Home Technology Communications Cybersecurity Starts With Communication – And We May Be Getting It Wrong

Cybersecurity Starts With Communication – And We May Be Getting It Wrong

Representational image of cybersecurity

This post is also available in: עברית (Hebrew)

Cybersecurity advice is only effective if people understand it. Organizations routinely warn users about phishing, malware, trojans, and viruses, expecting those terms to communicate the nature of a threat. But a new study suggests that the language widely used to describe cyberattacks may actually reduce public understanding instead of improving it.

Researchers have found that people consistently understood cybersecurity incidents better when they were described using plain, literal language rather than the figurative terminology commonly used throughout the industry.

Many cybersecurity terms originated within technical and hacker communities, where metaphorical language became part of everyday communication. Words such as “phishing,” “virus,” and “trojan” are now deeply embedded in security culture, but researchers argue that these expressions can be confusing for people without a technical background.

To investigate the issue, researchers created two versions of the same cybersecurity scenarios. One used familiar industry terminology, while the other replaced those expressions with more direct descriptions of what was actually happening. Participants then answered questions measuring how well they understood each incident.

The results showed that those who read the literal descriptions achieved significantly higher comprehension scores than participants exposed to the figurative versions. According to TechXplore, although misunderstandings occurred in both groups, the findings suggest that simplifying terminology can make cyber incidents easier for non-experts to understand.

The study challenges a long-standing assumption in science communication that metaphors naturally help explain complex subjects. In cybersecurity, researchers argue, the opposite may often be true because many of the metaphors are meaningful only to people already familiar with the field.

From a cybersecurity perspective, the findings have practical implications. Organizations frequently notify customers about phishing campaigns, malware infections, or other security incidents. If recipients do not fully understand those terms, they may fail to recognize the seriousness of the situation or take the appropriate protective actions.

The issue is particularly important for critical infrastructure operators, government agencies, and emergency response organizations that must communicate cyber incidents quickly and clearly to both employees and the public. Effective communication can influence how rapidly users change passwords, recognize fraudulent messages, or report suspicious activity.

The researchers conclude that language should be considered an integral part of cybersecurity rather than simply a communication tool. As cyber threats become increasingly common, explaining them in clear, accessible terms may help improve public understanding and strengthen overall cyber resilience.

The research was published here.