Estimated reading time: 4 minutes
For Cybersecurity Awareness Month, a career communicator on the words the cyber industry uses, specifically the word cyber.
Mark Twain had a line for this. “The difference between the almost right word and the right word is really a large matter,” he wrote to George Bainton in 1888. “‘Tis the difference between the lightning-bug and the lightning.”
I learned it in a third-year university writing class I had no business taking and was warned to avoid. Ülle Lewes, Ph.D., taught it with a story. A friend of hers had been murdered in a crime of opportunity. Someone offered condolences on her friend’s passing. Before our small class, Professor Lewes let us have it. “She didn’t pass away,” she bellowed. “She was f***ing murdered.” I can still feel the moment.
Words carry weight. I have spent a career as a journalist, TV producer, and writer trying to put the right one in the right place. Which brings me, in Cybersecurity Awareness Month, to the words of my current beat.
Cyber risk, cyber insurance, and cyber resilience run on acronyms. I asked Claude how many. Hundreds, it said, and counting. EDR, XDR, SIEM, SOAR. BEC, RaaS, IAB, TTP. Three years ago, new to the beat, I kept a spreadsheet of them. It grew faster than I learned. Eventually I closed it.
It felt familiar. In the early 2000s, I produced military history documentaries, and the US military speaks fluent shorthand. That shorthand speeds communication among people who share the code. Outside the circle, it can dull the edge of things that ought to cut.
Jargon serves the professionals. The risk lands on everyone. The person who opens the door to a criminal is rarely a security engineer. It is the store clerk who clicks the link. It is the employee who approves a login prompt they never triggered, or pastes customer data into an unapproved AI tool. And it is the help desk worker who resets a password for a caller who sounds just right.
Being clever is no exemption. This week Proofpoint described a phishing campaign aimed at AI policy experts at think tanks and universities. The clerk and the CEO hold the same key, and criminals know it.
So here is a thought I’m not sure the industry is ready for. Maybe we strip out the word cyber. Cybercrime is crime. Hackers are criminals. A ransomware gang is an extortion racket with better software. Digital business is no longer a sector. It is the economy, from one-person LLCs to global giants.
Consider Jaguar Land Rover. In 2025, a cyberattack stopped its production lines for about five weeks. The Cyber Monitoring Centre put the cost to the UK economy at around £1.9 billion, across some 5,000 organizations. The government guaranteed a £1.5 billion loan to keep the company and its suppliers standing. Some of us still cover this story. Now imagine the same damage done with a bomb, or a fire. Smoke over a car plant is a picture. As a TV producer, I know what we would have done with it. The rebuilding would have been a national story. A frozen server makes no picture at all.
That is the trouble. The risk feels invisible. The same ones and zeros that bring Netflix to our phones move cash between bank accounts an ocean apart. Invisible risks are easy to ignore. Plain words make them visible.
You don’t have to explain it as if you’re talking to a fifth grader. But a fifth grader should be able to follow it. Say it plainly. Say it cleanly. If they lean in, double-click. Yes, I know. That’s jargon too.
This is an opinion column. The views are the author’s own. It draws on Cyber Insurance News reporting, linked where cited. Interested in writing a column? Email martinhinton@cyberinsurancenews.org to discuss it.
Related Cyber Insurance Posts
- Most UK Retailers Hit By Cyber Disruption Say They Overspend On Cyber
- Incident Response Made Clear: Powerful Words, Tough Choices, and a Cyber Insurance Reality Check(Opens in a new browser tab)
- SMB Cybersecurity 2025: Troubling Report Exposes Protection Gaps Despite High Awareness(Opens in a new browser tab)