← All writing

Nobody reads your security advice

What I learned writing a cybersecurity book for people who don't care about cybersecurity.

Here's the advice: use a password manager, enable two-factor authentication, don't reuse passwords, keep your software updated, be careful what you click.

You've read it before. You know it's correct. Check honestly whether you've done all five.

That gap — between people knowing the advice and people following it — is the entire problem, and the security industry has spent twenty years responding to it by repeating the advice louder.

I wrote a book about this, aimed at people who are not engineers. The writing taught me more about why the advice fails than any amount of reading had.

The advice is written for people who already agree

"Just use a password manager" is four words hiding an afternoon of work. Install it, learn it, move a hundred accounts over, hit the site that breaks autofill, fail to log in on your phone at a checkout, and now you associate security with humiliation.

The person giving that advice did this years ago and has forgotten the cost. They're not describing a small action. They're describing a small action *for them*.

Any advice that ignores friction is advice for people who were going to comply anyway.

Fear doesn't work, and it makes things worse

The standard move is to escalate. Statistics about breaches. Someone's life savings gone. Scare them into compliance.

It doesn't work, and I don't think it fails for the reason people assume. It's not that the threat sounds unrealistic. It's that it sounds *inevitable*.

The young people I wrote for aren't naive about being tracked, scraped and breached. They assume it. They've watched every platform they use leak, and watched nothing happen to anyone afterward. That's not ignorance. It's a learned conclusion that the outcome doesn't depend on their behaviour.

You cannot scare someone who has already given up. Adding another statistic confirms their model. The only thing that moves a fatalist is evidence that a specific action changes a specific outcome — small, concrete, provable.

Most of the list doesn't matter

A realistic threat model for an ordinary person is not a nation-state. It's credential stuffing — a password leaked from some forum in 2019 being sprayed at their bank. It's a phishing page. It's a friend's hijacked account asking for money. It's someone who has physical access to their unlocked phone.

Against those, almost all of the advice is noise, and three things carry the weight:

A unique password on the email account. Email is the skeleton key — every reset link goes there. If email falls, everything falls, in an order the attacker chooses.

Two-factor on that same email account. One account. Not everywhere, not yet. One.

Automatic updates on the phone. Because the alternative is asking someone to make a good decision every month forever, and they won't.

That's it. That's the list I'd give someone who will do exactly one thing this year. The other seventeen items are real, and they are for later, and leading with them is how you lose the reader before item three.

Lead with the scene, not the principle

The thing that changed my writing most:

Nobody absorbs "enable two-factor authentication." People absorb "someone gets into your email at 2am, resets your banking password, and deletes the notification before you wake up."

Same advice. One is a chore. The other is a scene you can picture yourself inside — and the action arrives as relief rather than homework.

Security writing fails because it's organised like documentation, as a list of controls, when it should be organised like a story: here's what happens, here's the one moment it could have gone differently, here's what sits at that moment.

What I'd tell anyone writing this stuff

Assume your reader is smart, busy, and has been let down by this advice before. Do not open by telling them the stakes are high; they know, and it reads as a sales pitch.

Open with the specific way it goes wrong. Name the one thing that would have stopped it. Then stop talking.

The measure of security writing isn't whether it's complete. It's whether anyone changed one setting because of it. By that measure most of what we publish — mine included, some days — is decoration.