternative exists. When a specialized term has no suitable common equivalent, they should provide a brief explanation at the start of the conversation instead of waiting for someone to ask. Proactive definitions reduce embarrassment, establish shared understanding, and give users and decision-makers a better basis for responding or making decisions.
Q: What can cybersecurity communication learn from doctors?
Doctors may use specialized medical vocabulary when speaking with other doctors or pharmacists, but they generally use familiar terms when communicating with patients. The talk illustrates this distinction by contrasting “acute viral rhinopharyngitis” with “common cold.” Security practitioners should apply the same audience-aware approach, reserving specialist terminology for appropriate peers and choosing accessible language when seeking understanding, participation, or action from users.
Q: Why are inconsistent definitions a security problem?
Inconsistent definitions make it difficult for practitioners, users, decision-makers, and lawmakers to act toward the same goal. Even a frequently used concept such as risk may be defined differently by colleagues and authoritative sources. If an organization has no shared vocabulary for fundamental concepts, people may interpret proposals, training, policies, and discussions differently, leading to confusion and decisions based on incompatible assumptions.
Q: How do you create an organizational protection glossary?
Identify five to ten terms that appear repeatedly in organizational proposals, training, policies, and routine discussions. Ask colleagues from security, information technology, and other parts of the organization to help establish clear definitions. The definitions do not need to match every external authority, but they must work for the organization and its users. Publish, distribute, attach, and apply the glossary consistently.
Q: What makes cybersecurity communication persuasive?
Persuasive cybersecurity communication creates a common language and addresses both understanding and emotion. The audience must be able to think through the message, believe it, care about it, and see how to act. Familiar, positive, and inclusive wording supports those goals. Menacing phrases, unexplained acronyms, and inconsistent terminology work against them by creating distance between practitioners and the communities they need to engage.
Summary & Key Takeaways
-
Security initiatives can fail even when they begin with strong intentions because practitioners do not communicate effectively with their user communities. Technical expertise, policies, architecture, and tools are insufficient when users feel alienated. Clear language creates shared understanding, encourages emotional and intellectual engagement, and helps people support safer digital environments.
-
The word “security” can evoke guards, guns, cages, locks, and the idea that protection belongs to somebody else. Replacing it with “protection” presents a familiar, positive action associated with homes, children, and country. That change can help users recognize their own role and become active participants in organizational protection.
-
Technical jargon and inconsistent definitions prevent informed participation. Practitioners should use common words whenever possible, explain unavoidable terminology without waiting for questions, and define frequently used concepts consistently. A practical organizational glossary can cover five to ten terms appearing regularly in proposals, policies, training, and other documents, then be published and used consistently.
Read in Other Languages (beta)
Share This Summary 📚
Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator
Explore More Summaries from RSAC Cybersecurity 📚






Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator