Turning Security into a Story
Most people don’t read technical papers about malware. They listen to voices they trust.
Graham Cluley built a second career around being one of those voices. At Sophos, from 1999 to 2013, he served as Senior Technology Consultant, Head of Corporate Communications, spokesperson, and editor of the Naked Security site—roles that all revolved around one skill: explaining complex threats in plain language.
His communication reached far beyond corporate press releases. He became a regular presence on TV and radio, breaking down new hacking techniques and virus outbreaks for a general audience, and worked with law enforcement agencies on investigations into hacking groups.
A Daily Blog and a Weekly Podcast
After leaving Sophos, Cluley launched grahamcluley.com, a daily blog mixing news, opinion, and advice on computer security. It became a hub for readers who wanted to understand not just what was happening online, but why it mattered.
He then extended that conversation into audio with the Smashing Security podcast, co-hosted with Carole Theriault. Each week, they dissect security incidents and digital oddities, bringing humour and accessibility to what could otherwise be dry or intimidating topics.
Cluley’s reach didn’t go unnoticed. Computer Weekly named him Twitter user of the year in both 2009 and 2010, highlighting his influence in online discussions about security. In April 2011, he was inducted into the InfoSecurity Europe Hall of Fame, a nod from the industry he helped to demystify.
The lasting impression is clear: when security is explained like a human story rather than a technical manual, people listen—and they learn to protect themselves.
