top of page


Cyber-archaeology
Recently, someone kindly pointed me at NBSIR 76-1041 “Security Analysis and Enhancements of Computer Operating Systems”, a fifty-year old standard from the US Department of Commerce, National Bureau of Standards (which became NIST in 1988). It was produced by the Research In Secured Operating Systems project at Lawrence Livermore Laboratory, home of the US nuclear weapons program since 1952. Parsing the glossary section revealed several alternative definitions for terms alrea
Jul 111 min read


A living document
Language is a constantly-evolving social construct: terms, phrasing, meanings, interpretations and implications all vary over time. Furthermore, they vary between individuals or communities and contexts. This morning, for instance, I have added "government security" to my working version of the Cybersecurity Hyperglossary, a term that can refer either to government-issued bonds or to the protective status of government - two markedly different meanings. I also defined "neol
Jul 102 min read


Context is everything
What is an "information system" to you? The newly-updated ISO 9000:2026 defines it as "Network of communication channels used within an organization" - an unusual and intriguing perspective, presumably expressed that way to suit the specific context of the Quality Assurance standards? Hmmmmm, I'm not sure. That (to me) rather curious definition of "information system" has caught my beady eye and left me quietly pondering, for days so far. The ISO 9000 definition set me wond
Jun 42 min read


Why 'cyber'?
Over in the hyperglossary community this week, we've been chatting about 'cyber' as in cybersecurity etc. The old guard who were already deeply immersed in the field prior to Y2k are distinctly cynical about cyber-everything. Been there, done that, using the teeshirts for rags. Deep-dive coming [takes a big breath ...] When a BBC article explored the origin of the term a decade ago, 'cyber' essentially meant 'the internet' ... although, as I recall back then, 'the web' was mo
May 54 min read


Sampler available
CRC Press has released an 80-page sampler of the book - from the front cover to the end of the 'A' section. It is representative of the entire book, with the following format throughout: Amazon is showing "Only 8 left in stock (more on the way)", so the paperback is selling well and the Kindle or eBook versions never run out. Got your copy yet? Making good use of it?
Apr 281 min read


Reflecting on a year's work
Most days I put some effort into the Cybersecurity Hyperglossary - checking and correcting things, reconsidering and updating meanings, researching the language, adding new terms and cross-linking. It's an absorbing process requiring deep concentration and focus. For this autist, it's satisfying and fun. I enjoy my work! Given my interest in metrics, I'm using a few simple statistics to measure my progress. Here's a snapshot: In the 12 months since submitting the manus
Apr 253 min read


Caging the beast
The past few days has seen a flurry of breathless articles in the cybersecurity press and blogosphere about Mythos , an exciting new AI model that can find and exploit software vulnerabilities, rapidly, efficiently, effectively, at scale. For the white-hats, it's a way to find and fix those vulnerabilities before they are exploited. For the black-hats, it's a way to find and exploit those vulnerabilities before they are fixed. Patently, this is 'dual-use technology' a.k.a. a
Apr 123 min read


Navigating the hyperglossary mesh
One way of studying a field as complex as cybersecurity is to focus in depth on a particular aspect, then move on to another. Keep going until you either run out of juice or end up pretty much back where you started, more clued-up and ready for another run through the maze. That's a fairly straightforward approach - not exactly a linear progression but a clear topic-wise sequence. Training courses typically start with the fundamentals, then move on to cover a series of more a
Apr 23 min read


Glossary integrity
'Integrity' can be a rich and fascinating property with numerous creative applications and implications in cybersecurity, information security, fraud prevention, safety, trust, commerce, interpersonal interactions and more. However, define 'integrity' too narrowly and the creative possibilities, as well as its value as a term of art, shrink dramatically. Take for example the glossary entry from the newly-updated Australian Government Information Security Manual : "Integrity:
Mar 232 min read


Book reviews flood-in
Both of them: two reviews so far , less than a month after the book was released. I invite and welcome but don't 'commission' book reviews. I am keen to receive 100% genuine comments and feedback about the Cybersecurity Hyperglossary from actual readers, no-holds-barred. If it shines, tell me. If it sucks, tell me. If something doesn't work for you, or doesn't suit your particular needs and preferences, let me know. Direct feedback plus reader reviews on sites such as Am
Mar 152 min read


Trigger words and hot potatoes
Targeting sloppy language Are there cybersecurity-related terms that confuse you, or that other people often confuse? Take ' accountability ' and ' responsibility ' for instance: it is rare to find clear, concise and accurate explanations of either, let alone both. In practice the wrong words are often used inadvertently by people - even professionals - who simply don't appreciate the distinction, or don't really care. Formal definitions in standards such as ISO/IEC 2700
Mar 131 min read


The value of notes
Valuable notes As I slogged my way through my digital master of the Cybersecurity Hyperglossary making assorted updates and corrections this morning, I noticed the frequency of 'value' and related word forms or terms (values, valued, valuable, invaluable, devalue, valuation, evaluate, evaluates, evaluated, evaluation ...). This is just one of many such examples. Scrabble players doubtless recognise the value of variants that extend a given string - 'UN-ZIP-PER-ING-S' being
Mar 82 min read


nb. Take note!
Chasing quantum-rabbits This morning, thanks to a note on LinkeDin by Walt Powell , I'm reading an intriguing semi-technical article about what appears to be a significant and potentially disruptive advance in quantum cryptanalysis. Since I'm not a pro cryptographer by trade and not exactly mathematically-gifted, I'm 'somewhat bewildered' by the article's terms and concepts. That prompts me to flip through the Cybersecurity Hyperglossary as I study the article and its sou
Mar 52 min read


Exploitation
I've been pondering the book's audience again lately, begging questions such as: Who benefits from the Cybersecurity Hyperglossary? What are their interests, jobs and concerns? How do they use it? What do they use it for? ... and ... What do they get out of it? I came up with the idea of preparing 'use cases', illustrative examples for various categories of reader. So far, I have identified and characterised 14 types of reader: Technology professionals IT administrators Rese
Mar 41 min read


Moving steadily along
Virtual advertising on the London Underground Just over a week post-launch, the book is doing OK, as far as I can tell at this point anyway. I've started tracking a few metrics but one of the most important (sales) inevitably lags by some months as invoices are paid, orders are fulfilled and accounts are updated. Meanwhile, I'm using indicators such as rankings, reader comments and reviews for rough clues as to how things are going. On Amazon, for instance, the book's initia
Mar 11 min read


Launching today
Finally! The wait is over! Cybersecurity Hyperglossary starts shipping today. I’ve been looking forward to this day since resolving to publish the book at the end of 2024. I didn’t fully appreciate just how much work remained to be done, and owe my sincere thanks to the publisher and editorial team. Turning my 800-page 285,000-word monster of a Word table with 5,555 rows, 40,000 internal cross-references and hundreds of Internet hyperlinks into a publishable book took an im
Feb 172 min read


Unboxing day
What a nice surprise in the post today, a parcel all the way from CRC Press in Abingdon, Oxfordshire. So exciting! Taylor & Francis came through with 836 crisply-printed pages in a clear font on good quality bright white paper, neatly laid out, smart-as. The international team of editors, typesetters and printers exhibited a remarkable dedication to quality and integrity over the ten long months it took to get to this point. Good job, well done all. Thank you! Today is the f
Feb 111 min read


Connecting the boardroom with the server room
In most organizations, there’s a massive language divide. While the technology team wades through the weeds of protocols, patches and pings , executives fly way overhead, debating margins, liabilities, investments and strategic goals. A serious cybersecurity incident puts these groups on a crash course. When the pressure piles up, the language gulf between tech and business people can cause frustrations to boil over. As communication volume goes through the roof but comprehen
Feb 92 min read


Painting the Forth bridge
Keeping up with change is all part of the 'fun' of composing a glossary in any field that is actively progressing, such as cybersecurity for instance. 'Cybersecurity' is a classic example - now a commonplace term ... that all but defies formal definition. The approach I've adopted with the Cybersecurity Hyperglossary is to locate, quote and cite 'official' definitions from standards and other definitive sources where available. Published glossaries are useful, and fortunately
Feb 22 min read


In the heat of the night
During a serious cybersecurity incident such as a ransomware attack, the boardroom becomes a pressure cooker. Execs need to know, urgently, liabilities and timelines from the CISO who is presently roasting over hot coals. Meanwhile .... The IT, incident response and cybersecurity teams are up to their [eye]balls in escalation procedures, web services, backups and forensics. The lawyers in Legal are figuring out precisely how much to disclose to the authorities and stock mark
Jan 302 min read
Hyperglossary blog
bottom of page
