Skip to main content

The (In)accessibility of Cybersecurity Communication

Cybersecurity, although a newer industry, has grown rapidly in recent years. Most people can agree that it’s an important industry but couldn’t explain why exactly. Vague ideas of hackers in black hoods stealing credit card numbers may come to mind when the topic of cybersecurity or internet safety. This problem stems from the lack of easily digestible internet safety resources. There are very few accessible resources that exist to teach everyday users the best practices and policies in cybersecurity.

Existing communication on cybersecurity's best practices and policy range from formal government policies to niche technology news outlets such as SC Media, The Hacker News, and AFCEA’s International Journal. The everyday user is not included in these audiences. Users who have no personal connection to what cybersecurity is and how it affects them are exceedingly unlikely to seek out information from cybersecurity company blogs, Homeland Security policy briefs, or niche magazines. Many young cybersecurity companies now house blogs and educational resources such as whitepapers and webinars, to market their products by informing their consumer base of the threat and providing the solution in one fell swoop. The goal of these articles is often to bridge the gap in security literacy between various departments, such IT and marketing, rather than to bridge the gap between the business and their users or consumers. This is evident in two common themes of these resources. Since professionals are their target audience, the documentation is frequently riddled with technical jargon or applied to specific business scenarios that the public cannot relate to.

The audience that cybersecurity content is written for is incredibly limited. This is one of the largest contributing factors to the inaccessibility of the information revolving around internet security and best practices. The recommended reading level for informative brochures and resources in the health industry is 5th grade to ensure that health literacy information can reach all patients. Although vastly different industries, this standard of providing accessible information should be mirrored in the technology industry. The ACM Code of Conduct dictates that technology professionals should strive to “improve public awareness and understanding of computing, related technologies, and their consequences.” And yet, a sample of a cybersecurity literature -- including blogs from cybersecurity companies, niche security magazines, large news outlets, and the White House Cybersecurity Strategy -- all scored reading levels of 10th grade or above. In fact, the average reading level of these sources was 13th grade, meaning that the intended audience of most of these articles is a reader with a college degree. However, 71% of U.S. adults who have less than a high school degree use the internet regularly.

Rather than taking a trickle-down approach to cybersecurity education that starts with cybersecurity experts and hopes that their advocacy within industry and policy is enough to protect the general population of users, we should be building a security literate user base from the ground up. There is no excuse for cybersecurity to be foreign idea anymore, as these threats are very real and cannot be stopped at a border. As such, it is important to provide the public with resources and knowledge to defend themselves. To effectively educate non-technical users on cybersecurity practices and policies, there are a few key shifts in the communication model that need to occur. First, the messaging needs to focus on relatability and education rather than scaring users into submission. Next, educational resources must be made more accessible by communicating threats and solutions at a level every user can understand and publishing them for varying audiences.

Cybersecurity is like infrastructure – you take it for granted and only realize its importance when you experience a problem, but then it is too late. Relating cybersecurity threats to the individual user can help tackle the sense of ambiguity surrounding the concepts. Despite the use of terms such as cyberwarfare, most cyber attacks are dependent on human error. By connecting users’ personal lives to phishing, identity theft, data breaches, and denial of service type attacks, they realize they have a personal stake in these threats.

The stigma that those outside of technical industries cannot understand security policy is dangerous. Just as the health industry provides accessible and easily understood resources for the general population’s safety, the technology industry must follow suit. Companies will need to spend less time and resources training their workforce to utilize cybersecurity best practices if adequate resources are provided to the general population. The more people with a basic understanding of how to protect their information online, the fewer people who will need to unlearn bad habits upon their entry to regulated industries. This means providing cybersecurity resources and literature being communicated on lower reading levels. Additionally, the dissemination of this information must be prominent enough to reach a variety of audiences.

Comments

Popular posts from this blog

Why Professional Writing?

How did I end up here? As I've gotten closer to graduating from college, I've had people ask me how I ended up on the path that I'm on and why I made the decisions that I did. It still makes me laugh a bit when someone asks me those questions because truthfully, I've never felt like I knew what I was doing. The short answer is that I continually made decisions that I thought would make me happier in the long run. When I applied to Purdue, I already knew I didn't want to go there. No offense, Purdue, but I grew up in West Lafayette, Indiana, and I'd promised to my parents for eight years that I would be moving away for college. To my utter dismay, after all of the college applications had been submitted and returned, I found myself needing to make a decision between going to an out of state college (my dream) and taking out student loans, or staying here and graduating debt-free. I'm here, so obviously I chose the latter. Applying to the Professional Writing ...

Writing Professionally Outside of Professional Writing

In an earlier entry, I noted that one of my vivid memories from my time in professional writing comes from the ironic realization that I was doing very little writing throughout one of my courses. Instead, this computer-aided publishing class mainly focused on the design of text and other content that already existed, with the actual writing in the class dealing with the decisions that went into the creation or modification of any presented design. In a sense, this course therefore focused more on the overall user experience of a document—how the user would view all the words and paragraphs and content as a whole—rather than how one would create the technical written elements that were necessary to form the document in the first place. Perhaps to balance this out, then, I want to discuss a recent writing experience that I find to be almost thematically opposite. One of the classes I took this semester was Purdue’s software engineering class, described on the university’s catalog as an ...

Virtual Learning Presents New Distractions for Elementary Students

  College students aren't the only ones using Zoom. For those of us in the academic world without children, it easy to forget that elementary students were also asked to adjust to this new e-learning way of life. Unfortunately, though, many of their questions remained unanswered when their world began changing so rapidly. This post will explore the thoughts and feelings of one current 4th grader. For privacy reasons, her name has been changed.  A 4th grader's personal anecdote.  In March 2020, two days before the elementary school shifted entirely to virtual learning, Sarah's father took her out of school and told her she would not be returning until the COVID-19 pandemic was under control. Sarah, who was still in 3rd grade at the time, did not understand what was going on, but she understood that, as her father said, she probably would not be returning to school for a while. The following Monday, Sarah received all of her textbooks and a Chromebook in the mail. Her teach...