Think you understand ‘phishing’? Think again. Why cybersecurity language is failing us and actually helping the scammers.
Cyberattacks now cost the global economy trillions, yet most people still struggle to understand what actually happens when a breach occurs.
And research suggests the language used to explain cybersecurity may be part of the problem.
Associate Professor Sky Marsen, an applied linguist and communications course director at Flinders University, and Professor Robert Biddle, a computer scientist based from Carleton University, Canada, conducted an experimental study comparing “figurative” cybersecurity language (terms such as phishing, virus, or trojan) with more literal explanations. They found that people understood incidents significantly better when the language was clearer and less metaphorical.
This challenges a widespread assumption in science communication – that metaphors help non-experts grasp complex ideas. In cybersecurity, the opposite may be true.
“These terms weren’t designed for the public in the first place,” explains Associate Professor Marsen.
“They emerged from inside hacker culture, and terms that may sound creative and playful within expert communities are often opaque to outsiders - when they are used in public communication, they can obscure rather than clarify what’s happening.”
Given the rise of cybersecurity concerns, Associate Professor Marsen says it’s timely to understand how non-experts understand cybersecurity words and metaphors – especially the figurative language created by computer scientists to describe cybersecurity incidents.
A lack of accurate information makes cybersecurity an issue that is difficult to clearly explain to the public – and this can lead to major losses for individuals and serious reputational damage for organisations.
“Organisations routinely tell customers they’ve been hit by phishing or a malware attack, but if people don’t fully understand what that means, they may not know how to respond or protect themselves,” says Associate Professor Marsen.
“Worse is that unclear communication can downplay the responsibility of organisations, or leave users vulnerable.”
Using cyberattack stories written in two different ways, one using creative terms and comparisons, and the other using more direct language, along with an online survey, the study explores whether these words and expressions help everyday people better understand cybersecurity or make it more confusing.
The results showed participants in the literal set scored significantly better in comprehension. However, participants made important errors in both literal and figurative versions. This underlines the need for organisations to employ language strategically and provide more effective explanations of cybersecurity situations.
Associate Professor Marsen says a key takeaway from this research is that paying attention to language choices in professional communication is not just a stylistic choice but a public safety issue.
- Associate Professor Sky Marsen,
Flinders University
Sturt Rd, Bedford Park
South Australia 5042
South Australia | Northern Territory
Global | Online
CRICOS Provider: 00114A TEQSA Provider ID: PRV12097 TEQSA category: Australian University
Flinders University uses cookies to ensure website functionality, personalisation and a variety of purposes as set out in its website privacy statement. This statement explains cookies and their use by Flinders.
If you consent to the use of our cookies then please click the button below:
If you do not consent to the use of all our cookies then please click the button below. Clicking this button will result in all cookies being rejected except for those that are required for essential functionality on our website.