Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • National Cybersecurity Awareness Month – Words to Avoid current page
Link copied

National Cybersecurity Awareness Month – Words to Avoid

Oct 20, 2017
Author:
Morey Haber Headshot 2024
Morey J. Haber
Chief Security Advisor
Blog banner default
National Cybersecurity Awareness Month – Words to Avoid
Morey Haber Headshot 2024
Morey J. Haber
Chief Security Advisor

Cybersecurity Awareness Month

TGIF (Thank Goodness, It’s Friday)! Yes, I altered the ‘G’ to be politically correct, but being politically correct has little room in cybersecurity. Breaches and incidents are rather binary and being politically correct about how much data has been lost, the number of passwords stolen, or even that the attack used a known vulnerability has little room when triaging a situation. It happened, or it didn’t. There is very little room for tact when stating a fact.

Unfortunately, our choice of words can have an impact, and there are several words we should always avoid as cybersecurity professionals. These words are not necessarily politically incorrect, but their context can definitely make things worse when dealing with a situation. Here are my personal favorites:

  • 100% protected – There is no such thing. A hacker will find a way around any defense, and to be in denial that an attack cannot occur is naïve, ignorant, and irresponsible. You are never 100% protected.
  • Future proof – This marketing term is totally over used and has spilled over to security professionals now too. Nothing is future proof. It is only good for the foreseeable future.
  • No competitors – Every vendor has a competitor. When choosing a cybersecurity solution make sure you look at all the competitors and challenge any claim that they are the only ones that can solve your problem.
  • Air gapped – Some devices, data, and resources should never have direct (or even proxied) Internet access. Explaining the problem due to the lack of security controls that prevent Internet access will only get you in more trouble. While Internet access is generically perfectly acceptable, explaining it as a part of a breach or incident can be problematic. Some things must be 100% air gapped even though we could argue, nothing is 100%.
  • No access control – The lack of segmentation, firewalls, and unrestricted lateral movement can be a deciding factor when a security incident turns into a breach. Blocking a threat from navigating around your network is just as critical as stopping it in the first place. If you have no access controls, no network zones, and allow unrestricted network communication, you might want to avoid explaining a situation without these basic tenants in place. After all, a flat network is a vulnerable network.
  • Bad passwords – If describing a breach correlates to the cause of using the “same password”, you might as well forget about ethics and begin revisiting why you have a security policy and security team in the first place. Passwords should never be reused anywhere, and if a password was compromised dig deep as to why.

Therefore, for Cybersecurity Awareness Month, let us improve our communications too. As we strive for better hygiene, let us avoid the terms that make the situation worse for everyone. They are not obscene, not offensive, but definitely do not help our cause in remaining secure and keeping threat actors at bay. Precision in communication, user behavior, and reporting vulnerabilities will help you avoid these terms that plague our industry with negative opinions and poor solutions.

Latest Posts
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
  • A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    May 26, 2026 A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    Blog
    3m
  • How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    May 21, 2026 How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    Blog
    5m
  • Cybersecurity as a Boardroom Priority for Major African TelCos
    May 12, 2026 Cybersecurity as a Boardroom Priority for Major African TelCos
    Blog
    8m
  • Geopolitics and Cybersecurity: Why Attackers Go After Identities and Privileged Access First
    May 11, 2026 Geopolitics and Cybersecurity: Why Attackers Go After Identities and Privileged Access First
    Blog
    4m
Related
  • Unix & Linux Security: How Do You Stack Up?
    Mar 16, 2017 Unix & Linux Security: How Do You Stack Up?
    Blog
    1m
  • APT Vehicle of Choice: The Accidental Insider
    Mar 5, 2012 APT Vehicle of Choice: The Accidental Insider
    Blog
    1m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.