Group Purchasing
Group Purchasing
UPDATED

SEC402: Cybersecurity Writing: Hack the Reader

SEC402Cybersecurity Leadership
  • 12 Hours (Self-Paced)
Course authored by:
Lenny Zeltser
Lenny Zeltser
SEC402
Course authored by:
Lenny Zeltser
Lenny Zeltser
  • 12 CPEs

    Apply your credits to renew your certifications

  • Self-paced

    Train at your own pace from wherever you are

  • Essential Skill Level

    Course material is for individuals with an understanding of IT or cyber security concepts

Improve persuasive communication techniques to breach readers' defenses, ensuring security reports influence decisions even when audiences resist engaging with technical content.

Course Overview

SEC402 teaches cybersecurity professionals to write so their reports, briefings, and emails get read and acted on. The technical insight is often there, but the writing that carries it loses the reader before the recommendation lands. This course teaches a reader-centered approach built around the five “golden” elements: structure, look, words, tone, and information. Students spot and fix problems in writing samples, including incident reports, threat reports, and assessment findings. They also learn how to use AI to draft, critique, and improve their writing, without ceding judgment to it.

Strategic Communication for Cybersecurity Impact

Want to write better? Learn to hack the reader! Discover how to find an opening, break down your readers' defenses, and capture their attention to deliver your message—even if they are too busy or indifferent to others' writing. This unique course, built exclusively for cybersecurity professionals, will strengthen your writing skills and boost your security career.

You will:

  • Uncover the five "golden elements" of effective reports, briefings, emails, and other cybersecurity writing.
  • Make these elements part of your arsenal through hands-on exercises that draw upon common security scenarios.
  • Learn the key topics you need to address in security reports and other written communications.
  • Understand how to pick the best words, structure, look, and tone.
  • Begin improving your skills at once by spotting and fixing weaknesses in security samples.
  • Receive practical checklists to ensure you will write clearly and effectively right away.

This isn't your normal writing course

The course builds upon the author's two decades of cybersecurity experience. You'll learn from examples relevant to security professionals, whether they're experts or beginners, managers or individual team members.

It also focuses on common writing problems you will learn to avoid, instead of presenting tedious grammar rules or theoretical explanations. You will advance your writing by reviewing and improving real-world cybersecurity samples.

You will master the writing secrets that will make you stand out in the eyes of your peers, colleagues, managers, and clients, learn to communicate your insights, requests, and recommendations persuasively and professionally, and make your cybersecurity writing remarkable.

Author Statement

"How can you stand out from other cybersecurity professionals with similar technical skills? How can you get your managers, clients, and colleagues to notice your contribution, accept your advice, and appreciate your input? Write better!

Here's an uncommon opportunity to improve your writing skills without sitting through tedious lectures or writing irrelevant essays. You'll make your writing remarkable by learning how to avoid common mistakes, working on real-world exercises to spot and correct cybersecurity writing problems. You'll write clearly and effectively right away with the help of practical checklists.

This course captures my experience of writing in cybersecurity for over two decades and incorporates insights from other members of the community. It's a course I wish I could have attended when I needed to improve my own writing skills. It's a course I know will help you propel your own cybersecurity career."

- Lenny Zeltser

What You'll Learn

  • Apply a reader-centered approach to incident, threat, and assessment reports
  • Organize your writing so busy colleagues and clients can scan, find what matters, and act
  • Make decisive choices about words and tone, including for difficult conversations
  • Match the information you include to the report type and the reader’s needs

Business Takeaways

  • Get more recommendations approved and implemented
  • Cut wasted time when stakeholders misread recommendations and incident updates
  • Get executives to read the analysis behind the recommendation
  • Minimize the back-and-forth between a security finding and a business decision
  • Reduce rework caused by reports that don’t answer the right questions

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in SEC402: Cybersecurity Writing: Hack the Reader.

Section 1Capturing Attention: Structure, Look, and Words

Section 1 introduces the reader-centered approach and the first three elements that determine whether your writing gets read. Students learn to organize cybersecurity reports and messages, so readers find the takeaway, make it easy to scan, and choose words that work for both technical and business audiences. Hands-on exercises use weak and strong examples.

Topics covered

  • Reader-centered methodology and the five “golden” elements
  • Document structure with strong summaries, headings, paragraphs, and top-down narrative
  • Visual layout and emphasis that direct the eye
  • Word choice for clear, persuasive cybersecurity writing
  • Using AI as a new kind of reader and drafting helper

Overview

Day 1 - Section 1: How to Strengthen Your Writing Skills-A Reader-Centered Approach

CPE/CMU Credits: 0.5

You'll learn how a reader-centered approach to writing allows you to prepare cybersecurity materials that connect with your audience. You'll discover how the five "golden elements" of writing work together to assist you with these tasks. These elements, which we discuss throughout the course, are:

  • The right structure
  • The right look
  • The right words
  • The right tone
  • The right information

You'll understand how to use the hands-on exercises in this course to avoid problems common to the security reports, emails, and other content you regularly create.

Day 1 - Section 2: The Right Structure

CPE/CMU Credits: 2.5

We all have way too much to read. You'll learn how to structure your writing so readers don't want to put it down. You'll discover how to:

  • Open with the idea your readers cares about most.
  • Organize the supporting ideas to make them easy to find, read, skip, and skim.
  • Design the structure to meet the needs of all your readers.

You'll understand how to use the right structure by spotting and fixing structural issues with many cybersecurity examples.

Day 1 - Section 3: The Right Look

CPE/CMU Credits: 3

You have just seconds to grab your reader. You'll learn how to give your writing the right look to hook your readers at a first glance. You'll be able to:

  • Create an appealing layout with lists and headings
  • Design readable paragraphs
  • Capitalize words correctly
  • Use just the right amount of formatting
  • Pick the best graphic for your objectives
  • Handle screenshots and tables effectively

You'll master the right look by examining security writing samples that have an amazingly misguided look. (Expect much fun.)

Section 2Earning Trust: Tone and Information

Section 2 turns to tone and information, which readers weigh before they trust you and act on what you wrote. Students learn to set a tone that stays professional, responsive, and constructive, even in disagreements and negative findings. They also learn what each report type, including incident, assessment, and threat reports, needs to deliver to readers.

Topics covered

  • The right tone: professional, responsive, constructive, and persuasive
  • The right information in cybersecurity incident reports
  • The right information in security assessment reports
  • The right information in malware and threat reports
  • Using AI to draft, review, and learn from public security reports

Overview

Day 2 - Section 4: The Right Words

CPE/CMU Credits: 2.5

The word is mightier than the sword. You'll learn how to pick the right words to inform and persuade your readers. You'll find out how to make sure your words are:

  • Clear: Use words your readers understand.
  • Concise: Cut words you don't need.
  • Consistent: Use parallel structure and uniform style.
  • Correct: Use proper terms and spelling.

The key to using the right words is deliberate practice. You'll have many opportunities to improve poorly worded cybersecurity text.

Day 2 - Section 5: The Right Tone

CPE/CMU Credits: 2

Tone is the key to creating a bond with your reader. You'll learn how to make your tone:

  • Professional and appropriate for the reader
  • Responsive to difficult situations
  • Constructive, helping the reader solve problems
  • Persuasive, motivating the reader to take action or make a decision

Real-world examples will help you learn to spot tone problems, so you can turn them into writing that says just what your reader will understand and appreciate.

Day 2 - Section 6: The Right Information - Cybersecurity Incident Reports

CPE/CMU Credits: 0.5

What do readers of your cybersecurity incident report want to know? You'll learn to include the right information in such writing, so you can:

  • Inform your readers about the incident
  • Instill confidence that the proper steps have been taken
  • Address concerns about relevant business risks
  • Highlight the need for improvements, if any

The best way to learn how to write a good incident report is to look for problems in bad ones. You'll have many opportunities to do this.

Day 2 - Section 7: The Right Information - Pen Testing and Other Security Assessment Reports

CPE/CMU Credits: 0.5

Learn how to craft a security assessment report so the readers truly benefit from your insights. Master the skill of including just the right information to:

  • Describe assessment methodology and scope
  • Provide meaningful analysis, rather than raw findings
  • Offer guidance that readers appreciate
  • Include figures to support your conclusions

You'll review many problematic penetration testing and other security assessment reports, so you'll understand how to avoid their pitfalls.

Day 2 - Section 8: The Right Information - Malware and Other Threat Reports

CPE/CMU Credits: 0.5

Writing about cybersecurity threats, such as phishing messages, malware infections, and attack groups, can be challenging because of the multiple audiences that might read the reports. Learn how to include the right information in such writing, so your readers:

  • Understand why the threat is relevant
  • Know what to do after reviewing your report
  • Trust the basis for your analysis
  • Appreciate your research and advice

You'll learn to include the right information in threat reports with the help of hands-on exercises, during which you'll spot and fix information-related weaknesses.

Things You Need To Know

A laptop or desktop with a current web browser, since the course runs through the SANS OnDemand portal. The exercises don’t require specialized software, just your usual reading and writing tools. 

Cybersecurity professionals who write reports, briefings, emails, or other content as part of their job. The course works for managers and individual contributors, consultants and in-house staff, beginners and experts. If your job depends in part on whether your writing gets read and acted on, this course is for you. 

  • Two books and one handout in print and digital format
  • MP3 audio recordings of the full course
  • Four months of access to the SANS OnDemand portal

No specific technical prerequisites. The course works for cybersecurity professionals at any level, from analysts and engineers to managers and executives. Some familiarity with the kinds of writing security teams produce, like incident reports, advisories, and emails, helps but isn’t required. 

SEC402 covers foundational materials that apply across SANS curricula. Cybersecurity professionals often take SEC402 alongside their technical and leadership training. 

Cybersecurity writing turns security knowledge into reports, briefings, and emails that the right people read and act on. It matters because security recommendations only protect the organization when someone with authority decides to follow them. 

Cybersecurity professionals who write well influence more decisions and earn more credit for their analysis. Over time, strong writers get invited into the decisions other professionals only hear about secondhand. 

Relevant Job Roles

Cybersecurity Legal Advice (OPM 731)

NICE: Oversight and Governance

Responsible for providing cybersecurity legal advice and recommendations, including monitoring related legislation and regulations.

Explore learning path

Systems Authorization (OPM 611)

NICE: Oversight and Governance

Responsible for operating an information system at an acceptable level of risk to organizational operations, organizational assets, individuals, other organizations, and the nation.

Explore learning path

Security Manager Training, Salary, and Career Path

Cybersecurity Leadership

Daily focus is on the leadership of technical teams. Includes titles such as Manager, Information Security Specialist, and Program/Project Leader.

Explore learning path

Communications Security (COMSEC) Management (OPM 723)

NICE: Oversight and Governance

Responsible for managing the Communications Security (COMSEC) resources of an organization.

Explore learning path

Cybersecurity Instruction (OPM 712)

NICE: Oversight and Governance

Responsible for developing and conducting cybersecurity awareness, training, or education.

Explore learning path

Knowledge Management (OPM 431)

NICE: Implementation and Operation

Responsible for managing and administering processes and tools to identify, document, and access an organization’s intellectual capital.

Explore learning path

Technology Program Auditing (OPM 805)

NICE: Oversight and Governance

Responsible for conducting evaluations of technology programs or their individual components to determine compliance with published standards.

Explore learning path

Incident Response Team Member

Digital Forensics and Incident Response

This dynamic and fast-paced role involves identifying, mitigating, and eradicating attackers while their operations are still unfolding.

Explore learning path

Course Schedule and Pricing

Have Questions?Contact Us
  • Location & instructor

    Virtual (OnDemand)

    Instructed by
    Date & Time
    OnDemand (Anytime)Self-Paced, 4 months access
    Course price
    $3,505 USD*Prices exclude applicable local taxes
    Registration Options
Showing 1 of 1

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources