A humanistic approach to cybersecurity

It is possible to change our approach to defending our cyber security. In "Hacking the Mind", the book by Pierguido Iezzi and Gennaro Fusco, there is a new way of managing cyber threats that is effective and free from excessive technical jargon

18 SEP 26
Last updated: 04:03 PM
Translated by AI
Image of A humanistic approach to cybersecurity

Photo by Philipp Katzenberger via Unsplash

Writing a book on cybersecurity is no easy task. There is always the risk of either boring experts with explanations that are (to them) redundant, or frustrating non-technical readers with statements they are unable to understand. ‘Hacking the Mind: Words, Algorithms and Deceptions. How to Defend Your Digital Freedom’, the book by Pierguido Iezzi and Gennaro Fusco, does not have this problem because it manages to speak to both those who are well-versed in ‘cyber’ matters and those who are not very familiar with the subject. This is a good thing, because it is a book that should be read by both technical and non-technical readers, given that it offers a humanistic – or at the very least, non-technical – approach to problems which, until now, were thought to be solvable only through technical means.
We must recognise that cybersecurity is not just a technical issue, but also a matter of rhetoric. … Traditionally, cyberattacks relied on technical exploits: viruses, Trojans and system vulnerabilities. Today, a significant proportion of threats come via text: emails, text messages, chatbots and notifications.
It’s true. Until now, the focus has been on protecting systems from threats that were, all things considered, ‘silly’: phishing messages riddled with Fantozzi-style grammatical errors; malicious attachments that were all identical; crudely imitated fake websites. No more than a couple of years ago, a colleague of mine, reading yet another message written in surreal Italian, remarked: “Why don’t they just have them translated by an automated system?” Since the advent of AI, most malicious payloads – be they attachments, messages or web pages – are flawless, both in form and content, and are often indistinguishable from the originals.
What once required human resources to write, proofread and publish posts – incurring significant costs – can now be handled by a script that creates and publishes thousands of automated posts a day at marginal, virtually zero cost. This reduction in barriers to entry means that even players with limited resources can launch large-scale, sophisticated campaigns. 
Moreover, the content of malicious messages has evolved and now draws on rhetorical techniques designed to trigger unconscious reactions in the victim.
  • Urgenza: “Agisci subito”; “Hai 24 ore per evitare la sospensione”.
  • Minaccia: “Il tuo conto verrà disabilitato”; “Abbiamo rilevato attività fraudolente”.
  • Autorità: Un messaggio dell'AD ti dice di fare qualcosa
Unlike other authors, who merely list problems without offering any solutions or propose ‘Disney-esque’ solutions that have no practical application beyond their imagination, Iezzi and Fusco provide realistic solutions to all the dangers they highlight. These are realistic and ‘uncomfortable’ solutions because they run counter to the way cybercrime has been tackled up to now.
Cybersecurity courses should incorporate modules on digital literacy, which go beyond simply deciphering technical indicators (suspicious URLs, infected attachments, etc.) to also train people to interpret messages at a deeper level. The aim is not merely to recognise a scam, but to train the mind to critically scrutinise the words used.
On the subject of data protection, they state:
We should be talking about data sovereignty and not just digital sovereignty. Because the digital realm is a tool, a treasure chest. But if we focus solely on the container, we risk losing sight of the real point of interest: the content. Data is the real treasure, and without it the entire container loses its value. [… treat data as a vital infrastructure, on a par with energy and water, not as a by-product of digital life.
And, regarding AI:
Even claiming that AI possesses some sort of universal ethics is a daunting task, given that agentic AI – which makes decisions based on intent and feeds on data – is not neutral: it reflects and amplifies the values of those who design and govern it. […] In a pluralistic world, the aim is not to impose a universal morality, but to defend one’s own principles in practice, through verifiable rules, independent inspections, effective sanctions and international agreements that reconcile trade with protection.
In short, "Hacking the Mind" is an innovative book: both for what it asserts and for the way it tackles issues. Personally, I do not agree with all their assertions, but – just as is the case with St Augustine – I cannot help but admire and respect the logical process that generated them. As a security professional and a member of the public, I hope that Iezzi and Fusco’s book will be read not only by technical experts, but also by those with decision-making power over their work, so that the solutions they propose can be applied to the way we manage cyber threats – both current and potential.