Security Mindset Fundamentals and Second Language Learning
Chapter I. Statement of the Problem
Cybercrime costs the world trillions of dollars every year, leaving nations, businesses,
institutions, and individuals in a wake of “data corruption and destruction, theft of funds,
intellectual property, personal and financial data, disruption of business … , damage to …
reputation, [and] loss of productivity” (Sviatun et al., 2021, p. 751). Continued inadequate
security may result in $90 trillion in losses by 2030 (Clinton & Perera, 2016, p. xiii), and current
efforts to secure digital spaces have still left much to be desired (Burrell, 2020; Georgescu, 2021;
Nobles, 2018; Petruzzelli & Sharma, 2019; Sviatun et al., 2021). Underlying this is the
“persistent problem” (Feiner, 2021, para. 9) of a critical cybersecurity workforce shortage in the
United States and elsewhere (Crumpler & Lewis, 2019; Furnell, 2021; McQuaid & Cervantes,
2019).
On the world stage, U.S. President Biden met with President Putin of Russia in June 2021
to address cybersecurity issues, a discussion of increasing importance for the United States given
that the number of attacks on the United States has been growing, including Kremlin-sponsored
misinformation campaigns and malicious code suspected of coming from Russian territory
(Kiyan, 2021). Against a backdrop of highly publicized incidents such as the SolarWinds attack,
Stuxnet, and WannaCry, a barrage of calls to improve cybersecurity has emanated from a variety
of sectors including business (e.g., Walton et al., 2021), government (e.g., Norris et al., 2019),
healthcare (e.g., Coventry & Branley, 2018), and education (e.g., Ulven & Wangen, 2021).
In these calls to improve personal, institutional, and national security, cybersecurity
education has often been viewed as an integral part of the response (Chen et al., 2021; Rahman et
al., 2020). The Cyberspace Solarium Commission’s “urgent call to action” (Montgomery et al.,
2020, p. 1) recommended that “digital literacy, civics education, and public awareness” (p. 5) be
promoted by the U.S. government as a way “to build societal resilience to foreign, malign
cyberenabled information operations” (p. 5). As part of corporate efforts to cut U.S. cybersecurity
workforce shortages in half, Microsoft announced plans to bring 250,000 cybersecurity
professionals into the workforce by 2025 (Feiner, 2021) through collaboration with U.S.
community colleges. In 2021 alone, sweeping cybersecurity demands captured the attention of
U.S. legislators considering legislation in no fewer than 45 U.S. states that dealt significantly
with cybersecurity, often by supporting initiatives with cybersecurity education and training in
mind (National Conference of State Legislatures, 2022).
Yet looming ahead are also changes in technology that will render current cybersecurity
protocols obsolete (Espitia, 2021; Mavroeidis et al., 2018; Piattini, 2020). Quantum computing,
for example, which Piattini (2020) called “the next revolution” (p. 23), could have dire
implications for current security infrastructure and practices; Copeland (2021) put the issue in
stark relief when reporting how current algorithms needing “roughly 10 billion years to decrypt”
(para. 1) could take a quantum computer “as little as 10 seconds” (para. 1). Many cybersecurity
experts now anticipate that this technology will be operable within five years (Waters, 2021).
Problem Statement
In this landscape, cybersecurity knowledge risks being continuously outdated (Dawson &
Thomson, 2018) even for professionals who grasp the details of these threats—to say nothing of
“the majority of the world” (Hamilton, in Siraj et al., 2021, p. 336) who, without pursuing deeply
technical careers, likely will not. Already exploding into the public sphere are AI applications
such as ChatGPT, Google’s Bard, and the new Microsoft Bing, potentially situating humans and
machines “right on the edge of a new security landscape” (Williams, 2023, para. 7).
Pointing to the risks of such a rapidly shifting threatscape (Georgescu, 2021; Siraj et al.,
2021), concerned by the workforce shortfall (Burrell, 2020; Petruzzelli & Sharma, 2019), and
critical of the public’s cyber hygiene practices (Kostyuk & Wayne, 2021), scholars have devoted
much attention to the current state and potential role of cybersecurity education (e.g., Chen et al.,
2021; Švábenský et al., 2020). A burgeoning concern is that cybersecurity education is
insufficiently developed in U.S. schools (Javidi & Sheybani, 2018; Petruzzelli & Sharma, 2019)
and still relatively little is known about “effective ways to engage, educate, or retain
cybersecurity students” (Scheponik et al., 2016). While cybersecurity education has been
portrayed as vitally important for responding to many of the threats of the landscape depicted
above (Austin, 2020; Georgescu, 2021; Rahman et al., 2020), it has also been portrayed as in dire
need of reimagining (Austin, 2020; John et al., 2020; Tebekaemi & Zhao, 2022).
In efforts to reimagine various aspects of cybersecurity education, scholars have pointed
to traditional approaches (Crumpler & Lewis, 2019; Dutton, 2017; Jacob, 2018; Sharevski et al.,
2018) that are increasingly out of step with the emerging consensus that cybersecurity is
fundamentally a human problem (Carley, 2020; Hanna & Blanken-Webb, 2022; Morris et al.,
2018; Severance, 2016; Sharevski et al., 2018). Hamman and Hopkinson (2016) contended that
despite decades of rapid change and emerging technology, what had not changed were the
underlying adversarial tactics of cybercrime, while Schneier (2023) maintained that “Hacking is
as old as humanity” (p. 224). A push to focus on security’s “underlying [human] problems”
(Severance, 2016, p. 7) has thus gained traction among cybersecurity thinkers.
Perhaps with this eye toward bolstering cybersecurity’s more enduring elements, scholars
have cited the need for a wider range of academic disciplines to engage in non-technical aspects
of cybersecurity education (Craigen et al., 2014)—proposing expansion into other more
humancentric fields areas such as leadership, entrepreneurship (Javidi & Sheybani, 2018), and
the
social sciences (National Academies of Sciences, Engineering, and Medicine, 2019). While
“niche mission sets” (Austin, 2020, p. 5) duly remain integral parts of cybersecurity education, a
more “comprehensive and multidisciplinary” (p. 5) vision for cybersecurity has emerged as well.
Such a vision has served to broaden cybersecurity education efforts beyond technical training for
dealing with specific disaster scenarios (Austin, 2020).
These broader efforts have also seen an increased interest in the development of
underlying, flexible security thinking in both technical (e.g., Dark, 2015; Pournaghshband, 2013;
Schneider, 2013; Schoenmakers et al., 2023) and non-technical populations (e.g., Dutton, 2017;
Dutton et al., 2019; Esteves et al., 2017; Jarjoui, 2023). Siraj et al. (2021) asserted that “teaching
the ‘security mindset’ [to all individuals who design/develop/deploy/upkeep/use digital systems]
might be one of the most important aspects” (p. 2) of cybersecurity education today. Yet others
have asserted that developing security mindsets in the general population might also benefit
cybersecurity overall (Dutton, 2017; Dutton et al., 2019).
The importance of security mindsets notwithstanding, cybersecurity educators lack the
“conceptual clarity” (Schoenmakers et al., 2023, p. 2) necessary for effective training with
respect to security mindsets. In fact, scholars have debated whether it can even be taught (Dark,
2015; Schneier, 2008; Siraj et al., 2021). The key to greater clarity about security mindsets—and
cybersecurity more generally—may in fact hinge on the aforementioned efforts to draw from
other disciplines (Craigen et al., 2014; Schoenmakers et al., 2023). In practice, however,
interdisciplinary and multidisciplinary efforts have far to go (e.g., Austin, 2020; Furnell &
Bishop, 2020; Jacob et al., 2018; Wagner, 2022).
In this interdisciplinary push to develop learners’ basic cybersecurity thinking and reach
wider, more diverse populations, the role L2 learning—including foreign language (FL), English
language learning (ELL), and sign language—has yet to be fully considered. Foster-Marks
(2021) cited “lack of scholarly treatment” (para. 41) on explicit connections between L2 learning
and more general computer programming skills, despite observing “particularly strong” parallels
between them. In a similar vein, Krendel (2018) noted “plenty of research areas in cybersecurity
that would be improved by the input of enthusiastic linguists” (para. 1) such as “lie detection,
and detecting security threats from within an organization—all topics that a conversation analyst
or a grammarian would devour” (para. 5).
Despite this paucity of treatment, the content and processes in L2 classrooms may
nevertheless be particularly well-suited to meet the challenge of introducing student to
foundational cybersecurity thinking (Kuiken, 2023)—given the analytical, creative, and practical
aspects of L2 subject matter itself (see Sternberg, 2002). Such aspects are also shared with
fundamental components of cybersecurity adversarial thinking (Hamman & Hopkinson, 2016).
While L2 textbooks contain instructional content and learning tasks intended to promote
language competencies (Suryani, 2018), researchers have yet to investigate if or how L2 content
might serve as a meaningful vehicle to introduce learners to security mindset fundamentals in FL
learning and ELL settings.
In this vein, I conducted a qualitative content analysis (QCA) of L2 textbook content to
illuminate possible links for future exploitation by educational entities seeking to introduce L2
learners to security mindset concepts. It is my hope that such an endeavor might contribute to
both widening and strengthening current cybersecurity educational efforts—through the
consideration of additional pathways for promoting security mindsets within contexts of human
connection and communication.
Purpose of Study
Based on the literature review of 2024, there have been no documented instances of
leveraging themes in L2 learning to cultivate or teach security thinking and topics (see Kuiken,
2023). The objective of this study, therefore, was to investigate how K12+ L2 learning content
might support the introduction of security mindset fundamentals to L2 learners. Specifically, I
aimed to determine if existing L2 textbook content could provide opportunities for learners to
engage with analytical, creative, practical, and situational aspects of security thinking. I also
sought to investigate how L2 textbook content might provide a basis for L2 learners to consider
more explicit underlying security-related questions and issues (e.g., phishing, the CIA triad of
confidentiality, integrity, and availability, etc.). In this way, the study focused on both security
thinking and thinking about security.
I paired QCA with imaginative variation (IV) as a means to view content through the lens
of security mindset fundamentals, enabling me to identify features of the L2 content that could be
connected to security mindset fundamentals and subsequently imagine the ways in which these
connections could be leveraged as part of “a deliberate effort” (Kaza, as found in Siraj et al.,
2021, p. 2) to exploit links between cybersecurity and language more fully. The decision to
examine existing L2 content was made for the purpose of gaining insight into what might be
reasonably achieved within the current curricular infrastructure of L2 learning using various
types of materials already available, as well as provide some indication about the potential need
for developing ancillary materials specifically for cybersecurity purposes.
Theoretical Frameworks
As a lens for viewing and naming potential connections between L2 learning and security
mindset fundamentals, this inquiry drew on two frameworks. Hamman and Hopkinson’s (2016)
adaptation of Sternberg’s (1988) Triarchic Theory of Intelligence (TTI) provided the main
structure for my study’s conceptual framework. To a lesser extent, I drew on Endsley’s (1995)
Theory of Situational Awareness (SA), particularly as interpreted by Horneman (2019) for
cybersecurity. Both TTI and situational awareness affirm the importance of actual contexts: TTI
is concerned with how cognition works in various real-world situations (Dahal, 2007) while
situational awareness pits one’s specific knowledge of “what should be” (Horneman, 2019, para.
9) against specific details in one’s operational space. As such, these theoretical frameworks were
able to support an examination of both abstract and concrete themes relevant to security thinking.
TTI and Adversarial Thinking
In the context of cybersecurity adversarial thinking, Hamman and Hopkinson (2016)
developed a framework for understanding “the ability to approach system rules, operational
spaces, and player actions from a hacker’s perspective” (p. 4) using the analytical, creative, and
practical aspects of intelligence identified by Sternberg’s (1988) TTI. While theoretical aspects of
TTI have been contested by scholars owing to a lack of empirical evidence (Gottfredson, 2003;
McDaniel & Whetzel, 2003), Hamman and Hopkinson (2016) nevertheless saw its
potential for robust practical application in cybersecurity educational settings. They reframed
TTI’s main aspects for adversarial thinking as follows.
Analytical Component. The analytical component of adversarial thinking entails
technical acumen, including a firm grasp of “protocols, programming languages, and operating
systems” (Hamman & Hopkinson, 2016, p. 12). Hamman and Hopkinson (2016) likened these to
“book smarts” (Hamman & Hopkinson, 2016, p. 6) involving knowledge of technical rules and
systems. Just as other scholars have maintained that such “knowledge is helpful or perhaps even
necessary for a security mindset, but not sufficient” (Schoenmakers et al., 2023, p, 3), Hamman
and Hopkinson went on to present additional components in their treatment of adversarial
thinking as well.
Creative Component. The creative component of adversarial thinking entails
“identifying unsafe security assumptions through manipulating and stretching technology in
unexpected ways” (Hamman & Hopkinson, 2016, p. 12). At its heart, creativity hinges on unique
perspectives that result in new things being built out of old things (Hamman & Hopkinson,
2016). Where technical intelligence means a facility for following rules, creativity means a
facility for subverting rules (Dark & Mirkovic, 2015; Hamman & Hopkinson, 2016). This is tied
up with one’s capacity to deal with ambiguity and novel experiences, to repurpose formulaic
phenomena to do something new, to view the world in novel ways, and to “explor[e] possibilities
that many people would never consider” (Hamman & Hopkinson, 2016, p. 8).
Practical Component. Practical intelligence in adversarial thinking involves “reasoning
strategically to plan and execute attacks, evade detection, and overcome obstacles” (Hamman &
Hopkinson, 2016, p. 12). Hamman and Hopkinson (2016) linked these “street smarts” (p. 6) to
social engineering attacks and one’s capacity to anticipate the actions of others and strategize
accordingly.
While Hamman and Hopkinson’s (2016) framework offers a valuable tool for
understanding certain fundamental components of security thinking, they recognized the
possibility for future work to consider additional aspects of security thinking. With this in mind
—and recognizing that security mindsets can often entail more than adversarial thinking alone
(Stajano, 2023a)—I took their mention of “operational spaces” (Dark & Mirkovic, 2015, in
Hamman & Hopkinson, 2016, p. 4) as my impetus for including situational awareness concepts
in this study’s framework as well.
Situational Awareness
Situational awareness underlies robust security mindsets (Polaris Corporate Risk
Management, n.d.) and encapsulates a process of perceiving, comprehending, and projecting
(Endsley, 1995). Whereas Endsley’s (1995) Situation Awareness Model (SAM) identified many
components in this process, Horneman (2019) aimed to render Endsley’s (1995) SAM more
practical for cyberspace. Horneman (2019) summarized situational awareness as the ability to
compare what ought to be with what actually is in a given situation and then, crucially, “do
something about the difference” (para. 9). By viewing adversarial thinking capacities through
this lens, a dynamic big picture emerges wherein the integration of internal and external
processes “informs the projected status of the world” (Stanton et al., 2001, p. 6).
A Security Mindset Model
The components of a security mindset which I identified to drive an analysis of L2
textbook content were informed by TTI and situational awareness. Taken together, these
permitted me to attend to both syncretic and global aspects of security thinking and L2 learning
in textbook content. Sternberg (1998) himself maintained that TTI could inform educational
praxis in all levels and all subjects. Likewise, Endsley’s (1995) SAM is “a broad theoretical
construct with many application areas” (Stanton et al., 2001, p. 6). Given this potential for broad
application, TTI and SAM seemed well-equipped to facilitate an investigation of fundamental
components in two seemingly disparate endeavors, L2 learning and security.
However, while it is true that Sternberg’s and Endsley’s generic frameworks enriched
understandings throughout my analysis and interpretation, it is important to clarify that the
conceptual framework ultimately driving this inquiry was tailored to cybersecurity. The
conceptual framework that I employed hinged on specific conceptions of Sternberg’s TTI and
Endsley’s SAM adapted to cybersecurity discussions about adversarial thinking (Hamman &
Hopkinson, 2016) and situational awareness (Horneman, 2019). Because of this specific
application, basic cybersecurity domain knowledge and concepts—including confidentiality,
integrity, and availability—play a role in this study’s conceptual framework as well.
Research Questions
The questions driving this inquiry into potential links between L2 learning and security
thinking were:
1. In what ways, if any, is L2 content amenable to opportunities for learners to engage
with analytical, creative, practical, and/or situational knowledge and capacities which
are foundational to security mindsets?
2. In what ways, if any, can L2 content provide opportunities for raising basic
cybersecurity concepts and domain knowledge for learners’ consideration?
Significance of the Study
That L2 learning content might potentially serve cybersecurity education in this way
diverges from established conceptions of how language has previously supported cybersecurity
efforts. Traditionally, the link between language and security has centered on the utility of a
specific language (e.g., Urdu, Arabic, etc.) for carrying out security work. The advantages of
fluency in particular languages have been noted within the general security sector (e.g., King,
2015; Taha, 2007). Others have attested to the prominent role that linguistics plays in
cybersecurity (Klavans, 2015). But such contributions have still depended on technical or highly
specialized skills, leaving students in non-technical fields with few opportunities to get into
cybersecurity (Sharevski et al., 2018). However, in identifying links between foundational
security thinking and L2 learning in general, cybersecurity educators are in a position to begin
working together with L2 educators to develop pedagogical materials that leverage these links;
the door is opened for L2 classrooms potentially everywhere to advertise security mindsets and
the foundational concepts that undergird them.
The significance of this study is underscored when considering the most recent National
K-12 Foreign Language Enrollment Survey Report (American Councils for International
Education [ACIE], 2017); almost 20% of K12 learners (or 10,638,282 students) in the U.S.
educational system were enrolled in a FL program in 2017, and that figure is much higher for the
percentage of students participating in some form of high school FL study before graduation (de
Brey et al., 2021). The number of children in ELL programs in the United States is estimated to
be more than 10% or around 5 million students (de Brey et al., 2021) and growing (U.S.
Department of Education, n.d.). While FL and ELL populations are not mutually exclusive, these
data nonetheless suggest a significant number of students could be in a position to be introduced
to fundamental security concepts. For these students, L2 classrooms could serve to raise
awareness about the various kinds of thinking and issues associated with technical, creative, and
practical subfields within potential careers in cybersecurity, of which many students are
chronically unaware (Baker, 2016; McQuaid & Cervantes, 2019).
Definition of Terms
Adversarial thinking - understood as thinking like a cyber threat actor (or malicious actor)
wherein one adopts the perspective of an adversary to anticipate the actions of attackers more
effectively (Hamman et al., 2017).
Ambiguity - is characterized by a lack of certainty that arises when various factors in a
situation cannot be known or reconciled with each other, impacting one’s ability to predict future
outcomes; being able to manage ambiguity is one of the “central skills to cybersecurity” (Hanna
& Blanken-Webb, 2022, p. 3).
Anonymity - is the “condition in identification whereby an entity can be recognized as
distinct, without sufficient identity information to establish a link to a known identity”
(Garfinkel, 2015, p. 39).
Authenticity - is “the property of being genuine and being able to be verified and trusted;
confidence in the validity of a transmission, a message, or message originator” (Joint Task
Force, 2018, p. 91).
Availability - is defined as having “timely and reliable access to and use of information”
(FISMA, in Barker, 2003, p. 13).
CIA Triad - is an acronym referring to cybersecurity’s aim of ensuring the confidentiality,
integrity, and availability of information.
Comprehension-based - refers to methodologies in L2 learning that emphasize
understanding the meaning of language and providing students with “comprehensible input”
(Krashen, 1982, p. 7) as a path toward language acquisition. This is different than communicative
approaches, “under which learning is thought to emerge through language production, i.e. a focus
on speech and writing” (Vijayalakshmi, 2017, p. 1).
Confidentiality - refers to information only being available to those for whom it is
intended (van der Ham, 2021).
Cyber hygiene - covers a range of effective cybersecurity best practices from installing
anti-virus software, securing emails, and managing passwords to identifying misinformation, but
has also been understood more broadly as an increased cyber vigilance or awareness (Vishwanath
et al., 2020). The term cyber hygiene routinely appears in the phrase poor cyber hygiene, which
may include behaviors such as sharing passwords or other personal information (Cain et al.,
2018) that can generate inroads for cyber threat actors to exploit (Thebarge et al., 2022).
Cybersecurity - broadly encompasses “the art of protecting networks, devices, and data
from unauthorized access or criminal use and the practice of ensuring confidentiality, integrity,
and availability of information” (CISA, 2021, para 1) in digital and cyber spaces.
Cybersecurity (the field or discipline) - is defined by the Joint Task Force on
Cybersecurity Education (2017) as “A computing-based discipline involving technology, people,
information, and processes to enable assured operations in the context of adversaries” (p. 16). It
encompasses “the creation, operation, analysis, and testing of secure computer systems” (Joint
Task Force on Cybersecurity Education, 2017, p. 16) and “is an interdisciplinary course of study,
including aspects of law, policy, human factors, ethics, and risk management” (p. 16).
Cyber threat actor - also called a malicious actor, is a person or group “that intentionally
cause[s] harm to digital devices or systems. Threat actors exploit vulnerabilities in computer
systems, networks, and software to perpetuate a variety of cyberattacks” (IBM, n.d., para 1).
Deictic - describes “words [that] do not have a constant meaning” (Stapleton, 2017, p. 9)
but take meaning from the extra-linguistic details of the contexts (e.g., proximity, time, gender,
social status, mood) in which they appear. All languages have deictic features. An example in
English is the phrase “You should have been here yesterday,” which cannot be sufficiently
interpreted without some knowledge of the context: you, here, and yesterday are all deictic words
and their meaning changes depending on who the listener is, and at what time and in what place
the speaker is.
Disinformation - “is false information which is deliberately intended to mislead—
intentionally misstating the facts” (American Psychological Association, n.d., para. 1).
Hacker - refers to a person “having a mindset of enthusiasm for exploring unintended
purposes, pushing beyond limits, and discovering the vulnerabilities, fundamental principles, and
alternate behaviors of complicated devices, complex systems, and society” (E. Moore, personal
communication, June 19, 2023). A hacker’s capacities can be used in technical and non-technical
environments and can be used for a range of activities, both ethical (white hat hacking) and/or
illegal (black hat hacking). As such, a hacker is not necessarily a cyber threat actor.
Hardening - refers to “a process intended to eliminate a means of attack by patching
vulnerabilities and turning off nonessential services” (Barker et al., 2015, p. 130).
“Hello, World!” - generally refers to “the first program anyone writes in a new language
or on a new computer … that outputs ‘Hello, world” onto a display device” (Langbridge, 2013,
p. 74). “Because it is typically one of the simplest programs in most programming languages, it
is … often used to illustrate to beginners the most basic syntax of a programming language, or to
verify that a language or system is operating correctly” (Langbridge, 2013, p. 74).
High-level - in computer programming refers to “human-friendly” (Ballejos, 2024, para.
3), highly abstract programming languages. Their abstraction conceals granular and complex
computer system details, “making it easier for individuals to write and understand the code”
(Ballejos, 2024, para. 2). High-level code is interpreted or compiled by another program into
“machine-friendly low-level code” (Ballejos, 2024, para. 3) for the computer to understand.
Integrity - “is the guarantee that data has not been tampered with” (Yee & Zolkipli, 2021,
p. 36).
K12+ - denotes the span of formal education from elementary school through higher
education. It can also encompass continuing education for adults.
K-12 - includes educational grades from kindergarten through high school.
L2 learning - refers to the learning of one’s non-native language. This can encompass
foreign languages (FL) (also referred to as world languages) such as French, German, and
Mandarin, as well as English language learning (ELL) for speakers of other languages (also
called ESL) (Kuiken, 2020). In addition, it encompasses American Sign Language (ASL)
learning. While non-modern languages such as Latin and Greek can also fall under this umbrella
of second languages, I have limited the term L2 learning to communicative modern languages for
the purposes of this study.
L2 textbooks - is a term denoting both electronically published and printed hard copies of
second-language learning curricular manuals.
Low-level - in computer programming refers to “everything that is close to the hardware
you are running your code on” (Eggleston, 2024, para. 5). Eggleston (2024) compared it to
building construction, wherein “you always start with the foundation and build on top of that.
Low-level development is that foundation—if you start with high-level programming, then you
don’t understand what’s going on underneath” (para. 5). In contrast with higher-level
programming languages, low-level coding is characterized by “very little abstraction”
(Eggleston, 2024, para. 1).
Malware - stands for malicious software and is “software that does any operation without
the user’s permission” (Gorugantu, 2018, p. 1) and is typically used in stealing information or
keeping it for ransom (Fanning, 2015).
Man-in-the-middle attack - “is defined as any attack in which the adversary devises a way
to access the networks and inserts himself in between the server and client communication”
(Elakrat & Jung, 2018, p. 780).
Mitigation - refers to steps taken to “reduce the level of risk associated with one or more
threat events, threat scenarios, or vulnerabilities” (Ross et al., 2021, p. 64).
Misinformation - “is false or inaccurate information—getting the facts wrong” (American
Psychological Association, n.d., para. 1).
Morphology - refers to one of the fundamental systems of a language’s grammar and has
to do with how words are formed by combining basic units of meaning (O’Grady et al., 1997).
As an example, English pluralization proscribes joining s (a bound morpheme) to the end of a
word
(a free morpheme) to make another word.
Non-adversarial threats - are threats “associated with accident or human error, structural
failure, or environmental causes” (Ross et al., 2021, p. 64).
Non-repudiation - refers to “assurance that the sender of information is provided with
proof of delivery and the recipient is provided with proof of the sender’s identity, so neither can
later deny having processed the information” (Swanson et al., 2006, p. 36).
Orthography - refers to a language’s system of “spelling according to accepted usage or
convention” (Orthography, n.d.) which can encompass a variety of standard practices including
punctuation and capitalization.
Phishing - is the most frequent type of social engineering threat (Livara & Hernandez,
2022; Sumner & Yuan, 2019). So-named because bait is used by attackers to lure people into
giving up personal information, attackers “fish” for this data to use or sell to other cybercriminals
on the dark web (Alabdan, 2020).
Phonetics - describes one of the fundamental systems that make up a language’s grammar
and has to do with “the articulation and perception of speech sounds” (O’Grady et al., 1997, p.
4). All spoken languages have phonetic systems.
Phonology - refers to one of the fundamental systems that make up a language’s grammar
and has to do with “the patterning of speech sounds” (O’Grady et al., 1997, p. 4).
Phonotactic rules - refers to how sequences of sounds can be combined according to the
conventions of specific languages (O’Grady et al., 1997). As an example, a Bulgarian speaker
may find the consonant cluster /zdr/ acceptable at the beginning of a word compared to an
English speaker who may find it problematic there, but permissible in the middle of a string of
sounds
(such as in “his drink”).
Pretexting - is when a threat actor pretends to be a trusted person and/or fabricates a story
about themselves that will make it more likely that a targeted individual will share desired
information or perform a service.
Pragmatics - is “the study of various factors involved in appropriate use and
understanding of language” (O’Grady et al., 1997, p. 725). This can include “the speaker’s
intentions and how they are surmised by the addressee, the speaker’s and the addressee’s
background attitudes and beliefs, their understanding of the context … and their knowledge of
how language can be used for a variety of purposes” (O’Grady et al., 1997, p. 725).
Privacy - is “freedom from intrusion into the private life or affairs of an individual when
that intrusion results from undue or illegal gathering and use of data about that individual”
(ISO/IEC 2382-8:1998, definition 08-01-23, as cited in Garfinkel, 2015, p. 43).
Ransomware - is “a variant of malware [that] encrypts files, data, and often locks
computer systems, and retains the decryption key until victims pay a ransom” (Bello &
Maurushat, 2020, Abstract).
Resilience - is “the ability to prepare for and adapt to changing conditions and withstand
and recover rapidly from disruption. Resilience includes the ability to withstand and recover
from deliberate attacks, accidents, or naturally occurring threats or incidents” (Ross et al., 2021,
p. 65).
Reward hacking - may result when the desire for “positive feedback” prompts a choice
“to prioritize earning reward [sic] instead of accomplishing their main task” (Mercer, 2023, para.
6). One example of reward hacking “involves an AI achieving a goal in a way the AI’s designers
neither wanted nor intended” (Schneier, 2023, p. 231). In a classroom setting, this may involve
learners finding shortcuts for completing activities (completion being the proxy goal) that bypass
the aspects of the activities meant to help learners develop certain skills (will skill development
being the intended goal).
Risk analysis - involves “comprehend[ing] the nature of risk and … determine[ing] the
level of risk” (Ross et al., 2021, p. 66).
Risk assessment - refers to the “Overall process of risk identification, risk analysis, and
risk evaluation” (Ross et al., 2021, p. 66)
Security - understood as “Freedom from those conditions that can cause loss of assets
with unacceptable consequences” (Ross et al., 2021, p. 67) or “protection against intentional
subversion or forced failure” (p. 67) and is made up “of four attributes—confidentiality, integrity,
availability, and accountability—plus aspects of a fifth, usability, all of which have the related
issue of their assurance” (p. 67).
Security mindsets - are defined as an ingrained habit of investigating and identifying how
things (including people, systems, and processes) can fail (Cappos & Weiss, 2014;
Pournaghshband, 2013; Schneier, 2008). Used here interchangeably with security thinking,
aspects of security mindsets have also surfaced under the guise of cybersecurity critical thinking
(California Academic Press, 2021), cybersecurity situational awareness (Padilla-Pagan Payano,
2018) adversarial thinking (Hamman & Hopkinson, 2016; Katz, 2019), and thinking like a
hacker (Katz, 2019). The concept has also been summed up as “critical thinking … and …
curiosity manifested” (R. Cloutier, personal communication, September 29, 2020). While
security mindsets are typically referred to in the singular as a security mindset, I have opted to
use the plural whenever possible in an effort to avoid implying that there is one fixed mindset
that constitutes security thinking (see also Padmos, 2018).
Semantics - refers to “the study of meaning in human language” (O’Grady et al., 1997, p.
729) and involves “the interpretation of words and sentences” (p. 4).
Social engineering - can be understood as “the art of manipulating people so they give up
confidential information” (Jin et al., 2018, p. 152) or behave in a certain way (Sherman &
Arampatzis, 2018). Social engineering “exploits our cognitive biases and basic instincts (e.g.,
trust) for the purpose of information-gathering, fraud, or system access” (Sherman & Arampatzis,
2018, para. 1) and may involve both humans and computers (Hijji & Alam, 2021; Salahdine &
Kaabouch, 2019).
Syntax - refers to “the system of rules and categories that underlies sentence formation in
human language” (O’Grady et al., 1997, p. 732). Syntax involves how words can be organized to
make phrases. As an example, English speakers understand from the sentence The mailman bit
the dog that the dog is the unexpected victim because mailman precedes dog. In other languages,
this word order may not be sufficient (or even possible) for conveying the dog’s unfortunate fate.
Technification - describes when an issue comes to be seen as first and foremost in need of
“expert, technical knowledge” to be resolved (Hansen & Nissenbaum, 2009, p. 1166) while
“presuppos[ing] a politically and normatively neutral agenda that technology serves” (p. 1167).
Textbook content - includes anything in a physical textbook or online curriculum
resource, such as introductory instructional material (e.g., chapter themes, presentation of
vocabulary, grammar charts), practice exercises (e.g., tasks that involve reading, writing,
speaking, and listening), and images (e.g, photos and drawings). It may also include table of
contents, notes for instructors, chapter pretests, and end-of-lesson comprehension checks, as well
as links to ancillary resources. If it is in the textbook, it is textbook content.
Unstructured data - “refers to information that lacks a predefined format or organization”
(Potdar, 2023, para. 1) and “exists in vast quantities across multiple sources, such as emails,
social media, documents, images, and more” (para. 2). Unstructured can be “arduous to sift
through and identify pertinent information” (Potdar, 2023, para. 2). This is compared to
structured data, which has an “inherent organization” (Potdar, 2023, para. 3) and can be easily
retrieved as in databases.
Value of information/data - refers to “a qualitative measure of the importance of
information” with respect to its sensitivity, importance to a particular mission, or the “potential
impact of loss of confidentiality and integrity and/or availability of the information” (CNSSI
4009-2015, in National Institute of Standards and Technology [NIST], n.d.).
Zero trust - conveys “the simple principle of ‘never trust, always verify’” (Samaniego &
Deters, 2018, p. 89) and is the idea behind the Zero-Trust (ZT) model developed in 2010 by the
analyst firm Forrester Research.
Chapter Summary
Cybercrime is costly and cybersecurity is concerned with the urgent and evolving task of
protecting the security of individuals, institutions, and nations. Cybersecurity education has been
viewed as a critical resource in meeting these challenges. Responding to a number of factors
including ballooning security workforce demands (Crumpler & Lewis, 2019; Furnell, 2021;
McQuaid & Cervantes, 2019) and criticism over the technification of cybersecurity (Hansen &
Nissenbaum, 2009), scholars have called for a wider range of fields to support and broaden
cybersecurity education efforts (Craigen et al., 2014; Javidi & Sheybani, 2018). In this,
researchers have yet to examine the contributions that K12+ L2 learning could make to
cybersecurity education efforts in the United States. Through qualitative content analysis (QCA)
paired with imaginative variation (IV), this study investigated how various content in commonly
available L2 textbooks could provide in-roads for broaching foundational security themes with
learners. This study was undertaken with the hope that by illuminating foundational links
between L2 learning and security thinking in existing materials—and better understanding what
can to be done to leverage them—curriculum designers and practitioners could find themselves
well-poised for meeting the educational challenge of promoting cybersecurity awareness among
a vast portion of the general K12+ student population.
Chapter II. Review of Cybersecurity Literature
The first chapter introduced current challenges facing cybersecurity and cybersecurity
education in the United States and the need for more robust attention to foundational security
thinking. I investigated if and what connections between security mindset fundamentals and
second language (L2) language learning material might be identified for future exploitation by
practitioners as a potential way to introduce a portion of the general population to fundamental
thinking, practices, and questions in cybersecurity. Among these L2 students are also potential
future members of the nation’s cybersecurity workforce who might benefit from “incidental
learning” that could “be powerful … in inspiring further study” (Noddings, 1995, p. 675). What
follows is an overview of the literature pertaining to current cybersecurity-related challenges and
the role of cybersecurity education in responding to those challenges, including
recommendations in the literature for improving cybersecurity education for both technical and
non-technical populations. Then, in focusing particular attention on the call to bring security
thinking to the fore, I conclude by examining existing frameworks for understanding security
mindset fundamentals and present an operationalized conception for this inquiry.
Cybersecurity Landscape
The cybersecurity landscape in the United States has rapidly evolved, marked by
increasing risk (Georgescu, 2021; Siraj et al., 2021). Superseding “nuclear war as the most
discussed global threat” (Binns, 2019, para. 2), cybercrime has been labeled the number one risk
to business operations in North America (The World Economic Forum, as cited in (ISC)2
Cybersecurity Workforce Study: Women in Cybersecurity Report, 2022). Governmental,
educational, and health institutions have increasingly been targeted (N. Khan et al., 2020).
Cyberattacks have beset private individuals as well (Karagiannopoulos et al., 2021; Monteith et
al., 2021). In this landscape, cybersecurity has been branded as increasingly vital (e.g., Alexei et
al., 2022; Norris et al., 2021; Walton et al., 2021). Circumstances shaping today’s cybersecurity
landscape are examined in more detail below.
Increasingly Pervasive Threats
More people and organizations have been impacted by more cyber threats than ever
before (Baker, 2016; Georgescu, 2021; N. Khan et al., 2020). An uptick in cyberattacks has been
fueled in part by the COVID-19 pandemic (N. Khan et al., 2020) and geopolitical events ((ISC)²
2022 Cybersecurity Workforce Study, 2022). Global COVID-19 pandemic lockdowns incited
massive migrations from in-person to on-line, impacting how technology has been used both
personally and professionally (Georgescu, 2021; N. Khan et al., 2020; Venkatesha et al., 2021).
Such shifts have been blamed for ushering in weakened security and a rise in cybercrime
(BuilGil et al., 2021; Georgescu, 2021; Khweiled et al., 2021; Saleous et al., 2023). Nearly two-
thirds of companies surveyed reported a growing number of attempted breaches compared to
before the pandemic (Fortinet, 2020). Attacks on individuals also began to climb during this time
(Aldridge, 2021).
Erupting on the heels of a global pandemic, events such as the Russia-Ukraine war have
also contributed to a growing amount of cyber activity (Guchua et al., 2022; ((ISC)² 2022
Cybersecurity Workforce Study, 2022). This includes “widespread” (Willett, 2022, p. 17) cyber
vigilantism, also known as hacktivism, wherein non-state affiliated IT professionals have joined
in loosely organized efforts to sabotage Russian logistics from places around the globe
(Väljataga, 2022). Russia recently indicated that its response to this would be shaped by a
broader definition of what constitutes “legitimate military targets and direct participation”
(Väljataga, 2022, p. 3). In light of this, Väljataga (2022) urged cyber hacktivists not to get
involved so as to avoid escalating cyberwar. However, others have been more skeptical of the
actual impact of such hacktivism, believing that the press has largely served to advance an
“overhyped” (Vu et al., 2022, p. 1) narrative of cyberwar. One view published by a
Kremlinaffiliated news agency, complicit in this hype, nevertheless pointed to the issue of
increasing vulnerabilities in cyberspace—warning that after “this storm subsides, a large number
of people will be trained to launch … attacks and will have the tools to carry them out. Of
course, the targets of these attacks will be different” (Khantimirov, in TASS, 2022, para. 5). In
this way,
geopolitical conflicts may contribute to increased threats in cyberspace.
Even before the COVID-19 pandemic and current geopolitical unrest, cyberattacks were
becoming increasingly frequent owing to a growing number of activities being carried out using
technology (Walton et al., 2021). Vulnerabilities have been on what would seem to be an
inexorable rise in part due to the growing Internet of Things (IoT) (Sample et al., 2020; Sarker et
al., 2020; Schneier, 2018; A. Sharma et al., 2020). Defined as “the network of physical objects
that contain embedded technology to communicate and sense or interact with their internal states
or the external environment” (Gartner, Inc., n.d., para. 1), IoT examples include smart washing
machines, cars, printers, phones, and power substations—in short, anything connected over the
Internet (Schneier, 2018). In more recent years, IoT has expanded at a “staggering” (Schneier,
2018, p. 5) rate. Of particular concern is that countless IoT devices from baby monitors to
surveillance equipment can be used as vehicles for attack (Caravelli & Jones, 2019). More
devices mean more potential vulnerabilities and attack surfaces (R. Ahmad et al., 2022;
Aldawood & Skinner, 2020; Anand et al., 2020; Dawson & Thomson, 2018; Rizvi et al., 2020).
In a landscape marked by increasing susceptibility, a variety of threats abound (Ahsan et al.,
2022; Humayun et al., 2020; Schneier, 2018).
A Variety of Threats
Many types of cyber threats afflict people and organizations, such as malware,
webskimming, denial of service, remote desktop protocol attacks, brute-force attacks, man-in-
themiddle, ransomware, phishing, and pretexting (Georgescu, 2021; Li & Liu, 2021; Salahdine &
Kaabouch, 2019). In addition, there are cyber-based threats capable of influencing the behavior
of entire electorates (Pariser, 2011; Wylie, 2019). While these examples are not exhaustive, they
serve to testify to a wide range of threats in cyberspace spanning both the technical and social
(Almaiah et al., 2021), some of which are beyond the traditional purview of cybersecurity
professionals who are mainly generally tasked with securing devices, data, infrastructure, and
networks (Simplilearn Solutions, 2023). Yet when successful, any of these threats can result in a
loss of financial assets, reputation, productivity, privacy, or trust and stability (Georgescu, 2021;
Salahdine & Kaabouch, 2019; Carrapico & Farrand, 2020). In an effort to illustrate their
sociotechnical variety, I review diverse types of cyber-based threats below.
Technical Threats. Common cyber-technical threats (e.g., web-skimming, denial of
service attacks, remote desktop protocol attacks, and ransomware) frequently involve malicious
software, known as malware (Edgar & Manz, 2017). While malware is typically used for stealing
information or keeping it for a ransom (Fanning, 2015), more broadly speaking, it is
“software that does any operation without the user’s permission” (Gorugantu, 2018, p. 1).
Malware uses system vulnerabilities to gain access to a system and carry out unauthorized
actions (Edgar & Manz, 2017, p. 40), which can cause damage to users’ information, computers,
or networks (Gorugantu, 2018). Once malware has infected a device—which may result from a
user clicking on a link or installing software—its malicious code can render the device slow-
touseless, or create inroads for further exploitation (Nationwide, n.d). This further exploitation
may be made possible through different types of invasive malware called spyware; keyloggers
are one such example of spyware, able to capture anything typed on a device (Mallikarajunan et
al., 2019). In this way, attackers can gather usernames and passwords which can be used or sold
to provide access to even more targets. While devices infected with malware may run markedly
slower, breaches often go unnoticed—at least for a time—by users (Nationwide, n.d.). However,
the impact of these technical threats is hard to miss: in 2019, the average cost of a single malware
attack for businesses was reported to be $1.4 million (World Economic Forum, 2019). The
staggering price tag is largely due to the loss of information and interruption of business
associated with an attack (World Economic Forum, 2019).
Social Engineering Threats. Not all threats in cyberspace are technical. Social
engineering threats rely “on psychological and systematic techniques to manipulate users” (Hijji
& Alam, 2021, p. 7166). As such, they “cannot be controlled solely through the use of
technology” (Hijji & Alam, 2021, p. 7166). In cybersecurity, social engineering “is the practice
of taking advantage of human weaknesses through manipulation to accomplish a malicious goal”
(Aldawood & Skinner, 2018, Abstract). Jin et al. (2018) summed it up as “the [extremely
effective] art of manipulating people so they give up confidential information” (p. 152). As a
testament to this effectiveness, social engineering has been found to constitute 35% of attack
patterns identified in breaches, more frequent than any other pattern (Verizon, 2021, as found in
Fauzi et al., 2021). The U.S. Department of Justice (as found in Salahdine & Kaabouch, 2019)
described social engineering threats as “one of the most dangerous threats over the world” (p. 1).
With losses totaling $121.22 billion in 2016 alone, the United States has been the most-targeted
country in terms of social engineering threats (Salahdine & Kaabouch, 2019).
Since the onset of the COVID-19 pandemic, among the most common social engineering
attacks are phishing, scamming, and spamming (Hijji & Alam, 2021). Phishing is the most
frequent type of social engineering threat (Livara & Hernandez, 2022; Sumner & Yuan, 2019).
So-named because bait is used by attackers to lure people into giving up personal information,
attackers “fish” for this data to use or sell to other cybercriminals on the dark web (Alabdan,
2020). An example of a phishing attack may be an email that appears to be from a legitimate
sender (Figure 1).
Figure 1
An example of a phishing email
Note. This email, received February 7, 2023, was not a legitimate message from Yahoo. (From S.
Oliver, personal communication, February 7, 2023. Used with permission.)
Phishing messages may use language that will trigger an emotional reaction from users
(T. Sharma & Bashir, 2020). The sender often pressures a recipient into taking immediate action
to avoid consequences such as the termination of an account or the promise of a reward.
Receivers may be directed to click on a link and be prompted to enter a password or other
personally sensitive information. Once this information is obtained, the attacker can exploit it in
various ways, including locking users out of their account and gaining access to other
information or systems where more damage can be affected. Phishing attacks have been
increasing annually by 200% (Tanimu & Shiaeles, 2022). Businesses have lost hundreds of
billions of dollars from phishing, prompting numerous calls for the development of more
effective phishing detection methods (Do et al., 2022; Obaid et al., 2021; Odeh et al., 2021;
Tanimu & Shiaeles, 2022; Zuraiq & Alkasassbeh, 2019).
On a broader scale, social engineering has also been regarded as a tool for influencing
public opinion (Kilovaty, 2018; Sherman & Arampatzis, 2018). The terminology for this
phenomenon is somewhat fluid, but scholars have opted for phrases such as “psychological
targeting” (Matz et al., 2017; Sharp et al., 2018), “psychological mass persuasion” (Matz et al.,
2017), and “digital mass persuasion” (Day, 2019; Matz et al., 2017).
This genre of cyber-based threat differs from phishing in that its impact cannot be traced
to any one single incident, given that its efficacy depends on an aggregate of cyberactivity
(Kilovaty, 2018). The precise impact of such campaigns is also not well understood (van der
Linden, 2018). However, like other threats, digital mass persuasion may come with potentially
significant consequences (e.g., Matz et al., 2017). One example of attempts at digital mass
persuasion can be found in Cambridge Analytica’s efforts to manipulate voters through social
media to influence elections (see Hu, 2020). Cambridge Analytica leveraged data analytics—the
mining of huge amounts of information which can reveal trends and attitudinal shifts (Kannan et
al., 2016)—“to sway the electorate [and] rely on social network users’ participation in their own
psychological manipulation” (Berghel, 2018, p. 84). Cambridge Analytica sought to determine
which users might potentially be swayed by a particular message down to the level of the
individual (Amer & Noujaim, 2019; Isaak & Hanna, 2018). This was achieved in part by
analyzing users’ data trails; Cambridge Analytica claimed to have had access to more than 5,000
data points for every voter “from social media platforms, browsers, online purchases, voting
results, and more” (Isaak & Hanna, 2018, p. 57). Such data mining also helped Cambridge
Analytica to identify users unlikely to ever support a particular issue or candidate (Amer &
Noujaim, 2019). In those cases, rather than try to influence these users to think or vote
differently, such users were encouraged not to vote at all (Amer & Noujaim, 2019). As a result,
individuals living in the same household could have received disparate messages with respect to
a political candidate or a policy issue. Grimes (2017) warned against the resulting insularity for
its potential to hinder people’s capacity for telling fact from opinion.
More recently, some scholars have sought to understand the extent to which millions of
social media users’ data trails may have been used to cultivate echo chambers (e.g., Cinelli et al.,
2020). Speaking about Facebook, McNamee (as cited in Amer & Noujaim, 2019) described how
the social media service similarly employed users’ data trails to cultivate an individual
“reality” (1:24:05) for each of their more than 2 billion users, asserting that “once everybody has
their own reality—it’s relatively easy to manipulate them” (1:24:06). Decades before Cambridge
Analytica and Facebook were household names, Van Alstyne and Brynjolfsson (1996)
considered the consequences of digital echo chambers. In exploring the concept of
cyberbalkanization, wherein social network users almost exclusively “seek out interactions with
like-minded individuals” (p. 24), Van Alstyne and Brynjolfsson (1996) suggested that this
decreased users’ willingness “to trust important decisions to people whose values differ from
their own” (p. 24).
While social engineering threats are ultimately “based on psychological and systematic
techniques to manipulate users that cannot be controlled solely through the use of technology”
(Hijji & Alam, 2021, p. 7166), psychological mass persuasion tactics and other social
engineering attacks may be executed by humans or computers (Hijji & Alam, 2021; Salahdine &
Kaabouch, 2019). The security implications of this nexus between humans and computers are
briefly examined below.
A Blend of Threats. Contributing to the difficulty of understanding technical and social
cyber threats is just how profoundly these two categories of threats routinely intersect. Both
technical and social factors can make up a cyber threat (Connolly & Wall, 2019). Ransomware
provides one robust example of this, as it depends on malware in order to encrypt data, but may
rely on social engineering tactics as well to trick people into clicking on links that will provide an
in-road for the attack (Connolly & Wall, 2019). Frumento (as found in Aldawood & Skinner,
2020) suggested that in the case of organizations, attackers much prefer accessing systems
through human weaknesses than through any deficiencies in hardware or software, with 3% of
attacks targeting technical aspects and 97% targeting humans. Regardless of the percentages, the
blend of social and technical factors has left cybersecurity practitioners without a “silver bullet”
(Connolly & Wall, 2019, p. 14) for responding to the wide array of threats. As Jeong et al.
(2019) observed, “the most intractable aspects [of cybersecurity] are in fact sociotechnical” (p.
338).
Characteristics of the General Population
Whilst vulnerabilities abound, scholars have bemoaned that everyday end-users are not
aware of how severe the problem is (Bele et al., 2014), a view shared by those in the security
blogosphere and industry as well (e.g., Chandravanshi, 2022; Flynn, 2022; Fortra, LLC, 2022;
Marshall, 2020; Microsoft, n.d.). Even in cases when there is awareness, members of the general
population have seemed chronically indifferent to security matters (Bada et al., 2019; Harknett &
Stever, 2009).
Insufficient Awareness. Researchers have reported low cybersecurity awareness among
the general populace of many countries (Aljabri, 2021; Campean, 2019; Catota et al., 2018;
Chandarman & Van Niekerk, 2017; Chang & Coppel, 2020; Forrester et al., 2022; Nur, 2021;
Sambuli et al., 2016). Other work has highlighted the need for certain subsets within the general
population to heighten their cybersecurity awareness, such as Rahman et al.’s (2020) research on
children and adolescents, Richardson et al.’s (2020) focus on school communities, and
Blackwood-Brown et al.’s (2021) study of senior citizens. In discussing cybersecurity awareness,
researchers have focused on users’ awareness of the threats and potential impact, as well as their
cyber practices, commonly referred to as cyber hygiene (see Hoe, 2021; Neigel et al., 2020;
Nifakos et al., 2021). Yet Vishwanath et al. (2020) noted that “while many experts lament the
lack of cyber hygiene … there isn’t a single academic research article that explicates the
construct” (p. 3). Vishwanath et al. (2020) detailed how the term cyber hygiene covered a range
of effective cybersecurity best practices from installing anti-virus software, securing emails, and
managing passwords to identifying misinformation and, more nebulously, developing “improved
vigilance” (p. 3) and “heightened awareness” (p. 3). Poor cyber hygiene includes practices which
can create inroads for cyber threat actors frequently looking to exploit Internet users’ poor habits
(Thebarge et al., 2022, p. 325), such as the sharing of passwords or other personal information
(Cain et al., 2018). Calling for “bottom-up constructed resilience” (p. 117) in a discussion of
cybersecurity awareness in the European Union, Gajewski (2020) suggested that around 80% of
cyberattacks could be linked to poor cyber hygiene practices; a claim also made by the British
Ministry of Defence (UK Cabinet Office, 2011) nearly a decade before.
Lack of Care. For a while now, researchers have observed that user awareness does not
guarantee safe user practices (Aytes & Connolly, 2003). Kostyuk and Wayne (2021) highlighted
the “lack of care in personal online behavior” (p. 3). Cain et al. (2018) asserted that raising users’
awareness was only a “first step” (p. 44) and that it was also necessary to find ways “to improve
users’ cyber hygiene attitudes and behaviors” (p. 44). In countries whose populaces generally
exhibited sufficient levels of cyber threat awareness, users were still found to be implementing
bare-minimum safety practices (Zwilling et al., 2022). The implications of this may be
farreaching: insufficient cyber hygiene on the part of the mass public has been identified as
“problematic not just from a consumer or industry perspective, but also for national security writ
large” (Kostyuk & Wayne, 2021, p. 2).
Cybersecurity Workforce Shortfalls
Compounding the challenges associated with an increase in cyber threats and an
underinvested general populace are myriad issues that afflict the professional cybersecurity
workforce in the United States and abroad. These include personnel shortages, low diversity, and
narrowly developed skillsets (Burrel, 2020; Sharevski et al., 2018).
Shortages. Scholars and practitioners alike have repeatedly documented the “persistent
problem” (Feiner, 2021, para. 9) of a critical cybersecurity workforce shortage (Crumpler &
Lewis, 2019; Furnell, 2021; McQuaid & Cervantes, 2019). Characterized as “a profession in dire
need of more people” ((ISC)2 2022 Cybersecurity Workforce Study, 2022, p. 7), the cybersecurity
workforce recently reached a global gap of over 3 million people (Blažič, 2021; (ISC)2 2022
Cybersecurity Workforce Study, 2022; Sample et al., 2020). The number of dedicated
cybersecurity personnel has been climbing in most places ((ISC)2 2022 Cybersecurity
Workforce Study, 2022), yet is still outpaced by demand (Daniel et al., 2022; Givens, 2019;
(ISC)2 2022 Cybersecurity Workforce Study, 2022; Sample et al., 2020; Schuster & Wu, 2018).
Since 2022, unfilled positions in the cybersecurity workforce grew to more than double the
number of positions that were filled ((ISC)2 2023 Cybersecurity Workforce Study, 2023). In the
United States alone, there were an estimated 410,695 unfilled positions in 2022, representing an
increase of nine percent from the previous year ((ISC)2 2022 Cybersecurity Workforce Study,
2022).
Ground-level consequences of cybersecurity personnel shortages in the face of ballooning
demand include poorer risk assessment, inefficient mitigation, procedural oversights, slower
patches, improperly configured systems, and a lack of personnel for conducting training ((ISC)2
2022 Cybersecurity Workforce Study, 2022, p. 10). At a national level, ground-level deficiencies
add up (Kostyuk & Wayne, 2021). This cumulative impact ultimately endangers national
infrastructure and privacy (McQuaid & Cervantes, 2019). In this vein, researchers have
repeatedly linked workforce shortages to issues of national security (Burrell, 2020; Coulson et
al., 2018; Crumpler & Lewis, 2019; Jethwani et al., 2017; Libicki et al., 2014; Vogel, 2016).
Lack of Diversity in the Workforce. Scholars and practitioners have joined in noting a
lack of diversity in the cybersecurity workforce with respect to gender, racial and ethnic identity,
and training (e.g., J. Hall & Rao, 2020; Jethwani et al., 2017; Mountrouidou et al., 2019). The
most recent (ISC)² Cybersecurity Workforce Study (2022) called unequivocally for the need to
recruit “a more diverse range of skills and perspectives” (p. 66). Voices in cybersecurity have
also lamented the under-representation of women and minorities in cybersecurity, arguing that
teams made up of people with different backgrounds “do better and accomplish more” (Blair et
al., 2019, p. 59; Burrell & Nobles, 2018; (ISC)2 2022 Cybersecurity Workforce Study, 2022).
Women. In recent years, women have been outnumbered by men more than three to one
in cybersecurity jobs (Jethwani et al., 2017). Globally, less than a third of the cybersecurity
workforce under the age of 30 are women and that percentage falls by more than half for women
older than 60 ((ISC)2 2022 Cybersecurity Workforce Study, 2022). Recent estimates suggest that
women comprise less than a quarter of the cybersecurity workforce ((ISC)2 Cybersecurity
Workforce Study: Women in Cybersecurity Report, 2022) and in 2022, the United States’
cybersecurity workforce has been identified as one of the “least gender-diverse” in the world
([ISC]2 Cybersecurity Workforce Study, 2022, p. 41). While women have been increasingly
entering the field, many argue that the number is still not enough (Farber, 2021; Morgan, 2022;
(ISC)2 Cybersecurity Workforce Study: Women in Cybersecurity Report, 2022). Those
advocating for more women in cybersecurity have cited the need to address diversity (Blair et al.,
2019; Burrell, 2020; Farber, 2021), equality (Cybersecurity Guide, 2022) and shortages in the
workforce (Cybersecurity Guide, 2022; Jethwani et al., 2017; (ISC)2 Cybersecurity Workforce
Study: Women in Cybersecurity Report, 2022).
Minorities. Minority populations have been depicted by experienced cybersecurity
practitioners as “grossly underrepresented” (e.g., B. Allen, 2022, para. 6; Underwood, 2018, para.
4; Woods, 2015, para. 2) in the U.S. cybersecurity workforce. In 2018, Black individuals made
up only 9% of cybersecurity individuals in the United States, while Asians represented 8% and
Hispanic people just 4% in (Reed et al., 2018). In the United States, “the cybersecurity workforce
has historically been dominated by white men” ([ISC]2 Cybersecurity Workforce Study, 2022, p.
38), although there is evidence that this trend has been shifting toward the inclusion of more
minorities and the United States was at the top of the list in 2022 as the country with the most
diversity, equity, and inclusion initiatives in cybersecurity ([ISC]2 Cybersecurity Workforce
Study, 2022). One security executive (B. Allen, 2022) maintained that developing diversity was
“essential” (para 5) given that diversity in the workforce strengthens an organization’s ability to
“better identify risks and vulnerabilities, learn from past mistakes and develop more effective
security protocols” (para. 5). This sentiment has been shared widely in the literature (e.g., Blair et
al., 2019; [ISC]2 Cybersecurity Workforce Study, 2022;
Mountrouidou et al., 2019; Reed at al., 2018)—also appearing alongside the argument that hiring
more minority professionals could help address workforce shortages (e.g., Mountrouidou et al.,
2019; Reed et al., 2018).
Technification of the Workforce. In striving to meet the challenges of the cybersecurity
landscape, technical factors and roles have historically been emphasized (Blažič, 2022; Caulkins
et al., 2018; Gioe et al., 2019; J. Hall & Rao, 2020; Haney & Lutters, 2017). Scholars have also
often focused on cybersecurity professionals’ technical skills (Dawson & Thomson, 2018). Yet
there have been repeated calls to broaden this practical and theoretical emphasis beyond
“advanced technical competencies” (Baker, 2016, p. 6). Such calls have pointed to the
challenges associated with a narrow technical focus (e.g., J. Hall & Rao, 2020), presented below.
Underemphasis on Human Elements. Cybersecurity, fundamentally, is a human problem
(Carley, 2020; Morris et al., 2018; Sharevski et al., 2018). Consequently, approaches that
emphasize technical factors—to the detriment of human factors—may come with security risks
(J. Hall & Rao, 2020). Some of these risks include training up a workforce that may overlook
important skills related to human factors in cybersecurity such as the ability to strategize
(Hamman & Hopkinson, 2016) and address threats that target human behavior (Jacob et al.,
2018). Blanken-Webb and Cloutier (2020) suggested that cyber space could even “be understood
as an extension of our humanity” (p. 33). By emphasizing mainly technical aspects, cybersecurity
defenders may “miss the human side of the problem” (Greitzer, 2019, p. 1; Nobles, 2018).
Humans have frequently been deemed “the weakest link in the security chain” (He et al.,
2020; Salahdine & Kaabouch, 2019, p. 1; Richardson et al., 2020; Rohan et al., 2021). Alsharif et
al. (2022) claimed that more than a third of risks could be connected to a human factor, while
Fauzi et al. (2021) cited a 2021 Verizon report which indicated 85% of all breaches were linked
to human factors. Researchers have recorded a panoply of ways in which human factors have
been exploited (e.g., Aldawood & Skinner, 2020; Koyun & Al Janabi, 2017). For instance,
humans may exhibit set patterns of behavior when surfing the web of which they themselves are
not totally aware; attackers take note and are able to use this predictability to their advantage (Z.
Wang et al., 2021). Scholars have also asserted that people may be more likely to place their trust
in another human being rather than in technology (Salahdine & Kaabouch, 2019), although this
may depend on circumstances (see Sundar & Kim, 2019; Zonca et al., 2021). Nevertheless, the
human proclivity to trust, a fact which attackers routinely exploit, has been well-documented in
the literature on social engineering (e.g., Klimburg-Witjes & Wentland, 2021; Salahdine &
Kaabouch, 2019). In addition to human vulnerability through social engineering threats, humans
can pose inside threats to an organization, whether maliciously or accidentally (Bailey et al.,
2018; Greitzer, 2019; Hadlington, 2021; Prabhu & Thompson, 2022). Ninety-five percent of
cyber-attacks are the result of human faults (Alsharif et al., 2022; Nobles, 2018). Of these, most
are from insider threats (Alsharif et al., 2022).
Narrowly Developed Skillsets. Emphasizing technical factors in cybersecurity may leave
the workforce with highly developed technical skills but a dearth of skills in other areas that have
been increasingly recognized as necessary for cybersecurity as well (J. Hall & Rao, 2020; Haney
& Lutters, 2017). As Jeong et al. (2019) observed, “Cybersecurity cannot be addressed by
technology alone” (p. 338). Rather, a range of competences are needed (Crumpler & Lewis,
2019; J. Hall & Rao, 2020; Newhouse et al., 2017). These include skills such as communication
(Crumpler & Lewis, 2019; Haney & Lutters, 2017; K. Jones et al., 2018), collaboration
(Crumpler & Lewis, 2019; K. Jones et al., 2018), and problem-solving (Crumpler & Lewis,
2019). With a focus limited in scope, the cybersecurity workforce may also lack the training
necessary to tackle “broader … vulnerabilities” (Gioe et al., 2019, p. 30) such as digital mass
persuasion campaigns, presented above.
Moreover, when technical aspects of cybersecurity come to be privileged, cybersecurity
professionals may come to devalue non-technical contributions (J. Hall & Rao, 2020);
nontechnical knowledge is not only lacking, it may in fact be discouraged. This arguably touches
on what Hansen and Nissenbaum (2009) were writing about with respect to the technification of
cybersecurity. Technification of an issue results when the issue comes to be seen as needing
“expert, technical knowledge” to be resolved (Hansen & Nissenbaum, 2009, p. 1157). Hansen
and Nissenbaum (2009) explicitly argued that this has transpired with respect to cybersecurity,
wherein cybersecurity conversations and activities have been kept chiefly in the hands of
technical experts.
Technification has also likely shaped the current tech-heavy make-up of the workforce:
70% of cybersecurity professionals reportedly have degrees in computer and information
sciences or engineering fields at present ((ISC)2 2022 Cybersecurity Workforce Study, 2022)
while the remainder are “a mix of business, communications, social sciences, mathematics,
economics, biological and biomedical sciences and other degrees outside of IT” (p. 54).
However, there is some evidence that this composition is changing: the (ISC)2 2022
Cybersecurity Workforce Study (2022) reported that nearly 50% of cybersecurity professionals
under 30 have entered the workforce with non-IT backgrounds.
Change and Ambiguity: Rapidly Emerging Technologies and Novel Cybersecurity Challenges
Cybersecurity is ever-evolving as new ideas and practices are continually introduced
(Scheponik et al., 2016). Recent and forthcoming technologies routinely present new security
challenges for the cybersecurity workforce and everyday users (Aldawood & Skinner, 2018;
Caprolu et al., 2019; Piattini, 2020; Schneier, 2018; Tabrizchi & Kuchaki Rafsanjani, 2020).
Scholars have pointed to the impact that emerging technology such as artificial intelligence and
machine learning (R. Ahmad et al., 2022; Rani et al., 2022; Thakur et al., 2022) and cloud
computing (Kaur, 2022) has had on traditional security practices. While these can present new
security challenges, at the same time they have also been championed for their potential to
respond to evolving, more sophisticated threats (e.g., R. Ahmad et al., 2022; Rani et al., 2022;
Thakur et al., 2022).
In a rapidly changing environment such as this, security knowledge can be quickly
rendered obsolete (Dawson & Thomson, 2018). Daniel et al. (2022) spoke of a “shrinking
halflife” (p. 1) with regard to the usefulness of any cybersecurity training. Dawson and Thomson
(2018) predicted that the future workforce would “not be able to rest on their laurels … but …
have to be constantly seeking out the latest information” (p. 9). K. Jones et al. (2018) found that
many of the cybersecurity practitioners they surveyed felt that it was important to keep pace with
methodological and technological innovations.
Continuous and rapid changes have left the high-level politics of cybersecurity to deal
with tremendous ambiguity (Gow, 2019; Wenger & Dunn Cavelty, 2022). This lack of certainty
shapes more localized spheres of cybersecurity action as well; cybersecurity practitioners must
be ready for “uncertainty and ambiguity” (Dark, 2015, p. 61).
Cybersecurity Education
The section above outlined the way cybersecurity thinkers have depicted how factors
such as increasing threats, the general population, workforce shortfalls, and rapid changes in
technology have shaped the current cybersecurity landscape. Cybersecurity education and
training—which can include degree programs, workforce training, and public awareness
campaigns—has routinely been presented as an important means for addressing many of the
associated challenges. Such challenges include the need to build cybersecurity awareness
(Amankwa, 2021; Bada & Nurse, 2019), technical expertise (Crumpler & Lewis, 2019), and
human and social engineering expertise (Arachchilage & Love, 2014; Salahdine & Kaabouch,
2019; Taylor-Jackson et al., 2020), and the need to address workforce shortages (Blažič, 2021)
while keeping pace with rapid changes (Knapp et al., 2017). Although government regulation has
also been presented as important (e.g., Hathaway, 2013; Kogut et al., 2021; Schneier, 2018;
Srinivas et al., 2019; Walter et al., 2020), as a topic it is more contentious than conversations
surrounding the need for cybersecurity education. The topic of regulation is also largely beyond
the scope of this work, which is primarily dedicated to treating other issues related to curriculum
and pedagogy. What follows here is an overview of observations and recommendations of
practitioners and researchers as related to cybersecurity education and training in the United
States and abroad.
Responding to Increasingly Pervasive Threats
Discussing the impact of increases in devices and connectivity, N. Ahmad et al. (2021)
called for more cybersecurity education “at all levels and in every discipline” (p. 1456). Hardly
an isolated view, cybersecurity education has been widely framed as a critical part of responding
to cybersecurity threats (e.g., N. Ahmad et al., 2021; Patnayakuni & Patnayakuni, 2020).
Švábenský et al. (2020) credited the already emerging number of educational initiatives to the
increasing need for cybersecurity in the face of continued workforce shortages. In 2021 alone,
sweeping cybersecurity demands captured the attention of U.S. legislators considering legislation
in no fewer than 45 U.S. states with a significant eye toward cybersecurity, often through support
for “programs or incentives for cybersecurity training and education” (National Conference of
State Legislatures, 2022, para. 3). A number of federally sponsored initiatives encompassing
cybersecurity education have also been established; examples include the National Integrated
Cyber Education Research Center (NICERC), the CyberCorps: Scholarship for Service Program,
and the National Initiative for Cybersecurity Education (NICE) (Aggarwal & Reddie, 2018).
One of these federal initiatives, NICE, falls under the auspices of the National Institute of
Standards and Technology (NIST) and is recognized for its comprehensive framework, the NICE
Cybersecurity Workforce Framework (NCWF) (Jacob et al., 2018). The NCWF underscores,
among other values, the importance of communication, collaboration, questioning conventional
wisdom in educational practice, trying novel approaches, and engaging “stakeholders from
diverse backgrounds and with varying viewpoints” (NIST, 2022, para. 3). In the same way that
N. Ahmad et al. (2021) called for widespread participation from all stakeholders in cybersecurity
education, the NCWF—in attending to cybersecurity planning, awareness, education, training,
and workforce development (Newhouse et al., 2017; Paulsen et al., 2012)—has aimed to support
coordination across sectors involved in training, education, and the cybersecurity workforce.
Such coordination was largely hoped to be achievable through NCWF’s establishment of a
shared lexicon (Jacob et al., 2018; National Initiative for Cybersecurity Careers and Studies
[NICCS], 2022; NIST, 2022) and educators use the framework for curriculum development in a
wide number of educational settings (Jacob et al., 2018). Although some have criticized NCWF’s
failure to provide “actionable guidance” (Conklin et al., 2014, p. 2006) and “measurable
outcomes” (Jacob et al., 2018, p. 129) for educators and curriculum developers, national
cybersecurity education initiatives such as NICE—and efforts to increase coordination between
cybersecurity education and the industry writ large—can be seen as an important piece in
responding to the perceived increases and pervasiveness of threats.
Responding to a Variety of Threats. At the same time that broad, higher-level
cybersecurity education initiatives have been developed, there have also been discussions in the
literature about how to carry out effective cybersecurity education, training, and awareness
programs on the ground that are responsive to various specific types of security threats; below is
an overview of cybersecurity education as it pertains to recommendations and practices in the
contexts of technical and non-technical threats.
Cybersecurity Education and Technical Expertise. For cybersecurity education
programs geared toward preparing the future cybersecurity workforce, scholars have asserted the
need for a solid technical foundation: Crumpler and Lewis (2019) maintained that curricula
should focus on computing basics to prepare such students for “critical technical roles” (p. 9).
Siraj (in Siraj et al., 2021) unequivocally recommended that cybersecurity education for the
future workforce cover technical elements such as “programming vulnerabilities in coding
classes and how to avoid/fix them, database security concerns and fixes in database classes,
networking vulnerabilities and defense in network classes” (p. 335). For Siraj (in Siraj et al.,
2021), computing topics and security topics necessarily joined problems with solutions and
therefore neither should be broached separately in educational settings. Her view is consistent
with others such as Evans and Reeder (2010) who have contended that tasks such as creating,
detecting, and mitigating malware necessitate “deep technical skills” (p. 3) and involve
knowledge of programming and operating systems (Gorugantu, 2018). This consensus is likely
fueled by demands on security personnel to detect an ever-growing amount of increasingly
sophisticated malware, deemed by Aslan and Samet (2020) to be “a very challenging task” (p.
6250).
If technical aspects are challenging for trained cybersecurity professionals and students,
then it is even more so for non-technical end-users. In this vein, some researchers have
investigated the potential effectiveness of educational approaches designed to instruct everyday
end-users and business employees about malware threats (e.g., He et al., 2020; Moon et al.,
2020). He et al. (2020) concluded that education which successfully related malware issues to
employees’ own lives was more effective than generic training about the dangers of malware.
Moon et al. (2020) explored the utility of an educational gaming approach in training users about
malware, maintaining that end users who lack deep technical training might still be able to detect
the presence of malware in other ways, a view shared by Aviv et al. (2019). Moon et al. (2020)
and EasyDmarc (2022) submitted that several pathways might in fact exist for ordinary end-users
to detect the presence of malware—such as tracking if a device is running more slowly than
usual, noticing the redirection of a browser, experiencing anomalies when turning a device on
and off, or encountering files they don’t recognize. Moon et al. (2020) was also optimistic that
cybersecurity professionals could coach end-users to do this with a little “basic knowledge” (p.
1) and held that most cyberthreats were preventable through elementary cyber hygiene practices.
However, the idea that non-technical end-users could attain a more-than-basic level of technical
skill to sufficiently combat serious technical cyberthreats has been met with skepticism (e.g.,
Hamilton, as found in Siraj, 2021). As such, calls for providing everyday end-users with training
to combat serious technical threats have been notably absent from cybersecurity education
discussions.
The need for more people to be able to combat serious technical cyberthreats remains,
however, and is likely a driving force behind K-12 curricular efforts noted by Chen et al. (2021)
that reach beyond the development of basic cyber awareness to expose younger populations to
“higher-level cybersecurity technical skills” (p. 110). A recent example of efforts to develop
deeper technical capacities in the future cybersecurity workforce is the work of CYBER.ORG
(K-12 Cybersecurity Learning Standards, 2021). In partnering with educators and other
institutions, CYBER.ORG generated the first set of standards to be developed with an eye
toward national alignment of K-12 cybersecurity curricula (K-12 Cybersecurity Learning
Standards, 2021). A core theme of the K-12 Cybersecurity Learning Standards (K12CLS) is
computing systems (K-12 Cybersecurity Learning Standards, 2021). To develop technical
awareness and abilities in students, the K12CLS presents foundational concepts to younger
students that are then built on each year (K-12 Cybersecurity Learning Standards, 2021). The
goal is for high school students to graduate with a more targeted understanding of hardware,
software, and networks—some examples of which include experience with coding, an
understanding of risks associated with specific online protocols, and the ability to explain
components of hardware and operating systems (K-12 Cybersecurity Learning Standards, 2021).
Cybersecurity Education and Social Engineering. There is a need for cybersecurity
education to treat more than technical concerns alone (Jacob et al., 2018). Aldawood and
Skinner’s (2018) review of the literature revealed a robust consensus in the field about the need
for social engineering education and awareness-raising. Their review led them to conclude that
knowledge of social engineering was “considered … the most effective way to deal with social
engineering threats” (Aldawood & Skinner, 2018, p. 66). Yet despite this widespread belief in the
importance of social engineering education, robust opportunities at the undergraduate level for
such learning are sparse (Rege et al., 2019). Luse and Burkman (2021) held that social
engineering education was more challenging to teach than technical threats, given that social
engineering situations between students are much harder to arrange in a laboratory setting
without giving rise to ethical issues. In short, efforts to educate users about cybersecurity’s
human vulnerabilities have not kept pace with advancements in technical security measures
(Richardson et al., 2020; Tioh et al., 2019).
The lack of social engineering education has been blamed for rendering users more
vulnerable, making them easier targets in social engineering attacks, and leaving them a preferred
mode of infiltration for cyber threat actors (Mohammed & Apeh, 2016; Tioh et al., 2019).
Lamenting the tendency among businesses to focus on technological security solutions rather
than provide cybersecurity education to their employees, Ghafir et al. (2018) argued that it was
indeed necessary to “reshape the workforce into competent guardians” (p. 4991) in order to
deal adequately with social engineering threats.
However, just as the lack of social engineering education has been criticized, social
engineering programs that do exist have been criticized as well: a participant in Aldawood and
Skinner’s (2020) study cautioned that despite education and awareness being presented as “the
major solution” (p. 67326) for social engineering threats, some training could leave individuals
feeling threatened without having learned any appropriate responses. Mohammed and Apeh
(2016) criticized existing social engineering awareness education campaigns for being so overly
general that they failed to change users’ habits in a way that would sufficiently mitigate such
threats. They argued for the value of designing awareness campaigns that incorporated
differentiated instructional approaches to meet the needs of a variety of learners (Mohammed &
Apeh, 2016). Luse and Burkman (2021) were critical of scholarship exclusively focused on
awareness-raising, as it ignored the value of experiential learning in social engineering. In an
effort to move beyond awareness to experiential learning with respect to phishing threats, they
presented a hands-on, real-world, interactive approach to teaching about social engineering
threats which they argued was effective for teaching both technical and behavioral elements of
social engineering (Luse & Burkman, 2021).
Like Luse and Burkman (2021), others have also investigated various approaches to
teaching social engineering concepts. Ngambeki et al. (2021) presented a social-constructivist
approach for teaching about social engineering. They argued that in studying psychological,
legal, and computer science components of cyberattacks, familiarity with these could
subsequently be employed to identify vulnerabilities. Still others have looked to gamify social
engineering education (e.g., Jin et al., 2018; Tayouri, 2015; Tioh et al., 2019). Tioh et al. (2019)
explored the use of a game to teach non-technical end-users applicable, real-world ways to
mitigate common social engineering threats. Jin et al. (2018) found that game-based learning was
“an excellent platform” (p. 157) for high school students participating in a GenCyber camp to
learn how to deal with potential social engineering attacks. Consistent with Luse and Burkman’s
(2021) call for experiential, hands-on learning, Jin et al.’s (2018) model incorporated virtual
reality three-dimensional games. In this way, gaming approaches have attempted to respond in
part to the aforementioned difficulties associated with teaching people how to handle social
engineering threats.
Responding to a Blend of Threats. Cybersecurity responses must account for a complex
set of both human and technical factors (Malatji et al., 2019; McEvoy & Kowalski, 2019). With
this in mind, Tayouri (2015) proposed “combining education and training with best-of-breed
technology” (p. 1100) for ordinary end-users in the face of varied threats. For Tayouri (2015), an
effective two-pronged solution would include educating users about cybersecurity’s human
factors while still looking to the industry for technical solutions to complement users’ education.
Crumpler and Lewis (2019) also rejected a singular approach. Concerned with how best to
prepare aspiring cybersecurity professionals, they affirmed that “no single education program”
(Crumpler & Lewis, 2019, p. 3) could teach all the technical and soft skills demanded by
employers for combatting threats. Addressing formal cybersecurity education as well, Jacob et al.
(2018) called for a moment of reckoning between technical and human aspects, writing that
“attacks exploiting human behavior are inseparable from cybersecurity” (p. 129). In their view,
prevention, response, and defense training thus hinged “as much on the technical aspects as on
the human factors” (Jacob et al., 2018, p. 129). Jacob et al. (2018) went on to argue that
interdisciplinary cybersecurity education could unite these disparate aspects—a notion revisited
later in this chapter as it has enjoyed a great deal of currency among scholars.
Cybersecurity Education and the General Population
Low cybersecurity awareness has characterized the general populace of many countries
(Aljabri, 2021; Campean, 2019; Catota et al., 2018; Chandarman & Van Niekerk, 2017; Chang &
Coppel, 2020; Forrester et al., 2022; Nur, 2021; Sambuli et al., 2016). Education has been
proposed as an important part of increasing awareness to decrease the impact of cyberthreats
(Aldawood & Skinner, 2019; Rahman et al., 2020). Quayyum et al. (2021) understood
cybersecurity awareness as users’ knowledge of cyberthreats relating to computer and data
vulnerabilities and users’ understanding of their responsibility to take protective measures.
Quayyum et al. (2021) therefore suggested that awareness education had “two primary purposes:
alerting the internet users about cybersecurity risks and enhancing the internet users’
understanding of cybersecurity risks to be sufficiently committed to embracing security during
internet use” (p. 2).
In this vein, the U.S. Government Accountability's Office in 2009 and 2010 pointed to the
need for “publiciz[ing] and rais[ing] awareness about the seriousness of the cybersecurity
problem” (Harknett & Stever, 2011, p. 458). The National Initiative for Cybersecurity Education
(NICE) was launched shortly thereafter and was tasked, among other things, with developing
cybersecurity awareness (Harknett & Stever, 2011, p. 458). By July 2010, the Obama
administration announced a “national public awareness and education campaign” (Harknett &
Stever, 2011, p. 458). NICE’s efforts were placed under the auspices of several agencies, which
Harknett and Stever (2011) maintained contributed to a lack of clear messaging that so often
weakened the impact of public awareness campaigns. Harknett and Stever (2011) called for more
strategic coordination to facilitate pithier, more uniform messaging, which they held was one of
the keys to changing the publics’ behavior. They also warned that the efforts to engage the public
in cybersecurity would “be impossible if cyberspace continues to be conceived primarily as a
private concern rather than a public good” (Harknett & Stever, 2009, p. 10). For them, education
had an important role to play to “establish a relationship between the general public and
cybersecurity” (Harknett & Stever, 2009, p. 10).
Harknett and Stever (2009, 2011) were not alone in noting that existing public
cybersecurity awareness campaigns have often left much to be desired (e.g., Bada et al., 2019;
He et al., 2020; Jarjoui, 2023; Nagyfejeo & Von Solms, 2020). While such programs have been
viewed as necessary in terms of spreading information, they have not always been sufficient for
changing behavior (Bada et al., 2019; He et al., 2020; Rhee et al., 2005). Several factors have
been identified for why cybersecurity awareness campaigns are ineffective: information
presented in complicated, ambiguous, impersonal, irrelevant, or overly general ways may hinder
people from taking action to secure their cyber activities (Bada et al., 2019; He et al., 2020;
Richardson et al., 2020). Scholars have also cautioned against using threats or intimidation or
presenting doomsday scenarios to incite compliance (Bada et al., 2019; de Bruijn & Janssen,
2017). Such tactics are not productive (Bada et al., 2019, p. 3) and can engender feelings of
passivity, indifference, or even denial (de Bruijn & Janssen, 2017). For more effective outcomes,
cybersecurity directives should focus on clarity and relatability (Bada et al., 2019; Richardson et
al., 2020). Nevertheless, even after cybersecurity awareness education, some individuals may
simply feel that the chances that they will be victimized are so low there is no need for action
(He et al., 2020).
The Non-Cybersecurity Workforce. Recommendations for developing more effective
awareness education programs for members of the general workforce have called for more
interactive content (Aldawood & Skinner, 2019; Hewlett Packard Enterprise, 2015), cultural
responsiveness (Bada et al., 2019; Hewlett Packard Enterprise, 2015), personal relevance to both
work and home settings (He et al., 2020), and fostering cyber mindfulness in individual
employees to increase organizational resilience (Jarjoui, 2023). In addition, Anwar et al. (2017)
argued for developing gender-responsive interventions for business employees, noting that
women had consistently rated confidence in their cybersecurity abilities “significantly lower”
(Anwar et al., 2017, p. 5) than their male counterparts had rated themselves, a variable found to
impact security behaviors. While scholars have focused on how to develop more efficacious
awareness training for members of the general workforce, not everyone has endorsed security
awareness training for non-technical employees. Schneier (2013) called it “a contentious topic”
(para. 1). He held that organizational resources could “be spent better elsewhere” (Schneier,
2013, para. 1) and that focusing on training end-users only served to distract from “greater
failings in security design” (para. 1). Distraction or not, cybersecurity awareness education for
members of the public has come to be seen as an important part of cybersecurity, extending far
beyond business employees; the UK Cabinet Office released its 2011 Cybersecurity Strategy
report calling for the improvement of “cyber security education at all levels” (UK Cabinet
Office, 2011, p. 31).
The K-12 Student Population. Part of strategies to develop safe cybersecurity practices
at all levels has been to focus on youngers students. In the United States, the National Integrated
Cyber Education Research Center (NICERC) represents one such initiative to make
cybersecurity curricula accessible to students at elementary, middle and high school levels and is
“part of a broader US federal effort to reach out to all schools” (Aggarwal & Reddie, 2018, p.
298). Several arguments for introducing cybersecurity education to younger learners have been
put forth in the literature (e.g., Pencheva et al., 2020; Rahman et al., 2020; Salahdine &
Kaabouch, 2019; Seo et al., 2019; Tayouri, 2015). Training for young students has been depicted
as critical for fulfilling students’ immediate safety needs (Rahman et al., 2020; Seo et al., 2019).
Cybersecurity education for younger populations has also been framed as necessary for reducing
the number of would-be future victims (Salahdine & Kaabouch, 2019). Tayouri (2015), who was
in favor of cybersecurity being introduced as early as the first grade, appealed to a need to
protect learners’ “first steps in the cyber world” (p. 1098), but also viewed educating children as
a means to shore up cybersecurity’s human factor more broadly, an argument echoed by
Pencheva et al. (2020). Many of these ideas seem to affirm the value of empowering individuals
to better protect themselves and care for others in cyberspaces, a theme developed by Blanken-
Webb and Cloutier (2020) in their call for an ethic of care to inform “all levels of cybersecurity
education” (p. 36)—not the least of which are “the critical developmental years when young
computer enthusiasts first discover hacking techniques” (p. 36).
In addition to these considerations underscoring the particular vulnerability of the general
population’s youngest members, still even more discussions have framed K12+ cybersecurity
education as a vital component of national security (e.g., AlDaajeh et al., 2022; Blažič, 2022;
Conklin et al., 2014; Jin et al., 2018; Kessler & Ramsay, 2013). With an eye toward “enormous
economic and social consequences caused by various cyber-attacks” (Chen et al., 2021, p. 108),
governmental support for K-12 cybersecurity education has also grown in recent years in the
hopes of “build[ing] an educated and skillful workforce” (p. 108) to ease persistent workforce
shortages, discussed next.
Cybersecurity Education Efforts to Address Workforce Shortfalls
Severe shortfalls beset the cybersecurity workforce globally and in the United States
(Crumpler & Lewis, 2019; Furnell, 2021; McQuaid & Cervantes, 2019). Issues in cybersecurity
education have been presented both as reasons for—and solutions to—these shortfalls (e.g.,
Blažič, 2022; Crumpler & Lewis, 2019).
Addressing Personnel Shortages Through Education. Blair (2017) reported Intel
Corporation’s findings in 2016 that fewer than one in 10 top universities offered a cybersecurity
major or minor. The low amount of cybersecurity educational programs has been insufficient for
keeping pace with the growing number of unfilled cybersecurity jobs (e.g., Blair, 2017; McQuaid
& Cervantes, 2019). In response to this reality, places of learning “worldwide have started to …
offer cybersecurity programs to address the shortage of cybersecurity professionals” (Cabaj et
al., 2018, p. 3). As new initiatives and programs emerge, scholars have recognized the need to
learn how to optimally design cybersecurity training and education (Patnayakuni and
Patnayakuni, 2020) and to identify the core skills that such programs should emphasize when
training the future workforce (Crumpler & Lewis, 2019; Dawson & Thomson, 2018;
Patnayakuni & Patnayakuni, 2020) so as to “produce both the volume and quality of workforce”
(Patnayakuni & Patnayakuni, 2020, p. 82) necessary to fill empty cybersecurity jobs.
To this end, the US government has announced multiple education-related initiatives
aimed at growing the nation’s cybersecurity workforce, including hundreds of GenCyber summer
camps for K-12 students and teachers sponsored by the National Science Foundation
and the National Security Agency (Jin et al., 2018). Another government initiative helping to
target shortages in the workforce and create “a more robust pipeline for cyber talent” (Crumpler
& Lewis, 2019, p. 9) is the US National Centers of Academic Excellence program, which
prompts higher education cybersecurity programs to follow standards set forth by the DHS and
NSA. and DHS.
The private sector’s response has also been noteworthy. Microsoft recently announced
their goal to reduce U.S. workforce shortages in half by recruiting and training a quarter of a
million people by 2025 in partnership with U.S. community colleges (Feiner, 2021). Likewise, to
widen the “pipeline of employees” (Morgan, 2017, para. 12), IBM has pledged their support for
alternative models of education that emphasize “skills, experience and aptitudes as opposed to
traditional hiring models which focus on degrees alone” (para. 12).
While the need for more educational and training opportunities has been recognized,
McQuaid and Cervantes (2019) identified a lack of interested applicants as another problem.
This points to the need for generating greater awareness of cybersecurity as a viable career
(Baker, 2016; Kerven et al., 2017; McQuaid & Cervantes, 2019). Baker (2016) noted that despite
numerous initiatives, “the message of the opportunities within the cyber field and the importance
of the work, either hasn’t reached, or hasn’t interested, enough people to make a significant
difference in the growth of the workforce population or those pursuing it as a career path” (p.
20). Rankin and Thomas (2020) found that with respect to Black females, “most had no clear
understanding of the field of computing nor the range of career opportunities available in the
field” (p. 202) likely owing to a lack of computer science opportunities in grade school.
This dearth of awareness of cybersecurity job opportunities has been partly blamed on
introducing cybersecurity education to students too late (McQuaid & Cervantes, 2019). Morgan
(2017) reported Raytheon’s findings that two-thirds of students in high school had never had an
educator or job counselor suggest a cybersecurity career to them. Ivy et al. (2019) suggested that
training teachers across the curriculum to incorporate cybersecurity principles in their classes
was one way to “engage students early and seed a cybersecurity workforce pathway” (p. 1).
Educational Efforts to Increase Diversity. Discussions about diversity in cybersecurity
have examined a number of traits including gender, racial and ethnic identity, and background
training (e.g., J. Hall & Rao, 2020; Jethwani et al., 2017; Mountrouidou et al., 2019). Building
more diversity in cybersecurity may be crucial for several reasons; Mountrouidou et al. (2019)
surmised that adding more diverse workers to the existing workforce could ease labor shortages,
engender outside-the-box collaboration and innovation, and serve as an antidote to pitfalls
associated with ingrained biases. The need for a more diverse workforce has immediate
implications for cybersecurity education (Mountrouidou et al., 2019). Mountrouidou et al. (2019)
held that “instructors must … prepare future cybersecurity team members not only in relevant
cyber-centric skills but also in the skills essential to be productive contributors in diverse
multidisciplinary teams” (p. 158). In addition to preparing students for success in more diverse
groups, educators must also find ways to recruit, train, and retain members of more diverse
populations, discussed below.
Cybersecurity Education and Women. In investigating why women in cybersecurity are
so underrepresented, researchers have sought to identify barriers that women face to entering the
profession (Cobb, 2018; Jethwani et al., 2017; Peacock & Irons, 2017; Withanaarachchi &
Vithana, 2022). Owing possibly to misconceptions about what cybersecurity entails and the lack
of female mentors and role models, girls often start to disengage with computing topics at school
during adolescence (Jethwani et al., 2017; Peacock & Irons, 2017). In addition, girls may find a
lack support at school for pursuing cybersecurity pathways (Peacock & Irons, 2017) while
encountering curriculum and classroom practices that are “not female friendly” (Burrell &
Nobels, 2018, p. 76). Masculine stereotypes within cybersecurity may also deter females from
pursuing cybersecurity career paths (Jethwani et al., 2017; Peacock & Irons, 2017). Those
looking to recruit more women may need to contend with a number of other negative stereotypes
as well: Hansen and Nissenbaum (2009) noted Hollywood’s proclivity to stigmatize “female
cyber savvy characters … as tomboys, disabled, plus-sized, or goth” (p. 1167). In short, there is
not just one contributing factor (Withanaarachchi & Vithana, 2022) and by university, women
end up earning less than a fifth of all computer science degrees (Jethwani et al., 2017).
To address some of these barriers, cybersecurity education for girls should begin at a
younger age—and definitely before girls reach university (Jethwani et al., 2017; Peacock &
Irons, 2017). Peacock and Irons (2017) suggested that because girls develop their self-image with
respect to STEM fields at an early age, it may be important to consider reaching out to parents to
advertise the potential benefits “that computing and cybersecurity can offer to their daughters”
(p. 40).
Types of educational approaches that may be more or less appropriate for girls and
women have also been researched; Jin et al. (2018) reported that females responded less
positively than males to game-based learning approaches in cybersecurity. However, Jethwani et
al. (2017) identified a number of practices that could be attractive to girls, such as “embedding
educational practice in the contexts of real-world problems” (p. 20). In addition, Jethwani et al.
(2017) postulated that cybersecurity’s creative or artistic aspects were especially attractive to
girls. Highlighting these aspects as well as the socially collaborative, applied nature of
cybersecurity work could serve to draw more women into the field (Jethwani et al., 2017).
Finally, the stakes for cybersecurity educators to work out how to attract, train, and retain
more women may be higher than at first glance; M. Khan (2020) held that recruiting more
women was more than just an issue of improving the quantity and quality of the cybersecurity
workforce. Rather, addressing the underrepresentation of women for M. Khan (2020) was also
about women’s social and economic empowerment.
Cybersecurity Education and Minority Populations. While diversity in the cybersecurity
workforce contributes to more effective security, in an already short-handed U.S. cybersecurity
workforce, minority populations are markedly underrepresented (B. Allen, 2022; Burrell &
Nobels, 2018; Nakama & Paullet, 2018). This underrepresentation has been presented as one of
the reasons for cybersecurity personnel shortages (e.g., Nakama & Paullet, 2018; Javidi et al.,
2019). Viewing this as an opportunity for cybersecurity education, some scholars have urged
those in higher education to find innovative methods that can appeal to a more diverse body of
students (e.g., Burrell & Nobels, 2018; Mountrouidou et al., 2019).
In considering how to build innovative cybersecurity education offerings for diverse
populations, Burrell and Nobels (2018) suggested that such efforts would depend on educational
institutions partnering with government and industry stakeholders. Another pioneering approach
explored by Nakama and Paullet (2018) hinged on non-traditional recruitment strategies to bring
in students from non-technical educational areas. Nakama and Paullet (2018) found that
advertising cybersecurity college classes specifically to high schoolers not enrolled in technical
educational tracks resulted in more diverse students participating in these early college
cybersecurity opportunities. In studying rural populations in Hawaii, they noted that an online
cybersecurity class format was often the only workable solution for reaching these students
(Nakama & Paullet, 2018). Deliberate invitations and formats may be crucial, given that other
minority populations such as Black females—despite existing efforts aimed at diverse groups—
have continued to “suffer from lack of early exposure of [computer science] in grades K-12”
(Rankin & Thomas, 2020, p. 202).
Speaking to this need for more exposure, Mountrouidou et al. (2018) proposed integrating
cybersecurity educational modules into regular education courses as a way to advertise
cybersecurity’s importance and main concepts to a more diverse body of students. Mountrouidou
et al.’s (2018) focus was largely on post-secondary education, but resembles Ivy et al.’s (2019)
more general call to incorporate cybersecurity education into K-12 settings to reach a wider pool
of potential candidates. Other initiatives to develop cybersecurity educational opportunities to
target underrepresented populations at even earlier ages have been noted in the literature, such as
the hundreds of summer camps funded by the National Security Agency (NSA) and the National
Science Foundation (NSF) which aim to “increase K-12 students' interest in cybersecurity and
the diversity of cybersecurity workforce” (Jin et al., 2018, p. 69). Given Nakama and Paullet’s
(2018) declaration that there is a “tidal wave of minorities and young women in rural
communities who are interested in cybersecurity education if given the opportunity to enroll
while in high school” (p. 49), such initiatives seem apt.
Cybersecurity Education and Technification. Traditional cybersecurity education
efforts have focused on developing the cybersecurity workforce’s technical expertise (J. Hall &
Rao, 2020; Hamman & Hopkinson, 2016; Jacob et al., 2018). Hamman and Hopkinson (2016)
affirmed the field’s predominantly technical origins in computer science, and Hansen and
Nissenbaum (2009) acknowledged that much of the requisite knowledge in cybersecurity was
“daunting” (p. 1166) and in many cases inaccessible to the general population; in this context,
cybersecurity largely became associated with technical experts and, crucially, not something to
“be left to amateurs” (p. 1167). Moreover, Hansen and Nissenbaum (2009) cautioned that
technification “presuppose[s] a politically and normatively neutral agenda” (p. 1167) when in
fact there are many political and politicized aspects of cybersecurity (Cavelty & Egloff, 2019;
McCarthy, 2018; Stevens, 2018). Given these realities, technification has thus had far-reaching
consequences for cybersecurity education which scholars have bemoaned (e.g., Conklin et al.,
2014; J. Hall & Rao, 2020). By privileging technical aspects, programs may risk leaving behind
students from non-technical fields, overlooking important organizational, human, and regulatory
issues in security (Jacob et al., 2018), and missing opportunities to examine underlying
assumptions (Hansen & Nissenbaum, 2009; Jacob et al., 2018).
Developing the Human Element in Cybersecurity Education. Given that 95% of cyber
incidents are thought to be due to human factors (Gyunka & Christiana, 2017; Nobles, 2018), a
workforce that neglects important human factors in cybersecurity can fail to adequately deal with
the variety of threats. For Jacob et al. (2018), threats targeting human behavior were “inseparable
from cybersecurity” (p. 129) and cautioned that “emphasizing technical aspects within cyber
education prepares a workforce to respond to only a certain part of the problem” (p. 129). Jeong
et al. (2019) noted however that research had started to reflect scholars’ increasing recognition
“that the human side of cybersecurity poses as much of a risk as the technical aspects” (p. 338).
Attention to human factors has also been gaining momentum in information technology (IT)
circles, with more recent work expanding beyond technical considerations to include a
behavioral focus as well (Richardson et al., 2020).
While humans are routinely framed as the weakest link in security (e.g., Baker, 2016; He
et al., 2020; Richardson et al., 2020; Rohan et al., 2021; Salahdine & Kaabouch, 2019), Metcalf
et al. (2023) challenged that prevailing view, advocating for a more nuanced view that humans
could in fact be security’s strongest link. Also eschewing a deficit view of end-users, Bello and
Maurushat (2020) argued that current approaches to mitigating ransomware were suboptimal
because they overlooked humans as potential solutions to the problem; they thus proposed social
engineering education for employees as an important mitigation strategy. Acknowledging the
reality of severe personnel shortages, Haney and Lutters (2017) pushed for “mak[ing] the most of
the workforce we have” (p. 1) by training up cybersecurity professionals with not only technical
acumen but “the ability to promote best practices, educate, persuade, and serve as change agents
for cybersecurity adoption” (p. 1). Crumpler and Lewis (2019) similarly noted that although
building technical proficiency should be “the first priority” (p. 9) in cybersecurity education,
schools could not disregard “the soft skills that can turn that technical knowledge into value for
their employers” (p. 9). Despite a “lack of empirical assessment” (Taylor-Jackson et al., 2020, p.
208) of such “critical soft skills” (Crumpler & Lewis, 2019, p. 9) needed to teach cybersecurity
students, scholars agree on the need to develop collaboration, communication, and/or problem-
solving (Crumpler & Lewis, 2019; Haney & Lutters, 2017; K. Jones et al., 2018). However,
Crumpler and Lewis (2019) pointed out that cybersecurity education in the
United States has not been sufficiently preparing students in these areas. Taylor-Jackson et al.
(2020) maintained that even when cybersecurity programs acknowledge the importance of
human factors, psychological elements in cybersecurity often remain underexplored. Yet with
psychology’s focus on themes such as motivation, prediction, human-centric design, and
organizational behavior, a wealth of applicable research already exists from which cybersecurity
education might pull (Taylor-Jackson et al., 2020). Taylor-Jackson et al.’s (2020)
recommendation to integrate psychology to develop cybersecurity’s human element underscores
the significance of interdisciplinary efforts in cybersecurity education, which I review below.
Broadening the Cybersecurity Workforce Through Interdisciplinary and
Multidisciplinary Education. In addition to educating the present and future cybersecurity
workforce about more of cybersecurity’s human factors, there is also a need to educate for
“broader … vulnerabilities” (Gioe et al., 2019, p. 30) that could be easily missed by a workforce
with a primarily technical background (Jacob et al., 2018). A statement from the National
Academy of Sciences encapsulates much of the case made for broadening the focus of
cybersecurity education:
Education, training, and workforce development activities that focus too much on narrow
technical knowledge and skills may discourage participation by people with much-
needed non-technical knowledge and skills, may overly concentrate attention and
resources on building technical capability and capacity, and may discourage technically
proficient people from developing non-technical skills. The result would fall short of
delivering the workforce the nation requires. (National Research Council, 2013, p. 26, as
found in Sussman, 2020)
A survey of the literature, however, repeatedly attests to the narrow, deeply siloed nature of
cybersecurity programs (e.g., Austin, 2020; Furnell & Bishop, 2020; Jacob et al., 2018; Wagner,
2022); Jacob et al. (2018) declared that cybersecurity educational programs have been “stove
piped for decades in the education system of the nation” (p. 62). Moreover, a recent investigation
of 10 cybersecurity curriculum frameworks revealed that a majority of these favored a technical
focus (Yang, 2021). Dai (2018) blamed cybersecurity education for leaving graduates with
“microscopic perspectives” (Abstract).
To achieve a more “balanced cybersecurity workforce” (p. 124), Jacob et al. (2018)
argued that an interdisciplinary approach to cybersecurity education was key, and that it would be
critical to address cybersecurity education’s “technological sovereignty” (p. 125). The view that
effective cybersecurity education involves interdisciplinary efforts has been espoused by many
others as well (e.g., Abraham & Shih, 2015; Austin, 2020; Blair et al., 2019; Craigen et al., 2014;
Ivy et al., 2019; Jacob et al., 2019; Jeong et al., 2019; Kessler & Ramsay, 2013;
Mountrouidou et al., 2019; Payne et al., 2021; Scheponik et al., 2016; Sharevski et al., 2018;
Suryotrisongko & Musashi, 2019; Sussman, 2020). Austin (2020) pithily summed it up as “the
essential interdisciplinarity of cyber security education” (p. 1).
There are numerous examples of researchers proposing and/or implementing
interdisciplinary approaches for cybersecurity education (e.g., Ivy et al., 2019; Jacob et al., 2018;
Payne et al., 2021; Taylor-Jackson et al., 2020). These conceptions have varied in scale: Payne et
al. (2021) presented an account of the authors’ experiences designing and implementing a single
course, whereas Jacob et al.’s (2018) “Multi-discipline, Multi-level, Multi-thread model” (p. 67)
represented a four-year opportunity for students “to explore technical and non-technical content
… by integrating disciplinary and interdisciplinary electives at different levels” (p. 67).
TaylorJackson et al. (2020) considered how to effectively incorporate principles from the
discipline of psychology into cybersecurity education.
While the above examples represent more recent scholarship, Sharevski et al. (2018)
pointed out that cybersecurity interdisciplinary approaches have been around for a while, and that
the task at hand should rather be to enhance the scope of these efforts. For Jacob et al.
(2018), increasing the scope of cybersecurity education meant including “political, ethical,
social, cultural, religious, and economic perspectives” (p. 125). However, Sharevski et al. (2018)
was critical of approaches limited to traditional interdisciplinary choices, maintaining that these
fixed choices still cut students off from yet other domains and hindered adequate
experimentation. In thinking outside the box, Sharevski et al. (2018) sought to reimagine how
interdisciplinarity might promote more experiential learning as well; their novel approach to
broaden the cybersecurity workforce is arguably in step with Austin’s (2020) call to more
fundamentally “reorient thinking” (p. 1) about building human capital more broadly in
cybersecurity, something which he saw as necessitating “a redesign of education” (p. 2).
Interdisciplinary discussions have affirmed the continued importance of technical
education in cybersecurity (e.g., Crumpler & Lewis, 2019; Jacob et al., 2018) while also arguing
for the equally essential role that non-technical disciplines play (Jacob et al., 2018). However, in
advocating for the introduction of “a global perspective through interdisciplinary studies and
employing ‘cross pollination’ of disciplines” (p. 125) to “clos[e] the gap between ‘technically
focused’ cybersecurity and the non-traditional backgrounds” (p. 125), Jacob et al. (2018)
affirmed that it is not just a balance of technical and non-technical skills in the workforce that is
needed, but a way for each to understand the other.
Cybersecurity Education in the Context of a Future Marked by Change and Ambiguity
Dawson and Thomson (2018) speculated that it was conceivable that even within three
months, trained security professionals could find their training outdated. Blažič (2022) echoed
this sentiment, writing that rapid advancements brought about by new technology meant that
requisite cybersecurity skills in highly technical areas were particularly fast-changing. Scholars
have explored and imagined different ways of addressing the field’s certain change and lack of
certainty, discussed below.
Calls for Continuous Learning. To keep pace with new technologies and the evolving
security threats and solutions they pose, continuous learning is critical (Dawson & Thomson,
2018; Knapp et al., 2017; LeClair et al., 2013; Udroiu & Vevera, 2018). This need for continual
education and training applies not only to cybersecurity professionals, but to ordinary technology
users as well (He et al., 2020; Sherman & Arampatzis, 2018). He et al. (2020) highlighted the
notion of “people patching” (Rayome, 2017, as cited in He et al., 2020, p. 6), arguing for the
need to perennially “update employees with the latest security vulnerabilities” (p. 6).
Calls for Preparing Current Cybersecurity Students for Future Changes. Petre et al.
(2021) recognized the difficulties that the need for continuous learning spelled for cybersecurity
education programs in particular when preparing future cybersecurity professionals. They raised
the question of whether training should focus on the “industry standard tools and applications”
(Petre et al., 2021, p. 20) of the field or “underlying principles, on the assumption that they will
generalize to a variety of tools, and on the assumption that tools will change in any case?” (p.
20). To this point, Crumpler and Lewis (2019) were fairly unequivocal in their call to equip
cybersecurity students with fundamental knowledge. For Crumpler and Lewis (2019), both
hands-on experience and mastery of fundamentals in computing and information security
fundamentals were key to graduates’ adaptability in the future in the face of evolving technology
and threats. Others who have joined in the call for equipping students with industry-specific core
knowledge and skills have stressed that such an education should be implemented so as to
support graduates’ future capacities to update their skillsets throughout their lives (Blažič, 2022,
p. 3028; Patnayakuni & Patnayakuni, 2020). Blažič (2022) added to this the importance of
transferable learning for future settings. In this way, multiple scholars have affirmed a
relationship between mastering domain knowledge and being able to adapt in the future, in line
with McMorrow’s (2010) observation that effective cybersecurity demands both “a deep
understanding of underlying principles, and close contact with developing issues” (p. 13).
Calls to Attend to Security’s Enduring Aspects. Conklin et al.’s (2014) view that
“security, by its very nature, requires a deep understanding not just of the technology, but of
security principles” (p. 2007) affirms the importance of attending to security’s enduring aspects.
Moreover, Hamman and Hopkinson (2016) contended that despite decades of rapid change and
emerging technology, what had not changed were the underlying adversarial tactics of
cybercrime. In this vein, cybersecurity practitioners interviewed by K. Jones et al. (2018)
expressed the view that:
it was important for undergraduates interested in cyber to gain strong computer science
fundamentals and understanding of security methodologies. They characterized this
knowledge as being consistent across time whereas the other [knowledge, skills, and
abilities] were characterized as changing so often that a successful cyber personnel must
stay relevant through constant research and self-study. (p. 10)
In the context of a cybersecurity landscape marked by change and ambiguity, scholars have
sought to leverage underlying, enduring aspects of security in calling for more flexible, abstract,
or foundational security thinking in people (e.g., Dark, 2015; Esteves et al., 2017;
Pournaghshband, 2013; Schneider, 2013).
Pointing out that new threats continually arise, Schneider (2013) held that students who
could only defend against familiar attacks would be at a disadvantage; the antidote he proposed
was adversarial thinking. For Schneider (2013), the call to develop more general adversarial
thinking didn’t mean that finding “specific technical solutions” (p. 3) to a particular attack
scenario was any less important, but that it was equally vital for cybersecurity students to be able
to think more abstractly in order to generalize from known scenarios to future ones. Dark (2015)
urged cybersecurity educators to consider how students fundamentally reasoned about
cybersecurity as a way to develop more effective curricula to promote security mindsets. She
viewed this as a critical aspect of students’ capacity to deal with “complex and emergent
behaviors” (Dark, 2015, p. 61).
In addition to cybersecurity students, there have been calls to develop other students’
security thinking (Pournaghshband, 2013; Young & Krishnamurthi, 2021). Young and
Krishnamurthi (2021) noted that while security mindsets were viewed as “a critical attribute” (p.
213) in cybersecurity, students in other fields including computer science were generally not
being taught security basics (Crumpler & Lewis, 2019; Young & Krishnamurthi, 2021).
Pournaghshband (2013) argued that it was nevertheless “essential” (p. 348) to develop security
mindsets in computer science students’ earlier rather than later so that thinking about security
would ultimately become natural to them when they were programming later on.
Some have suggested the need for developing this kind of thinking even more broadly.
Esteves et al. (2017) urged those in the corporate workforce to “understand both hackers’ tactics
and their mindsets” (p. 71) to better fight cyberthreats. Others have considered developing
security mindsets in “the larger public of Internet users” (Dutton, 2017, p. 7) to enhance
cybersecurity efforts overall (Dutton, 2017; Dutton et al., 2019).
In this way, voices from the scholarly literature and beyond have sounded the call for
cybersecurity education to attend to security fundamentals as a way to face difficult, novel, and
ambiguous security challenges (e.g., Dark, 2015; Dutton, 2017; Severance, 2016; Siraj et al.,
2021; Young & Krishnamurthi, 2021). In the next section, I develop various fundamental aspects
associated with security mindsets.
Security Mindsets
For the purposes of this research, security mindsets are defined as an ingrained habit of
investigating and identifying how things (including people, systems, and processes) can fail.
Used here interchangeably with security thinking, security mindsets can be said to engage
components of situational awareness and adversarial thinking, with these components informed
by domain-specific knowledge and skills.
Through its evolution in the literature, the concept of a security mindset has been
presented in various ways (Schoenmakers et al., 2023), and what security mindsets attend to may
also vary in scope (Dutton, 2017). Multiple possibilities for referring to security mindsets exist as
well (Peterson, 2021; Young & Krishnamurthi, 2021). For example, integral aspects of security
mindsets have surfaced under the guise of cybersecurity critical thinking (California Academic
Press, 2021), cybersecurity situational awareness (Padilla-Pagan Payano, 2018), attacker
mindsets (Carpenter, 2021), and adversarial thinking (Hamman & Hopkinson, 2016; Katz, 2019;
Young & Krishnamurthi, 2021). While security mindsets entail something broader than
adversarial thinking alone, these terms have sometimes been used interchangeably in popular
usage.
When describing security mindsets, Schneier (2008) presented them in terms of
imagining how things might fail or be exploited. Similarly, Severance (2016) equated security
mindsets with attempting “to understand the unexpected directions from which attacks might
come” (p. 8). Katz (2019) suggested that security mindsets meant “anticipat[ing] the strategic
actions of others” (p. 15). Nassiokas (2021b) described “a heightened security mindset” (para. 3)
as “noticing anomalies or ‘things that don’t fit’ in a specific scenario or context” (para. 3).
Esteves et al. (2017) identified the need for having “open and adaptive” (p. 72) mindsets to
understand the explorative and exploitative aspects of hackers’ mindsets; Severance (2016) and
Vigna (2019) joined in a similar call for security experts to “think like a hacker” (Vigna, 2019,
para. 3). Schneier’s (2008) rationale for adopting a security mindset captures much of the
conversation on security thinking when writing that:
Good engineering involves thinking about how things can be made to work; the security
mindset involves thinking about how things can be made to fail. It involves thinking like
an attacker, an adversary or a criminal. You don’t have to exploit the vulnerabilities you
find, but if you don’t see the world that way, you’ll never notice most security problems.
(para. 6)
Though not in disagreement with understanding security mindsets as thinking like a hacker,
Hamman and Hopkinson (2016) suggested that this was still too imprecise for educators to create
meaningful cybersecurity curricula. They proposed instead that security thinking be viewed as
“the ability to approach system rules, operational spaces, and player actions from a hacker’s
perspective” (Hamman & Hopkinson, 2016, p. 4). Developing this further, Hamman and
Hopkinson (2016) drew on Sternberg’s (1988) Theory of Triarchic Intelligence (TTI) to identify
analytical, creative, and practical components of adversarial thinking. Below, I present this
framework and examine its application to security thinking.
A Framework for Security Thinking: TTI
Sternberg’s (1988) TTI is a cognitive-contextual theory, similar to Gardner’s (1983)
wellknown theory of multiple intelligences (Dahal, 2007). As such, both TTI and the Theory of
Multiple Intelligences are concerned with how cognition works in various situations (Dahal,
2007). However, whereas Gardner (1983) conceived of multiple discrete intelligences, Sternberg
(1988) saw intelligence as a single notion—albeit comprised of multiple parts that dealt with a
person’s internal experience, external experience, and the negotiation between the two (Dahal,
2007). In this way, TTI recognizes that cognitive processes are not independent of the diverse
settings in which they function (Dahal, 2007; M. K. Gardner, 2011). TTI’s independent aspects
deal with “(1) the mechanics of intelligence; (2) the continuum of experience; and (3) the fit of
an individual to the environment” (M. K. Gardner, 2011, p. 91). These three elements can be
linked to analytical, creative, and practical aspects of intelligence (Chisholm et al., 2009;
Hamman & Hopkinson, 2016; Sternberg, 2002), of which Hamman and Hopkinson (2016)
crafted a user-friendly description (Table 1).
Table 1
Triarchic Theory of Intelligence
Area Description Popular Conception Exemplar
Analytical Mathematical ability and logical reasoning Book smarts Einstein
Creative The ability to make unique connections and
see the world in original ways Creativity Van Gogh
Practical The ability to plan, strategize, and
accomplish goals Street smarts Napoleon
Note. Adapted from "Teaching Adversarial Thinking for Cybersecurity," by S. T. Hamman and
K. M. Hopkinson, 2016, Journal of The Colloquium for Information Systems Security Education,
4(1), p. 6.
Critics have cited a lack of empirical research in support of TTI’s claim that these aspects
of intelligence are in fact uncorrelated with one another in an individual (Gottfredson, 2003;
McDaniel & Whetzel, 2003). In their criticism of TTI, Gottfredson and Saklofske (2009)
bemoaned the “confusion or misunderstanding” (Abstract) over measuring and assessing
intelligence. Whereas TTI had not yet been sufficiently defended by empirical research, there
was on the other hand ample support for the predictive power of a single general intelligence
factor, g (Gottfredson, 2003). Despite criticism of Sternberg’s theory among intelligence
theorists, TTI has value for its potential for practical application in educational settings
(Davidson, 2009). While acknowledging on-going debates over the nature of intelligence, it is
still possible to extract a useful organizational tool from TTI when considering a variety of
potential capacities in the classroom. It is in this vein that Hamman and Hopkinson (2016)
applied Sternberg’s (1988) general theory of intelligence to cybersecurity adversarial thinking for
the benefit of educators.
Based on TTI’s analytical, creative, and practical intelligence components, Hamman and
Hopkinson (2016) developed a three-part definition of security thinking as “the ability to embody
the technological capabilities, the unconventional perspectives, and the strategic reasoning of
hackers” (p. 11). They elaborated that:
The word embody used in the definition is intended to capture the sense in which actors
embody the characters they play. It connotes “becoming one” with hackers and seeing the
world through their eyes. To the extent that cybersecurity students can acquire this
ability, in their future careers they will be able to identify the digital fingerprints of
hackers in their systems and compete with them on a level playing field (the analytical
component), identify and fix security vulnerabilities before hackers have the opportunity
to exploit them (the creative component), and anticipate future attacks, thwart attacks in
progress, and help track down hackers (the practical component). (Hamman &
Hopkinson, 2016, p. 11).29
Hamman and Hopkinson’s (2016) cybersecurity-specific conception of TTI is shown in Table 2.
Table 2
Triarchic Theory of Intelligence Applied to Adversarial Thinking
Area Adversarial Thinking Application Example Attack Summary
Analytical
Understanding technology at a deep
level, including computer
networking protocols, programming
languages, and
operating systems
Buffer Overflow30 Technological
capabilities
Creative
Identifying unsafe security
assumptions through manipulating
and stretching technology in
unexpected ways
IP Fragmentation31 Unconventional
perspectives
Practical
Reasoning strategically to plan and
execute attacks, evade detection,
and overcome obstacles
Social Engineering Strategic reasoning
Note. Adapted from "Teaching Adversarial Thinking for Cybersecurity," by S. T. Hamman and
K. M. Hopkinson, 2016, Journal of The Colloquium for Information Systems Security Education,
29 Hamman and Hopkinson (2016) held that “While not all areas are strictly necessary, a hacker without analytical
intelligence (i.e., technical expertise) is a nonstarter, one lacking creative intelligence never discovers novel
vulnerabilities and is fully dependent on recycled, and likely widely known, hacks, and one without practical
intelligence has little chance of successfully evading detection or of overcoming unexpected hurdles” (p. 11). 30 A
buffer refers to “an area of memory allocated with a fixed size … commonly used as a temporary holding zone”
(Foster et al., 2005, p. 13) for data. A buffer overflow happens “when a buffer … has more data copied to it than it
can handle” (Foster et al., 2005, p. 18), resulting in systems crashing and potential intrusion attempts.
31 IP fragmentation involves when packets of information about network identification and location are broken “into
smaller chunks, known as fragments, so that they can be transmitted over a network” (Walsh, 2023, para. 5) that
limits the size of a packet able to be sent. Fragments are then “transmitted across the network and reassembled at their
destination to reconstruct the original packet” (para. 5). This process can be exploited several ways, resulting in a
slower or crashed system (Walsh, 2023).
4(1), p. 12.
In their treatment of these aspects of adversarial thinking, Hamman and Hopkinson
(2016) also assumed an awareness on the part of hackers of their “operational spaces” (p. 4).
While this situational awareness was not specifically developed by Hamman and Hopkinson
(2016) within their TTI adversarial thinking framework, this attention and responsiveness to
setting is critical. Further attesting to the importance of setting was Hamman and Hopkinson’s
recognition of the limitations of treating analytical, creative, and practical aspects separately and
abstractly; they sought to address this with the inclusion of a “real-world example” (p. 10) to
illustrate these aspects of intelligence working together. Thus, in attending to operational spaces
and in situating these aspects in a real context, I argue that Hamman and Hopkinson (2016)
affirmed the importance of cyber threat actors’ situational thinking. Answering to the call for
“future work [to] build on this research by potentially expanding the definition to include other
aspects of a hacker’s mind” (Hamman & Hopkinson, 2016) p. 17), I propose including such
attention and responsiveness to operational spaces—i.e., situational awareness—as an additional
category in the conceptual framework that will ultimately be guiding my own study. This is also
in line with views held by those in the cybersecurity community that security mindsets
encompass more than adversarial thinking alone (e.g., Stajano, 2023a).
TTI and Situational Awareness. Foundational to security thinking are aspects of
situational awareness. For one risk management company, situational awareness was maybe “the
most obvious element of the security mindset” (Polaris Corporate Risk Management, n.d., para.
5) and “the foundation of a strong security mindset” (para. 5). Situational awareness encapsulates
a process of perceiving, comprehending, and projecting (Endsley, 1995). In this process, external
information is merged with internal “knowledge and goals, which in turn informs the projected
status of the world” (Stanton et al., 2001, p. 6). Conceptions of situational awareness (e.g.,
Endsley, 1995; Horneman, 2019; Stanton et al., 2001) can serve to enrich understandings of how
adversarial thinking components work together in response to diverse operational spaces.
Endsley (1995) identified perception, comprehension, and projection as three successive levels of
situational awareness. Endsley’s (1995) model (Figure 2) assumes increasing awareness on the
part of an actor, with basic input being processed in progressively sophisticated ways (see
Stanton et al., 2001).
Figure 2
Endsley’s (1995) Model of Situation Awareness in dynamic decision making
Note. Adapted from “Toward a Theory of Situation Awareness in Dynamic Systems,” by M. R.
Endsley, 1995, Human Factors, 37(1), p. 5.
Just as Hamman and Hopkinson (2016) sought to reimagine TTI for cybersecurity,
Horneman (2019), too, aimed to render Endsley’s (1995) framework more practical for
cyberspaces. Horneman (2019) summarized it as “1. Know what should be. 2. Track what is. 3.
Infer when should be and is do not match. 4. Do something about the differences” (para. 9). By
viewing security thinking capabilities through this lens, a dynamic big picture emerges wherein
understanding depends on weighing outside information against “knowledge and goals, which in
turn informs the projected status of the world” (Stanton et al., 2001, p. 6). Situational thinking
impels analytical, creative, and practical aspects of intelligence to be rooted in a context, forcing
it out of the abstract and into the applied; its inclusion in a security mindset framework describes
the catalytic mechanism by which components of adversarial thinking are set into motion,
together, in real-world operational spaces which—as Dark and Mirkovic (2015, in Hamman &
Hopkinson, 2016) pointed out—can be “material, cyber, social, and physical” (p. 4).
This understanding offers a useful and complimentary perspective to Hamman and
Hopkinson’s (2016) more specific application of TTI, which was within the narrower context of
adversarial thinking. However, robust security mindsets encompass more than adversarial
thinking (Stajano, 2023a). Drawing on elements of situational thinking resulted in a more
comprehensive conceptual framework for the study, able to capture additional aspects of security
thinking as opposed to those associated with the adversarial thinking parts of security mindsets
alone.
A Conceptual Framework for This Study. On its own, Hamman and Hopkinson’s
(2016) work already offers a valuable tool for understanding various fundamental components of
security thinking. Its components comprised the bulk of this study’s conceptual framework,
helping to align theory and inquiry throughout data collection and analysis. However, in drawing
on aspects of situational awareness as well, a useful schema emerged of not only specific
capacities but of the interplay between them and their relationship to experience and domain
knowledge (Figure 3). These elements work together to protect the penultimate concerns of
security that make up the security triad: confidentiality, integrity, and availability.
Figure 3
Foundational elements of security mindsets
Note: This conception draws on the work of Endsley (1995), Hamman and Hopkinson (2016),
Horneman (2019), and Sternberg (1988). A similar version is found in Kuiken (2023).
This blended framework served as a guide for examining content in language textbooks,
as I sought to identify if and how analytical, creative, and practical capacities, and situational
awareness were invoked during students’ engagement with textbook explanations and activities.
My investigation was undertaken with an eye toward enriching educational efforts, just as
Hamman and Hopkinson’s (2016) objective was to build a framework that could support
educational goals—a further point of alignment between their work and my own inquiry.
However, the scholarship attests to a rich debate over how—or even if—security mindsets can be
developed through educational efforts. I review this debate below.
Teaching Security Mindsets
Dark (2015) wrote that “when cybersecurity educators talk about what graduates need to
know, the answer is often summarized in two words: security mindset” (p. 61). Severance (2016)
pointed out, however, that the present difficulty with this was the absence of any “‘principles of
the security mindset’ section in a textbook that we can all learn and then apply” (p. 8). Moreover,
some scholars have questioned whether security mindsets can even be taught (Dark, 2015;
Schneier, 2008; Siraj et al., 2021). Hamilton (as found in Siraj, 2021) felt that the possibility of
developing a security mindset in general populations was doubtful. Schneier (2008) speculated
that teaching security mindsets was potentially far more difficult than teaching domain-related
knowledge, questioning “how much of this is innate, and how much is teachable” (para. 7). Dark
(2015) also questioned if it were possible to teach students how to identify and handle
ambiguous, complex, and dynamic situations in traditional instructional settings. Stajano (2023b)
viewed it as “perhaps impossible to teach this mindset” (30:40).
On the other hand, Dark (2015) argued, this kind of thinking could still be fostered in
cybersecurity students, which could be achieved by reimagining schools as places of experiential
learning. Hamman and Hopkinson’s (2016) assessment was also nuanced with respect to whether
or not security thinking could be taught. They postulated that aspects of adversarial thinking
could be developed in learners by first identifying these aspects and then tying them to specific
outcomes for the benefit of cybersecurity educators (Hamman & Hopkinson, 2016). While they
similarly questioned if unconventional thinking could be developed (or simply identified) in
students, they maintained that at least students’ strategic reasoning could indeed be improved
through instruction (Hamman & Hopkinson, 2016).
Others have expressed even more optimism at the possibility of fostering security
thinking through intentional educational experiences: Servin et al. (2020) reported finding an
effective way to develop learners’ security thinking through an adversarial teaching approach,
while Srivatanakul and Moore (2021) proposed various “hands-on” (Abstract) activities that they
suggested would support security mindsets in computer science undergraduates. Kaza (as found
in Siraj et al., 2021), who also championed the possibility of teaching security mindsets, called
for “a deliberate effort,” (p. 2) urging for currently-taught topics to be supplemented with
security-related resources.35 Juurvee and Arnold’s (2021) account of successful efforts in Estonia
to develop a sweeping culture of security thinking—far beyond scientists and engineers—further
supports the case for deliberate efforts.
The suggestion that deliberate teaching is needed to support the development of students’
security mindsets also aligns with Wegrzecka-Kowalewski’s (2018) research on teaching critical
thinking skills. As security thinking has been viewed by some in the industry as a specific kind of
critical thinking (Pherson, n.d; Techstrong Group, 2018), Wegrzecka-Kowalewski’s (2018)
research may be particularly germane to this debate. She asserted that:
The prerequisite to successful critical thinking instruction is that it must be explicit.
Halpern (1983), among other scholars, argues that critical thinking skills need to be
taught explicitly because critical thinking skills cannot be expected to develop as a
byproduct of content courses. … The context of real-life applications while learning
critical thinking skills has also been found beneficial not only for the development of
critical thinking skills but also for future transfer. (Wegrzecka-Kowalewski, 2018, pp. 26
- 28)
This conception of explicit teaching is perhaps both challenged and enriched by Severance’s
(2016) view that a security mindset “takes a long time to develop, and draws from many diverse
areas of study, [such that] students can think of their entire education as preparation for a career
in security” (Severance, 2016, p. 8). Arguably, these two views are not mutually exclusive, and
fostering a security mindset involves both implicit and explicit learning.
Chapter Summary
In reviewing the landscape of cybersecurity, important challenges emerged. These
included severe cybersecurity personnel shortages in the face of increasing vulnerabilities, the
variety of threats and their complex socio-technical nature, the general populace’s attitudes and
behaviors, a lack of diversity in the cybersecurity workforce, and insufficient attention to
nontechnical factors amidst an ever-evolving cybersecurity landscape.
Cybersecurity education now faces the task of responding to and keeping pace with these
thorny and pervasive challenges. I reviewed criticisms of traditional approaches and
recommendations for new approaches, including multidisciplinary efforts, attracting more
diverse populations, and calls to develop more enduring, fundamental aspects of security such as
security mindsets. I presented a conceptual framework for my inquiry based on Hamman and
Hopkinson’s
(2016) cognitive-conceptual model of adversarial thinking and notions of situational awareness
(see Endsley, 1995; Horneman, 2019). Although a review of the literature unveiled a robust
debate over whether this kind of thinking could be taught or fostered, it also affirmed the need
for greater development of people’s security thinking—in both cybersecurity students and in the
general populace—as well as the need to attract more students to cybersecurity and involve more
disciplines in doing so. In line with these concerns noted above, I now turn to the discipline of
L2 learning. In Chapter III, I provide an overview of L2 learning as a means to bridge broader
issues in L2 education with cybersecurity education. In Chapter IV, I evaluate more specifically
the theoretical possibility for leveraging L2 learning to engage L2 learners with security mindset
fundamentals.
Chapter III. Review of L2 Learning Literature
In this chapter, I review real-world and theoretical aspects of L2 instruction and learning
in an effort to survey some of the historical, practical, and foundational themes likely to shape
any future endeavors to bring security concepts to bear in L2 learning settings through L2
learning content. In particular, I examine trends in the field of L2 learning, including U.S. public
school enrollment figures, key ideas, common practices, and recommendations.
L2 Terminology
Disciplines pertaining to L2 acquisition, learning, and instruction are replete with
specialized terms and acronyms. As these fields have progressed, some of this vocabulary has
been deemed problematic or imprecise (e.g., Jaschik, 2011; Webster & Lu, 2012). New terms
have been introduced which have replaced or subsequently coexisted alongside others. Given
that multiple terms may refer to similar or overlapping concepts, a review of the L2 learning
literature necessitates at least some familiarity with this variation. Terms reflecting current trends
in the field of L2 learning are presented below.
Second Language
The term second language (or L2) itself has been subject to a dynamic discussion over
terminology (Kuiken, 2020). Taking issue with the word second, critics maintain that such
terminology glosses over the fact that students may already speak or be learning more than one
other language (e.g., Gass & Selinker, 2008; Webster & Lu, 2012). Some have preferred other
terms such as target language (TL) learning, which refers to the study of any language hoping to
be learned (Kuiken, 2020). Similarly, Webster and Lu (2012) proposed the incorporation of the
phrase additional languages (AL) into the lexicon as a way to be more inclusive, presenting
English as an Additional Language (EAL) and French as an Additional Language (FAL) as
examples. What is generally agreed upon is that the process of learning one’s first language is
different than for subsequent languages, to the extent that “many researchers … account for them
with totally separate theories” (MacWhinney, 2005, p. 2).
Foreign Language
Another case of terminological variation in the field of SLA surrounds the term Foreign
Language (FL) (Kuiken, 2020). In the United States where English is most widely spoken, FL
has commonly been used to refer to other language subjects such as French and Spanish.
However, as some in the field have moved away from the term foreign, citing its potentially
divisive connotation, these subjects have come to be categorized in other ways (Jaschik, 2011).
While I refer to FL in this work, additional terms that are now in use include international
languages (Jaschik, 2011) and world languages (Kuiken, 2020). Adding to the complexity, the
term second language (L2) has often also been used interchangeably with FL, although
sociolinguists and pedagogues maintain a distinction between L2 (the lingua franca where one
lives that differs from one’s native language) and FL (a language not widely spoken where one
lives) (Hasa, 2018).
Second Language Acquisition
Further muddying the waters, the field of Second Language Acquisition (SLA) does
pertain to issues in both FL learning and L2 learning, in affirmation of the fact that the same
essential processes underpin learners’ acquisition of both (Ellis, 2010). Based on this
understanding, and in an effort to connect this discourse to the field of SLA and its applied
subfield of Instructed Second Language Acquisition (ISLA), I have opted to retain the use of the
term second language (L2) in the phrase L2 learning or L2 teaching, for example, when referring
broadly to the study of any non-native languages, while acknowledging that in other scholarly
works, L2 by itself is often contrasted with FL.
English Learning
While English as a Second Language, or ESL, has been a familiar way for many to
denote the study of English by non-native speakers in the United States, other acronyms for
English learning have gained currency as well. Some of these include EAL (English as an
Additional Language), ESOL (English for Speakers of Other Languages) and ELL (English
Language Learning) (Schaefer & Warhol, 2020; Webster & Lu, 2012). Often the choice depends
on the instructional context; in countries outside the United States, EFL (English as a Foreign
Language) is widely employed (e.g., Burgos & Molina, 2020; Ja'ashan, 2020; Natsir & Sanjaya,
2014; Xiuwen & Razali, 2021). ELL is perhaps the most common way of denoting “learning
English as a new language for academic purposes” (Webster & Lu, 2012, p. 89). For this reason,
I have chosen to employ the term ELL, although it should be noted that the term ESL is still also
commonly used in the United States. Choice of term notwithstanding, Gunderson (2021) raised
an important point that labels such ESL and ELL risk constructing “unidimensional” (p. 436)
categories that fail to convey the diversity within student populations. However, as my inquiry is
not ultimately concerned with the variation that characterizes L2 learning populations—but
rather with fundamental underlying processes shared by them—such terminology is appropriate
given the bounds of this investigation.
Reconciling Terminology
As evidenced above, ELL and FL programs in the United States often have distinct
terminology; this reflects a practical disconnect which has left scholarship on language education
in the United States typically to treat either ELL or FL, with little synthesis of the two (Kuiken,
2020). In introducing the landscape of K12+ L2 learning here, I thus initially refer to FL and
ELL separately. Linguistically speaking, however, such differences in terminology and practice
obscure fundamental commonalities between ELL and FL learning, given that both FL and ELL
students are faced with the same fundamental task of learning another language (Kuiken, 2020).
As it is this fundamental task that is most relevant to my inquiry, I subsequently group FL
learning and ELL together in later discussions about the potential of L2 learning for practicing
security thinking. Thus, unless otherwise specified, I employ the term L2 learning when referring
to them both.
The Landscape of U.S. K12+ L2 Instruction and Learning
While ELL and FL programs in the United States have often been the focus of two
separate discussions in the literature, in their implementation they have also been characterized
by disparate resources, staff, training, materials, classrooms, and student populations (Kuiken,
2020). This practical disconnect between ESOL and FL disciplines are highlighted in historical
overviews of the two fields; at the same time, discussions about methodology expose significant
pedagogical overlap. The following is an overview of FL and ELL instruction and learning with a
focus on the United States.
Historical Overview of FL Study
In places where English is already predominantly spoken, the position that “Language is
fundamental to what it means to be human” (Lawes, 2018, p. 122) and can broaden “peoples’
horizons and to break down barriers between people” (p. 122) has routinely underpinned
arguments for the study of FL. In addition to appeals to one’s humanity, other more specific
arguments for FL study have been made. Of particular relevance to this inquiry are scholarly
claims that L2 learning can positively impact learners’ capacity for analysis (J. Jiang et al.,
2016), creativity (Galante, 2020; Piccardo, 2017; Skutnabb-Kangas, 2002), and critical thinking
(Liang & Fung, 2021). The list goes on; Gallagher-Brett (2004) produced a sweeping
compilation of “more than 700 reasons to study languages” (p. 2) based on research conducted
by the UK Subject Centre for Languages as part of campaign in the United Kingdom and
European Union to “encourage more people to learn languages in and out of school” (p. 2).
Such widespread support for FL learning has not always been the case in the United
States. In the early 1920s, public FL instruction was outlawed in 34 US states (Hartmaier, 2021).
FL study came briefly to the fore in public schools in the aftermath of World War II (Hartmaier,
2021). However, English usage was so prevalent at the time that many Americans came to regard
FL learning as “unnecessary” (Hartmaier, 2021, p. 52). This attitude would begin to change
during the Cold War as a result of growing competition between the United States and the Soviet
Union (García et al., 2019; Hartmaier, 2021). Hartmaier (2021) noted that “for the first time in
decades, Americans perceived multilingualism as a valuable skill” (p. 52).
Given the relationship between societal attitudes and language education policies
(Hartmaier, 2021), it was perhaps only a matter of time before the U.S. Government enacted
legislation to support FL instruction. In 1958, the National Defense Education Act (Public Law
85-864) guaranteed support to states and local school districts for “modern foreign languages,
and other critical subjects” (de Brey et al., 2021, p. 413). The reversal of the trajectory of FL
instruction in the United States cannot be understated; compared to the 1920s when it was
banned in public schools in over half the country, by the end of the 1990s non-English instruction
was offered by all public school districts, with 40 U.S. states also mandating that a minimum of
two years of FL be made available to learners (Hartmaier, 2021). All other states had
requirements in place for students going to college to study at least one other language
(Hartmaier, 2021).
Following the height of Cold War, FL study continued to be popular (Hartmaier, 2021),
although any arguments for multilingualism seemed to be increasingly tied to specific languages,
particularly with respect to a language’s perceived economic competitiveness (see C. Mitchell,
2017). As people turned their attention toward the United States’ biggest economic competitors,
interest in certain languages such as Japanese arose (Hartmaier, 2021). Following the September
11, 2001 attacks on the World Trade Center, arguments for FL instruction in strategic areas would
continue to hinge on strategic issues, particularly those related to national security
(Hartmaier, 2021). Klein and Rice’s (2014) views in a report titled US Education Reform and
National Security encapsulate this:
Americans’ failure to learn strategic languages, coupled with a lack of formal instruction
about the history and cultures of the rest of the world, limits U.S. citizens’ global
awareness, cross-cultural competence, and ability to assess situations and respond
appropriately in an increasingly interconnected world. … However, the opportunity to
learn [strategic languages] and about the people who speak them should be available to
many students across the United States, and all students should have access to high-
quality foreign language programs starting in the earliest grades. (p. 47) From this, it
is possible to draw parallels between national security justifications for cybersecurity
education (e.g., Kessler & Ramsay, 2013) and such strategic arguments noted above for FL
education. Yet, while cybersecurity education has witnessed an increase in programs (Dark &
Mirkovic, 2015), the overall number of FL programs has been declining (Johnson, 2019;
Looney & Lusin, 2019). I review these current trends impacting FL programs next.
Trends in FL Programs and Enrollment
When one talks about FL today, it is generally in reference to:
A group of instructional programs that describes the structure and use of language that is
common or indigenous to people of a given community or nation, geographical area, or
set of cultural traditions. Programs cover such features as sound, literature, syntax,
phonology, semantics, sentences, prose, and verse, as well as the development of skills
and attitudes used in communicating and evaluating thoughts and feelings through oral
and written language. (de Brey et al., 2021, p. 580)
The most recent National K-12 Foreign Language Enrollment Survey Report (American
Councils for International Education [ACIE], 2017) reported that almost 20% of K12 learners (or
10,638,282 students) in the U.S. educational system were enrolled in a FL program in 2017. That
figure is much higher for the percentage of students who have had some form of high school FL
study by the time they graduate (de Brey et al., 2021), whether it be a single semester of
beginning German or four years of advanced-placement track Spanish. However, while such
figures represent a sizeable chunk of the U.S. student populace, the overall number of higher
education FL programs has declined in recent years (Johnson, 2019). The Modern Language
Association’s (MLA) Enrollments in Languages Other Than English in United States Institutions
of Higher Education, Summer 2016 and Fall 2016: Final Report revealed that between 2013 and
2016, more than 650 FL programs disappeared in higher education (Looney & Lusin, 2019).
As this “astounding news” (Hamilton & Nevadomski Berdan, 2019, para 1) failed to draw much
attention in the media, Hamilton and Nevadomski Berdan (2019) labeled declining FL
enrollment a “quiet crisis” (para 1). They (Hamilton & Nevadomski Berdan, 2019) were not
alone when they framed the lack of FL programs and dwindling enrollment as a threat to national
security (e.g., Ben-Ghiat, 2019; Flaherty, 2018; Johnson, 2019; Stein-Smith, 2019, 2020;
Sterniak, 2008). Citing waning enrollment and a larger trend of the disappearance of teacher
preparation programs in general (García et al., 2019), the literature has also documented a
“critical” (Kissau, 2020, p. 11) shortage of FL teachers in the United States (see Sutcher et al.,
2016). As a result, schools are increasingly managing the reality of limited staffing through
technological solutions such as virtual courses (ACIE, 2017). Most recently, the latest MLA
census affirmed that this trend has continued, revealing a 16.6% drop in higher education FL
enrollments from 2016 and 2021 (MLA, 2023; see Figure 4).
These trends notwithstanding, K12 FL enrollment in the United is still widespread (see
ACIE, 2017). Moreover, certain languages have been growing in popularity and even seen the
creation and expansion of their programs; interest in Standard Chinese, for example, has soared
in recent years (Zheng & Zheng, 2020) while enrollment in Korean language courses grew by
38.3% from 2016 to 2021 (MLA, 2023). At present, Spanish continues to enjoy the highest FL
enrollment figures in the United States at both the K12 (ACIE, 2017) and in higher education
(Johnson, 2019; MLA, 2023).
Figure 4
Fall language enrollments in higher education by year
Note. Reproduced from the MLA press release “New MLA Report Highlights the Need for
Investment in Language Study; US Colleges and Universities With Robust support for
Languages Maintain Strong Programs Despite Overall Decline in Language Enrollments,” by
MLA, 2023, p. 2.
The American Councils for International Education’s (ACIE) 2017 report found that the
number of high school Spanish FL programs was trailed by French, German, Latin, Standard
Chinese, ASL, Japanese, Arabic, Russian, Greek, Korean, Portuguese, Azeri, Turkish, and Hindi
(see Table 3). In addition, lesson-commonly taught (LCT) languages such as a number of Native
American languages, Persian, Filipino, Vietnamese, Hebrew, Polish, and Swahili have also been
offered at the K12 level (ACIE, 2017). In higher education as of 2016, the list of FLs with the most
students enrolled showed a similar mix (see Table 3): Spanish, followed by French, ASL,
German, Japanese, Italian, Standard Chinese, Arabic, Latin, Russian, Korean, Ancient Greek,
Portuguese, Biblical Hebrew, and Modern Hebrew (Looney & Lusin, 2019).
Table 3
FL ranking in High School and Higher Education in the United States
Rank 2017 High School FL programs
ranked by total number of programs
(ACIE, 2017)
2016 Higher Education Enrollment in
FL ranked by total student enrollment
(Looney & Lusin, 2019)
1 Spanish Spanish
2 French French
3 German ASL
4 Latin German
5 Chinese Japanese
6 ASL Italian
7 Japanese Standard Chinese
8 Arabic Arabic
9 Russian Latin
10 Greek Russian
11 Korean Korean
12 Portuguese Ancient Greek
13 Azeri Portuguese
14 Turkish Biblical Hebrew
15 Hindi Modern Hebrew
Hartmaier (2021) suggested that shifting attitudes about globalization as a result of the COVID19
pandemic may once again impact FL policy and usage; how this will shape future FL programs
and enrollment remains to be seen. One thing that can be said now, however, is that the L2
learning landscape in the United States at large is comprised of a panoply of both commonly and
less-commonly taught languages, and attest to a vast pedagogical infrastructure already in place.
Key Ideas in FL
There are a set of core ideas which underpin the teaching of many of these languages in
both K12 and higher education (see Abbott & Phillips, 2011). In 1996, the American Council on
the Teaching of Foreign Languages (ACTFL) introduced the “Five C’s”—a set of concepts for
language-learning published by the National Standards in Foreign Language Education Project—
intended to serve as a guide for language learning settings (Lear & Abbott, 2008). The Five C’s
refer to Communication, Cultures, Connections, Comparisons, and Communities (Table 4).
Table 4
Description of Five C’s Goal Areas
Goal Area Description
Communication Communicate effectively in more than one language in order
to function in a variety of situations and for multiple
purposes
Cultures Interact with cultural competence and understanding
Connections Connect with other disciplines and acquire information and diverse
perspectives in order to use the language to function in academic and
career-related situations
Comparisons Develop insight into the nature of language and culture in order to interact
with cultural competence
Communities Communicate and interact with cultural competence in order to participate
in multilingual communities at home and around the world
Note. Adapted from “World-readiness Standards for Learning Languages,” by American Council
on the Teaching of Foreign Languages (ACTFL), n.d., p. 1.
They describe overarching goals that can be applied to any language and level in question,
including languages such as French, ASL, and classical languages such as Latin or Greek
(American Council on the Teaching of Foreign Languages [ACTFL], n.d.). These standards have
been found to be influential at all levels of K12+ language learning and their “integrated
nature … has been accepted by the profession” (Abbott & Phillips, 2011, p. 2). The Five C’s
have been explicitly adopted by most U.S. States (Abbott & Phillips, 2011, p. 7). In addition,
Discovering French Today! French 1 (Valette & Valette, 2013) is one example of a published
textbook that has incorporated the Five C’s as a guiding framework. Any attention to the
introduction and development of security mindset fundamentals in FL learning settings can
therefore likely be expected to coexist with such well-established goal areas.
While the Five C’s have enjoyed widespread acceptance by L2 instructors, other ideas
have been central to debates within the field as well, such as whether to focus more on literature
or communication (Frantz, 1996). Such debates have influenced FL teaching methods and
instructional trends (e.g., Babaee & Yahya, 2014), examined in the next subsection.
Teaching Methods in FL
Richards and Rodgers (2014) observed that teaching “is usually based on an analysis of
the nature of the subject itself” (p. viii). Out of this analysis may stem “a set of core teaching and
learning principles together with a body of classroom practices” (p. viii) also known as an
approach or method. It can be said that the four “pillars” (Shamsiddinovna, 2022, p. 84) of FL
are reading, writing, listening, and speaking. Since the 1900s, various L2 teaching methods have
evolved in dynamic fashion to address, each to varying degrees, these skills (Richards &
Rodgers, 2014). Today’s FL (and ELL) instructors can thus select from “various teaching
methods or approaches … to meet the particular needs of learners, the condition of the school
and the educational setting” (Fauziati, 2009, p. iii).
Some well-known L2 teaching methods include the Grammar-Translation Method
(GTM), Communicative Language Teaching (CLT), Task-based language teaching (TBLT),
Content and Language Integrated Learning (CLIL), Cooperative Language Learning (CLL), The
Direct Method, Audiolingualism, Total Physical Response (TPR), The Silent Way, and The Natural
approach (G. Hall, 2016; Sanako, 2022). Ciftcioglu (2022) pointed out that:
Although the history of foreign language education has been influenced by many ideas
and theories, in general, it can be said that there have always been two approaches to
teaching. One is the practical, direct, or inductive approach, and the other is the
analytical, descriptive, and utilitarian approach. (para. 10)
In many ways, GTM has encapsulated much of the former and CLT much of the latter. I present
these two methods below before briefly considering their pedagogical implications in the context
of fostering learners’ security mindsets.
GTM. GTM is also called the Traditional Method (As’ari et al., 2021). A centuries-old L2
teaching method, GTM “was simply applied, with few exceptions, as a model for modern
language instruction” (Abbott, 2013, p. 4) from the end of the 1800s into the 1960s when
alternative approaches gained more significant traction. GTM focuses on teaching students the
grammar and vocabulary of the TL; the main objective is for students to be able to translate
between their own language(s) and the TL, largely through reading and writing (Kong, 2011;
Natsir & Sanjaya, 2014). GTM’s emphasis is on systems and procedures, with rules and
meanings presented explicitly (Kong, 2011; Natsir & Sanjaya, 2014; Shamsiddinovna, 2022).
Students are typically expected to memorize this information and apply it to their translation
efforts (Kong, 2011; Natsir & Sanjaya, 2014; Shamsiddinovna, 2022). Although GTM has
become less popular in U.S. K12+ FL classrooms, the method is still used by many instructors of
classical languages such as Latin and Greek. As an example, Latin teachers might present
students with sentences such as Agricola est in agro. At some point prior, students would have
been given the meaning of the vocabulary and the structure and significance of inflected forms.
The students’ task is then to translate such a sentence into their own language by applying this
prior information deductively, engaging their analytical knowledge of the L2 system. GTM
arguably provides students with an opportunity to consider the mechanics of linguistic systems—
with procedural knowledge being a cornerstone of GTM (see Swan, 1985; Thamarana, 2015).
CLT. CLT (also called the Communicative Approach) relies on a communicative
approach to L2 learning (Thamarana, 2015). As Swan (1985) put it, in CLT, “it is meanings
rather than structures which are given priority” (p. 78). Critics of one of CLT’s predecessors,
GTM, asserted that the traditional emphasis on procedural knowledge seemed to come at the
expense of students’ practical communication skills in the TL (Swan, 1985; Thamarana, 2015).
Supporters of CLT argued that L2 teachers needed to “go beyond teaching grammatical rules”
(Thamarana, 2015, p. 64) to engage students with the TL in more meaningful ways; this could be
done not by treating language as a purely academic affair but by relating language to real-world
situations. Common ways of doing this in CLT have included role-playing, interviewing, sharing
opinions, working in groups, and quests involving the seeking out of missing information (R.
Mitchell, 1988), testifying to a shift in CLT noted by Thornbury (2011) “from a concern for what
language is (and the way it is represented in the mind) to a concern for what language does (and
the way it operates in the world)” (p. 188). Hall (2016) highlighted CLT’s focus on
“communicative competence” (p. 10), citing Hymes’ (1972) pithy understanding of the concept
as knowing “when to speak, when not, and … what to talk about with whom, when, where and in
what manner” (p. 10).
In the early 2000s, CLT’s ideas were applied around the globe and CLT was considered
the predominant L2 teaching method (G. Hall, 2016). Research findings related to the content of
teaching methodology courses in FL teacher preparation programs showed that by 2011, CLT
was covered in 94% of surveyed methods courses (Abbott & Phillips, 2011). In keeping with L2
teaching’s historically continuous development, however, scholars have more recently asked how
a popular approach such as CLT might be implemented to consider the “constraints and needs of
particular contexts and cultures of learning” (Richards & Rodgers, 2014, as cited in G.
Hall, 2016, p. 12) given the “more localized” (p. 12) nature of L2 instruction today. Fueled in
part by this desire for more adaptability, basic ideas from CLT have contributed to the
development of other related methods (G. Hall, 2016).
Combining Methods: GTM and CLT. While GTM and CLT have represented two
different approaches in L2 teaching, Swan (1985) questioned if these two approaches, often
pitted against each other, really needed to be at odds. He argued that “Language courses involve
far too many components, and the relationships between the components are far too complex, for
us to be able to subordinate everything to a tidy progression of structures, functions, notions, or
anything else” (Swan, 1985, p. 79). Indeed, there have been persuasive arguments for combining
aspects of CLT with GTM (e.g., Kong, 2011; Natsir & Sanjaya, 2014). Spada (2007) suggested
“that a balance needs to be struck within CLT—one that allows for the integration of more direct
instruction of language (including grammatical, lexical, and socio-pragmatic features) with
communicative skills” (Abstract).
Such views have also been shared by designers and practitioners. Mikhail (2020) noted
that Azar, an author of a popular ELL textbook (Basic English Grammar Fourth Edition by Azar
and Hagen [2014]) and proponent of Grammar-Based Instruction (GBI), favored the integration
of communicative tasks with grammatical structures. Shamsiddinovna (2022) reported that in the
case of teaching English as a FL, “Most teachers of modern universities prefer these two
methods, and they are often used in combination” (p. 83). This combination is important to note,
as it points to how L2 pedagogy can attend to both analytical and practical aspects of language,
at the expense of neither. For example, L2 learning activities consistent with GTM could provide
learners with robust opportunities for analysis (see Bers, 2019) while CLT activities could help
students engage their practical skills in real-world situations (Thamarana, 2015; Thornbury,
2011). Here, it becomes possible to identify potentially important overlaps between some of the
fundamental concerns of cybersecurity education and those of FL education, such as the interplay
between technical knowledge and practical experience.
L2 Teaching Methods and Computing Fundamentals. While general computing skills
do not equate to cybersecurity, their important overlap invites consideration (see Yue, 2016).
Bers’ (2019) treatment of “coding as another language” (title), or CAL, suggests further potential
for compatibility between teaching certain computing fundamentals and teaching language.
Building on the idea that coding could be compared to natural language, Bers (2019) considered
a pedagogical approach for teaching students to code. While Bers (2019) omitted any explicit
mention of GTM or CLT, her account and criticisms of how coding has been taught would seem
to echo the trajectory and debate in L2 teaching. In particular, Bers (2019) was critical of how
STEM teaching methodologies often approached challenges “in a sequenced order of increased
complexity” (p. 503). This was problematic because it “reduc[ed] the potential of learning how
to code to a problem-solving activity” (Bers, 2019, p. 503) and overlooked programming’s
“expressiveness and communicative functions” (p. 503). Bers (2019) explained that: The CAL
approach … leverages the teaching of literacy by broadening the range of languages children
are exposed to, including programming languages. Just like with natural languages, learning
how to program involves learning how to use a symbolic system, its syntax and grammar, to
express and communicate ideas. (p. 524)
Similar to how Azar conceived of grammar as a foundation for “communicative activities”
(Mikhail, 2020, p. 7) in order to “give learners the chance to creatively utilize target forms” (p.
7), Bers (2019), too, suggested that procedural aspects, though not to be ignored, were ultimately
in service of expression and communication.
Bers (2019) is not alone in noting how language-teaching pedagogy might inform
computing pedagogy (see Baldwin & Macredie, 1999; Robertson & Lee, 1995). Robertson and
Lee’s (1995) work also posited a relationship between human language and programming skills
while Baldwin and Macredie (1999) held that L2 learning strategies could “provide useful
insights” (p. 167) for teaching students how to program.
While most of the discussion here on L2 teaching methods can be applied to both FL and
ELL, I turn now to ELL’s unique position in the landscape of U.S. K12+ L2 instruction and
learning.
Historical Overview of ELL Study
Malakoff and Hakuta (1990) reported that “In the United States, bilingual education was
not uncommon in the eighteenth and nineteenth centuries. Linguistic pluralism and diversity
were acknowledged and tolerated, if not always encouraged” (p. 28). In the nineteenth and
twentieth centuries, however, the advent of English-only laws which had banned public FL
instruction in a majority of U.S. states also profoundly shaped the education of ELL students
(Malakoff & Hakuta, 1990). Because instruction in languages other than English was disallowed,
students who spoke little to no English found themselves in a “sink or swim” situation (Malakoff
& Hakuta, 1990; Stein, 1985).
The 1960s represented a turning point for ELL in the United States when it became clear
that “sink or swim” environments were not effective for educating the nation’s non-
Englishspeaking children (Malakoff & Hakuta, 1990). This change in perspective vis-à-vis
language education has been linked to the impact of the Civil Rights movement (Malakoff &
Hakuta, 1990). Out of this came legislation such as Title III of the 1965 Elementary and
Secondary Education Act (ESEA), which provides support for language instruction programs so
that ELL students acquire English (Ruiz et al., 2011).
While Title III represented a significant step toward targeted language education for ELL
students in the United States, five years after ESEA was passed, a compliance review initiated
under Title IV (in Malakoff & Hakuna, 1990) found that numerous ELL learners were still being
denied “equality of educational opportunity” (p. 33). Less than five years after that, the U.S.
Supreme Court ruled in 1974 Lau v. Nichols, a case involving the language education of
thousands of Chinese-speaking students, that “providing non-English-speaking students with
textbooks, teachers, and a curriculum does not constitute an equal opportunity for education”
(Ruiz et al., 2011, p. 24). The ruling paved the way for more legislation in support of bilingual
education (Malakoff & Hakuta, 1990). The topic, however, remained contentious (Malakoff &
Hakuta, 1990). Since then, the debate over ELL has continued to play out in various times and
places, perhaps one of the most notable ways being California Proposition 227 and Proposition
58. Proposition 227 was passed in 1998 and mandated that schools in California provide
Englishonly instruction to ELL students, yet less than two decades later in 2016 most of it was
repealed by California Proposition 58 which once again permitted languages other than English
to be used in public education instructional settings (California Proposition 58, 2016).
The Office for Civil Rights (OCR), the agency responsible for enforcing Title VI, “does
not require or advocate a particular program of instruction for ELL students and nothing in
federal law requires one form of instruction over another” (U.S. Department of Education, 2020,
para. 4). Thus, educators are faced with a rather open-ended federal mandate to ensure that
efforts to educate their ELL students are “(1) based on a sound educational theory; (2) adequately
supported so that the program has a realistic chance of success; and (3) periodically evaluated
and revised, if necessary” (U.S. Department of Education, 2020, para. 4).
Trends in ELL Programs and Enrollment
Various kinds of ELL programs have therefore developed over time (Malakoff & Hakuta,
1990). Malakoff and Hakuta (1990) cited half a dozen bilingual education models “which are
best seen as prototypes within which considerable variation and combination can occur” (p. 38).
These archetypal approaches to educating ELL students when Malakoff and Hakuta (1990) were
writing over three decades ago were “(1) transitional bilingual education, (2) maintenance
bilingual education, (3) submersion model, (4) English as a second language, (5) U.S. immersion
or sheltered English, and (6) the immersion model” (p. 38). Scholarship continues to reflect the
relevance of these categories (e.g., Acosta et al., 2019; Honigsfeld, 2009; Umansky & Reardon,
2014). More recently, based on a survey of ELL policies in 50 states, Rafa et al. (2020) found
that English as a Second Language, Sheltered English/Structured English Immersion,
Bilingual/Bilingual-Bicultural, and Dual language immersion/two-way bilingual approaches to
be the most common approaches to ELL instruction in the United States today (Table 5).
Table 5
ELL Approaches and Their Descriptions
Name of Approach Description
English as a Second
Language
Academic content is taught in English in mainstream classrooms, and
students receive ESL instruction to develop English language skills.
Sheltered
English/Structured
English Immersion
Academic content is taught only in English and in EL-only classrooms.
Instruction is adjusted to students’ English proficiency levels.
Bilingual/
BilingualBicultural
English learners receive academic instruction in English and a second
language, eventually transitioning to English instruction only with a
goal of moving to a mainstream classroom. Transitional bilingual
programs complete these transitions rapidly.
Dual language
immersion/two-way
bilingual
Students are taught academic content in two languages with a goal of
developing proficiency in both languages. Some programs include
both
English learners and English-only students”
Note: Adapted from “50-State Comparison: English Learner Policies,” by A. Rafa, B. Erwin, E.
Brixey, M. McCann, and Z. Perez Jr., 2020, Education Commission of the States, para. 1. Rafa
et al. (2020) reported that while researchers have not always agreed over the effectiveness of
various approaches, there was a consensus that ELL students were more successful with
“some type of English language instruction” (para. 1). An ongoing and important debate for ELL
educators involves the question of whether L2 instruction should occur “through separate
coursework or whether content areas … should infuse this content into already existing
disciplines” (Hallman & Meineke, 2016, p. 69).
These debates impact a sizeable population of learners; the number of children in ELL
programs in the United States is estimated to be more than 10% or around 5 million students (de
Brey et al., 2021) and growing (United States Department of Education, n.d.). Since the year
2000, the U.S. educational system has gained over 1,000,000 new ELL students, who today
comprise nearly 10% of the total K-12 public school population in the United States (U.S.
Department of Education, n.d.). In the wake of immigration and resettlement trends, U.S. school
districts have on average seen their ELL student populations of refugees, migrants, asylum
seekers, and others increase by as much as 60% in recent years, in contrast with 7% growth of
the general student population (Grantmakers for Education, 2013). In 2020, U.S. President-elect
Biden pledged to increase the annual number of refugees admitted to the country once again
(White, 2020). Ortiz and Woika (2017) reported that the U.S. Department of Education
“projected that by the year 2030, 40% of the school population will speak English as a second
language” (para. 3); many of these students will be enrolled as ELL students in some capacity. Of
these ELL students, most are born in the United States and enter the U.S. educational system as
American citizens (Hallman & Meineke, 2016; Sanchez, 2017), yet they will likely not attain the
same educational outcomes as their fellow citizens (Hallman & Meineke, 2016). This reality
shapes many of the key issues in ELL, discussed below.
Key Issues Shaping ELL
The consensus among researchers has been that countless English language learners have
been chronically underserved in U.S. schools (Matza, 2016; Previti, 2017; Walker, 2016; Zinth,
2013), with long-term ELL students often facing uniquely severe challenges (Artigliere, 2019).
Scholars have long taken on the task of investigating critical issues surrounding ELL to draw
attention to these educational problems (e.g., Auerbach & Burgess, 1985; Ferlazzo, 2021; Zehr,
2010). Anyon’s (1980) seminal research detailed the profound influence that hidden curriculum
could have on students’ concepts of authority, work, and social status. She argued that implicit
messages about the kind of post-graduation jobs students were destined for varied according to
social class; educators for example emphasized “docility and obedience” (Anyon, 1980, p. 67)
for students in working class communities while “initiative and personal assertiveness” (p. 67)
were valued for students of “the managerial classes” (p. 67). Anyon’s (1980) ideas have been
perennially influential for critical ELL scholars, including seminal scholarship by Auerbach and
Burgess (1985). Building on Anyon’s (1980) view that neutrality of curriculum was a myth,
Auerbach and Burgess (1985) examined how materials specifically designed for ELL settings
mirrored versus shaped learners’ realities. Auerbach and Burgess (1985) acknowledged that both
formal and hidden aspects of curriculum could impact the educational experiences and
trajectories of ELL students in different ways than the general student population. In examining
explicit and implicit curriculum lessons in popular ELL textbooks, they argued that a curricular
focus on problem-solving reinforced hierarchies and rendered students “subservient” (Auerbach
& Burgess, 1985, p. 475). They urged teachers to move away from the increasingly popular
social-efficiency ELL curriculum to find a more empowering curriculum (Auerbach & Burgess,
1985). In addition, they recommended teachers reflect on aspects of the hidden curriculum, such
as how ELL texts present reality, make assumptions about social roles, and support creative
participation and critical thinking (Auerbach & Burgess, 1985).
Picking up the torch of promoting students’ “critical competence” (p. 3), McBain (2011)
called for opportunities “at the level of the classroom to observe, imitate and practice critical
agency and to reflect upon it” (p. 3). Motivated to understand what instructional strategies might
improve critical thinking in ELL students, McBain (2011) investigated higher order thinking
skills (HOTS) of students in an English bilingual high school program. Although McBain (2011)
was in Thailand and not the United States, his work nevertheless serves to show how bilingual
education can be effective. He found that the most successful ELL students demonstrated a
capacity for “logical thinking and reasoning including skills such as comparison, classification,
sequencing, cause/effect, patterning, webbing, analogies, deductive and inductive reasoning,
forecasting, planning, hypothesizing, and critiquing” (McBain, 2011, p. 2). Stressing the
importance of improving such skills, McBain (2011) suggested that lower-achieving ELL
students could benefit from instructors helping them grasp “a wider understanding of the
grammar, vocabulary and syntax” (p. 7) and pointed to a body of research affirming the
importance of reading in fostering such critical thinking skills. For McBain (2011), it was vital
that students learn in settings “in which they can develop a feeling of social responsibility” (p. 3).
McBain (2011) was not alone in recommending a more critical approach; support for
critical awareness has been repeated by others (e.g., Hayik, 2016; Sayedayn, 2019). While
scholars have reimagined ELL pedagogy to respond to these key issues, Camps (2016) looked
beyond curriculum to the policy shaping ELL programs and instruction. She argued that the
wording itself of U.S. language education policy made self-sufficiency, rather than
selfdetermination, the goal of ELL efforts which has subsequently shaped ELL educational
experiences (Camps, 2016).
Teaching Methods in ELL
Just as ELL curriculum has been the subject of debate, so have teaching methods; ELL
teachers face a “profusion of competing methods” (Allwright & Hanks, 2009, p. 38) that have
arisen over time. Hall (2016) noted that:
there is no ‘definitive list’ of methods across the methodological literature of [English
language teaching] as a whole. This absence could, according to one’s perspective, be the
result of a fast-moving and ever-changing field; a lack of agreement and theoretical
consistency about method and methods … or quite simply, the practical constraints of
word and page limit facing any author! (p. 5)
Although debates over effective ELL instruction have been influenced by critical pedagogy in
ways that FL instruction historically has not (Kuiken, 2020), both FL and ELL overlap in their
use of myriad L2 teaching methods. These include CLT and GT methods, as previously presented
in this chapter. Nevertheless, the balance between grammar and communication may vary
slightly between ELL and FL settings as a result of these populations’ differing preferences
(Mikhail, 2020). For example, Loewen et al. (2009, in Mikhail, 2020) found ELL students “were
less convinced about the need for grammar instruction and error correction and were more
enthusiastic about improving communicative skills than were foreign language learners” (p. 17),
leading Mikhail (2020) to suggest that “context, past language experience, and the target
language itself” (p. 17) impacts student attitudes about grammar instruction. Yet, despite this
variation and the fact that ELL and FL programs are often subject to different policies and
treated as separate endeavors (Bale, 2014; Kuiken, 2020), the same fundamental tasks
characterize ELL and FL.
Chapter Summary
In this chapter, I presented some overarching realities of L2 education such as large and
diverse student populations, existing infrastructure, key ideas, and common teaching methods
that might be significant to cybersecurity educational efforts. I began with a historical and
methodological overview of FL and ELL study, mindful of the need to take various elements into
account when incorporating principles from other disciplines into cybersecurity learning (see
Taylor-Jackson et al., 2020). In paying particular attention to social context and practice, this
review served to underscore an arguably compatible and perhaps complementary relationship
between cybersecurity education and L2 education in the United States with respect to these
disciplines’ broader goals and pedagogical aims. In the next chapter, I turn specifically to the
fundamental tasks and topics that characterize L2 learning. I survey the literature to consider
how, from a theoretical point of view, such foundational aspects of language might lend
themselves to broaching security mindset fundamentals in L2 learning contexts to support
cybersecurity educational aims.
Chapter IV: Synthesis Between Security Mindsets and Language
In what follows, I examine the idea that content and processes in K12+ language learning
classrooms may be particularly well-suited to meet the challenge of introducing students to
foundational elements of security thinking. Through a synthesis of literature pertaining both to
security thinking and language/L2 learning, I investigate, from a theoretical standpoint, the claim
that L2 learning could potentially be used to support opportunities for engaging students with
security mindset fundamentals. In doing so, I lay the groundwork for my subsequent qualitative
content analysis (QCA) of existing L2 learning material.
Exploiting Features of Language
At a foundational level, one kind of way that L2 settings could invoke security mindset
fundamentals hinges on characteristics associated with human language itself; languages are
rulegoverned (Bhandari, 2020), creative (Adger, 2019), practical (Charlow, 2022), and situated
(Inbar et al., 2001). These characteristics correspond neatly to the basic conceptual elements of
adversarial thinking (see Hamman & Hopkinson, 2016) and situational awareness. Of course,
learners can attend to analytical, creative, practical, and situational ideas without any thought to
security thinking (as current anecdotal evidence in L2 classrooms suggests). As such, I do not
intend to make the case that simply by learning another language, students develop explicit
awareness of security thinking and concepts. Rather, my aim in this section is to examine the
theoretical possibility for links to be made between security mindset themes and L2 learning
themes which might then be exploited to support learners’ engagement with security mindset
fundamentals. While it is conceivable that such engagement could serve to foster greater
sensitivity in learners toward the kinds of analytic, creative, practical, and situational
discernment
required of security thinking, it would be the task of subsequent research to determine what the
impact of such engagement might be. Below, I present fundamental characteristics of language
and consider how they might relate to analytical, creative, practical, and situational aspects of
security thinking. I also consider potential points of connection between features of language and
basic domain knowledge and concepts in cybersecurity.
Connections With Analytical Capacities
Human languages can be described as rule-governed and protocol-rich systems made up
of phonetic/phonological, morphological, syntactic, semantic, and pragmatic subsystems
(O’Grady et al., 1997). While these systems can be subjected to intense analysis, speakers may
not be consciously aware of this structure at all when learning their native tongues. On the other
hand, L2 learners are often working more slowly and deliberately than they would in their native
languages (Grant et al., 2023) and are presented with a second chance to consider language’s
fundamental features (Krashen, 1981). For example, L2 materials often highlight different
subsystems of language with sections dedicated to explaining and practicing pronunciation,
grammar and vocabulary, and social contexts. Whether students are explicitly taught—or merely
exposed to—these subsystems in L2 settings, engagement with them requires interacting with
rules and systems in some capacity (Snow & Hoefnagel-Höhle, 1975). Such aspects of L2
learning may or may not foster greater sensitivity toward the kind of analytic discernment
required of security thinking, but it is possible that one might at least find in-roads here for
introducing students to analytical capabilities more deliberately—perhaps alerting students to
analytical processes while drawing out explicit connections with security thinking.
To have a more informed sense of how analytical aspects of L2 learning might align with
those in security thinking, I reviewed the literature for more detailed insights into analytical
themes germane to cybersecurity fundamentals. Table 6 presents examples from the literature of
various aspects of analytical security thinking. Such examples, though not exhaustive, lend
greater precision to efforts to identify potential links between L2 learning and security mindsets.
Table 6
Various Aspects Associated With Analytical Thinking in Security Mindsets55
Aspect Associated With
Analytical Thinking in
Security Mindsets
Examples From the Literature
Interaction with systems,
rules, and protocols
• Interaction with systems, rules, and/or protocols (Hamman &
Hopkinson, 2016)
• Pulling things apart, e.g., dissecting protocols56 (Hamman &
Hopkinson, 2016)
Attention to patterns and
outliers • Opportunity to identify differences in predicted patterns of
behavior (Nassiokas, 2021b)
• Opportunity to spot components “that don’t fit” (Nassiokas,
2021b, para. 3)
• “Identifying faults, defects” (Buckley et al., 2018, p. 451)
Disambiguation57
• Exposure to ambiguity/opportunity to deal with ambiguity
(Dark, 2015)
• Disambiguation of “unstructured data” (Sheldon, 2023, para. 9)
• “Decontextualize meanings” (Sternberg, 2002, p. 26)
• “Use context clues” (Sternberg, 2002, p. 25)
55 Analytical, creative, and practical aspects of security thinking were frequently broached by security scholars
offering recommendations for how to foster such capabilities.
56 Dissection with respect to network security refers to “the action of dissecting the network’s protocols and
studying and analyzing them” (GeeksforGeeks, 2023, para. 4).
57 When writing about L2 learning in his development of TTI, Sternberg (2002) explained that disambiguation
involved “decontextualize[ing] meanings” (p. 26) and “us[ing] context clues” (p. 25). Though Sternberg (2002) was
not writing specifically about security thinking, this furthers an understanding of what disambiguation entails and
subsequently informed my investigation.
Connections With Creative Capacities
If analytical thinking involves understanding, implementing, and troubleshooting rules in
a system, then creative thinking means a facility for playing with these rules (Hamman &
Hopkinson, 2016). It may be relevant, therefore, that language is a creative system steeped in
novelty with respect to combining words and rules (R. Jones & Richards, 2015; O’Grady et al.,
1997, Ricœur, 1973; see also Maniam, 2004). I therefore submit that L2 learners face the
possibility of moving beyond predictable, academic, or formulaic responses to imagine
unorthodox outcomes with the tools at their disposal. L2 learning could in theory be a vehicle for
experimenting with elements such as sounds, words, phrases, and gestures to be combined in
previously unmodelled or unprescribed ways and to great effect. Word choice (Lakoff, 2014) or
accents (X. Jiang et al., 2020) could be experimented with to alter the impact that messages have
on listeners’ attitudes and behaviors—underscoring a relationship between creativity and
strategic action.
The question central to my efforts here remains: “Might these possibilities for creativity
relate to security thinking?” To compare and contrast aspects of creativity in L2 learning with
creativity in security thinking, I reviewed the literature for examples associated with creativity in
cybersecurity contexts. Table 7 presents some foundational aspects of creativity germane to
cybersecurity thinking.
Table 7
Various Aspects Associated With Creativity in Security Mindsets
Aspect Associated With
Creativity in Security Mindsets Examples From the Literature
Interaction with novel and
unconventional perspectives
• Opportunity to imagine unorthodox responses (Hamman &
Hopkinson, 2016)
• Making “unique connections and see the world in original
ways” (Hamman & Hopkinson, 2016, p. 6)
Interaction with hacks/hacking • “Identify[ing] ways to alter the … operational space” (Dark
& Mirkovic, 2015, p. 78).
• Opportunity to “think about how to exploit and subvert
[system rules]” (Dark & Mirkovic, 2015, p. 78)
• Identifying things that could be exploited by bad actors
(Hamman & Hopkinson, 2016)
Innovation and
experimentation
• “Put[ting] old information together in a new way”
(Sternberg, as found in Hamman & Hopkinson, 2016,
p. 8)
• Exposure to creativity/innovation (Craigen et al.,
2014) • “Think[ing] outside the box” (Schneier as found in
Severance, 2016, p. 8), particularly when faced with
the improbability of success if playing strictly by the
rules
Opportunity for open-ended
challenges
• Exposure “to open-ended challenges” (Severance, 2016, p.
8)
Connections With Practical Capacities
Language production is practical whenever it has “a direct bearing on what we want and
plan to do” (Charlow, 2011, p. 1). For example, speakers employ practical aspects of language
when giving commands or making judgments (Charlow, 2011). Both L2 and native speakers can
endeavor to impact elements of their real-world environment through speech acts such as
greetings, commands, exclamations, questions—employing topic choice, usage, pronunciation,
and formality protocols to achieve a specific outcome. Language comprehension may be linked
to practical knowledge and capacities as well. In everyday communication, speaker anticipation
plays a role in listening comprehension (Huettig, 2015); prediction has also been found to
support perception and comprehension in bilingual speakers (Foucart et al., 2014).
Central both to how people produce and comprehend language are pragmatic factors such
as speaker intent, “the addressee’s background attitudes and beliefs, their understanding of the
context … and their knowledge of how language can be used for a variety of purposes” (O’Grady
et al., 1997, p. 725). In this way, pragmatic aspects of language might thus be highlighted for L2
learners as a way to link practical strategies for communication with various social engineering
tools (see Sharevski et al., 2019).
There are other practical issues associated with L2 learning, too. L2 learners experience
both the possibility for and effects of making errors (Guzmán-Muñoz, 2020; Teravainen-Goff,
2022). L2 learners may also have opportunities to navigate unscripted, multi-person dialogue
situations that promote acting and reacting, i.e., “interactional competence” (Schwab, 2011, p. 3).
Such aspects of L2 learning—shaping one’s environment, anticipation, error management, and
interacting in evolving scenarios with others—may be theoretically relevant to various practical
aspects of security mindsets that have been identified in the literature (Table 8).
Table 8
Various Aspects Associated With Practical Capacities in Security Mindsets
Aspect Associated With
Practical Capacities in
Security Mindsets
Examples From the Literature
Strategic reasoning and planning • Opportunity to employ strategies (Hamman & Hopkinson, 2016)
• “Select targets, conduct reconnaissance” (Hamman & Hopkinson,
2016, p. 9)
• Plan out actions (attacks) (Hamman & Hopkinson, 2016
• Avoid detection (Hamman & Hopkinson, 2016; Katz, 2019)
• Adapt, shape, and/or select environments (Sternberg, 2002)
• Opportunity to reason “about the best strategy to adopt in a given
multi-agent scenario, taking into account … how the agent’s choice
of strategy will affect the choices of others” (van der Hoek et al.,
2005, Abstract)
Social engineering • Exposure to social engineering strategies (Hamman & Hopkinson,
2016)
• Awareness of how “social and communication skills” can be used
to get “people to release essential information or to perform critical
actions” (Esteves et al., 2017, p. 72)
Anticipation others’ actions/
attending to others’
motivations
• “Identifying possible player actions” (Schneider, 2013, p. 4)
•Attend to the motivations of others (Katz, 2019)
• Anticipate others’ actions (Hamman & Hopkinson, 2016; Katz,
2019)
• “Tak[e] into account the likely behaviour of other participants in
the scenario, and, in particular, how the agent’s choice of
strategy will affect the choices of others” (van der Hoek et
al., 2005, Abstract)
Real-world connections • Exposure to/opportunity for real-world application (Jethwani et al.,
2017)
• Managing circumstances with no guaranteed outcomes
(Schaltegger et al., 2024)
• Opportunity to view exchanges in terms of adversaries (Severance,
2016)
• “Allow students to be exposed to the ramifications of writing
insecure code and designing vulnerable networks” (Kaza, in Siraj
et al., 2021, p. 336); more fundamentally, opportunities for students
to experience the consequences of mistakes
Connections With Situational Capacities
Languages can be viewed as situated (Inbar et al., 2001; Saussure, 1916/1986) in multiple
ways. Discussions in L2 learning about cultural appropriation (see Kramsch, 2014) attest to the
fact that languages operate in broader global, historical, and cultural contexts. Surveying this
discussion, Kramsch (2014) viewed cultural acquisition as “a desirable goal” (p. 33) in L2
learning settings “as long as culture acquisition only means the ability to momentarily see the
world through the eyes of a native speaker or to occasionally behave in ways that conform to
native speaker expectations” (p. 33). In addition to cultural and historical contexts that can open
the door for developing L2 learners’ broader global and cultural awareness, language can also be
situated in immediate concrete physical spaces. As conversations unfold between speakers in
settings, opportunities may arise for deepening L2 learners’ attunement to one’s local
environment as well.
Languages often reflect their immediate connection to setting in myriad ways, with deixis
being one example (see Stapleton, 2017). Deictic words depend on extra-linguistic contextual
details for their meaning. All languages have deictic features (O’Grady et al., 1997) and
depending on the language, deixis may oblige speakers to encode key information in their
utterances about proximity, time, gender, social status, mood, and so forth. As such, L2 learners
may have to keep track of a slightly different set of situational details in the L2 when attempting
to create or comprehend an utterance and these details can be of tremendous import; O’Grady et
al. (1997) invited readers to consider “the striking difference in perspective” (p. 297) due to the
deictic aspects of the verbs in “The bear is coming into the tent!” (p. 298) and “The bear is going
into the tent!” (p. 298).
While the situational awareness described above hinges on external knowledge of the
world outside the language, linguistic situational awareness also plays an important role at the
mechanical level within the language itself. Here, awareness refers to what one knows about the
architecture of language as well as “conscious perception and sensitivity in language learning …
and … use” (Association for Language Awareness, n.d., para. 1). Learners perceive and
comprehend these language mechanics with varying degrees of awareness (Robinson et al.,
2013) and may occur at various levels of the language. As learners develop an awareness of
“what should be” (Horneman, 2019, para. 9) with respect to the L2—along with their capacity to
“track what is” (para. 9)—they may be increasingly equipped to engage in the kind of continual
self-correction that often characterizes L2 learning. The continual comparison between is and
should be could also help L2 students make judgements about the trustworthiness of information,
interlocutors, and platforms. Taking all this into account, and drawing on analytical, creative,
practical, and situational aspects in L2 learning, the door is opened for introducing students to the
importance—and underlying mechanics—of making informed judgements responsive to one’s
situation. Whether mastering the rules of an alternative linguistic system or navigating various
socio-cultural contexts, in many ways, language production and comprehension relies on
speakers’ attention to contexts and conventions.
In addition to the theoretical opportunities afforded by L2 learning for honing one’s
observational capacities (i.e., “perception and sensitivity” [Association for Language Awareness,
n.d., para. 1]), language itself can be a primary tool for information gathering. L2 learners can
use language to ask questions and elicit information. In navigating less familiar contexts that may
leave L2 learners feeling more vulnerable, students may be more readily convinced of the value
of information gathering and noticing potential “holes and vulnerabilities … that could be
hurdles” (Esteves et al., 2017, p. 73) when surveying new concepts, topics, and tasks.
To gauge the how situational aspects of L2 learning might be related to aspects of security
mindsets, I reviewed literature about various concrete aspects of situational awareness for the
purposes of evaluating more precisely potential theoretical connections (see Table 9). With Table
9 in mind, possibilities emerge for connecting situational aspects of language more explicitly
with situational aspects of security thinking.
Table 9
Various Aspects Associated With Situational Awareness in Security Mindsets
Aspect Associated With
Situational Awareness in
Security Mindsets
Examples From the Literature
Perception, comprehension,
and projection
• Exposure to / opportunity for perception, comprehension, and/or
projection (Endsley, 1995)
• “Track[ing] what is” in light of “what should be” (Horneman, 2019, para.
9) • “Infer[ring] when should be and is do not match” (Horneman, 2019,
para. 9)
• Predicting how events will unfold (L. Jiang et al., 2022)
Sense of setting • Having an “operational picture” (i.e., knowledge of the “position and
status of important infrastructure” and adversaries/others) (D. Allen,
2015, p. 6)
Global situational
awareness
• See activities that are happening throughout the world (Software
Engineering Institute Carnegie Mellon university [SEI], 2015)
• Understand potential local impact of global events (SEI, 2015)
Information gathering • Opportunity for surveying/information gathering (Esteves et al., 2017, p.
73)
• Opportunity to “take note of … holes and vulnerabilities … that could be
hurdles” (Esteves et al., 2017, p. 73), i.e., ask, “How could this fail?”
• Opportunity to “know what should be” (Horneman, 2019, para. 9)
• “Incorporat[e] multiple data sources” (D. Allen, 2015, p. 15)
• “Ensure timely updates (e.g., maps, diagrams, [tactics, techniques, and
procedures])” (D. Allen, 2015, p. 16)
• “Continuously validate feed integrity” (D. Allen, 2015, p. 16)
Connections With Foundational Cybersecurity Domain Knowledge and Concepts
In addition to having the potential to support opportunities for L2 learners to engage with
analytical, creative, practical, and situational aspects of security mindsets, topics and tasks in L2
learning may also be amenable to opportunities for broaching foundational security concepts.
For example, in L2 settings learners may engage in communication tasks such as
dialogues. As these exchanges generally involve the transmission and receipt of ideas, they could
conceivably also afford moments for highlighting basic ideas that underpin the CIA triad (which
stands for confidentiality, integrity, and availability); students could be encouraged to reflect on
various reasons one might take measures to protect confidentiality (depending on the kinds of
messages being transmitted or the environments in which they are being transmitted), types of
errors that could impact the integrity of the message with respect to meaning or impact, or
various factors that could ensure or threaten the intended receiver’s ability to access the message.
Possibilities for broaching basic security topics might also theoretically be rooted in the
specific topics selected by L2 learning curriculum designers. While talking about one’s name and
birthday are not inherent to language, they might serve as logical platforms for broaching other
introductory concepts in cybersecurity such as privacy and data sensitivity, or examples of
passwords that might be easily guessed by unauthorized users.
And finally, language has the capacity to be used to conceivably broach any theme.
Therefore, it would be theoretically possible for existing L2 learning resources to have built a
lesson around themes central to security thinking. Appendix A: Examples of Basic Cybersecurity
Concepts, Domain Knowledge, and Skills lists various examples of fundamental cybersecurity
domain concepts and knowledge that emerged as a result of my review of cybersecurity
literature. While not exhaustive, this list served as a guide with respect to some basic
cybersecurity domain concepts that I felt it would be important to keep in mind during my
analysis of actual L2 learning content, which is outlined in the next chapter.
A Novel Conception
As noted in the first chapter, the links between L2 learning and security thinking
conceived here diverge from conventional ideas of how language can support cybersecurity
efforts, which have often focused on the value of specific languages for carrying out security
work. Indeed, within the general security sector, the advantages of fluency in particular
languages such as Arabic, Russian, or Urdu are well documented (e.g., King, 2015; Taha, 2007)
and others have noted the prominent role that linguistics plays in cybersecurity (Klavans, 2015).
Klavans (2015) noted, for example, that “computational linguistic analysis and translation of
Twitter, along with blogs and other social media, has become a full-fledged field of study,
showing how language analysis is key to understanding cyber-activism” (p. 11). Klavans (2015)
also noted that modeling based on linguistic principles could “reveal multiple viewpoints,
influences, centers of power, disputed topics, and overall sentiment” (p. 11) Such relationships
between language and security, however, still hinge on narrowly specialized or technical skills.
As a result, fewer pathways exist for students in non-technical fields to get into cybersecurity
(Sharevski et al., 2018).
Yet in exploiting more fundamental connections between security thinking and language
learning, the opportunity may present itself for L2 classrooms anywhere to contribute to the
development of a much larger number of learners’ interaction with security concepts. Dutton et
al. (2019) believed that “helping to increase the understanding of safe practices, encouraging end
users to take personal responsibility, and developing a cybersecurity mind-set could increase the
engagement of end users and thus enhance cybersecurity capacity" (p. 287).
Chapter Summary
In my review of the literature, I posited that L2 instructional settings could potentially
provide a security mindset basic training ground in multiple ways. One way that L2 settings
might facilitate L2 students’ introduction to security mindset fundamentals hinges on exploiting
key aspects of language itself that are analytical, creative, practical, and situational. Above, I
reviewed these key aspects and their relationship to this study’s conceptual framework. Yet
another way to engage students with security mindset fundamentals in L2 settings hinges on
leveraging the details of specific topics chosen by L2 instructors and materials designers by
connecting these to security mindset fundamentals. I reviewed these possibilities above as well.
Having concluded that connections could be made in theory between L2 learning and
security thinking for the purposes of introducing cybersecurity themes to the nation’s K12+ L2
learners, I was poised to move from a literature-based review of theoretical possibilities into an
applied investigation of real avenues for practical exploitation. Simply put, I had developed in
my mind a sense of what could be and was eager to investigate what actually was. I next drafted
a plan for investigating of existing L2 learning materials to advance an understanding of how
currently available L2 materials might be leveraged for cybersecurity educational purposes and
— recognizing that existing materials were not designed with this in mind—to shed light on what
might need to be done to capitalize on possible connections more fully. The methodology that I
adopted for this process is outlined in the next chapter.
Chapter V: Methodology
In this chapter, I outline the procedure I followed for applying qualitative content analysis
(QCA) and Imaginative Variation (IV) to L2 learning materials. I discuss how the selected
approach, method, and design supported an investigation into how existing L2 materials might
serve to introduce L2 learners to security mindset fundamentals.
The five security mindset fundamentals central to my investigation—which I presented in
my framework for security thinking in Chapter II—constituted the five main categories in my
QCA’s deductive coding frame. In Chapter IV, I developed these five security mindset
fundamentals in more detail, permitting me to add subcategories to the coding frame for more
precision.
I paired QCA with imaginative variation (IV) as a means to view L2 content through the
lens of security mindset fundamentals. This enabled me to identify features of the L2 content that
could be connected to security mindset fundamentals and subsequently imagine the ways in
which these connections could be leveraged as part of “a deliberate effort” (Kaza, as found in
Siraj et al., 2021, p. 2) to exploit links between cybersecurity and language more fully. The
study’s principal research questions were:
1. In what ways, if any, is L2 content amenable to opportunities for learners to engage
with analytical, creative, practical, and/or situational knowledge and capacities which
are foundational to security mindsets?
2. In what ways, if any, can L2 content provide opportunities for raising basic
cybersecurity concepts and domain knowledge for learners’ consideration?
The pairing of QCA and IV served to facilitate an examination of both what is and what might be
for the purpose of broadening cybersecurity education’s toolkit. In other words, the study’s
research methodology was selected for its ability to advance discussions in both theory and
practice. This was in line with calls for a shift “in the research community to consider … how
research can be helpful for teachers” (Sato & Loewen, 2019, p. 29).
Rationale for Approach
My research study was shaped by a qualitative approach. Basic qualitative research is
marked by humans discovering and interpreting meaning (Merriam & Tisdell, 2016). In this
process of discovery, data may be collected in various ways (Merriam & Tisdell, 2016). Findings
come in the form of “recurring patterns or themes supported by the data” (Merriam & Tisdell,
2016, p. 25). The researcher is the primary instrument, typically seeking a global interpretation of
the phenomenon (Merriam & Tisdell, 2016).
With these parameters in mind, a basic qualitative approach presented itself as
appropriate for my own inquiry. Such an approach allowed for an iterative, context-driven and
data-driven analysis of rich textbook content in my efforts to uncover and interpret the kinds of
“recurring patterns or themes” (Merriam & Tisdell, 2016, p. 25) that define basic qualitative
research.
Research Method and Design
I applied QCA to L2 textbook content (such as images, explanatory material and
examples, and learning activities) to view and describe all the content in selected portions of L2
learning materials relative to this study’s conceptual framework. QCA is “a method for
systematically describing the meaning of qualitative material” (Schreier, 2012, p. 1) and relies on
“classifying material as instances of the categories of a coding frame” (p. 1).
Content analysis was once used almost exclusively for quantitative inquiry but has gained
momentum as a qualitative research method in its own right (Bowen, 2009; Schreier, 2012).
Given this history, QCAs have often retained a quantitative component. Yet, while some scholars
have made it a point to note that quantitative elements are not required in content analyses (e.g.,
Bowen, 2009; Schreier, 2012), it may still be useful to recognize that QCA can allow for
quantitative aspects to be embedded within a qualitative research study. Miles et al. (2020)
asserted that even in qualitative inquiry, “we cannot escape our need to sometimes quantify our
experience with terms such as ‘most,’ ‘few’ ‘excellent,’ and ‘only’” (p. 36). With the generation
of themes in QCA comes the ability to examine frequency of themes also, giving added depth to
a study. I therefore retained the possibility in my QCA to take note of both the types and
frequency of coding segments that involved various security fundamentals in L2 textbook
content.
In addition to this flexibility, QCA presented other advantages. Documents and other
materials represent data sources that are often readily available and plentiful (Merriam & Tisdell,
2016). The same exact content can be examined by multiple researchers at multiple times, and
the relevance of materials can often be evaluated right away (Merriam & Tisdell, 2016).
Documents and artifacts are contextual and thus rooted “in the real world” (Merriam & Tisdell,
2016, p. 183) and thus may be even more effective than interviews or observations. However,
because materials in QCA are not reactive in the same way that human participants are,
researchers may be left without a way to clarify or ask for further information (Merriam &
Tisdell, 2016). What is more, if the content does not align neatly with a selected theoretical
framework, there is sometimes little that a researcher can do about it. These limitations
notwithstanding, QCA served to advance my own inquiry by supporting a rigorous investigation
of textbook content in which it was possible for me to attend to quality, variety, and frequency of
themes.
Within this QCA, I practiced IV to approach L2 content through the lens of another
domain (security mindsets), allowing me to explore different possibilities for developing security
topics rooted in L2 content. At its heart, IV involves a change in viewpoint as a way to reimagine
something (see Turley et al., 2016). With roots in phenomenology, IV has been used in
qualitative research in novel ways (e.g., Bevan, 2014; Turley et al., 2016). For Turley et al.
(2016), IV was a “best described as a mental experiment. … to view the phenomenon under
investigation from varying perspectives” (Abstract). Also a phenomenological researcher,
Mohanty’s (1991) view was that “Such a change of attitude … ‘transform[s the real existent]’
into one pure possibility amongst other possibilities. Richard Zaner, in a striking locution, calls it
‘an act of possibilizing’” (p. 263).
As my own application of IV was not within the bounds of a traditional
phenomenological research study, it is worth noting how others have also imagined potentially
broader applications of IV. Roemischer (2013) viewed IV essentially as meaning making; in this
vein, IV has an important role to play for its potential to humanize—or “rehumaniz[e]”
(Roemischer, 2013, p. 8)—abstractions in educational settings. Writing about mathematics,
Roemischer (2013) argued that it:
is not an inhuman activity. People made it for human purposes. The key to humanizing it,
or, better, rehumanizing it for children is to tie the computational tasks back to the human
intentions, hopes, fears, etc. that generated them in the first place. If children can see a
particular solution to a particular human hope, intention, fear, or whatever, then we can
embed the skill in a context that is meaningful. (Roemischer, 2013, p. 8)
I propose that Roemischer’s (2013) claims apply to abstractions at the center of my inquiry of
security and language as well. In my endeavor to reimagine L2 content—making new meaning
of it by adopting a security-related point of view—I drew on the prior notions of IV highlighted
above while adapting them to the details of my study, supporting a more systematic inquiry.
Sample Selection
The research sample was an “intentional, convenience sample” (LaBelle, 2010, Abstract)
drawn from three L2 resources representing different modes, approaches, and languages. These
resources were:
•a beginning French language textbook that supported a communicative approach
•a beginning ELL textbook featuring Grammar-Based Instruction
•a comprehension-based beginning online Spanish language program
The languages represented by these resources at the time of this study were among the most
widely learned in the United States according to K12+ L2 enrollment figures (see ACIE, 2017;
de Brey et al., 2021). Below, I describe and provide a justification for the selection of these L2
learning materials.
Beginning FL French Textbook
I surveyed content from a published hard copy of the FL textbook, Discovering French
Today! French 1: Teacher’s edition (Valette & Valette, 2013). This is the most recent edition for a
physical textbook in the Discovering French series. The Discovering French Today! French 1
textbook aligned with the National Standards Five C’s, provides pathways for differentiated
instruction, and has been used with students who may or may not be in Advanced Placement
tracks (Valette & Valette, 2013). The authors’ introduction to the teacher’s edition detailed how
the Discovering French Today! French 1 textbook contains “carefully structured content and
communicative features” (Valette & Valette, 2013, p. T3) and “emphasizes communication with
accuracy and stresses meaningful cultural contexts” (p. T3). The textbook also directed teachers
and learners to digital resources to “extend and enhance … learning through integrated
technology” (Valette & Valette, 2013, p. T3).
My selection of the French textbook was partly based on my personal familiarity with it
as a classroom instructor. At present, I use the Discovering French series to teach Beginning
French to university students. I have used it to teach middle school students as well. As a result
of these experiences, I was already familiar with the content in Discovering French Today!
French 1: Teacher’s edition (Valette & Valette, 2013) and able to leverage prior knowledge. I had
access to the most recent teacher’s edition Discovering French Today! French 1: Teacher’s
edition (Valette & Valette, 2013) due to my role as a French language instructor. Although there
are other ancillary materials accompanying the textbook such as assessment design tools,
CDs/DVDs, and workbooks with answer keys, I did not analyze these, owing to the already rich
source of data available in the textbook.
I applied QCA/IV to all of Unit 1 (pp. 12-41), which contained six different sub-lessons
(1a, 1b, 1c, 2a, 2b, and 2c) emphasizing listening and speaking in French followed by
“recapitulation and review” (Teacher note, p. 38) section and an “Entracte” (p. 40) dedicated to
reading and culture. In this analysis, I included graphic images and corresponding notes for
instructors in the margins as well, as they developed explanations and activities further. While
my in-depth QCA concluded at the end of Unit 1, I also reviewed the rest of the units to situate
the analyzed portion within the rest of the textbook (see Appendix B: Overview of French
Textbook Contents and Organization). This helped me to determine that the unit I selected for
analysis was not an outlier with respect to the other units in the textbook.
Beginning ELL Textbook
In addition to a FL textbook, I gathered data from a hard copy of a student edition of a
popular ELL textbook, Basic English Grammar Fifth Edition (Azar & Hagen, 2022). This
resource is part of the Azar-Hagen Grammar Series, which relies on the influential
GrammarBased Teaching (GBT) method which Azar adopted and began to develop as the basis
of her textbook series more than four decades ago (Brock, 2015). Azar’s language teaching
materials
continue to be used in the United States and around the world (Brock, 2015).
Basic English Grammar Fifth Edition (Azar & Hagen, 2022) “blends direct grammar
instruction with carefully sequenced practice to develop speaking, writing, listening, and reading
skills” (p. x) for beginning ELL students and is meant to serve “principally as a classroom
teaching text but also … as an introductory reference for students and teachers” (p. x). Azar and
Hagen (2022) sought to avoid “presenting grammar as a mere collection of rules” (p. x),
endeavoring instead to create a “logical framework to help [students] make sense of the language
they see and hear” (p. x).
My own experience with the Azar-Hagen Grammar Series comes from using the Basic
English Grammar Fourth Edition (Azar & Hagen, 2014) while working with ELL students at the
university level. While both the fourth and fifth editions are silent on the issue of target audience
age, based on personal experience, the textbook series is appropriate for beginner ELL high
school students and adult learners. I currently own the student edition of Basic English Grammar
Fifth Edition (Azar & Hagen, 2022).
I performed QCA/IV on Chapter 1 (pp. 1-25), titled “Using Be,” which covered language
learning content related to the verb to be. This included a chapter pretest, “Jump-Start Your
English” sections, vocabulary, grammar charts, listening practice,66 reading and writing tasks,
end-of-lesson and “learning checks” (p. xi). In addition to written text, I also examined images
such as photos and drawings. While there were also links to digital curricular resources, I limited
my analysis to content in the physical textbook. For a more detailed overview of the contents and
organization of Basic English Grammar Fifth Edition (Azar & Hagen, 2022) and how Chapter 1
aligned with the rest of the textbook, see Appendix C: Overview of ELL Textbook Contents and
Organization.
Beginning Online FL Spanish Curricular Resource
In searching for a popular FL Spanish online textbook, I reached out to educators in my
local school district and found that their middle school and high school FL Spanish students used
The Somos Curriculum®, or Somos. Somos was developed by Martina Bex and first published by
The Comprehensible Classroom in 2012 and is “used in over 100,000 classrooms and districts
worldwide” (The Comprehensible Classroom, n.d.b, para. 1). It is a digital, downloadable
curriculum resource for beginning and intermediate Spanish language teaching. Somos materials
are stored in Google Drive and Unit 1 can be accessed by anyone for free. The Comprehensible
Classroom produces and updates this content for Somos, which is intended to support
“proficiency-oriented … comprehension-based … acquisition focused” (TCC, n.d.b, paras. 1-3)
L2 instruction. This approach to L2 instruction is based on their assumption that:
Language acquisition is inherently different than the study of other subject matter.
Language acquisition is a subconscious process over which no one—not the teacher, not
the students—has any control. If [teachers] are committed to an acquisition based
approach to language education, then we must resist the urge to revert to explicit
instruction as well as the systems that can be used to evaluate language learning
(meaning, memorization and application of vocabulary and grammar items). (Somos 1
Lesson Plan, pp. 37-38)
This view impacted the organization and content of the organization and content of Somos Unit 1
curriculum: stories (e.g., texts, videos, and songs)—rather than grammar points—were primary.
With Somos, lessons do not teach for mastery, and students are not assessed on discrete grammar
points or vocabulary items. In each lesson, language is used naturally to complete a given
communicative task—this means that students are exposed to many grammatical
structures from Day 1. (TCC, n.d.a, para. 8)
In addition to communication and comprehension, Somos incorporates authentic language
sources, including news, advertisements, songs, tweets, infographics, and YouTube clips with an
emphasis on real-world communication and culture. I applied QCA/IV to Somos Unit 1 content,
which was organized around the children’s song Los pollitos dicen. For a more detailed overview
of the The Somos Curriculum 1, see Appendix D: Overview of Spanish Curriculum
Resource Contents and Organization.
While I had no prior experience with Somos, I am very familiar with at least one of the
comprehension-based strategies employed by Somos, Total Physical Response (TPR), and I have
a working knowledge of “proficiency oriented language instruction” (TCC, n.d.a, para. 4) on
which this curriculum is based. In addition, Somos aligns with the American Council on the
Teaching of Foreign Languages’ (ACTFL) proficiency guidelines with which I also have
experience.
Justification for Sample Selection
These selections are informed by the study’s purpose: to illuminate existing and potential
avenues in current L2 learning materials for introducing students to security mindset
fundamentals. Although school-specific, course-specific, and teacher-specific artifacts also
represent a wealth of curricular materials for potential examination, these are not always
accessible to a larger circle of second-language practitioners often operating in a wide variety of
educational settings where the only constant may be the presence of a textbook (Hadley, 2018).
Given this diverse landscape marked by local adaptation, examining widely known and available
textbooks is a logical choice, as my hope is to generate findings relevant to practitioners in
myriad language learning settings. The decision to select both hard copies and online formats
reflects the reality that L2 programs have the option of adopting either mode. And one
contributor on a popular online L2 learning platform pointed out that both hard copies as well as
digital formats can contain “all the target language content” (Kreisa, 2022, para. 1) necessary for
L2 study.
Data Collection and Analysis Procedures
In qualitative research, data collection procedures and data analysis procedures often
overlap (Schreier, 2012). While quantitative research steps are linear, the steps making up
qualitative research are generally iterative (Schreier, 2012). This was particularly true for my
QCA study. Data collection and analysis procedures are thus presented together in this section
wherein I address issues such as protocol, observation, artifacts, and the procedures I followed
for developing and applying a coding frame for analysis. The “adaptability of the qualitative
research process” (Schreier, 2021, p. 24) became apparent during my QCA data collection and
analysis, aptly situated within the qualitative tradition.
Preparing for Data Analysis
Schreier (2012) noted that QCA researchers can become “overwhelmed” (p. 58) as they
begin their data analysis process. However, careful preparation can help to alleviate this, such as
building a coding frame and selecting effective units for analysis and coding (Schreier, 2012). I
discuss this process in the context of my own study below.
Developing a Coding Frame. Coding frames are made up of main categories, often with
subcategories (Schreier, 2012). These categories assist the researcher to structure the material and
to recognize relevant content; categories also guide researchers in identifying what the most
important aspects are (Schreier, 2012). A coding frame is then constructed around these
important elements (Schreier, 2012). While a coding frame can support inductive and/or
deductive inquiry in QCA (Schreier, 2012), the coding frame I employed in this study was
deductive, built around previously identified categories.
Schreier (2012) counselled that “Where main categories are concerned, the research
questions point the way” (p. 61). Thus, taking the lead from my first research question, I
selected key security mindset fundamentals as main categories for my analysis. These categories
were: analytical aspects of security thinking, creative aspects of security thinking, practical
aspects of security thinking, and situational awareness. They were drawn from Hamman and
Hopkinson’s (2016) conception of Sternberg’s (1988) Triarchic Theory of Intelligence (TTI);
Hamman and Hopkinson’s (2016) attention to operational spaces provided the impetus for the
subsequent addition of situational awareness (see Endsley, 1995; Horneman, 2019). Figure 3
illustrates how these four main categories—analytical, creative, practical, and situational—are
positioned as foundational elements of security thinking in this study’s coding frame.
Figure 3
Foundational elements of security mindsets
Note: This conception, introduced in Chapter II, draws on the work of Endsley (1995), Hamman
and Hopkinson (2016), Horneman (2019), and Sternberg (1988).
To further develop and clarify my coding frame, I added subcategories to each main category.
Examples provided along with each subcategory delivered more specific insight into the nature
of each of the four main categories identified by the first research question. I pulled these from
my review of the literature in Chapters II and IV to create the final deductive coding frame
(Appendix E: Deductive Coding Frame: Main Categories and Subcategories for Content
Analysis) that served as a checklist during analysis.
Guided by the second research question, I evaluated each coding segment’s content for its
potential to be connected to specific security-related ideas. This fifth category diverged from the
other four security categories presented above in that its focus was not on the foundational
capacities undergirding security thinking, but rather on the foundational domain-explicit
knowledge that shapes security thinking. Some examples of these include the notions of
confidentiality, integrity, availability, authentication, non-repudiation, privacy, information value,
anonymity, risk assessment, and the notion of adversarial thinking. Definitions for these terms
and others have been included in Chapter I. Appendix A presents a list of these and other
concepts as examples of foundational domain knowledge and skills germane to cybersecurity
thinking.
Segmentation and Units of Analysis. With my initial coding frame established, I next
considered how to divide up my material into smaller segments for applying these categories
(Schreier, 2012). Schreier (2012) advised that when deciding “where one unit ends and another
begins, you make use of a structure that is already inherent in your material” (Schreier, 2012, p.
143). Because the resources in the sample had divided content into segments already, I
capitalized on this pre-existing structure and approached each segment as a unit for analysis
within the first chapters of the selected textbooks.
Finally, to situate my analysis of beginning chapters within the rest of the textbook and
capture the broader range of themes contained therein, I reviewed the general contents of the rest
of the resources (Appendices A, B, and C).
Data Analysis Procedure
To assist with the identification of security mindset themes guided by my first four main
categories, I created concept-driven checklists (Appendix E: Deductive Coding Frame: Main
Categories and Subcategories for Content Analysis) rooted in cybersecurity literature that served
as the basis for examining the content. Keeping in mind that with conceptual coding, data is
considered by “visible indicators of underlying, more general concepts” (Schreier, 2012, p.40), I
searched for instances in the textbook content where learners’ underlying analytical, creative, and
practical aspects of intelligence were likely to be engaged if they were interacting with material
(such as when encountering explanatory content, looking at images, and completing activities).
In addition, I searched for instances where textbook content could invoke elements of learners’
situational awareness. Similarly, for the last main category, while examining the content for
connections with the other categories, I also considered how any given coding segment could be
used as a platform for raising security-specific domain knowledge and related issues. I referred to
a list of examples compiled from practitioner and researcher insights (Appendix A), keeping
these in mind as I examined L2 content for possible in-roads for raising awareness of explicit
issues relevant to cybersecurity mindsets. To provide an example of what is meant by identifying
in-roads, a textbook exercise directing students to share phone numbers
with one another could be identified as providing a potential starting-point for developing L2
students’ notions of confidentiality (Where can you share so that only the intended audience can
know your number?), integrity (What types of things might interfere with your ability to convey
this information accurately?), the value of information (What might my phone number be
“worth” to other people?), anonymity (If the only thing others can see is my phone number, can
they know it’s me?), and/or privacy (Can using your phone number impact your privacy?). In any
single example, there were potentially numerous security-related ideas to be identified, and I do
not presume to have considered all of the possibilities. Rather, in considering if there were (or
were not) potential avenues for development, I sought to make note of the various compelling
examples which readily appeared to me.
In this process, I relied on IV to imagine what modifications might be applied to a given
coding segment in order to more powerfully capitalize on the in-roads that I identified. Such
imagined modifications included, but were not limited to: the addition of commentary intended
to help learners connect a feature of L2 learning to security themes, deliberate changes in the
setting of dialogues or activities, or adjusting a stated objective, for example.
IV was an important feature of my analysis because without taking the step to imagine
how specific L2 content could be leveraged to explicitly engage questions about security, the
analytical, creative, practical, and situational fundamentals of L2 learning risked continuing to be
being perceived as generic abstractions, still not yet specifically shared with security. I
determined that merely identifying various L2 content that could engage learners’ analytical
capacities and then presenting such content an opportunity to introduce L2 learners to analytical
security thinking would produce considerably less meaningful insight for future scholarship and
practice. Similarly, without taking the time to imagine how to explicitly connect security-specific
domain knowledge and concepts to existing L2 content, the introduction of such concepts might
risk appearing weak or forced. In this, IV was critical in imagining how concepts could be
explicitly named and thus more powerfully connected. Together, QCA and IV were selected for
their ability to advance this study’s purpose of exploring both if and how L2 content might be
leveraged to engage learners’ security thinking and thinking about security.
Iterative Aspects of the Data Analysis Process. Concept-driven aspects of my study
permitted me to generate categories (e.g., analytical, creative, practical, and situational) that I
could apply to the text. Data-driven aspects of my study also pushed me to refine and revise my
coding frame, such as the inclusion of a more robustly developed notion of situational awareness
and various security-specific topics. However, such changes to my conceptual framework were
consistent with QCA practices, wherein “you will add more questions if a new aspect … has
caught your attention, and you will continue to adapt your instrument … until it really fits your
material” (Schreier, 2012, p. 24). Once my initial data analysis was complete, I continued in
cyclic fashion, going back and recoding earlier material again to check for consistency.
Recording and Storing
Throughout the process of identifying what security mindset themes could be involved in
each segment of curricular material, I generated “reflective comments … [about my] feelings,
reactions, hunches, initial interpretations, speculations, and working hypotheses” (Merriam &
Tisdell, 2016, p. 151) as well as “factual descriptions of what is going on” (p. 151). I found that
the most time-efficient and secure approach was to enter observations directly into a Microsoft ®
Word document during my preliminary analysis. I used Word’s “insert table” function to create a
table with multiple columns for organizing the segments, observations, and perceived opportunities
for exploitation (Appendix F: Example of Columns for Recording My Data
Analysis). In the first column titled “Coding Segment: Original Content,” I copied and pasted
photographs or screenshots of each of the original coding segments, labeled by page and/or
section number. In the second column titled “Description,” I entered a summary of the content or
description of the learning task. In a third column labeled “Language Learning and Security
Components,” I recorded any main categories I judged as being central to engaging with each
segment and linked it to specific evidence based in the content. I also noted security-specific
domain knowledge and concepts that I perceived as being able to be developed through any
practicable in-roads provided by the coding segment. A final “Miscellaneous” column serves as a
space for any other notes, references, or vocabulary items, though it was not integral to
investigating my research questions.
Data Security and Retrieval
In QCA research concerned with public documents such as textbooks, data storage
becomes mainly a question of organization and searchability rather than taking measures to
protect the identity of data sources. To meet these basic needs of organization and searchability, I
used Microsoft ® Word to create a document in which to type my notes and to subsequently
search within the text I generated. I did not protect or encrypt documents for purposes of
anonymity as the materials I worked with were publicly available.
Ethical Concerns
Just as procedural issues can be varied and extensive, researchers also contend with
myriad ethical issues throughout the research process (Creswell & Poth, 2018). Many qualitative
researchers interact with human subjects and must therefore take steps to protect these
participants (Brinkmann & Kvale, 2015; Creswell & Poth, 2018). Though there was no direct
interaction with human participants for this QCA study, other ethical issues such as research
integrity and quality presented themselves. These are discussed in the next section.
Research Integrity and Quality
Issues of trustworthiness are faced by all qualitative researchers regardless of design
(Creswell & Poth, 2018). Addressing these issues is an integral part of all quality research studies
(Creswell & Poth, 2018).
Validity and Reliability
Schreier (2012) defended using the terms validity and reliability to discuss issues of
trustworthiness related to QCA. While validity and reliability are “positivist constructs” (p. 191)
from quantitative research, Schreier (2012) asserted that the distinction between quantitative
content analysis and QCA was not cut and dry; adopting different terms would have the effect of
divorcing QCA from its origins and ongoing discourses about content analysis. Schreier (2012)
continued that despite the availability of various other concepts, including “credibility,
trustworthiness, auditability, or authenticity” (p. 191), such terms were problematic due to a lack
of consensus among scholars over precise usage and meaning.
Reliability. Consistency emerges as a useful concept for examining reliability in QCA
(Schreier, 2012). Consistency can be assessed in two ways: different researchers can compare
how they coded the same material, or a single researcher can code the material and then revisit
the same material after some time to recode and check their judgements (Schreier, 2012).
Schreier (2012) recommended a wait-period of ten to fourteen days before recoding if the latter
strategy was employed.
As I was the only coder for this study, I employed a wait-period to revisit my coded
material after at least 10 days to compare my initial judgements with my subsequent judgements
about that material. I also noted how my coding strategy evolved from earlier attempts to later
attempts in seeking to establish a level of coherence that was born out of a deeply iterative effort.
Validity. The extent to which a research instrument “captures what it sets out to capture”
(Schreier, 2012, p. 175) speaks to the degree of validity in a study. In QCA, this instrument is a
coding frame (Schreier, 2012). When discussing validity in the context of QCA, Schreier (2012)
pointed to the importance of coding frame categories being sufficiently linked to the concepts
found in one’s research questions. Therefore, alignment between research questions and coding
frames are crucial to validity in QCA (Schreier, 2012). For this reason, I dedicated time and
attention to examining and developing my own understanding of a variety of potential theoretical
categories that related to my research questions. I undertook this prior to interacting with content
in L2 materials to help organize my examination of how these categories played a role in L2
learning content. Yet it is important to note that validity is also linked to the concepts of
exhaustiveness, or how effectively the coding frame treats all relevant aspects of your data
(Schreier, 2012). Therefore, I remained open to the discovery of potential additional categories.
In this way, my flexibility also supported the validity of this inquiry.
To strengthen the validity of my coding frame, I worked to align my coding frame with
my research questions. Additionally, I moved from relying on concept-driven categories only to
including data-driven categories in the coding frame as well. This flexibility permitted me to
capture more aspects of the data relevant to the research questions.
Researcher Competence
Miles et al. (2020) cited researcher competence and “research malpractice” (p. 53) in
their treatment of ethical issues in qualitative research. The researcher should have the
experience and expertise necessary to conduct their particular study well (Miles et al., 2020).
Reflecting on this, my proposed study required me to be knowledgeable about
fundamental security mindset concepts as well as L2 learning concepts. My undergraduate
degree in French Language and graduate degree in General Linguistics—which informed my
review of the literature on L2 learning and instruction in Chapter III—allowed me to bring
theoretical knowledge of L2 learning concepts to bear on my study. I also have practical and
pedagogical experience rooted in several years of language teaching in various settings,
including FL, ELL, and EFL. In these roles ranging from teaching fifth grade to higher
education, I became extremely familiar with one of the selected textbooks, Discovering French
Today! French 1A: Teacher’s edition (Valette & Valette, 2013). In addition, though less extensive,
I had some prior experience using an earlier edition of another selected text, Basic English
Grammar Fifth Edition (Azar & Hagen, 2022).
In addition to relevant knowledge, the language skills I possess also supported this particular
inquiry. A native English speaker, I am also fluent in French. Though I have no formal training
in Spanish language, I have a working knowledge of Spanish’s basic features which was
sufficient for examining the Spanish text for beginning learners in the study’s sample.
However, I have no experience as a trained cybersecurity professional. To gauge if
seasoned cybersecurity thinkers felt my topic could be treated adequately by someone with my
background and level of technical knowledge, I presented an overview of my research topic at
the 2022 conference of the Colloquium on Information Systems Security Education (CISSE)
titled The 26th Colloquium: Pedagogy for Cybersecurity (CISSE, n.d.). Owing perhaps to the fact
that this was an investigation of foundational aspects of security and consequently did not depend
on overly technical information, I received encouraging and constructive feedback. CISSE
reviewers selected my submission for presentation and publication after a rigorous peer review
process. From that process, I gained a dissertation committee member for the present study, Dr.
Erik Moore, whose research interests include cybersecurity and education. Dr. Moore connected
me with another external examiner, Dr. Steven Fulton, recently named Outstanding Academic
Educator in Computer and Cyber Science. My ongoing and extensive review of cybersecurity
scholarship has also served to increase my grasp of cybersecurity concepts and problems, built
on a foundation initially laid during Dr. Jane Blanken-Webb’s Cybersecurity for
Educational Leaders (Acalog™ Academic Catalog Management System™, n.d.) course at
Wilkes University in the fall of 2020.
Competence depends on more than relevant knowledge and skills alone, however; quality
is also determined by care that a researcher puts into following “some reasonable set of standards
or established practices” (Miles et al., 2020, p. 57). It can be argued that researchers have a
collective duty to follow best research practices so that the findings and interpretations they
generate can be accepted by others with confidence. Under the guidance and scrutiny of a
doctoral dissertation committee also ascribing to ideals of rigor and trustworthiness, I am
optimistic that the set of careful procedures regarding data collection, analysis, and imagination
outlined above ultimately contributed to the production of “useful and accessible” (Sato &
Loewen, 2019) research for others.
Researcher Bias
As the researcher, I was the primary instrument (Merriam, 2002). In this study’s current
iteration, the identification of possible connections between L2 and features of a security mindset
hinged on my own estimation of what is possible. My role in this study raised for me
philosophical questions about how far I could go in the claims I made about my data. Therefore,
one key action I took was to generate a robust audit trail with respect to these claims; I grounded
my judgments about potential connections between L2 content and security fundamentals in
concrete examples from the content and recorded this so that others might judge as well.
I also refrained from cherry-picking content across textbooks that looked particularly
relevant to my investigation. Instead, I applied QCA to all potential coding segments within the
beginning portions of each textbook, including all images, explanations, and exercises therein—
as this is arguably the part of any textbook that the most learners are likely get through. This is
important as it relates to one of the purposes of my inquiry; namely to explore if and how
connections between security mindset and L2 learning fundamentals manifest themselves in
available L2 content.
Chapter Summary
In this chapter, I outlined my plan for applying QCA/IV to L2 learning materials. I
discussed why this approach, method, and design were selected to support an inquiry into how
existing L2 learning content might be connected to (a) analytical, creative, practical, and/or
situational aspects of security thinking and (b) security-specific basic domain knowledge and
concepts such as confidentiality, integrity, and availability. I also described how IV could help
me to identify ways that L2 content might be leveraged to introduce students more meaningfully
or explicitly to foundational security themes. In addition, I treated questions related to data
recording and storage, and ethical issues.
In conclusion, Medgyes (2017, in Sato & Loewen, 2019) suggested that the burden was
upon “researchers to prove their worth” (p. 29). In the spirit of this, this study’s methodology was
designed to advance discussions in both theory and practice; my aim was to explore if the
theoretical connections between security mindset and L2 learning fundamentals (posited in
Chapter IV) could be identified in existing L2 content and to subsequently consider how such
content might be applied more intentionally for the purposes of cybersecurity education.
Chapter VI: Findings
Cybersecurity challenges in the United States have evolved and increased rapidly,
exacerbated by workforce shortcomings such as insufficient diversity (Burrell, 2020), narrow
skillsets (Sharevski, 2018), and a lack of personnel (Crumpler & Lewis, 2019), anemic public
awareness (Aldawood & Skinner, 2020; Bada & Nurse, 2019), novel threats (Georgescu, 2021;
Siraj et al., 2021), and uncertainty (Dark, 2015). As cyberthreats emerge from an intractable
tangle of social and technical vulnerabilities, calls for more interdisciplinary educational
approaches have been sounded (e.g., Austin, 2020; Furnell & Bishop, 2020; Jacob et al., 2018;
Wagner, 2022). Along with these, are calls for education to attend to various foundational
cybersecurity knowledge and skills as well (Crumpler & Lewis, 2019; K. Jones et al., 2018). In
this milieu, security mindsets—born out of an underlying curiosity that manifests in ingrained
habits of investigating and identifying how things can fail (Cappos & Weiss, 2014;
Pournaghshband, 2013; Schneier, 2008)—have been presented as “essential … for successful
cybersecurity practice” (Peterson, 2021, para. 1). Such a way of thinking has been posited as
valuable both to aspiring cybersecurity professionals (Pournaghshband, 2013) and the vast
population of non-technical end-users (Dutton, 2017; Jarjoui, 2023).
To this end, I examined the possibility of leveraging second language (L2) learning
content as an interdisciplinary vehicle for promoting security mindset fundamentals within L2
learning settings in the United States. I applied qualitative content analysis (QCA) to the
beginning of three L2 textbooks in conjunction with imaginative variation (IV) to identify
security-related avenues for exploitation. QCA paired with IV allowed me to investigate:
1. In what ways, if any, is L2 content amenable to opportunities for learners to engage with
analytical, creative, practical, and/or situational knowledge and capacities which
are foundational to security mindsets?
2. In what ways, if any, can L2 content provide opportunities for raising basic
cybersecurity concepts and domain knowledge for learners’ consideration? These
research questions took their shape from the study’s conceptual framework, based in part
on Hamman and Hopkinson’s (2016) conception of Sternberg’s (1988) Triarchic Theory
of Intelligence. Hamman and Hopkinson’s (2016) work on adversarial thinking provided
the rationale for four of the five main categories in this study’s conceptual framework.
These deductive categories—analytical, creative, practical, and situational knowledge
and capacities germane to security thinking (Appendix E: Deductive Coding Frame:
Main Categories and
Subcategories for Content Analysis)—helped to organize my analysis. While Hamman and
Hopkinson (2016) focused on analytical, creative, and practical capacities in their triarchic
framework for adversarial thinking, their attention to “operational spaces” (Dark & Mirkovic,
2015, in Hamman & Hopkinson, 2016, p. 4) laid the foundation for including situational
awareness as an additional category in this study’s conceptual framework. Horneman’s (2019)
adaptation of Endsley’s (1995) model of situational awareness subsequently helped to develop
further key aspects of this main category. Finally, because specific security-related foundational
domain knowledge and concepts are what help to shape security mindsets as such, I adopted
domain knowledge and concepts as a fifth and final category (Appendix A) to make up the
study’s coding frame. All together, these categories made up the checklist of security mindset
fundamentals that supported my inquiry into if and how foundational security mindset
knowledge, capacities, and concepts might be meaningfully introduced to L2 learners by
connecting such themes to currently available L2 content.
L2 Content Sample and Description
The sample included material from a French textbook, an ELL textbook, and an online
Spanish curricular resource. While these resources reflect only some of the variety in U.S. K12+
L2 learning with respect to language, approach, emphasis, organization, and format, these
beginner-level materials nevertheless served as a logical starting point for my inquiry, given their
popular usage and widespread availability.
Beginning French Textbook
Discovering French Today! French 1, Teacher’s Education (Valette & Valette, 2013) was
an example of a French textbook emphasizing a communicative language approach supported by
grammatical accuracy and the introduction of cultural contexts. I applied a QCA with IV to all of
Unit 1 (pp. 12-37), which contained six different sub-lessons emphasizing listening and speaking
in French followed by “recapitulation and review” (Teacher note, p. 38) section and an
“Entracte” (p. 40) dedicated to reading and culture.
Owing to the fact that I was working with the teacher’s edition of Discovering French
Today! French 1 (Valette & Valette, 2013), I was able to gain extensive insight into its various
features and had access to the authors’ explicit descriptions of each feature’s intended
contribution to L2 learning.
Beginning ELL Textbook
The authors of Basic English Grammar Fifth Edition (Azar & Hagen, 2022) spoke to
various issues regarding organization and emphasis as well. Azar and Hagen (2020) described
their textbook as “a beginning skills text for English language learners” (p. x) meant to serve
“principally as a classroom teaching text but also … as an introductory reference for students and
teachers” (p. x). The authors blended “direct grammar instruction with carefully sequenced
practice” (p. x) to target the core skills of speaking, writing, listening, and reading using
everyday language. This was reflected in the textbook’s overall feel as a series of exercises—
relating to real-world issues—which were all anchored to instructive grammar charts. I applied a
QCA with IV to Chapter 1 (pp. 1-25) which covered language learning content related to the verb
to be.
The ELL text differed from Discovering French Today! French 1 (Valette & Valette,
2013) in its assumption that students would likely not be able to read all of the explanatory
material: the textbook authors explained that “charts were designed so that the example sentences
… are for students, and the explanations … help teachers present grammar points.
Students are not expected to understand language in the explanations” (Azar & Hagen, 2022, p.
xiii). Additionally, unlike the other textbooks in this study, the first chapter of Basic English
Grammar Fifth Edition (Azar & Hagen, 2022)—though deeply infused with culturally relevant
content—did not contain sections dedicated explicitly to culture. This is consistent with the
reality that ELL instruction in the United States already takes place immersed within the target
culture.
Beginning Spanish Curriculum
A final resource completed the sample for this study. The Somos Curriculum®, or Somos,
was created for beginning and intermediate Spanish language teaching. This digital,
downloadable curriculum resource was designed to support language acquisition through
comprehension-based strategies. As such, Somos’s particular approach to communicative
language instruction has prioritized L2 comprehension even over L2 production. The content of
the Somos 1 Unit 1 curriculum reflected this by emphasizing the need for learners to understand
and connect with the meaning of texts, videos, and songs first, instead of beginning with specific
grammar points. Somos Unit 1, the unit to which I applied a QCA with IV, was organized around
the children’s song Los pollitos dicen.
Somos’ primary emphasis on meaning was distinct from the other resources in the study:
the French and ELL textbooks frequently highlighted abstract aspects of language—whether
pronunciation, spelling, grammar, vocabulary, structure, or usage—which were then
contextualized in exercises and activities. Like the French textbook, however, the Somos
curriculum also ascribes to ACTFL World Readiness Standards which encompass the Five C’s of
Communication, Cultures, Connections, Comparisons, and Communities (see ACTFL, n.d).
Textbook Sample as a Whole
All resources covered introductory-level lessons for beginning learners and included
listening, reading, speaking, and writing tasks enhanced with colorful visuals. While approach
and content matter sometimes overlapped, each resource also had distinct features that revealed
how their various authors viewed the task of supporting L2 acquisition and instruction. As such,
the content and feel of each L2 resource varied from curriculum to curriculum. However, all
authors provided insights and justifications for the overall text as well as specific types of
content. For example, all authors affirmed the value of incorporating real-world images and
supporting authentic language production. Authors also acknowledged that learners could have
different strengths and proficiency levels; hence all resources provided differentiated
opportunities for optional or additional learning. In addition, communication was an important
stated objective in all resources, and all authors noted that at least some explicit attention to
grammar and usage was useful in achieving this objective. Rooted in language acquisition
research and practice, all of the resources in the sample presented themselves as viable L2
curricular materials able to support beginning L2 acquisition. Figure 5 shows some of the
commonalities and differences I observed between the three L2 resources.
Figure 5
Comparing and contrasting the L2 resources selected for analysis
Findings: Security Mindset Fundamentals and Topics in L2 Textbooks
In what follows, I present my findings with respect to the ways in which I judged L2
textbook content as amenable to opportunities for introducing L2 learners to foundational aspects
of security thinking. Findings have been organized in two main ways to help the reader get a
sense of how both (a) a single coding segment can be leveraged to introduce L2 learners to
multiple, intertwining security mindset fundamentals and (b) a particular security mindset
• Physical textbook
• Romance
language
Spanish
L2 resource :
Week 1
• Grammar aids
communication
• Comprehension
aids communication
• Beginning
level
• Digital
format
• Viable
resource
• Activities that
purposefully include
unfamiliar
language
• Geared toward
native English
speakers • Supports
partner
dialogue
• Supports
whole class
dialogue
• Cultural vignettes that
focus on social practices
• Global references • Supports immersive
language instruction
French
L2 resource :
Unit 1
English
L2 resource :
Chapter 1
fundamental can be highlighted across multiple segments throughout an L2 resource. In
presenting findings both ways, I can convey more accurately the relationship I observed between
the foundational parts and the whole to which they belonged. While I found it useful to target
security mindset fundamentals in isolation as a means for gaining a sense of how each
fundamental aspect related to topics and tasks in the L2 content, in practice, L2 learners would
presumably be engaging with most or all of this L2 content—not in isolation but in concert. I
therefore sought to capture the bigger picture that would also emerge from such engagement.
To this end, I begin my presentation of findings by highlighting a cohesive excerpt from
the ELL textbook. This excerpt of L2 content is based on one coding segment from my analysis.
Segmentation of the data in this study was inspired by each resource’s own segments; these were
typically activities/exercises, images, or explanatory material such as a sample dialogue or a
grammar chart. It was QCA that gave my analysis its shape, allowed me to capitalize on this
preexisting organization, and ultimately to categorize and condense what I saw. It was IV that
permitted me to look at everything through the lens of security mindset fundamentals. To
familiarize the reader with how QCA and IV worked together in the analysis, I describe the
selected ELL coding segment and the concurrent imaginative process. Specifically, I name:
•the L2 content that I identified as germane to cybersecurity mindset fundamentals, based
on the security mindset fundamentals that I connected them to using IV (applying a
different lens to the material); and
•ideas that I generated for deliberately developing these connections, which were also
supported by my use of IV (as an act of possibilizing).
The reader will notice that my application of IV in this process resulted in considerable
expansion with respect to the material. In some cases, I needed more than one page to convey my
findings regarding only a few lines of L2 content.
At the same time, my use of QCA—a method that ultimately seeks to organize material
by reducing it (Schreier, 2012)—allowed me to sort and condense security-germane content
(which I identified using IV) from all of the L2 resources into the five main categories of the
study’s coding framework. In this case, rather than expanding on a few lines of content from a
single coding segment, I reduced rich examples from across the ELL textbook into just a few
themes. Insights generated from this aspect of my analysis have been largely presented in table
format, with the intention of offering readers a broader sense of the types of content and the
connections that can be made throughout the resources. With respect to all of the specific
examples I identified in the content, the tables I present in this chapter and the appendices are by
no means exhaustive.
In offering an in-depth—and at times granular—treatment of the ELL textbook, I have
aimed to familiarize readers with my imaginative thought process. While the same analysis was
applied to all materials, a truncated version of findings is subsequently provided for the French
textbook and Spanish curriculum. I have limited my report in this chapter of those resources to
any new insights and notable differences, in view of how insights generated from the French and
Spanish resources were generally found to parallel those from the ELL textbook. I direct the
reader to material in the appendices for further specifics regarding these resources.
Beginning ELL Textbook: Expanding on a Single Example of Content
When students crack open their ELL textbook to page 1, they are greeted by the Chapter
1 Pretest. This activity has been included in the textbook to “allow learners to assess what they
already know and orient themselves to the chapter material” (ELL, p. x). The textbook’s authors
acknowledged that beginning students would almost certainly make mistakes in this activity
(Azar & Hagen, 2022). However—owing to research that “indicates that taking a pretest may
enhance learning even if students get every answer wrong” (p. x)—the authors have not
only put it in the textbook, but it is the very first activity that students encounter.
The pretest begins with the question “What do I already know?” (p. 1). Next, students see
a prompt to identify “the correct sentences” (p. 1). Below that, a dozen sentences are to be
evaluated for errors (Figure 6).
Figure 6
Chapter 1 Pretest from ELL textbook
PRETEST: What do I already know?
Check (√ ) the correct sentences.
1. ____ Bus 7 is here. (Chart 1-1)
2. ____ Jack he is late. (Chart 1-1)
3. ____ Elle and Sophie is absent. (Chart 1-2)
4. ____ You and I are ready. (Chart 1-2)
5. ____ Beijing is city. (Chart 1-3)
6. ____ Hawaii is a island. (Chart 1-3)
7. ____ Kuwait and Syria are country. (Chart 1-4)
8. ____ They,re hungry. (Chart 1-5)
9. ____ He no a doctor. (Chart 1-6)
10. ____ It is expensive. (Chart 1-7)
11. ____ Rika is in the classroom. (Chart 1-8)
12. ____ Josh is not upstairs. (Chart 1-9)
Note. Reproduced from Basic English Grammar Fifth Edition by Azar and Hagen, 2022, p. 1.
To assess grammatical accuracy effectively, students would require some familiarity with
the orthographic, morphological, and syntactic systems of the L2 to help them discern which of
the many rules governing each system are pertinent in each pretest scenario. However, many of
the beginners looking at this page aren’t familiar with these rules yet; this is a language that
students are just starting to learn. For the same reason, much of the vocabulary is also unfamiliar
to students, further contributing to their sense of uncertainty. There are no corresponding images
available, either.
As learners read through the sentences, however, they have opportunities to use context
clues to begin sorting through some of the data. For instance, drawing on students’ basic global
and cultural awareness, students may recognize several proper nouns in the activity as
geographical places and personal names. It is also possible for them to notice the systematic use
of capitalization at the beginning of all sentences and punctuation following the same pattern at
the end. While learners employing these strategies are still left to manage a significant level of
ambiguity, there is one thing they are sure of: any of the 12 sentences may have had an error
deliberatly inserted into it. Students, attempting to make sense of “what is” (Horneman, 2019,
para. 9), thus cautiously bear in mind that what they see may not be “what should be” (para. 9).
Outside-the-box thinkers may find opportunities to look elsewhere for answers; responses
to select exercises throughout the textbook can be found starting on page 509 (although students
checking the back of the textbook will find that no answers have been provided for this particular
activity). Ethical concerns notwithstanding, students also face the possibility of looking at
another classmate’s guesses. Seasoned instructors are generally aware of these possibilities and
how they could be exploited by students (Hamman & Hopkinson, 2016); instructors may
subsequently find ways to discourage such learners from engaging in what is fundamentally
known as reward hacking, i.e., wherein the desire for “positive feedback” prompts a choice “to
prioritize earning reward [sic] instead of accomplishing their main task” (Mercer, 2023, para. 6).
In a classroom setting, this may involve learners finding shortcuts for completing activities
(completion being the proxy goal) that bypass the aspects of the activities meant to help learners
develop certain skills (with skill development being the intended goal).
In the end, any student tackling this pretest—whether attempting to follow or subvert the
rules—might agree that this whole enterprise of recognizing defects and outliers (see Buckley et
al., 2018; Nassiokas, 2021b) would be swifter and more accurate if only they knew the rules of
the new system! For true beginners, this is a near-impossible task.
Despite their initial struggle, ELL textbook users may already intuit that their “ability to
detect even minute changes in the data” (Frankel et al., 2008, p. 3-10) will grow as their English
knowledge increases. Thus, at the end of each sentence in the pretest, students have been
provided with the name of a corresponding informational grammar chart that appears later in
Chapter 1 (e.g., Chart 1-1, which is on the next page). Here, learners are equipped with a road
map for information gathering (see Esteves et al., 2017) and a way to survey what lies ahead—
many lessons about the verb to be.
I generated the above description of the Chapter 1 Pretest while referring to the study’s
coding frame (Appendices D and E) with a view toward the security mindset fundamentals in the
study’s conceptual framework (Figure 3).
Figure 3
Foundational elements of security mindsets
Note: This conception, introduced in Chapter II, draws on the work of Endsley (1995), Hamman
and Hopkinson (2016), Horneman (2019), and Sternberg (1988).
By using IV to approach the Chapter 1 Pretest through the lens of another domain (i.e.,
cybersecurity), I was able to name aspects of L2 content that may serve as a starting point for
introducing beginning L2 learners to various security mindset fundamentals. In the Chapter 1
Pretest, learners:
•encounter rules and protocols of a new system (see Hamman & Hopkinson, 2016);
•are exposed to ambiguity and uncertainty (see Dark, 2015);
•must compare “what is” (Horneman, 2019, para. 9) with “what should be” (para. 9) in
order to “infer when [these] do not match” (para. 9);
•are unlikely to succeed and may consider “think[ing] outside the box” (Schneier as found
in Severance, 2016, p. 8) about “how to exploit and subvert” (Dark & Mirkovic, 2015, p.
78) implicit rules (i.e., “Don’t cheat”) as a way to satisfy explicit goals (i.e., “Check (√ )
the correct sentences” [ELL, Chapter 1 Pretest, p. 1]);
•have an opportunity to draw on global awareness (see SEI, 2015);
•have an opportunity to identify patterns (see Nassiokas, 2021b);
•have an opportunity to spot components “that don’t fit” (Nassiokas, 2021b, para. 3) and
detect faults (see Buckley et al., 2018);
•have an opportunity to consider the consequences of the particular mistakes they
encounter (see Siraj et al., 2021. p. 336); and
•face scenarios where they know input may have been purposefully corrupted. (Here, I am
thinking of Schneier’s [as found in Severance, 2016] notion of “an adversary relationship
between … parties” [p. 7] wherein someone is “trying to thwart you at every turn” [p. 7].
The textbook’s authors acknowledged that pretests, which feature the intentional
corruption of examples, were designed in such a way that learners could conceivably “get
every answer wrong” [ELL, p. x].)
Given that my research questions asked “in what ways” L2 content is amenable to
opportunities for engaging students with security mindset fundamentals, I next considered how
these identified features of the Chapter 1 Pretest could be specifically exploited to engage
students with security mindset fundamentals. In this way, IV also helped to inform my judgments
with respect to the possibility (i.e. feasibility) of the opportunities I identified in the content—
and thus the amount of work that might conceivably lie ahead for curriculum designers to
leverage them more fully, which I reflect on in the next chapter. As an example, after I identified
error detection as a key feature of the Chapter 1 Pretest content, I was then in a position to
imagine more precise ways that this L2 content could facilitate (i.e., possibilize) a deliberate
introduction of security mindset fundamentals to L2 learners. Bearing in mind the fact that the
Chapter 1 Pretest enables students to search for deliberately inserted errors, I imagined that it
would be possible for instructors/instructional materials to use this as a starting point for:
•defining and developing the notion of data integrity (see Yee & Zolkipli, 2021) for
students. (Targeted fundamentals: data integrity);
•connecting analytical fundamentals of security thinking to real-world career opportunities
by raising students’ awareness of various cybersecurity roles in which technical error
detection plays a key role. (Targeted fundamentals: analytical thinking, types of
cybersecurity roles, the notion of error detection);
•providing students with opportunities later on to write their own sentences into which
other classmates can attempt to make changes/insert errors. Using the Chapter 1 Pretest
as a model, students then attempt to spot the changes made to their own sentences.
Extending the activity in this way can support an introduction to types of exploits such as
man-in-the-middle attacks, as well as the notion of hardening, which is “a process
intended to eliminate a means of attack by patching vulnerabilities” (Barker et al., 2015,
p. 130). For example, what can students do to reduce the chances that others will be able
to alter sentences (such as writing in pen versus pencil)? (Targeted fundamentals:
analytical capacities, creative capacities, practical capacities, and domain concepts of
integrity, adversarial thinking, and types of cyberattacks);
•having students revisit the Chapter 1 Pretest after some time so students can experience
firsthand how “know[ing] what should be” (Horneman, 2019, para. 9) and “track[ing]
what is” (para. 9) enables them to spot errors. Supplementary curricular materials can
highlight how relevant domain knowledge contributes to security thinking as well;
spotting “things that don’t fit” (Nassiokas, 2021b, para. 3) in any given context hinges on
knowing what ought to be in the context. (Targeted fundamentals: analytical capacities,
situational capacities, the role of specific domain knowledge in security thinking, error
detection); and
•encouraging students (with the instructor’s help) to consider the impact that different
types of mistakes (related to spelling, vocabulary, grammar, etc.) may have on the overall
Chapter 1 Pretest sentences (funny, harmful, confusing, etc.), i.e., ask “How can this go
wrong? What can transpire if this type of error happens?” This can also be generalized to
other scenarios. Students can also consider the notion of hacking in light of Schneier’s (as
found in Severance, 2016) depiction as something “that works one way, and add some
other piece to it, and suddenly it does something else—maybe something it wasn’t
intended to do” (p. 8). (Targeted fundamental: the concept of risk assessment, hacking).
In addition to error detection in the Chapter 1 Pretest, I also saw unfamiliar syntax and
vocabulary in the pretest as germane to security mindset fundamentals as these could
expose L2 learners to ambiguity and uncertainty (see Dark, 2015). I envisioned how
novel L2 content could be leveraged to introduce learners to various security mindset
fundamentals. Conceivably, this could be a pathway for:
•acknowledging students’ possible discomfort when viewing the Chapter 1 Pretest while
permitting students to reflect on the need to balance (a) being comfortable with ambiguity
and (b) the desire to resolve ambiguity. (Targeted fundamental: the notions of ambiguity
and disambiguation);
•encouraging students to consider the risks associated with resolving ambiguity too swiftly
through the use of specific examples related to both L2 learning and security situations.
(Targeted fundamentals: the notions of ambiguity and disambiguation);
•modeling how to use context clues to disambiguate meaning and structures. (Targeted
fundamentals: analytical capacities such as disambiguation); and
•providing learners with opportunities for self-awareness: what do I feel like when I
encounter ambiguity? How much uncertainty can I tolerate in my environment? Such
questions can subsequently be revisited wherever pertinent throughout the course
(Targeted fundamentals: the notions of self-awareness and situational awareness). Along
with deliberate errors and unfamiliar language in the Chapter 1 Pretest, this activity also
included specific names and geographic locations. I imagined that these details in the L2 content
could be leveraged to engage students with security mindset fundamentals by:
•encouraging students to reflect on how being familiar with other countries can help
reduce some of the ambiguity students may face in various situations, including when
engaging with the Chapter 1 Pretest. (Targeted fundamentals: global situational
awareness, the notion of disambiguation);
•prompting students to consider how recognizing personal names and their potential
origins in the Chapter 1 Pretest can help to fill in possible situational details and orient
oneself at the level of the language. (Targeted fundamentals: analytical knowledge and
capacities, global situational awareness); and
•highlighting how recognizing place names plays a role in their L2 learning experience
and extending this to interactions in cyberspace. An activity invoking global situational
awareness might be used to point out why recognizing places can be helpful when
following an information packet as it pings around the Internet. Students can use
traceroute commands to identify pings, find their associated locations, and consider
locational factors that impact Internet ping speed. (Targeted fundamentals: analytical
capacities, global situational awareness, basic technical domain concepts).
The fact that the Chapter 1 Pretest featured consistent patterns (in capitalization and punctuation)
could also serve as an avenue for introducing students to fundamental aspects of security
mindsets. To connect this aspect of the Chapter 1 Pretest with security mindset fundamentals
more deliberately, I conceived that instructors/instructional materials might:
•signal to students that the kind of thinking involved in perceiving patterns in Chapter 1
Pretest can support both L2 learning and security thinking as it helps with spotting any
anomalies that could point to the need for further investigation. Students could be
challenged to practice pattern recognition subsequently throughout the L2 learning
experience. (Targeted fundamentals: analytical capacities, the notion of curiosity); and
•encourage the students who noticed patterns in the Chapter 1 Pretest to note their
potential facility for analytical thinking relative to their classmates, as it may be an
indication that they would find a particular cybersecurity role stimulating. (Targeted
fundamentals: analytical capacities, basic cybersecurity domain roles).
As a final example here, the improbability of success for beginner students completing the
Chapter 1 Pretest was another feature of the L2 content that I identified as pertinent to my study.
I envisioned leveraging this aspect in at least two ways to introduce both creative and practical
aspects of security thinking to L2 students more explicitly. Instructors/instructional materials
could:
•address how “think[ing] outside the box” (Schneier as found in Severance, 2016, p. 8)
may result in a form of reward hacking if it entails exploiting/subverting rules (see Dark
& Mirkovic, 2015) of the Chapter 1 Pretest. In this, students could be prompted to
consider how particular uses of one’s creativity capacities may or may not undermine
their long-term language acquisition. Additionally, students could be introduced to
examples of white hat/black hat creativity. (Targeted fundamentals: creative capacities,
the notion of hacking the reward, types of hacking); and
•affirm the value of seeing and making mistakes in the Chapter 1 Pretest; describe how
exposure to errors and being allowed to manage them play a role in both L2 learning and
the development of real-world security mindset capacities (e.g., writing secure code and
creating secure networks [see Siraj et al., 2021]). (Targeted fundamentals: practical
capacities).
Before moving on to the next subsection it is important to note that in the Chapter 1 Pretest
content, there was no explicit mention of security themes. Yet, upon identifying the analytical,
creative, practical, or situational elements that were embedded in the Chapter 1 Pretest content, I
was able to imagine ways in which this content could be leveraged to draw meaningful
connections with security mindset fundamentals.
Beginning ELL Textbook: Condensing Themes From Multiple Examples of Content
The Chapter 1 Pretest represented just one coding segment in the QCA applied to the ELL
textbook. There were 71 additional coding segments in the first chapter of the ELL. Just as I
made various connections between L2 content in the Chapter 1 Pretest and the security mindset
categories/subcategories in my coding frame, I continued to imagine a variety of possible
security-germane connections with L2 content throughout the remainder of the first chapter.
While some of these connections were similar to those that I identified in the Chapter 1 Pretest,
new possibilities for connection emerged as well. I present my findings below with respect to
each of the five main categories in my QCA’s coding frame, this time drawing on multiple
examples from across the ELL textbook.
Analytical Knowledge and Capacities. Familiarity with systems, rules, and protocols
underpins analytical aspects of adversarial thinking (Hamman & Hopkinson, 2016), a key aspect
of security mindsets. Other analytical tasks associated with security thinking include pattern
recognition and outlier identification (see Nassiokas, 2021b) and disambiguation (see Dark,
2015). In all of the coding segments of Chapter 1 in the ELL textbook, I was able to connect at
least one of these analytical subcategories to some aspect of the L2 content.
I noted that some of the possibilities that I named for connecting L2 topics and tasks to
analytical knowledge and capacities felt weak or stretched to me when I viewed each one
individually. However, as my analysis progressed, these connections showed themselves to be
part of a persistent and ubiquitous thread of analytical possibilities woven throughout the ELL
content; some activities even featured multiple analytical aspects for students to manage
simultaneously (e.g., ELL, Exercise 30, p. 17; Exercise 42, pp. 25-26).
Table 10 provides a few of these possibilities for engaging learners with analytical
knowledge and capacities germane to security thinking. Listed in the middle column are some
specific aspects of L2 content that I identified as having the potential to introduce, develop,
and/or reinforce for L2 learners various analytical foundational capacities or knowledge that
underpin robust security mindsets.
Table 10
Examples of ELL Content Amenable to Opportunities for Engaging L2 Learners With Analytical
Knowledge and Capacities
Examples of Coding
segment(s)
Specific aspect of the content that I
connected to analytical capacities
Making it meaningful: what could be
said/done to engage students’ awareness
of security thinking
ELL, Exercise 7, p. 5
ELL, Exercise 11, Part I, p. 7
Patterns (antonym relationships and
alphabetization) → Attention to
patterns and outliers (see
Nassiokas, 2021b)
Emphasize that analytical thinking helps
identify patterns which can speed up
comprehension as well as help to see
things that might not belong, a key
part of security thinking. “Who
noticed any patterns here?” Risk:
apophenia (seeing patterns that don’t
exist)
ELL, Chart 1-3, p. 6
ELL, Chart 1-4, p. 8 Charts that introduce exceptions to
rules (such as pluralization;
when nouns ending in -y are
concerned, one must “omit the y
and add -ies” [p. 8] rather than
simply add -s) → Attention to
patterns and outliers (see
Nassiokas, 2021b)
Analytical capacities and domain
knowledge together play a role in
error detection. Explain that spotting
defects (see Buckley et al., 2018)
depends on knowing the difference
between special cases and true
errors. “Can you find any true errors
in this chapter?”
ELL, Exercise 18, p. 11
ELL, Exercise 19, p. 11 Task: transform long forms into
contracted forms or expand
contracted forms into long forms
→ Interaction with
systems, rules, and protocols
(see Hamman & Hopkinson,
2016)
This task involves analytical capacities
and relies on familiarity with
morphological rules and procedures.
“Students interested in this kind of
task might also like [various
cybersecurity roles].”
ELL, Exercise 20, p. 12 Task: replace words in red with
pronouns, contract new forms
with verb to be (e.g, prompt:
Sara is a student = She’s in my
class) → Interaction with systems,
rules, and protocols
(see Hamman & Hopkinson,
2016)
This task involves analytical capacities
and relies on knowing
morphosyntactic rules and
procedures. In addition to relating
this kind of task to various
cybersecurity roles as in the example
above, ask, “What data is lost
through this procedure?
ELL, Exercise 23, p. 13 New vocabulary presented without
explicit definition or translation;
picture provided for
disambiguation → Exposure to
ambiguity (see Dark, 2015),
disambiguation (see Sheldon,
2023)
Explain why disambiguation strategies
are an important part of analytical
thinking in cybersecurity and
language learning. “Get comfortable
with (some degree of) uncertainty.”
Table 10 is not exhaustive. Because analytical connections were so readily identified, this
contributed to my sense that a relationship between analysis and L2 learning was baked into the
ELL textbook. By simply pointing out to learners these relevant themes when they arise, even in
a cursory way, L2 textbook content could help sensitize students to the kinds of foundational
analytical knowledge and capacities relevant to security thinking. Rather than any one
connection on its own being compelling enough to meaningfully engage learners with
foundational analytical knowledge and capacities, I concluded that it was in the aggregate of
analytical connections that L2 textbook content could be most powerfully leveraged.
Creative Perspectives and Capacities. Tied up with one’s capacity to manipulate rules
and deal with ambiguity are strong creative capacities (Hamman & Hopkinson, 2016). Creative
capacities have been linked to novelty such as “unconventional perspectives” (Hamman &
Hopkinson, 2016, p. 13) and making “unique connections and see[ing] the world in original
ways” (p. 6). In Chapter IV, I highlighted aspects of creative thinking germane to adversarial
thinking, such as putting old things together in new ways (Hamman & Hopkinson, 2016), and
imaging how rules and operational spaces could be subverted or exploited (Dark & Mirkovic,
2015, p. 78) to achieve unconventional outcomes. The capacity to imagine unorthodox responses
was also presented as a key aspect of creative adversarial thinking (Hamman & Hopkinson,
2016).
Compared to analytical knowledge and capacities, I identified fewer instances in which
ELL textbook content supported learner engagement with creative perspectives and capacities.
Whereas the analytical connections I identified were often linked to situations in which it would
be essential for students to engage with some aspect of analytical thinking to complete a task, the
opportunities I noted for creativity did not often depend on creativity to complete the task. On
the one hand, learning the word and (first introduced in the Chapter 1 Pretest) could present an
opportunity for ELL learners on day one to explore and exploit language’s capacity for infinite
combinations, even with very limited vocabulary. On the other hand, even if this possibility were
pointed out, I imagine that it would take a deliberate effort to encourage all learners to play with
its syntactic potential. I thus acknowledged during my analysis that exposing L2 learners to new
rules, vocabularies, and concepts might not necessarily engage learners in a way that would
prompt them to think in unorthodox ways. Likewise, just as handing a person a digital device
might not automatically compel them to look for potential exploits, the content in the ELL
textbook offered potential opportunities for creativity without any guarantee of engagement.
Sensitive to this, the content identified below (Table 11) as amenable to providing opportunities
for engaging learners’ creativity should first and foremost be thought of as a starting place for
increasing learners’ sensitivity to various creative possibilities.
The examples in Table 11 are not exhaustive, yet this short list of possibilities for
engaging L2 learners with creative perspectives and capacities already demonstrates diversity
with respect to multiple linguistic and extra-linguistic features in the ELL Chapter 1. Thus, I
imagined that one specific way to take advantage of this variety might be in prompting students
regularly throughout Chapter 1 (and beyond) to consider “What can you do with X?” and ‘What
else can be done with X?” Such an approach could be useful for acclimatizing students to
outside-the-box ways of thinking that are foundational to robust security mindsets while also
potentially encouraging students to improvise language rather than parrot examples; learning
strategies involving improvisation were found in one study to impact English learners’ oral
language proficiency more positively than strategies based on memorization (Liu, 2006).
Table 11
Examples of ELL Content Amenable to Engaging Learners with Creative Perspectives and
Capacities
Coding
segment
examples
Specific aspect of the content that I
connected to creative capacities
Making it meaningful: what could be said/done to
engage students’ awareness of security thinking
ELL, Chart
1-2, p. 4
A syntactic tool (the conjunction and) for
joining things together → “Put[ting] old
information together in a new way”
(Sternberg, as found in Hamman &
Hopkinson, 2016, p. 8)
Introduce students to the idea that “Just because
something is usually used one way doesn’t mean
it can’t be used another way.” Show how and can
infinitely extend phrases; draw students’ attention
to possibilities such as creating infinite loops and
utterances never said in the language before—
with only a few basic words.
ELL, Chart
1-3, p. 6 ;
Exercise
10, p. 6 ;
Exercise
26, p. 15
Novel categorizations of the world (e.g., lack
of grammatical gender, careers portrayed as
available to women) for some ELL students
→ Interaction with novel and
unconventional perspectives
Explore with students how “we make assumptions
about how the world works. Being exposed to
alternatives can help name assumptions,
recognize other ways, and see outside the box.”
(See Bellovin, 2013; Severance, 2016)
ELL,
Exercise
14, Part II,
p. 9
Task: change sentences from singular into
plural (e.g., prompt: A soda is a drink =
Sodas are drinks.), which means hands-on
opportunities for manipulating discrete
parts of a system. → Interaction with
hacks/hacking
Introduce the notion of hacking and/or patching
relevant bits into formulae: “By adding the
desired character/characters, you can make the
message do something different than before.”
ELL,
Exercise
29, p. 17
Lack-of-exact-equivalency-of-concept (e.g.,
vocabulary for colors in English that often
do not align with other speaker groups’
categorical perceptions of color [see
McNeill, 1972]) → Making “unique
connections and see the world in original
ways” (Hamman & Hopkinson, 2016, p. 6)
An opportunity for learners to redefine their
categories or consider the existence of new ones,
to challenge what may have previously taken for
granted, and help make “unique connections and
see the world in original ways” (Hamman &
Hopkinson, 2016, p. 6). Use this to underscore
the kinds of creative thinking that underpin
exploits.
ELL,
Exercise
15, p. 10
Competition: Teams are tasked with
completing sentences (e.g., London … is a
city. / … is a big city. / … is cold.). The
winning team is the one “with the most
correct sentences” (ELL, Exercise 15, p.
10). Students generally only know a few
words at this point in the textbook, pushing
them to work within the constraints of a
limited vocabulary. → “Think[ing] outside
the box” (Schneier as found in Severance,
2016, p. 8), particularly when faced with
the improbability of success if playing
strictly by the rules
Point out the possibility for making bizarre yet
technically correct sentences such as “London is
not a dog.” In addition to pushing the bounds of
what constitutes a “correct sentence” (ELL,
Exercise 15, p. 10) students could also
- tap into language’s structural capacity for infinity
(e.g., “London is not not not a city.)
- eavesdrop on other groups to obtain answers
- distract or mislead other groups by feeding them
incorrect answers These possibilities can be
explicitly highlighted to attune students to
creativity in security thinking and raise ethical
issues.
While I found that it was a challenging process for me to connect security-germane
creative perspectives and capacities to the ELL Chapter 1 content, I still found examples
throughout the chapter that opened up the potential for engaging with creative perspectives and
capacities. Moreover, I remarked that the culminating activity, which was to “write a paragraph
about Mars” (ELL, Exercise 43, Part II, p. 27), was noticeably more open-ended than the first
activity, which was to “check (√) the correct sentences” (ELL, Chapter 1 Pretest, p. 1). This
raised for me the question of whether opportunities for creativity might increase as
textbooksupported language tasks became more sophisticated. However, my analysis was limited
to elementary material in the first chapter of the textbook and this was beyond the scope of
inquiry.
When examining the content for possible connections to security-germane creative
perspectives and capacities, the interconnected nature of relationships with other security mindset
fundamentals was also frequently evident: in Table 11, I identified ELL textbook content (ELL,
Exercise 15, p. 10) that could illustrate how creativity depends on familiarity with system rules—
thus intertwining with analytical capacities. At the same time, I also noted how students’
capacities to imagine outside-the-box possibilities for exploitation could fuel the implementation
of strategies for shaping one’s environment—thus intertwining with practical
capacities. I discuss these next.
Practical Knowledge and Capacities. In Chapter IV, I highlighted a variety of themes
relevant to practical aspects of security mindsets. These included exposure to social engineering
strategies (Hamman & Hopkinson, 2016); strategies for adapting, shaping, and/or selecting
environments (Sternberg, 2002); attending to motivation (Katz 2019); and anticipating others’
actions (Hamman & Hopkinson, 2016). Other characteristics of real-world situations were noted
as central to practical thinking as well, such as the need to manage circumstances with no
guaranteed outcomes (Schaltegger et al., 2024), experiencing the consequences of mistakes such
as “writing insecure code” (Kaza, as found in Sirak et al., 2021, p. 336), working in “multi-agent
scenario[s]” (van der Hoek et al., 2005, Abstract), and having opportunities to view exchanges in
terms of adversaries (Severance, 2016). With this in mind, Table 12 provides various examples of
some of the L2 content that I identified in the ELL textbook as amenable to engaging students
with practical capacities.
Table 12
Examples of ELL Content Amenable to Engaging Learners with Practical Knowledge/Capacities
Coding segment
examples
Specific aspect of the content that I
connected to practical capacities
Making it meaningful: ideas to engage student
awareness of security thinking
ELL, Exercise 4,
Parts I, II & III,
p. 3
Content focuses on moods and states, not only of the
learner, but also of other classmates: vocabulary
includes happy, sad, hot, cold, nervous, relaxed,
hungry, and tired. → Attending to the
motivations of others (Katz, 2019)
Anticipating others’ actions (Hamman &
Hopkinson, 2016; Katz, 2019) is a crucial
aspect of practical security thinking. How can
knowing others’ state and/or knowing your own
state help you to identify “possible player
actions” (Schneider, 2013, p. 4)?
ELL, Jump-start
your English, p.
3; Exercise 17,
p. 10; Jump-start
your English, p. 19
Task: elicit information (exposure to implicit
strategies for beginning conversations in ways
that puts others at ease) → Awareness of how
“social and communication skills” can be used
to get “people to release essential information or
to perform critical actions” (Esteves et al., 2017,
p. 72)
Point out to students how these practical aspects of
language can be used to get “people to release
essential information or to perform critical
actions” (Esteves et al., 2017, p. 72). Give
some examples of specific social engineering
strategies.
ELL, Chart 1-5,
p. 11; Exercise
19, p. 11
Contractions as an example of native-speaker usage
→ Avoid detection (Hamman &
Hopkinson, 2016; Katz, 2019)
Underscore adapting to an environment as a way to
not draw attention to oneself (i.e., fit in or
evade detection). “Contracting forms is one
way to mimic native English speakers. What are
advantages of adopting such practices?”
ELL, Jump-start
your English, p. 19
Content instructs learners to “use [their] own
names and information” (Jump-start Your
English, p. 19) → Exposure to/opportunity for
real-world application (Jethwani et al., 2017)
With real-world application, students consider more
meaningfully what’s at stake when sharing
information. “What is okay to share with
whom, when, where, and why? How could your
information be used?”
ELL, Jump-start
your English, p. 19
Content provides a range of possible responses
(based on a diagram of a continuum: “great,”
“good,” “not so good,” etc.) in an interview
exchange → Recognizing the possibility for no
guaranteed outcomes (see Schaltegger et al.,
2024)
Human exchanges—though often formulaic and
predictable—can still follow a number of
different paths. “How might an interaction be
impacted if you reply ‘fine’ versus ‘not so
good’? How can your response influence
someone else’s response?”
ELL, Exercise
37, p. 23
Task: Partner A gives a command such as “Put your
hand under your chair” (ELL, Exercise 37, p.
23) and then Partner B does it. →
Awareness of how “social and communication
skills” can be used to get “people to release
essential information or to perform critical
actions” (Esteves et al., 2017, p. 72)
People use language to shape environments and
influence outcomes. This content highlights a
tool at learners’ disposal for more effectively
anticipating others’ actions—here, the trick is
simply to use language to motivate another
person to perform specific actions/shape one’s
environment.
Owing to the fact that ELL Chapter 1 content routinely invoked everyday knowledge
(e.g., places around town, family members, learners’ personal details) or was modeled on
realworld situations (e.g., introducing oneself, meeting a new teacher), textbook content
throughout the sample afforded learners repeated opportunities to engage with practical themes.
In dialogues and competitive games in the L2 content, I identified opportunities for L2 learners
to navigate tasks without a guaranteed outcome (see Schaltegger et al., 2024) as well as
experience the consequences of one’s own mistakes (Siraj et al., 2021) while working
strategically in “multiagent scenario[s]” (van der Hoek et al., 2005, Abstract).
Apart from (arguably) the competitive game activities, ELL content did not present any
exchanges in terms of adversaries (Severance, 2016). Using IV, however, it was only a short leap
to imagine that any existing textbook-supported interactions could be framed in terms of
adversaries. Take, for example, a listening activity (ELL, Exercise 17, p. 10) that featured an
adult introducing herself to students as “the substitute teacher.” In the dialogue, these students
subsequently greet the substitute and share personal information. If learners were invited to
consider the possibility that the person was not actually the substitute at all—but an imposter
using the role to gain an advantage—the exercise could be amenable to opportunities for
introducing practical social engineering strategies such as pretexting. Whether a potential
adversary relationship is overlaid onto an activity seriously or humorously as in the case above—
see Chowdhury’s (2022) discussion and promising findings with respect to “humor as a
pedagogical tool” (p. 175)—discussions about and the probability (or improbability!) of such a
threat could be highlighted. Once again, students could engage with various security mindset
fundamentals in the context of everyday interactions.
Situational Knowledge and Capacities. Situational awareness encapsulates a process of
perceiving, comprehending, and projecting (Endsley, 1995), which drives one’s ability to
compare what ought to be with what actually is in a given situation (Horneman, 2019). At its
core, this depends on the integration of internal and external processes (Stanton et al., 2001),
which is why information gathering and global literateness are often key contributors to these
processes (see Allen, 2015; Horneman, 2019). In addition, another vital aspect of situational
awareness is a capacity to notice “holes and vulnerabilities … that could be hurdles” (Esteves et
al., 2017, p. 73). With this in mind, I searched for ELL textbook content that could be leveraged
to support the meaningful introduction of situational awareness to L2 learners. Table 13
provides various examples of some of the L2 content that I identified in the ELL textbook as
amenable to opportunities for engaging students with some of these situational knowledge and
capacities.
Table 13
ELL Content Amenable to Engaging Learners with Situational Knowledge and Capacities
Coding
segment
examples
Specific aspect of the content that I connected
to situational capacities
Making it meaningful: what could be said/done to
engage students’ awareness of security thinking
ELL, Exercise 33,
p. 20
Task: students describe their current city or town
(with vocabulary such as friendly, safe,
dangerous, crowded, and noisy), compare their
answers with a classmate, and note any
differences → sense of setting
Attention to key details in one’s environment can be
used to discuss the role of situational awareness
in security thinking. Concrete examples can be
used to extend this to cyberspaces.
ELL, Exercise 29,
p. 17
Task: students look around classroom or outside to
identify things with specific colors in their
immediate environment → perception and
comprehension (see Endsley, 1995)
Highlight the essential role of perception in
comprehending the details of one’s environment.
Concrete examples can be used to extend this to
cyberspaces.
ELL, Jump-start
your
English, p. 3
ELL, Exercise 4,
p. 3
Asking for or eliciting information (e.g., people’s
names, nationalities/places of origin,
affective state → surveying/information
gathering (Esteves et al., 2017)
Content can be used to highlight processes that
support information gathering; connect
information gathering to the notion of security
mindsets as a kind of “curiosity manifested” (R.
Cloutier, personal communication, September 29,
2020).
ELL, Exercise 21,
p. 12
ELL, Exercise
11, p. 7
Task: students check their answers → track[ing]
what is” in light of “what should be”
(Horneman, 2019, para. 9) and “infer[ring]
when should be and is do not match” (para.
9)
Situational awareness involves knowing “what should
be” (Horneman, 2019, para. 9) and being able to
compare it to “what is” (para. 9). Content offers a
logical starting point for highlighting how these
skills play an important role in troubleshooting.
ELL, Exercise 23,
p. 13:
In the photo, there is a reflection in the astronaut’s
helmet → perception and comprehension (see
Endsley, 1995) and “incorporat[e] multiple
data sources” (D.
Allen, 2015, p. 15)
Use this as an example to consider sometimes
overlooked details in physical and cyber spaces.
How might details such as reflections in images
posted online inadvertently reveal
information/impact anonymity?
To support the introduction of rules, vocabulary, locations, and customs, textbook content
routinely provided learners with opportunities to perceive and comprehend stimuli (photos,
illustrations, maps, and text). In this way, perception and comprehension presented themselves as
basic necessity for the effective completion of most learning tasks. Because of the pervasive
nature of opportunities to monitor, detect, recognize, interpret, and evaluate, perception and
comprehension might be described as the ongoing background music, the cantus firmus, of L2
learning. Content itself did not draw explicit attention to these processes, yet many activities
could be used to consciously introduce students to them and perennially connect them to
cybersecurity fundamentals through contexts more familiar to students.
While the above suggests possibilities for very general engagement with situational
knowledge and capacities, I found that the ELL textbook Chapter 1 also contained material that
could be leveraged to support more specifically learners’ global awareness. Previously, I noted
the value of global awareness to cybersecurity and to national security more generally, based on
Klein and Rice’s (2014) assessment that “a lack of formal instruction about the history and
cultures of the rest of the world, limits U.S. citizens’ global awareness, cross-cultural
competence, and ability to assess situations and respond appropriately in an increasingly
interconnected world” (p. 47). Based on this, I sought to identify if ELL textbook content could
provide learners not only with an immediate sense of setting, but occasions to attend to broader
environments as well. The ELL textbook chapter incorporated many geographical places, such as
Asia, Bangkok, Brazil, Canada, China, Ethiopia, France, Hawaii, Kuwait, Lebanon, London,
Syria, Toronto, Vancouver, and Vietnam. In addition, names in the text included many of global
origins, such as Amita, Ali, Kofi, Franco, Nadia, Paulo, Rika, Sai, Taka, and Yuri that could serve
as a springboard for activating or developing students’ global awareness. ELL content also
showed types of food popular in the United States (ELL, Exercises 13, p. 8; Exercise 14, p. 9).
This content could be leveraged in numerous ways—for example, as a catalyst for discussions
about how familiarity with these details can help learners begin to recognize target audiences or
origins—or as a chance for students to consider what geo-locational information they may be
revealing about themselves when sharing names, cities, and foods online.
Thus, in various ways, I judged ELL textbook content to be amenable to opportunities for
engaging students with situational knowledge and capacities.
Foundational Cybersecurity Domain Knowledge and Skills. De Bruijn and Janssen
(2017) considered how to raise cybersecurity awareness more effectively by “connecting
cybersecurity to values other than security alone” (p. 6) and “to other tangible and clear issues”
(p. 7). To this end—and with the understanding that analytical, creative, practical, and situational
security mindset fundamentals take their shape from concerns at the heart of cybersecurity—I
examined textbooks for content that would support the introduction of various topics related to
security. Table 14 presents examples of some of the L2 content that I identified in the ELL
textbook and the ways in which I imagined them being amenable to opportunities for raising
security-specific issues with L2 learners.
Table 14
Examples of ELL Content Amenable to Providing Opportunities to Introduce Cybersecurity
Domain Knowledge and Skills
Specific aspect of the content
(coding segment) Introduction of Basic Cybersecurity Domain Knowledge/Skills
Vocabulary: sick, nervous, relaxed, and
tired (ELL, Exercise 4, p. 3)
Vulnerability
In which states are people more/less vulnerable to social engineering and other threats?
More than one answer is possible
(ELL, Exercise 2, p. 2)
Ambiguity
What are some ways to handle the possibility that there is more than one solution? How
could a strong desire to resolve ambiguity potentially fail students?
Vocabulary for places around town
(ELL, Exercise 10, p. 6)
Adversarial thinking
If you were a thief, why would each place be interesting to you? Which places may be
most vulnerable and for what reasons? Bridging (the perceived gap between)
physical and cyber, if you were a cybercriminal, why might each place be interesting
to you?
Telephone game (ELL, Exercise 32,
Part II, p. 20)
CIA: Integrity, Availability
As students build a message through a chain of classmates, what are some threats to the
original message’s integrity and availability?
Missing words (ELL, Exercise 38, p.
23)
Data recovery, Integrity
How are strategies for restoring/recovering missing important to information security?
How can the availability of data impact the integrity of a message?
Exchanging personal information
(ELL, Jump-start your English, p. 3)
Value of information/data, Cyber hygiene
When might it be unsafe to share one’s name? What can hackers/others do with your
name? What should factor into our comfort about decisions to share personal
information?
What information can be entered/posted where and when online?
Conversations involving age and
financial status (ELL, Exercise 28, pp.
16-17)
Privacy, Value of information/data
Culturally, what information is considered private? Security-wise, what information
should be regarded as private? Discuss the notion of data type and data value with
respect to age and financial status.
Photo content (ELL, Exercise 26, p.
15 ; ELL, Exercise 13, p. 8; ELL,
Exercise 14, p. 9; ELL, Exercise 36, p.
22 ; ELL, Exercise 12, p. 7) :
Adversarial thinking, Integrity, Situational awareness
What information is publicly available just by examining the photo(s) and how could
that information be used? What are some ways an image could have been changed
or enhanced? Is it possible to tell if the photo is authentic? How could this difficulty
be exploited by bad actors? How are our implicit assumptions influenced by details
in an image? What information is lost when backgrounds are removed from photos?
Students make judgements about a
situation based on visual images (is the
woman sick or well? Is the coffee hot
or cold?) (ELL, Ex. 31, pp. 18-19)
Risk assessment
What are the stakes of getting these judgements wrong? Which judgements are more
high-stakes and why? Difference between being and looking like something.
Photograph of a cat, dog, mouse,
rabbit, and bird who are all cuddled
up together (ELL, Exercise 36, p. 22)
Integrity, Patterns and outliers
Departure from normal behavioral patterns is a avenue for introducing students to
concepts such as image integrity and how knowing behavioral patterns—so as to
spot outliers—may be a tool for challenging the notion that things are simply as
they appear.
Conversation tasks (ELL, Jump-start
your English, p. 3 & 19; ELL, Exercise
17 p. 10; ELL, Exercise 21, p. 12)
Social engineering
Investigate the mechanics of starting a conversation and gaining trust. What social
engineering strategies are built into our social protocols? How can reciprocity be
exploited by bad actors?
Vocabulary for family members (ELL,
Exercise 25, Part I, p. 14)
Assumptions
Who do we assume is trustworthy? How can that be taken advantage of? (pretexting)
I observed that the high-level content I related to cybersecurity domain knowledge and concepts
also invoked lower-level analytical, creative, practical, and situational knowledge and capacities,
such as:
•considering differences in predicted patterns of behavior (analytical);
•adopting a novel perspective (creative);
•reciprocity strategies (practical); and
•perceiving, comprehending, and projecting with respect to photos of various scenes
(situational).
In this way, I saw how foundational connections with security mindset capacities in the ELL
content possibilized coherent opportunities to introduce more specific security mindset issues as
well. While connections were sometimes rooted in phenomena generally associated with
communicative language (i.e., rule-governed features, pragmatics, etc.), I was also able to
imagine connections for development through the particular topics selected by the textbook’s
authors (such as family vocabulary, typical foods, and types of jobs). For example, some ELL
activities (e.g., ELL, Jump-start your English, Part II, p. 3, Exercise 22, p. 12) prompted learners
to share and ask for personal data such as names; I saw this as affording integrated moments for
learners to consider the value of their data and appropriate contexts for sharing. Here, learners
could easily explore open-ended security-related questions such as “What type of data is a
personal name and what is its potential value to others/hackers?” I also noticed that some L2
topics and tasks more readily lent themselves to being identified as amenable to introducing
security mindset concepts; compare, for example, an opportunity to read a short paragraph about
Venus (ELL, Exercise 43, Part I, p. 26) with an opportunity to play a competitive game in teams
(ELL, Exercise 15, p. 10). The implications of this for future curriculum possibilities are
discussed in the next chapter.
ELL Textbook in Review
My analysis of an ELL textbook permitted me to investigate possibilities for making
connections between security mindset fundamentals and the L2 processes, practices, and topics
within the textbook. I sought to identify if and how analytical, creative, practical, and situational
features in the content could be meaningfully related to foundational aspects of security thinking.
In addition, I aimed to articulate some of the ways in which textbook material could be used to
highlight higher-level domain knowledge and skills foundational to cybersecurity.
In doing so, I noticed that features of L2 learning might be most effectively exploited
through direct instruction as a means to alert students to security mindset knowledge and
capacities. In this vein, I demonstrated how pointing out salient aspects of L2 content
subsequently allowed for drawing explicit connections between topics and tasks in L2 learning
and those germane to security thinking.
I also observed that textbook material was amenable to providing far more than one-
anddone introductions of various security mindset themes. Because the salient features that I
identified were embedded throughout the analyzed portion of the textbook, I saw how L2 content
could be used to repeatedly emphasize security mindset fundamentals—in a manner arguably
consistent with the ingrained habits of security mindsets themselves.
Connections Across Textbooks
In conjunction with these findings from the ELL textbook, I analyzed two other resources
as well. This allowed me to note similarities and differences between L2 resources with respect
to the opportunities that I identified for engaging learners with security mindset fundamentals. In
what follows, I present my findings as they relate two more single coding segments, one from the
French textbook and one from the digital Spanish curriculum. While the Chapter 1 Pretest in the
ELL textbook reflected an emphasis on mechanical details and real-world topics, readers will
notice that the content highlighted below from the French textbook embodies a more
communicative and cultural focus. Finally, the Spanish excerpt that I have chosen to highlight
captures the central role of stories in a comprehension-based L2 program. In presenting these
findings, I point out commonalities between the resources as well as distinctions that emerged
from variations in languages and instructional approaches.
Beginning French Textbook: Expanding on a Single Example of Content
When French language learners arrive the end of Unit 1 in their textbook, they encounter
a final section called “À votre tour!” (French, pp. 38-39) which contains “open-ended activities”
(French, p. T34) so learners can “demonstrate what they can do with the language, and …
monitor their own progress through critical thinking and self-expression” (p. T34). In this
section, the second-to-last exercise is a “culminating listening and speaking activit[y]” (French,
p. T41) in which two students must act out a friendly picnic scene using the provided prompts
(Figure 7).
Figure 7
“En scène” speaking and listening activity from French textbook
5 En scène
PARLER With a classmate, act out the following scene.
CHARACTERS:
You and a French guest
SITUATION:
You are in France. Your French friends have invited you
to a picnic. You meet one of the guests and have a
conversation.
• Greet the guest. • Tell the guest how old you are and ask his/her age. • Ask how things are. • (The
guest waves to a friend.) Ask the guest the • Tell the guest that you are American name of his/her
friend.
and ask the guest if he/she is French. • (It is the end of the picnic.) Say good-bye.
Note. Reproduced from Discovering French Today! French 1, Teacher’s Education by Valette
and Valette, 2013, p. 39.
While one student plays themself in the scene, the second student is assigned the role of
French picnic guest who has also been invited to the picnic (French, Exercise 5, p. 39). In their
respective roles, L2 learners will greet one another, share personal information, and then say
good-bye. The two characters are not yet acquainted with each other at the start of the exchange.
•Because the content allows students to use the details of their own life or play the role of
a realistic character so as to support “students’ use of language beyond the classroom
setting” (French, p. T41), I identified this as an opportunity for real-world application
(see Jethwani et al., 2017)—an important piece in developing more practical aspects
associated with security thinking (see Luse & Burkman, 2021; Siraj et al., 2021).
Before partners begin speaking, they must take note of a few situational details: the
conversation takes place in France at a picnic, and they have been invited to this event by
“French friends” (French, Exercise 5, p. 39). Learners may instinctively fill in other details—
perhaps they imagine being outdoors in good weather during the daytime—but any further
details have not been provided; the hand-drawn illustration accompanying the exercise also
contains no background information.
•Because a sense of setting is provided, I identified this as an opportunity to engage
learners with the notion of situational awareness and the utility of having an accurate
“operational picture” (D. Allen, 2015, p. 6).
Just as the setting provided is not overly descriptive, there is also a conversational guide
for students that is not overly prescriptive; a note in the margin tells instructors that “answers will
vary” (French, Teacher’s note, p. 39).
•Because this task allows for students to accomplish its various aspects in many ways, I
saw this as an opportunity to expose L2 learners to open-ended challenges (see
Severance, 2016, p. 8) able to bolster both creative and practical aspects of security
thinking.
When students begin conversing, they have an opportunity to act out French greeting
protocols such as saying hello and shaking hands. As students adopt these French conversational
practices to fit into their simulated French environment, they must also make choices about
whether they will use less formal or more formal French greetings.
•Because learners are encouraged to adopt culturally appropriate behaviors and linguistic
forms with a particular setting, there is an opportunity to highlight practical security
mindset notions such as fitting in to evade detection (Hamman & Hopkinson, 2016) and
adapting to one’s environment (Sternberg, 2002).
The next task is to ask the French guest “how things are” (French, Exercise 5, p. 39).
Learners once again have the ability to accomplish this in more than one way. They can also offer
varying and theoretically infinite responses (e.g., Things are going well. / Things are going very,
very well. / Things are going very, very, very, very well, etc.), which can be more or less polite
(e.g., Things are going well, thanks.).
•Because this aspect of the task leaves room for students to exploit the flexible and
generative nature of language, I identified this as an opportunity to imagine unorthodox
responses (Hamman & Hopkinson, 2016) which can be highlighted as an important
creative aspect of security thinking.
The student is then prompted to give their own nationality before inquiring the nationality
of the French picnic guest. The French picnic guest may respond by giving their nationality.
•Because the content prompts students to give information as a way to facilitate getting
that information from another person (i.e., introduces reciprocity), there is an opportunity
to develop practical themes associated with security mindsets such as how “social and
communication skills” can be used to get “people to release essential information or to
perform critical actions” (Esteves et al., 2017, p. 72).
•Because this aspect involves people’s nationalities and takes place in an international
setting, there is an opportunity to connect learners to situational themes such as global
awareness (SEI, 2015).
•Because nowhere in the activity is it explicitly stated that the French guest must respond
to any of the inquiries, there is a technical loophole for learners to exploit; this can be
pointed out as a way to introduce the notion of a hack as “something that a system allows
but which is unintended and unanticipated by its designers” (Schneier, 2023, p. 9).
Employing the same share-ask formula, the first student tells their own age and then asks
the same information of the French guest.
•Because French numbers follow a different pattern than English, learners may need to
reflect on this alternative way of representing numerical concepts in order to satisfy this
aspect of the dialogue. I saw this aspect of the activity as exposing students to “see[ing]
the world in original ways” (Hamman & Hopkinson, 2016, p. 6), a foundational part of
creative perspectives and capacities in security thinking.
•Because the activity prompts students to ask for information, i.e., engage in surveying
and information gathering (Esteves et al, 2017, p. 73), this aspect of the activity can be
used to broach situational awareness.
•Because learners are guided to exchange personal information (asking telling ages,
nationalities), there is an opportunity to consider topics such as the value and sensitivity
of such information.
•Because content directs students to share information with a stranger simply by virtue of
having a mutual acquaintance, I named an opportunity to introduce students to zero-trust
principles.
After these exchanges, the French guest suddenly pretends to wave at another person at
the picnic. The first student is prompted by the textbook to ask who it is. Once the French guest
identifies their friend (which necessitates choosing between various phrases and forms), students
arrive at “the end of the picnic” (French, Exercise 5, p. 39) and the characters bid each other
good-bye.
• With the exchange completed, I saw an avenue for encouraging learners to reflect back on
what information was ultimately shared and what assumptions were made about the
person they shared it with.
The authors of the French textbook held the view that “recombination and re-entry of
previously learned material provide students with opportunities to demonstrate how well they can
communicate in French” (French, p. T40). The French picnic activity above represented precisely
this kind opportunity, wherein students would be situated in a novel scenario and tasked with
“put[ting] old information together in a new way” (Sternberg, as found in Hamman &
Hopkinson, 2016, p. 8). By affording opportunities for students to stitch elements together into
new-to-them phrases, the textbook was presenting students with one of their first opportunities
for more “open-ended … self-expression” (p. T34). I saw this as able to support an introduction
to basic concepts in cybersecurity such as the relationship between low-level goals (e.g.,
attention to grammar and syntax, for example) and high-level goals (e.g., communicating
meaning). But—as learners would be just venturing out with these newly acquired building
blocks of language in the hopes of uttering things that meant something—I also saw how the L2
content could introduce learners to their very own “Hello, World!” moments. For computer
programmers, this refers to “the first program anyone writes in a new language or on a new
computer … that outputs ‘Hello, world’ onto a display device” (Langbridge, 2013, p. 74). In the
wake of such moments, fledgling programmers are poised to move from parroting “the most
basic syntax of a programming language” (Langbridge, 2013, p. 74) to a new expressive reality;
possibilities abound in terms of what might be done with these newly acquired building blocks.
Pariser (2011) noted that “if [a programmer is] clever enough, [they] can make and manipulate
anything [they] can imagine” (p. 166).
Approaching this culminating speaking activity (French, Exercise 5, p. 39) through the
lens of security mindsets permitted me to name aspects of the L2 content that could serve as a
starting point for introducing textbook users to fundamentals associated with security thinking.
To gain a sense of how I extended my application of IV further to imagine various concrete ways
to possibilize these connections, see Appendix G: Imagining Ways to Leverage a Single Example
of French Textbook Content. As with the other L2 resources in this study, the security-relevant
themes that I identified in this speaking activity were not named as such in the content.
Nevertheless, I noted a number of connections with security fundamentals in this activity—and
throughout the content—that could be exploited as avenues for introducing security thinking to
L2 students.
Beginning French Textbook: Condensing Themes From Across Multiple Examples of Content
I identified content that could be connected to each of the five main categories in my
QCA’s coding frame.
Analytical knowledge and capacities. One of the particular ways in which I found the
French textbook to be amenable to learners’ engagement with security-germane analytical
knowledge and capacities was through content that afforded explicit opportunities for students to
observe and apply procedural rules—such as attaching/separating affixes to/from root stems or
extracting parts of sentences (such as words or phrases) to insert other parts in accordance with
technical linguistic formulae. There were textbook-supported opportunities for students to check
their work as well. French textbook material also supported opportunities for learners to
experience uncertainty, ambiguity, and disambiguation; new language was generally presented in
context first, with clarifying material not provided until later. As with all of the resources, I found
that analytical capacities and knowledge were invoked throughout. For some specific examples
of L2 content that I identified as amenable to opportunities for engaging French textbook users
with analytical security mindset fundamentals, see Appendix H: Analytical
Connections in French Textbook.
Creative Perspectives and Capacities. With respect to creative perspectives and
capacities, I judged that the French textbook could afford learners with robust avenues for
viewing, approaching, and interacting with the world in alternative ways—through repeated
exposure to new social conventions, grammatical categories, and contexts. While there were also
plenty of textbook-supported opportunities for students to manipulate linguistic rules and social
norms, there was little in the L2 content that suggested learners ought to experiment with or
exploit these norms and rules. Here, I saw how L2 content could support an introduction to
creative capacities, but I acknowledged that L2 content did not, at present, seem to. For a brief
overview of some of the L2 content that I identified as amenable to opportunities for engaging
French textbook users with creative security mindset fundamentals, see Appendix I: Creative
Connections in French Textbook.
Practical Knowledge and Capacities. I also found ways that the French textbook could
support opportunities for learners to engage with practical knowledge and capacities. I perceived
a greater emphasis on social protocols and politeness strategies in the French textbook compared
to other resources, which likely contributed to my identification of rich avenues for broaching
topics related to social engineering. However, opportunities for strategic reasoning may have
been weaker because many of the activities, exercises, and dialogues involve pre-scripted rather
than open-ended language. I imagined that such content could nevertheless be easily modified to
permit learners to make more decisions about what language to use and how to use it. I also saw
repeated opportunities for textbook learners to make predictions about language and behavior,
but there was little evidence to suggest to me that French textbook content in its current state
would sufficiently excite learners into taking the time to do this. I consequently imagined the
practical value of introducing (the potential for) an adversary or threat to motivate students.
Appendix J: Practical Connections in French Textbook contains specific examples from the
French textbook that I identified as amenable to opportunities for engaging learners with
practical security mindset fundamentals.
Situational Awareness. One of the ways that I found the French textbook could support
L2 learners’ engagement with situational knowledge and capacities was through its attention to
the details of various physical settings. Compared the other resources, the French textbook
frequently provided times and places in which activities were set as well as the personal details
of interlocutors. While all languages have elements that take their meaning from extra-linguistic
details in one’s external environment (see O’Grady et al., 1997l; Stapleton, 2017), French (and
Spanish) grammar may sometimes oblige speakers to encode situational details in ways that
English grammar doesn’t have to, such as time of day, gender of people, and relative social
status. I found that these mechanics were indeed broached in the French textbook content. I
imagined that in having to attend to such details, students could be prompted to reflect on them
more intentionally to make judgements about the trustworthiness of information, interlocutors,
and platforms; opportunities for perception, comprehension, and projection with respect to
operational spaces were thusly embedded in the French content.
As with all the resources, the French textbook also contained maps and referred to places
around the world, and there were multiple opportunities for learners to ask questions. I identified
such content as providing a platform for developing learners’ global knowledge and information
gathering capacities. For specific examples of French L2 content that I identified as supporting
opportunities for learners to engage with a variety of situational knowledge and capacities, see
Appendix K: Situational Connections in French Textbook.
Basic Cybersecurity Concepts and Domain Knowledge. My analysis revealed that
content in the French textbook was amenable to opportunities for broaching a variety of
cybersecurity domain concepts in multifarious ways. In all three resources, there were aspects
inherent to communicative language that supported opportunities for introducing students to
basic cybersecurity concepts. The French textbook in particular highlighted issues associated
with pragmatic language. Referring to how people understand and use language (O’Grady et al.,
1997), pragmatics is “especially concerned with implicit meaning, with inference and the unsaid”
(Levinson, 2001, p. 1). Central to this are factors such as speaker intent, “the addressee’s
background attitudes and beliefs, their understanding of the context … and their knowledge of
how language can be used for a variety of purposes” (O’Grady et al., 1997, p. 725). Numerous
examples of pragmatic language were present in all of the L2 resources (e.g., greetings, asking
questions, making statements, adapting one’s politeness and/or formality, etc.), but the French
textbook pointed these aspects out the most often. I imagined that these instances could be
leveraged to move from the more general idea that “language can be used for a variety of
purposes” (O’Grady et al., 1997, p. 725) toward the security-specific idea that language can be
used to get “people to release essential information or to perform critical actions” (Esteves et al.,
2017, p. 72). In addressing the foundational mechanics of how “social and communication skills”
(Esteves et al., 2017, p. 72) can be used by attackers, the focus might then be extended to include
consequences, such as data being compromised—circling back to other foundational concepts such
as confidentiality, integrity, and/or availability.
Possibilities for broaching basic security topics were not always grounded in phenomena
inherent to L2 learning and communication, however. Sometimes the connections I made
between L2 content and security mindsets concepts were rooted in specific choices made by the
authors. Along with the other resources, the French textbook dealt with the topics related to
personally identifiable information. Specifically in the French textbook, activities invoking
names, ages, origins, family members, and phone numbers could serve as a starting point for
developing opportunities for learners to engage with concepts such as data value, sensitivity,
anonymity, privacy, and cyber-hygiene. Appendix L: Basic Cybersecurity Concepts and Domain
Knowledge in French Textbook contains several examples of content from the French textbook
that I saw as able to provide opportunities to broach basic cybersecurity concepts and domain
knowledge with learners.
French Textbook in Review
Similar to the ELL textbook, I found that I was routinely able to connect processes,
practices, and topics within the French textbook to analytical, creative, practical, situational, and
domain-specific aspects of security thinking. It is noteworthy that both the ELL and French
textbooks linked linguistic building blocks (grammar rules and pronunciation, for example) with
overarching communication goals (greetings and information gathering, for instance). I saw how
this combination could support opportunities for students to hold continuously in tension
lowlevel aspects of language (i.e., the trees—and sometimes the twigs, leaves, and bark) and
high-
level aspects of language (i.e., the forest). Importantly, I saw how this could be leveraged to
encourage an individual to apply the question “How could x fail?” to both the trees and the
forest.
Beginning Spanish Curriculum: Expanding on a Single Example of Content
While the ELL textbook and French textbook often highlighted grammar to support
learners’ communication goals, the digital Spanish curriculum took a different approach. This
resource prioritized comprehension and meaning making as a way to develop students’
communicative proficiency. The example of Spanish L2 content in the section below illustrates
the central role that stories played in this comprehension-based L2 curriculum.
On the last day of their first unit in the beginning Spanish curriculum, L2 learners watch
a video of wildebeests on a riverbank arguing over an ambiguous lump floating up out of the
water (Figure 8).
Figure 8
Still frame from wildebeest ClipChat activity
Note: This screen shot is reproduced from the video Wildebeest by Birdbox Studio (2012, 0:48).
In this comprehension-based activity, the lesson plan directs instructors to “use the
ClipChat strategy to tell … students the Wildebeest story as you point to still frames from the
short film to support their understanding” (Spanish, Lesson Plan, p. 37). “ClipChat is a version of
MovieTalk, an instructional strategy developed by Dr. Ashley Hastings, that provides students
with extensive input that is comprehensible” (Spanish, Lesson Plan, p. 36). With this technique,
“the instructor pauses the film frequently and describes everything that is visible on the screen
and everything that has happened since the last pause” (Spanish, Lesson Plan, p. 36) in the target
language. Instructors can access a sample script to inspire their play-by-play narration of the
video (Appendix M: Script for Wildebeest ClipChat Activity in Spanish Resource). On the
students’ end, ClipChat activities boil down to “interpret[ing] a story while watching a short
film” (Spanish, Lesson Plan, p. 36). The stated lesson objective is for learners to “understand a
simple present-tense narrative in Spanish” (Spanish, Lesson Plan, p. 36).
At the start of the clip (0:07), students watch as two wildebeests stare at an object
bobbing in the water. While there are no words throughout the clip—just grunts—viewers are
able to follow the wildebeests’ conversation through illustrated speech bubbles that periodically
appear in tandem with the grunts (see Figure 8):
1. After a few seconds of watching the lump in silence, the first wildebeest announces
that it is a crocodile (0:11).
2. The second wildebeest shakes its head and says that it is a log (0:14).
3. The first wildebeest, after repeating that it is a crocodile (0:17), picks up a pebble and
tosses it at the object (0:19).
4. As nothing happens, the second wildebeest reiterates that it’s a log.
5. The first wildebeest wastes no time in responding that it is a crocodile (0:23), grabs a
stick, and pokes the object in question. The object jiggles only slightly.
6. The second wildebeest, unconvinced, still maintains that it is a log (0:29).
7. The first wildebeest, even more adamant now, declares that it is a crocodile (0:30) and
starts splashing water on the object (0:32).
8. When nothing transpires, the first wildebeest jumps from the water’s edge to stand on
top of the object (0:35).
9. After a moment, the first wildebeest starts to speak but is precipitously interrupted
when the lump snaps its head up out of the water and swallows the wildebeest whole
(0:39).
10. Following the incident, the back of the crocodile resurfaces, looking just like as much
like a log as it did before.
11. The second wildebeest, having witnessed the entire affair, ultimately accepts that it is
a crocodile (0:47).
12. The frame widens to reveal a third wildebeest on the scene—presumably a recent
arrival—who pronounces the object to be a log (0:49).
The video clip concludes here.
As with the material in the other resources in this study, I approached this particular
ClipChat activity through the lens of security mindset fundamentals, which made it possible for
me to then draw links between different aspects of the material and security mindset
fundamentals. Some of these connections that I identified were those that I saw as able to give
students first-hand opportunities to practice foundational aspects of security thinking.
Perhaps the strongest example of this can be found in how the ClipChat activity is
infused with opportunities for students to work through ambiguity; because this exercise is
narrated by the instructor using almost entirely new vocabulary, learners must rely on context
clues (e.g., visual input, teacher gestures, lexical cognates such as animals and cocodrilo) to
make meaning. What is more, the lesson plan states that teachers should not “be afraid to use
more unfamiliar vocabulary than … in other situations (Spanish, Lesson Plan, p. 39). This is
“because the students will have the support of visuals (still frames from the video) to understand
the story that you are telling” (Spanish, Lesson Plan, p. 39). As such, “they will be able to
understand what you are saying much better than if you were simply telling a story with gesture”
(Spanish, Lesson Plan, p. 39). It was though this potential for exposure to ambiguity and
opportunities to deal with it (see Dark, 2015) that I identified the content as amenable for
engaging learners’ analytical capacities.
Similarly, with respect to setting details in the video, I identified situational awareness as
a relevant security mindset fundamental. Here, I saw how the L2 content could support an
opportunity for perceiving an unknown object in an environment while at the same time inspiring
learners to try to comprehend its meaning. I imagined that this could also serve as a pathway for
sensitizing students to the value of anticipating “future states or events of the elements of the
environment” (L. Jiang et al., 2022, p. 57527); at least for the character in the video clip,
predicting how events will unfold is a matter of life and death!
At the same time that learners may be trying to guess how the video will play out, the L2
content affords learners an opportunity to watch the wildebeests in the video clip attempt to do
the same thing. Indeed, this comprehension activity predominantly involves students observing
and understanding the actions and decision-making of others. For this reason, I classified much
of this activity as lending itself more logically to encouraging students to think about various
security mindset fundamentals rather than providing students with opportunities to practice
security mindset fundamentals, above examples notwithstanding. Avenues for this kind of
security-oriented metacognition were rooted in various aspects of the plot, such as:
•how the wildebeests try to make sense of an unverified object in their environment—I
connected this with possibilities for considering the notion of ambiguity (see Dark, 2015),
the role of analytical capacities such as disambiguation, and the interplay of analytical
capacities and situational awareness;
•how the first wildebeest seeks to show that the object is a crocodile—I connected this to
situational awareness and the notions of perception, comprehension, and projection (see
Endsley, 1995). These three aspects of situational awareness have an important role to
play in the scenario. However, while the first wildebeest employs analytical thinking to
aid comprehension, it (disastrously) stops short of projection until it becomes too late;
•how the crocodile looks and acts very much like a log—this feature of the content can be
connected to adversarial thinking and practical strategies, particularly those employed by
cyber actors to avoid detection (see Hamman & Hopkinson, 2016; Katz, 2019). These
concepts can be invoked yet again when the crocodile hides itself immediately following
the attack;
•how the crocodile stays in the water near the riverbank—this environment is
advantageous for camouflaging the crocodile and attracting prey, notably wildebeests. I
connected this to foundational practical capacities such as adapting, shaping, and/or
selecting environments (see Sternberg, 2002);
•the predator-prey relationship between the wildebeests and the object—I connected this
to practical themes, as (a) the content presents an opportunity for viewing an exchange in
terms of age-old foes (see Severance, 2016) and (b) there is an opportunity to reason
“about the best strategy to adopt in a given multi-agent scenario, taking into account the
likely behaviour of other participants in the scenario, and, in particular, how the agent’s
choice of strategy will affect the choices of others” (van der Hoek et al., 2005, Abstract).
•how the first wildebeest draws increasingly closer to the object—the crocodile may be
allowing the wildebeest to feel more and more secure before attacking. I viewed this as
relevant to practical capacities on the part of the crocodile. The wildebeests, on the other
hand, not only displayed a lack of practical capacities, but a lack of creativity as well. I
noted a failure of imagination on the part of the wildebeests to consider how feeling
increasingly secure might be exploited by a potential crocodile (see Hamman &
Hopkinson, 2016);
•the wildebeests’ failure to take measures to protect themselves—this aspect of the content
underscores a missed opportunity to “take note of … holes and vulnerabilities … that
could be hurdles” (see Esteves et al, 2017, p. 73) by asking “How could this fail?” I also
connected this to the notion of security mindsets (see Schoenmakers et al., 2023) writ
large;
•how the wildebeests argue over the “operational picture” (D. Allen, 2015, p. 6)—I
connected this to situational awareness themes, as there is an opportunity to highlight and
examine the kinds of surveying and information gathering (see Esteves et al, 2017) that
the characters undertake in the clip. Similarly, I saw the different assumptions voiced by
the wildebeests as an opportunity to clarify concepts such as disinformation and
misinformation for students—which one characterizes the views expressed by the
incorrect wildebeests?
•when the crocodile attacks—this incident may have been avoided if the wildebeests had
considered the questions How can this fail? How likely is it that this will fail? and How
catastrophic would it be if this failed? I therefore linked this to the valuable role that risk
assessment can play (see Ross et al., 2021). Also germane to this aspect of the content is
the idea of information gathering (see Esteves et al, 2017) gone wrong. I judged concepts
such as mitigation and resilience to be germane as well; and
•the fable-like, universal nature of the story—there is an opportunity for students to
consider the moral(s) of the story, which can be applied to a host of real-world
experiences (see Jethwani et al., 2017).
Approaching this Spanish comprehension-based activity through the lens of security
mindsets facilitated my identification of L2 content able to serve as a springboard for introducing
learners to security mindset fundamentals. For me, the humorous story quality of this coding
segment was what seemed to bring an excitement not necessarily inspired by the single cases I
analyzed in the other resources. Consistent with what I found in the other resources, however, I
noted that the security fundamentals I linked to this activity could also be linked to many other
examples across the resource, discussed next.
Beginning Spanish Curriculum: Condensing Themes From Across Multiple Examples of
Content
In searching for inroads in the Spanish resource that could support an introduction to
security mindset fundamentals, I found examples of content relevant to all of the main categories
in my QCA’s coding frame.
Analytical Knowledge and Capacities. All resources contained material that could
support opportunities for students to engage with analytical knowledge and capacities. One
notable difference between the comprehension-based Spanish curriculum and the other resources,
however, was that the Spanish resource generally presented grammatical structures implicitly
with far fewer grammatical explanations. The ELL and French textbooks, on the other hand,
often presented grammatical structures and rules explicitly, which I imagined could support more
immediate connections with analytical knowledge germane to security mindset fundamentals.
Yet, even though the Spanish curriculum didn’t explicitly highlight grammar nearly as often as
the other resources, by virtue of being a language, Spanish still has inherent structures that
govern the relationships between words and rules. Consequently, I noted a panoply of low-level
linguistic elements in the Spanish resource. In this way, I saw that any of the resources could be
leveraged to connect learners with security-relevant analytical knowledge and capacities, so long
as a deliberate effort were made to highlight the various building blocks in question.
With respect to ambiguity and uncertainty, I found that the Spanish resource might
present L2 learners particularly robust opportunities for navigating ambiguity and uncertainty;
the comprehension-based quality of the resource continuously afforded occasions for making
meaning out of linguistic input through decontextualization and disambiguation.
For some examples of Spanish content that I identified as amenable to opportunities for
engaging learners with analytical security mindset fundamentals, see Appendix N: Analytical
Connections in Spanish Resource.
Creative Perspectives and Capacities. Compared to the French textbook in this study, I
found that the Spanish content I analyzed did not focus as much on comparing and contrasting
social conventions or differences between Spanish and other languages. As a consequence,
relatively fewer examples of content stood out to me as affording opportunities to view the world
in alternate ways.
The Spanish curriculum was nonetheless still quite amenable to opportunities for
engaging learners with creative perspectives and capacities. One of the ideas that often emerged
in the Spanish resource was that instructors should not panic if they failed to reach a certain point
in the curriculum by a certain time in the course. Rather, taking the time to go in depth and make
connections with students’ interests was portrayed as desirable (Spanish, Lesson Plan, p. ).
“Storyasking” (Spanish, Lesson Plan, p. 19) was a type of activity unique to the Spanish resource
that embodied this view; teachers were encouraged to introduce it to students as:
a really fun activity in which we create a story together. We use our imaginations to
describe someone or something in Spanish. I usually have a general idea about what the
story will be about, but you will come up with ideas to determine how it unfolds.
(Spanish, Lesson Plan, p. 19)
I saw the potential here for L2 content to support really robust creative processes, particularly in
light of the relationship between time and creativity that Sternberg and Lubart (1991) observed.
For a brief overview of some of the L2 content that I identified as amenable to opportunities for
engaging Spanish textbook users with creative security mindset fundamentals, see Appendix O:
Creative Connections in Spanish Resource.
Practical Knowledge and Capacities. The Spanish resource contained opportunities for
whole-class, open-ended speaking interactions. I imagined that these un-scripted, “multi-agent
scenario[s]” (van der Hoek et al., 2005, Abstract) could serve to expose learners to situations
characterized by fewer guaranteed outcomes, compared to those in the ELL and French
textbooks. Moreover, the Spanish resource and ELL textbook featured opportunities for learners
to reflect on personality traits and affective states. The Spanish resource provided multiple
opportunities for learners to develop detailed descriptions of classmates and celebrities, for
example. I saw this as a potential platform for directing learners’ attention toward considering
what may motivate other people and what details could be salient when anticipating their likely
actions. Finally, in step with the other resources, I found evidence to back up the claim that the
Spanish resource also emphasized “useful language in the class so that [students] are prepared to
communicate in the real world” (Spanish, Printable overview for parents and guardians).
Appendix P: Practical Connections in Spanish Resource contains examples of content from the
Spanish resource that I saw as able to support opportunities for learners to engage with practical
security mindset fundamentals.
Situational Awareness. Similar to the ELL and French textbooks, Spanish content
provided opportunities for learners to notice environments and attend to various situational
details. There were very basic ways that all resources could be said to involve perception,
comprehension, and projection. However, the Spanish resource stood out with respect to offering
learners a strategic overview of what to expect. While the ELL and French textbooks included
material meant to inform students about the kind of content to come in each lesson, the Spanish
went further in prompting learners to survey the terrain ahead more broadly in terms of overall
L2 coursework. One handout provided an overview of the types of tasks, themes, and
instructional methods one could expect to encounter during the course (Spanish, Parent Letter)
while another directed students “to take home your syllabus and read through it” to review the
information and consider “What did you read that makes you hesitant or causes you concern?”
(Spanish, Lesson Plan, p. 17). I identified such content as amenable to being leveraged to
sensitize learners to the value of situational awareness capacities such as “tak[ing] note of …
holes and vulnerabilities … that could be hurdles” (Esteves et al, 2017, p. 73) and gaining a
sense of “what should be” (Horneman, 2019, para. 9). For various examples of French L2
content that I named as germane to efforts to engage learners’ situational knowledge and
capacities, see Appendix Q: Situational Connections in Spanish Resource.
Basic Cybersecurity Concepts and Domain Knowledge. I found that
content in the
Spanish resource could support opportunities for broaching cybersecurity domain concepts.
While I saw a variety of cybersecurity concepts that could be broached by using the topics and
tasks in the Spanish content as a jumping off point, I most frequently identified opportunities in
the content for learners to reflect on data type (e.g., public, private, restricted) and data value
(Carnegie Mellon University, 2021; Siraj et al., 2021). Appendix R: Basic Cybersecurity
Concepts and Domain Knowledge in Spanish Resource provides other examples of content from
the Spanish resource that I imagined could be leveraged to introduce learners to various
foundational cybersecurity concepts and domain knowledge.
Spanish Resource in Review
The Spanish resource contained material that I identified as amenable to opportunities for
engaging learners with analytical, creative, practical, situational, and domain-specific
fundamentals of security thinking. To me, one of the most compelling characteristics of this
resource was its emphasis on time as an integral part of L2 learning. Content often featured
reminders for teachers that rather than completing lessons according to an external schedule, it
was worthwhile to spend the time necessary to help students work through things. While I noted
previously that such an outlook could be amenable to opportunities for creativity, I also identified
this aspect of the content as potentially more tolerant of the suggestions that learners
be allowed time to explore security fundamentals and concepts more generally. Moreover, this
outlook espoused in the Spanish content could support such exploration while simultaneously
supporting learners’ engagement with ambiguity. Sternberg and Lubart (1991) held that: In
many schools, most of the assignments students are given are due the next day or within a
very short period of time. In such circumstances students cannot develop a tolerance for
ambiguity because they cannot spare the time to allow a situation to be ambiguous. (p. 611)
In this way, not only the topics and tasks in the Spanish content were amenable to opportunities
for engaging learners with security mindset fundamentals, but its underlying approach could be
said to be amenable as well.
Conclusion
I sought to examine the ways in which currently available L2 textbook content could
support opportunities for L2 learners to engage with analytical, creative, practical, and/or
situational knowledge and capacities foundational to security mindsets. I also looked for ways
that L2 textbook content could support opportunities to broach basic cybersecurity concepts and
domain knowledge with L2 students. Findings shared in this chapter were generated by my
analysis of three beginning L2 learning resources: an ELL textbook, a French textbook, and a
downloadable digital Spanish resource.
To provide an in-depth account of how QCA and IV shaped my analysis, I highlighted a
single example of content from the ELL textbook. By pointing to the connections that I perceived
between the L2 content and various security mindset fundamentals, I detailed how this coding
segment could be leveraged in multiple ways to support opportunities for engaging L2 learners
with foundational security mindset themes (i.e., security-germane analytical, creative, practical,
situational, and domain knowledge and capacities). I next reported on the possibilities that I saw
for leveraging L2 content throughout resources—i.e., across multiple segments—with respect to
each security mindset fundamental to convey the relationship I observed between each of the
foundational parts and the whole to which they belonged.
I found that in all three of the L2 resources that I examined, it was possible for me to
identify avenues for engaging L2 students with security mindset fundamentals. While some
possibilities for broaching security mindset fundamentals were linked to abstract aspects of
language having to do with pronunciation, spelling, grammar, vocabulary, structure, or usage, for
example, other possibilities were linked to specific topics such as sharing personal information
and information gathering. The approach and emphases of particular resources sometimes
impacted how readily I was able to identify avenues for exploitation with respect to certain
security mindset fundamentals, but—although these variations sometimes influenced the
robustness or volume of particular connections I identified—all resources still showed
themselves to be amenable to connections with all of the security mindset fundamentals. In fact, I
imagined multiple ways in which every coding segment in every resource could serve as a
platform for broaching security mindset fundamentals—whether this entailed drawing students’
attention to a particular aspect of security thinking or providing students with an opportunity to
practice a foundational aspect of security thinking, or both.
When viewing any given connection between L2 content and security thinking in
isolation, I often noted that it could feel to me to be of little consequence; some connections were
certainly stronger than others. When viewing the sample as a whole, however, I found that all of
these connections contributed to a compelling aggregate of multifarious, oft-repeated
opportunities which I imagined could be leveraged powerfully to engage learners with analytical,
creative, practical, situational, and domain-specific fundamentals of security mindsets. As these
connections were rooted in tasks and topics throughout the resources, I concluded that there was
potential to leverage L2 content in a way that could support incidental, sustained engagement
with each of the security mindset fundamentals targeted in this study.
However, in this investigation, I observed no explicit mention of security themes in the
L2 content that I examined. Consequently, I found that imagining possibilities for leveraging L2
content depended on first naming these connections between L2 content and security mindset
fundamentals. The implicit, wholly untapped nature of connections suggested to me that any
future attempts to leverage this L2 content to engage L2 learners with security mindset
fundamentals hinges on a “deliberate effort” (Kaza, as found in Siraj et al., 2021, p. 2) to further
develop these inroads beyond simply naming them.
What these findings imply and why this may represent a uniquely valuable opportunity
for both cybersecurity education and L2 learning is discussed in the next chapter.
Chapter VII. Conclusions and Recommendations
The need is critical to prepare students for a future characterized by increasing
cybersecurity concerns (Austin, 2020; Georgescu, 2021; Kurt Peker & Fleenor, 2020, Rahman et
al., 2020). Increasingly, various measures have been recognized as valuable to shoring up overall
cybersecurity efforts. These include developing and recruiting the cybersecurity knowledgebase
of more people (Crumpler & Lewis, 2019), cultivating a diverse security-savvy workforce (e.g.,
Burrell & Nobels, 2018; Jethwani et al., 2017; Mountrouidou et al., 2019), leveraging expertise
from technical and non-technical disciplines (Craigen et al., 2014; J. Hall & Rao, 2020), and
cultivating robust security mindsets in experts and end users to help everyone weather changes
across dynamic security landscapes (e.g., Dark, 2015; Dutton, 2017; Dutton et al., 2019; Esteves
et al., 2017; Jarjoui, 2023; Pournaghshband, 2013; Schneider, 2013; Schoenmakers et al., 2023).
To this last point, one security practitioner observed that although the emphasis is often on
“technology and related developments in cyber security, it’s important that we go back to basics
and make sure we understand and promote the need for a security mindset” (Nassiokas, 2021a,
para. 8).
With this in mind, at a time when cybersecurity educational initiatives have been gaining
momentum in the United States, I considered what role K12+ language-learning programs might
play in responding to various challenges noted above. Given current widespread enrollment in
U.S. K12+ FL and ELL programs—and thus the hypothetical possibility for targeting a vast
student body—I was keen to identify viable opportunities for supporting cybersecurity
educational goals through L2 learning.
In particular, I wanted to explore how L2 study might serve as an interdisciplinary
pathway for introducing foundational security mindset concepts to L2 learners. I noted that L2
learning subject matter itself might be particularly well-suited to introducing these fundamentals
to learners; just as security mindsets could be said to engage analytical, creative, practical, and
situational knowledge and capacities (with these informed by cybersecurity concepts and domain
knowledge), language could be said to be rule-governed, creative, practical, and situated (see
Kuiken, 2023). Based on this, I suspected that a search for connections between cybersecurity
mindset fundamentals and L2 learning had the potential to be fruitful. I hoped this might be a
first step in understanding how to leverage L2 settings to introduce cybersecurity education
opportunities among the nation’s diverse student body of ELL and FL learners.
To this end, I investigated L2 curriculum resources for ELL, French, and Spanish learning
—in the form of two physical textbooks and one downloadable digital curriculum resource—to
gauge if and how existing ELL and FL content might present opportunities for introducing
(including naming, practicing, and/or reflecting upon) cybersecurity mindset themes to L2
learners.
The research method used to advance this investigation was a qualitative content analysis
(QCA). QCA presented itself as a logical choice as it “can … be used for exploratory research
when little is known about the content-based phenomenon being studied” (Parker et al., 2011, p.
2). I paired the QCA with IV, a methodological technique with roots in phenomenological
research, which helped me to view ELL, French, and Spanish L2 content through a security
mindset lens. This permitted me to identify specific content that could be connected to
foundational security mindset knowledge and capacities; it was in these connections that I saw
in-roads for engaging L2 students with such fundamentals. The study’s coding frame acted as a
checklist for me while I was examining the L2 content. This coding frame was made up of
security mindset fundamentals selected from a blend of two theoretical frameworks: Hamman
and Hopkinson’s (2016) adaptation of TTI (Sternberg, 1988) for adversarial thinking and
Endsley’s (1995) Model of Situational Awareness as presented by Horneman (2019). Together,
TTI’s attention to analytical, creative, and practical capacities, along with core aspects of
situational awareness, gave shape to the study’s research questions:
1. In what ways, if any, is L2 content amenable to opportunities for learners to engage
with analytical, creative, practical, and/or situational knowledge and capacities which
are foundational to security mindsets?
2. In what ways, if any, can L2 content provide opportunities for raising basic
cybersecurity concepts and domain knowledge for learners’ consideration?
In my investigation, I both reduced and expanded on data in L2 resources. Because QCA
allows researchers to organize material by condensing it into a few categories (Schreier, 2012), I
had the ability to collapse many examples of L2 content into a single coding category (e.g.,
having to do with analytical knowledge and capacities). IV, on the other hand, permitted me to
extend material in different possible ways. I saw the world in a grain of sand—and how even a
single word such as bonjour could provide textbook users with opportunities to develop their
appreciation for system rules (e.g., orthographic, phonological, morphological, and pragmatic)
while exposing them to an attention-getting and rapport-building tool used by social engineers.
Before beginning the analysis, I had suspected that security mindset fundamentals did indeed
manifest themselves in second language learning content; I was unprepared for just how
multifaceted this manifestation actually was.
Discussion and Implications of Research Findings
My analysis revealed that all curricular resources in this study contained multiple
examples of material amenable to providing opportunities for L2 learners to engage with
analytical, creative, practical, and situational knowledge and capacities associated with security
thinking. I also identified content in each L2 resource that could function as a springboard for
introducing basic cybersecurity concepts and domain knowledge. In what follows, I discuss these
findings with respect to each of the main categories in my coding frame which drove the
analysis. In this, I consider the nature, extent, and implications of avenues that I identified in L2
content for engaging L2 learners with security mindset.
Analytical Knowledge and Capacities
I found that analytical knowledge and capacities were invoked by the L2 content that I
examined. One of the particular ways in which L2 resources were found to be amenable to
learners’ engagement with analytical knowledge and capacities germane to security thinking was
through content that afforded opportunities for students to observe and apply procedural rules.
Through tasks involving the mechanics of language, I imagined how L2 content could support
learners’ ability to identify the technical elements needed to both build effective messages and
understand what was being built. Similarly, possibilities that I saw for spotting pattern outliers or
detecting errors (see Buckley et al., 2018; Nassiokas, 2021b) also hinged on students’ knowledge
of L2 rules and procedures.
Such low-level, arguably banal tasks are critical: while the analytical knowledge and
capacities invoked in attaching and separating affixes to and from root stems (for instance) are
neither sufficient for L2 learning nor for security mindsets, they are nevertheless vital to both
(Schoenmakers et al., 2023; Sternberg, 2002). Hamilton (as found in Siraj et al., 2021) argued
that “truly” (p. 336) comprehending cybersecurity threats involved “technical expertise” (p. 336).
Moreover, taking advantage of opportunities for creativity in the L2 resources depended on
students’ familiarity with systems rules and procedures as well—calling to mind Hamman and
Hopkinson’s (2016) assertion that recognizing possibilities for exploitation also depends on
analytical capacities. In the context of teaching cybersecurity students, they argued that “Any
attempt to teach adversarial thinking to students with little technical aptitude could prove futile,
because in order to understand how hackers think, a student must have some baseline level of
innate technical ability” (Hamman & Hopkinson, 2016, p. 15). In step with this, Schoenmakers et
al. (2023) found a consensus among cybersecurity professionals that “digital, physical, and social
worlds are filled with social conventions and abstractions … that … can be hacked or reimagined
with a more granular understanding of the world” (p. 6). It is significant, therefore, that in the L2
resources I investigated, content was found to afford learners regular opportunities to hone this
kind of granular socio-technical thinking. This was true even as the emphasis on structures versus
meaning varied between resources (with the French and ELL texts highlighting more of the
former and the Spanish resource the latter).
Regardless of resource or approach, L2 content was also found to be amenable to
engaging learners with disambiguation, another key aspect of security thinking. While L2
resources could regularly expose learners to uncertainty and ambiguity through novel words,
rules, and/or practices, the resources also featured content designed to help students disambiguate
meanings, structures, and functions. Both ambiguity and disambiguation played key roles in the
content I evaluated and aligns with what is known about L2 learning generally; students with a
low tolerance for ambiguity may be less likely to succeed in L2 (Sternberg,
2002). What is more, a lack of exposure to ambiguity may negatively impact L2 learning
(Daqing, 2021). Just as Dark (2015) recommended that cybersecurity students be allowed to face
ambiguity, so L2 students must “learn to cope with ambiguity because ambiguity is an
inescapable part in language learning” (Daqing, 2021, p. 252). It is significant for both L2
learning and security mindsets that I found L2 content could support continuous opportunities for
students to wrestle with multiple or imprecise meanings, often spanning both
technical/mechanical and social boundaries.
This drumbeat of opportunities for analytical connections noted above made it difficult
for me to imagine an L2 student using any of the resources would be able to completely avoid
every opportunity for engagement with system rules, patterns and outliers, error detection, and
disambiguation. Even with variations in pedagogical approach, each of the analyzed portions of
L2 content were found to be amenable to opportunities for learners to engage with analytical
knowledge and capacities foundational to security thinking. Yet at the same time that I found
connections with analytical fundamentals to be copious, I was also struck by how a connection
was not necessarily compelling or memorable on its own. That there were pervasive
opportunities to connect to analytical security mindset fundamentals—and that they might easily
go unnoticed—helped me to further imagine ways to ultimately exploit these analytical
connections in the L2 content. Two promising avenues emerged for leveraging L2 content.
One way that I saw it would be possible for L2 content to be leveraged for engaging
learners with analytical knowledge and capacities was to capitalize on the aggregate nature of
connections. I imagined that this could be achieved by pointing them out to learners whenever a
salient point of connection arose in the L2 content. This might initially require explicitly priming
students to underlying security concepts—such as disambiguation, familiarity with rules,
recognizing patterns, and detecting errors through direct instruction while also articulating how
these underpin security mindsets and L2 learning. Then, as the L2 learning experience unfolded,
I imagined that relevant moments could be briefly highlighted. However, while “clarity at the
start” (Walberg, 1990, p. 472) can be a quick way to guide “learners to see things the teacher’s
way” (p. 472) it can also inhibit learners’ “autonomy and deep personal insights” (p. 472).
Mindful of this, it is important that I was able to identify space in the lessons and activities for
also encouraging students to recognize relevant opportunities on their own. Regardless of
whether pertinent foundational connections with security thinking were named by students,
materials, or the instructor, the emphasis would be on familiarizing students with the roles that
analytical knowledge and capacities play across diverse settings—rather than on spending any
great length of time on any single example with respect to a cybersecurity skill or concept.
As well as capitalizing on L2 content to support persistent, incidental engagement with
security mindset fundamentals, another possibility for leveraging identified analytical
connections that I imagined was in selecting specific examples of L2 content and developing
these more deliberately to engage students more deeply with security mindset fundamentals. A
carefully chosen exercise could be used as a springboard for developing a mini-lesson or activity
involving analytical aspects of security mindset fundamentals. While this might mean ultimately
departing from the L2 textbook content, such security vignettes would nevertheless always be
derived from something in the L2 content. Security mindset fundamentals could thus still remain
tied to the contexts of everyday human interactions that I observed in the L2 resources,
potentially avoiding some of the pitfalls associated with generic “cookie-cutter” (Jarjoui, 2023,
p. 1) approaches to security awareness campaigns, which have been criticized as insufficient for
changing people’s behaviors (Bada et al., 2019; He et al., 2020; Richardson et al., 2020). As L2
learners are likely to be personally familiar with many of the everyday contexts presented in the
L2 resources that I examined (e.g., meeting/greeting people, sharing/asking for information about
people, etc.), security mindsets could be presented advantageously as relevant to these enduring
concepts in students’ daily lives. Just as “activities … relevant to learners’ lives and interests”
(Teravainen-Goff, 2022, p. 16) have been noted as valuable for student engagement in L2
learning, for cybersecurity educational purposes, such “real-world … scenarios” (Arabo &
Serpell, 2019, p. 139) are also more desirable than “just presenting theoretical and textbook
materials with some out of date scenarios” (p. 129).
Because much of the L2 content I identified as amenable to opportunities for learners to
engage with analytical aspects of security thinking hinged on features integral to L2 learning
(rather than the mutable topic choices of authors), these findings yielded by my imaginative
process likely have some application for other L2 resources not represented in the sample.
Irrespective of approach and language, whether students are explicitly taught or merely exposed
to subsystems in L2 settings, engagement with them requires at least some basic interaction with
rules and systems (Snow & Hoefnagel-Höhle, 1975). With this general understanding in mind,
and with respect to the findings of this study, I submit that there are countless untapped
possibilities for leveraging L2 content as a way to engage students with analytical knowledge and
capacities germane to security mindsets.
Creative Perspectives and Capacities
If analytical thinking involves understanding, implementing, and troubleshooting rules
and procedures in a system, then creative thinking means a facility for playing with these rules
and procedures (Hamman & Hopkinson, 2016). I found that opportunities for such creativity had
the potential to be supported by the L2 content that I examined. I identified occasions in all three
resources for learners not only to manipulate linguistic and social rules but potentially
experiment with them. I also found that L2 content presented learners with avenues for viewing,
approaching, and interacting with the world in alternative ways—through repeated exposure to
new social conventions, grammatical categories, and contexts. This was significant, because I
saw such content as able to offer learners a taste of the “unconventional perspectives” (p. 13) that
Hamman and Hopkinson (2016) linked to Schneier’s conception of hacker mindsets. These
perspectives may undergird hackers’ facility for experimentation owing to their ability to make
“unique connections and see the world in original ways” (Hamman & Hopkinson, 2016, p. 6).
That I identified L2 content amenable to opportunities for engaging learners’ creative
perspectives and capacities in L2 learning is in step with a scholarly view of human languages as
creative systems steeped in novelty (R. Jones & Richards, 2015; O’Grady et al., 1997, Ricœur,
1973; see also Maniam, 2004). Von Humbolt’s (in Maniam, 2004) famous description of
language—“the infinite use of finite means” (p. 13)—underscores the immense possibility for
creative thought and action. Indeed, L2 learning has been linked to an increase in learners’
creativity (see Agostini et al., 2021). L2 learners “need to learn new patterns … [and] appropriate
new ways of thinking about what they perceive as established and taken for granted”
(Wegrzecka-Kowalewski, 2018, p. 55). In bilingual education classrooms, a variety of students in
the classroom may serve to show students “that there is more than one lens through which to
perceive the world” (McAllister, 2024, para. 10).
However, the difference between adopting new perspectives or experimenting with rules
and actually subverting things is important in security contexts—and I saw no evidence in any of
the resources I examined that students were prompted to do the latter, even when I identified the
possibility for playing around with rules. While experimentation is a key aspect of creativity in
security thinking, grasping how it might be used to achieve unconventional outcomes (or bend,
break, and exploit conventions altogether) is also critical in cybersecurity contexts (see Dark &
Mirkovic, 2015; Hamman & Hopkinson, 2016). Because the L2 content I examined contained
activities that promoted experimentation but not exploitation, I imagined how such L2 materials
could be paired with deliberate efforts to draw students’ attention to such possibilities as a way to
highlight—if not necessarily always practice—this additional aspect of creative thinking (see
also Esteves et al. [2017] for their distinction between the “explorative and exploitative” [p. 72]
kinds of thinking that hackers may employ at different stages of an attack).
Here, Hamman and Hopkinson’s (2016) insights provided direction for moving forward.
Uncertain as to whether creativity was teachable, Hamman and Hopkinson (2016) posited that it
might still be “stimulat[ed]” (p. 15) by overlaying “the ‘hacker mindset’ with the creative
component of the intellect” (p. 15). They envisioned this as potentially engendering “novel
approaches for teaching the ‘unconventional perspectives’ of hackers” (p. 15). To this end, I
imagined that the question “How (else) can [the content in focus] be used?” could be introduced
as a pedagogical tool in L2 learning settings. Alongside discussions about how various words and
rules are typically employed in the target language, I imagined that routinely posing this question
could stimulate L2 learners’ attunement to myriad micro-possibilities throughout the L2 content
for security-germane creativity.
During my analysis, overlaying this hacker mindset on L2 content was ultimately what
helped me identify opportunities for engaging students with the creative perspectives and
capacities deemed important to exploits (and defending against them). I saw how L2 content
could serve as a vehicle for students to take creative risks that involve bending and breaking the
rules of various subsystems in the target language—from the grammatical power of not to swiftly
change an entire supposition, to modifying or falsifying one’s accent through attention to
pronunciation, students could be encouraged to consider how the L2 content they are learning
can be played with “to exploit and subvert [system rules]” (Dark & Mirkovic, 2015, p. 78). Even
social protocols—such as when to employ formal or informal greetings—were not simply rules
to be followed, but norms that could be finessed, presenting L2 learners with opportunities to
hack social dynamics that others take for granted and “alter … the operational space” (Dark &
Mirkovic, 2015, p. 78; see also Schneier, 2023).
All three of the L2 resources offered inroads for highlighting creative perspectives and
capacities regardless of approach. However, the extent to which I imagined creative possibilities
being supported by L2 content—and the overall robustness of these opportunities—varied among
the L2 resources I investigated. Because the French textbook tightly scaffolded learners’
speaking, learners had relatively fewer textbook-supported occasions to go off-script than in the
Spanish resource, which included relatively more open-ended speaking activities. The ELL
textbook was situated in between. Owing to how such differences were a result of variations not
inherent to the languages themselves, I suggest that L2 materials and instructors may greatly
influence the extent to which students realize (or do not realize) that possibilities for creativity
exist.
Whether or not students engaged in these opportunities personally or simply had their
attention regularly drawn to them, I imagined that this introduction to creative perspectives and
capacities through L2 content might play a foundational role in attuning students to this way of
thinking and the fact that there are people who think this way. As Schneier (2008) argued, “You
don’t have to exploit the vulnerabilities you find, but if you don’t see the world that way, you’ll
never notice most security problems” (para. 6).
Practical Knowledge and Capacities
In addition to finding ways that L2 content could engage learners with analytical and
creative aspects of security mindsets, I found that L2 resources could also support opportunities
for introducing learners to practical knowledge and capacities underpinning robust security
thinking.
One of the ways in L2 resources were found to be amenable to learners’ engagement with
practical knowledge and capacities was through content that exposed learners to practical aspects
of language, including politeness strategies and strategies for eliciting information from others.
I saw these as opportunities to raise learners’ awareness about how skillful communication can
be used to get “people to release essential information or to perform critical actions” (Esteves et
al., 2017, p. 72). Whenever the L2 resources broached formality, greeting protocols, or politeness
strategies, I saw them as in fact presenting tools in a hacker’s repertoire. Importantly, this could
be leveraged to help fill the need for social engineering education and awareness-raising (see
Aldawood & Skinner, 2018). Such practical aspects embedded in the L2 content could also be
used to emphasize to L2 learners the human side of some of cybersecurity’s most intractable
problems (see Carley, 2020; Hanna & Blanken-Webb, 2022; Morris et al., 2018; Severance,
2016; Sharevski et al., 2018).
Added to this were possibilities I identified in the L2 content for strategic reasoning and
planning, such as open-ended dialogues involving “multi-agent scenario[s]” (van der Hoek et al.,
2005, Abstract). These tasks could afford moments for L2 speakers to make decisions not only
about what to say but also to strategize over which particular way to say it, and to some extent,
anticipate the actions of others. I imagined that such exchanges could stimulate students to
consider their strategic choices rather more purposefully if overlaid with the possibility of an
adversarial relationship (see Hamman & Hopkinson, 2016). L2 resources also supported
moments for learners to practice adapting their behavior and language and as a way to operate
less conspicuously in their target environments; I saw this as offering viable inroads for
broaching the strategic notion of “evad[ing] detection” (Hamman & Hopkinson, 2016, p. 12;
Katz, 2019, Abstract)—salient to both attackers and security personnel.
There were also avenues for students to practice anticipating others’ actions and consider
their motivations, such as when L2 content referred to people’s mental, physical, or emotional
states. I named these as content-supported opportunities to connect learners more specifically to
an “important component of cybersecurity education” (Katz, 2019, Abstract), i.e., attempting to
understand the motivation of attackers “and how they think” (Abstract). More general avenues
existed across the L2 content for learners to make other kinds of predictions, including guessing
what was likely to come next during or after an utterance. These findings are in line with what is
known about language comprehension, namely that prediction is a skill that plays a role in
everyday communication (Huettig, 2015). Anticipation is also important in security thinking
(Hamman & Hopkinson, 2016; Hamman et al., 2017; Katz, 2019), and these L2-content
supported possibilities for anticipation could be leveraged to pave the way for other
cybersecurity education efforts that “attempt to teach students how to out-think their opponent”
(Katz, 2019, p. 3).
In language, human beings have a medium for negotiating their everyday environments.
The L2 resources that I examined captured this relationship between language and daily life and
I was subsequently able to identify many ways for L2 learners to engage with practical
knowledge and capacities; content supported myriad opportunities for both talking about and
practicing how to employ greetings, gestures, exclamations, questions, topics, pronunciation, or
formality to achieve specific outcomes. I imagined how L2 content could be leveraged to
promote a more hands-on introduction to practical knowledge and capacities as this seemed
particularly appropriate. Conversation scenarios supported by the L2 content (e.g., introducing
oneself to one’s classmates) could permit a hands-on introduction to pretexting and other social
engineering tactics. However, other real-world scenarios mediated chiefly by language—such as
phone calls, emails, and texts—were not featured in the L2 content that I investigated, even
though these could permit a more experiential introduction to pretexting, phishing, and other
social engineering tactics. Luse and Burkman (2021) persuasively argued that such experiential
learning was key for teaching both mechanical and behavioral elements of social engineering. In
view of this, I identified places in the L2 resources that could benefit from the addition or
substitution of L2 material (such as a phishing email in lieu of a paragraph about Venus [ELL,
Exercise 43, p. 26]) to support learners’ engagement with practical security mindset
fundamentals. I develop this proposal to deliberately substitute and/or add various L2 content in
my subsequent discussion of recommendations, given that such modifications could still support
primary L2 learning objectives (e.g., reading comprehension, vocabulary).
Situational Awareness
Language can be viewed as a situated phenomenon (Inbar et al., 2001; Saussure,
1916/1986). This can refer to broader cultural and historical contexts, but language can also be
situated in concrete physical spaces as conversations take place between speakers in settings. In
harmony with this understanding, the L2 resources I examined presented manifold examples of
content that could be exploited to encourage learners to attend to situational details, both real and
imagined.
One of the ways that I found resources supported L2 learners’ engagement with
situational knowledge and capacities was through the inclusion of multiple activities attending to
the details of various physical settings. The French textbook frequently explicitly provided times
and places in which activities were set as well as the personal details of interlocutors. The ELL
textbook emphasized content closely tied to learners’ environments (school, around town, etc.).
Through open-ended description tasks, the Spanish resource supported opportunities for learners
to notice details associated with the people around them. In these ways, I saw how opportunities
for perception, comprehension, and projection with respect to operational spaces were embedded
in the L2 content and could potentially be used to introduce and practice the situational capacity
of attending to one’s environment to better evaluate trustworthiness, pertinence, and
“reasonableness” (Jarjoui, 2023, para. 26).
In addition to immediate surroundings, resources invoked places around the globe for
learners. I categorized this content as useful for raising global situational awareness, a valuable
asset in cybersecurity for contributing to a fuller “operational picture” (D. Allen, 2015, p. 6).
Klein and Rice (2014) also underscored the importance of developing global awareness from a
broader national security perspective: “a lack of formal instruction about the history and cultures
of the rest of the world … limits U.S. citizens’ global awareness, cross-cultural competence, and
ability to assess situations and respond appropriately” (p. 47).
L2 content was found to be amenable to supporting opportunities for engaging with other
aspects of situational awareness as well. For example, L2 resources afforded opportunities for
students to discern potential “holes and vulnerabilities … that could be hurdles” (Esteves et al.,
2017, p. 73). This was both at the level of language mechanics (e.g., when resources cautioned
learners about grammatical exceptions) and usage. Textbook material also provided opportunities
for taking note of non-linguistic behavior (e.g., when content alerted students to differences in
cultural practices). Finally, because comparing an uncompleted version of an exercises on the
page with what a completed version ought to look like was implicit in many activities, I saw how
L2 content also supported foundational opportunities for learners to “track what is” (Horneman,
2019, para. 9) in light of “what should be” (para. 9). While these examples represented moments
for very basic observation and surveillance, L2 resources provided additional chances to practice
other more penetrating methods of information gathering (see Horneman, 2019) by giving
learners the tools to ask questions or elicit information from others directly.
However, with respect to these L2 content-supported opportunities for reconnaissance, I
noted that the idea of an adversary was absent—and with it perhaps one of the most potentially
compelling reasons for learners to want to look for vulnerabilities, investigate whether things
were as they should be, or ask questions. Simply put, the stakes associated with opportunities for
reconnaissance in the existing L2 content that I examined felt low to me. I saw this aspect of the
content as problematic for an effort to introduce students in a meaningful way to security
mindsets—particularly in light of security mindsets being portrayed as “curiosity manifested” (R.
Cloutier, personal communication, September 29, 2020). Therefore, finding how to encourage
students to both recognize and capitalize on opportunities for reconnaissance is a problem that I
revisit in my discussion, below, of recommendations for practice.
That existing L2 resources might fail to motivate learners to dive deeper—to experience
“the satisfaction of discovery” (Schoenmakers et al., 2023, p. 11) deemed compelling by many
security-minded people—pushed me to imagine how the content I analyzed might be adapted to
stimulate L2 learners’ curiosity. Contrasted with “the undesirable habit of overlooking security
bugs” (Pournaghshband, 2013, p. 348), what underlies robust security thinking is an ingrained
habit of actively seeking out information with respect to how things can fail (see Cappos &
Weiss, 2014). Recognizing that no sole act of information gathering could constitute the kind of
curiosity that characterizes security mindsets any more than repeated acts would if they were
forced upon learners, I reasoned that L2 learners would benefit most from willingly and
repeatedly jumping into such opportunities to gather information. Here, the idea that security can
be “exciting” (p. 7), put forth by Schneier (as found in Severance, 2016) points to a potential
solution. For Schneier (as found in Severance, 2016):
security has something that nothing else has: an adversary relationship between the
parties. When you do graphics or operating systems or anything else, there’s no one
trying to thwart you at every turn. That’s what you have in security, and that’s what
makes it exciting and interesting. (p. 7)
Severance (2016) was in agreement, writing that “because the ‘underlying problems’ in security
are often creative, highly motivated human adversaries, there are always surprising new twists
and turns” (p. 7). Hence, in much the same way that Hamman and Hopkinson (2016) posited the
value of overlaying Schneier’s concept of a “hacker’s mindset” (p. 15) to stimulate creative
perspectives and capacities, I imagined that overlaying the possibility of even a fictional threat
(adversarial or otherwise) on situations in the L2 content could similarly make things rather more
stimulating for students with respect to actively posing questions and conducting surveillance. In
this way, L2 content would be amenable not just to opportunities to connect learners with
situational awareness ideas but might also offer more compelling forums for learners to actually
seize these opportunities. What is more, the educational value of reconnaissance and information
gathering may extend far beyond L2 learning and security mindsets; Sizer and Sizer (1999) saw
questioning as “the habit that is most likely to lead to consequential scholarship and responsible
adulthood” (p. 190).
Foundational Cybersecurity Concepts and Domain Knowledge
The study’s second research question helped me explore the possibility of linking issues
in L2 learning with a number of foundational concepts in cybersecurity such as confidentiality,
integrity, and availability (CIA). I viewed such ideas at the heart of cybersecurity as important to
include in my analysis because domain-specific concerns are what give analytical, creative,
practical, and situational security mindset fundamentals their shape and purpose. To ignore these
domain particulars when endeavoring to introduce students to security mindset fundamentals
would also be to ignore an important assumption shared by both TTI and situational awareness
that contexts are consequential (Endsley, 1995; Sternberg, 2002). My analysis revealed that L2
content was amenable in various ways to opportunities for broaching cybersecurity domain
concepts. This was significant, as “early exposure to basic cybersecurity concerns and concepts”
(Kurt Peker & Fleenor, 2020, Abstract) may also be “key to developing awareness, piquing
student interest, and laying foundation for more complex skill development”
(Abstract).
Sometimes it was a feature universally associated with communicative language that
supported opportunities for introducing students to basic cybersecurity concepts. For example, I
imagined how speaking and writing tasks in the L2 resources could afford moments for
introducing the CIA triad. Questions about what and how things could go wrong when
transmitting messages could be broached with students, highlighting various factors that could
ensure or threaten senders’ and receivers’ communication goals. These concepts might then be
extended to cybersecurity contexts; Schneier (2023) saw computer code as “analogous” (p. 147)
to legislative language in the sense that written laws “will have bugs and vulnerabilities” (p. 110)
just “like computer code” (p. 110)—even though “the processes by which the two are created and
used are very different” (p. 147). He asserted in both language and code, “a bug to one is a
feature to another” (Schneier, 2023, p. 148). In introducing these notions first through everyday
contexts familiar to learners, the CIA triad might potentially avoid being (erroneously) viewed by
learners as abstract and only tenuously connected to daily life; scholars have cautioned against
impersonal, irrelevant, or overly general cybersecurity awareness efforts (Bada et al., 2019; He et
al., 2020; Richardson et al., 2020).
Possibilities for broaching basic security topics were not always grounded in phenomena
common to L2 learning and communication, however. Sometimes the connections I made
between L2 content and security mindsets concepts were rooted in specific choices made by the
authors. Speaking activities that emphasized sharing personal information, for example, afforded
opportunities for engaging learners with notions such as data value and sensitivity, cyberhygiene,
and risk analysis. These opportunities, though linked to specific content, may have the potential
to be applicable to a variety of other L2 resources not examined in this study; although
introducing and talking about oneself is not a task inherent to language in the same way that
analytical, creative, pragmatic, or situational features are, one can still expect to find this topic in
many other introductory L2 resources.
But what of the atypical material—unlikely to be found in other resources—that I
identified in my analysis? This kind of content also provided valuable in-roads for developing
diverse cybersecurity concepts. A case in point was an animated video from the Spanish
curriculum featuring wildebeests in disagreement over an object in the water (crocodile or log?),
which I named as an avenue for developing the notions of pretexting, misinformation, and risk
analysis for L2 students. This wasn’t a task that I encountered in any of the other resources—and
likely not one to be found in any other L2 curricula. And yet, there are at least two conclusions to
draw from this finding. First, the umbrella is already wide with respect to the kinds of content
currently being used to advance L2 goals. Second, L2 content doesn’t have to be considered
typical to be able to be leveraged for cybersecurity educational aims.
Not all content—atypical or otherwise—produced connections as robust as the wildebeest
example or conversations involving the exchange of personal information. While I noticed that
some themes and subjects in the content lent themselves more readily to being identified as
amenable to introducing security mindset concepts, nowhere in the content did I observe any
explicit references to security. In identifying myriad ways that existing L2 content could be
amenable to opportunities for engaging learners with security mindset fundamentals, it was up to
me as the researcher to explicitly name the connections each time between domains. This lack of
attention to cybersecurity concepts was to be expected, given that a primary objective of these L2
learning materials was for learners to acquire day-to-day language as it relates to daily life—not
to teach math, history, psychology, or other subject matters.
However, I submit that it is because these L2 resources related to issues in daily life that I
was able to identify places in the content for thinking about security. In these spaces—dialogues
featuring people exchanging information, activities in which strangers introduce themselves, and
grammar notes about how unarticulated consonants could sabotage the intended meaning of a
message, for example—I was able to imagine inroads for raising with cybersecurity mindset
fundamentals. My analysis left me with an appreciation for how themes in both language and
security are fundamentally bound up with questions of how human beings can relate to one
another.
Security Mindset Fundamentals: A Collective View
The QCA aspect of my methodology allowed me to organize my analysis around a few
main categories in order to isolate and explore instances of L2 content germane to each category.
The segmented nature of this approach was instrumental in gathering data and generating the
findings which are discussed above, but it is important to avoid giving the false impression that
the opportunities I saw simply coexisted without any sort of dynamic relationship. Just as diverse
connections with security mindset fundamentals could be said to be woven throughout the L2
content, these opportunities also regularly intersected with and built upon each other. A single L2
activity germane to analytical knowledge and capacities also routinely had the potential to
engage learners with creative, practical, and/or situational fundamentals.
While many examples felt mundane or inconsequential to me on their own (which was
what initially prompted me to imagine ways they might be more deliberately developed), this
faded when I experienced them as part of a powerful aggregate of micro-opportunities. I saw
how lower-lever interconnected possibilities for analysis and creativity built into the L2 content
could provide learners with a wonderfully rich backdrop for engaging with higher-level practical
and situational security mindset knowledge and capacities as well. In concert with each other, the
possibilities I found for connecting with security mindset fundamentals gained a depth not
otherwise perceived, and a sense of integrity within the content and processes of L2 learning. In
this way, I imagined L2 content able to support sustained interactions rather than just one-time
encounters with security mindset fundamentals. That security fundamentals might be treated in a
sustained, integrated fashion through L2 topics and tasks—not tacked on as “an afterthought”
(Jarjoui, 2023, p. 11)—is significant. Siraj (as found in Siraj et al., 2021) urged that computer
science students should not learn about “security … in isolation but rather related to all concepts”
(p. 1) when developing their security mindsets.
Even doing little more than highlighting fundamental connections where they arise may
in itself contribute to students’ potential future engagement with security fundamentals.
Noddings (2005) wrote that:
We sometimes forget just how powerful incidental learning can be. No responsible
educator would claim that all significant learning can be achieved incidentally, but much
that we acquire this way becomes more nearly permanent than the material deliberately
transmitted and tested in the planned work of classrooms. (p. 5)
This is not to say that a “deliberate effort” (Kaza, as found in Siraj et al., 2021, p. 2) has no value
in teaching students about security mindsets. Far from it; with respect to the related notion of
developing critical thinking in students, Wegrzecka-Kowalewski (2018) asserted that critical
thinking skills needed to be taught to learners directly, as these could not simply “be expected to
develop as a by-product of content courses” (p. 26). It is advantageous, then, that a panoply of
coherent avenues emerged in my analysis of L2 resources for highlighting security mindset
fundamentals more explicitly. I present recommendations for a more deliberate effort below.
Recommendations
Based on the findings and implications discussed above, I recommend next steps with
respect to future actions characterized by collaboration, research, and the generation of curricular
support. In proposing ways to move forward most effectively, I also suggest that it will be critical
to reflect on larger questions at the heart of cybersecurity, language, and education.
Recommendations for Future Action
I have suggested that exploiting analytical, creative, practical, and situational knowledge
and capacities in L2 learning—as a way to broach security mindset fundamentals—depends on
pointing them out and potentially expanding on them. This task necessarily falls on people and/or
materials in the L2 setting to do this. To increase the chances of successfully capitalizing on L2
learning content, there is a need for generating supplemental curricular materials,
interdisciplinary collaboration, and buy-in from L2 educators.
Supplementary Materials. It is likely unreasonable to expect a critical mass of L2
instructors to be security experts with prior domain knowledge. To lift the burden off L2
instructors, in order that implementation might not rely solely on the capacity of L2 teachers “to
recognize possibilities to generate discussions about language” (van der Broek, 2022, p. 60), I
recommend generating supporting curricular resources. Supplementary materials would serve to
help instructors highlight foundational elements of security thinking within the context of L2
learning. The curricular design process could build on initial insights that emerged from this
study, namely that to leverage various aspects of L2 content, materials can be developed that:
•name and connect general features of language with security mindset fundamentals;
•name and connect specific topic choices in the L2 content with security mindset
fundamentals;
•name and connect an aggregate of examples from L2 content with security mindset
fundamentals by pointing out the connection throughout the content, for example; and
•name and connect a single example of L2 content to draw out connections to offer
possibilities for more in-depth development as well.
Supplementary materials could take a number of forms, such as:
•stand-alone ancillary resources for teachers and/or students highlighting more general
connections, which could be combined with a variety of existing textbooks/curricular
programs;
•companion resources meant to accompany specific L2 curricular textbooks/programs;
•special security editions of current L2 resources, which would intentionally develop
connections between specific L2 content and cybersecurity mindset fundamentals (via
notes in the margins, special vignettes, etc.); and
•L2 curricular materials designed to promote security mindset fundamentals (such as
lessons involving phishing and pretexting which could be introduced through the
deliberate selection of texts without compromising students’ rich interaction with the
target language).
Security-oriented content might often be in beginners’ first languages; as students advanced, such
material could increasingly be presented in the L2.105
Future research will be necessary to inform such efforts. The question might be asked:
what L2 content might be substituted, emphasized, or added to engage L2 learners more
effectively with cybersecurity mindset fundamentals while supporting vital L2 learning goals?
And given that this study’s first research question only treated if and how existing L2 content
could engage learners with perspectives, knowledge, and capacities that underpin security
thinking, scholars might subsequently review and assess how differences in approach, content,
and other factors can target learners’ engagement with security thinking more or less effectively.
For example, when designing supporting materials to leverage L2 content that can encourage
learners’ engagement with creative perspectives and capacities, it is germane that exposure to
open-ended problems is framed as a key element in fostering security mindsets with respect to
“think[ing] outside the box” (Schneier, as found in Severance, 2016, p. 8). There are compelling
reasons to pursue these questions; Sternberg and Lubart (1991) (who were even more confident
than Hamman and Hopkinson (2016) that students’ creativity could be fostered) asserted that
“we can teach for creativity at any level, in any field. And if we want to improve our children and
our nation, this is exactly what we need to do” (p. 614).
Collaboration Between Cybersecurity and L2 Thinkers. The production of meaningful
materials for K12+ L2 classrooms is a goal that invites collaboration between both cybersecurity
educational thinkers and L2 educators/materials designers. Eapen et al. (2023) observed that
“domain experts … often struggle with generating or … accepting novel [emphasis original]
ideas” (para. 4) while “people who lack domain expertise may identify novel ideas but may be
unable to provide the details that would make the ideas feasible” (para. 5). Both groups are
needed to “translate messy ideas into coherent designs” (Eapen et al., 2023, para. 5). With
cybersecurity practitioners and L2 educators working together, security mindset themes can be
more accurately and authentically related to the variety of topics and tasks in L2 learning. This
partnership could also be the key to generating content to support learners’ developmentally
appropriate awareness about varied cybersecurity roles that emphasize diverse aspects of security
thinking (see Padmos, 2018). Such interdisciplinary efforts could serve to generate materials that
help students identify areas of personal aptitude and interest for potentially serious study further
down the road.
Although interdisciplinary action is easier said than done, it is precisely what
cybersecurity thinkers have been calling for (e.g., Abraham & Shih, 2015; Austin, 2020; Blair et
al., 2019; Craigen et al., 2014; Ivy et al., 2019; Jacob et al., 2019; Jeong et al., 2019; Kessler &
Ramsay, 2013; Mountrouidou et al., 2019; Payne et al., 2021; Scheponik et al., 2016; Sharevski
et al., 2018; Suryotrisongko & Musashi, 2019; Sussman, 2020). “A combination of technical and
nontechnical measures” (Peña & García, 2014, p. 465) is needed to mitigate cyber threats most
effectively and a public-private coordinated effort is needed “to develop and provide the
appropriate curriculum” (Abstract). A view put forth in a 2011 Department of Defense Strategy
for Operating in Cyberspace report (as found in Peña & García, 2014) encapsulated the sweeping
extent of what is ultimately required: “The defense of U.S. national security interests in
cyberspace depends on the talent and ingenuity of the American people” (p. 465). Engaging more
teachers from different subjects could foster innovation, impact more students, and ultimately
serve to widen the cybersecurity workforce pipeline (Ivy et al., 2019). While Ivy et al.
(2019) focused on the potential for growing the cybersecurity workforce, Kessler and Ramsey
(2013) proffered that such connections between cybersecurity concepts and non-traditional
content areas could more effectively provide students with an “all hazards” (p. 38) curricular
approach as found in the National Response Framework of the Department of Homeland
Security (DHS). Such an approach goes beyond strictly engineering and technology to develop
“intelligence gathering, threat analysis, planning, management, policy development, risk analysis
and mitigation, as well as antiterrorism/counterterrorism” (p. 38). To support these more
interdisciplinary DHS goals, Kessler and Ramsay (2013) called for greater integration of the social
sciences within cybersecurity, maintaining that it was valuable to “bridge the gap” (p. 38) between
technical engineers and social scientists in cybersecurity education.
Enlisting the Support of L2 Instructors. Asking L2 instructors to go beyond the routine
measurable outcomes of L2 learning—to help learners to make connections with life’s
fundamental security questions—is no small proposition. In an environment where K12
educators already find themselves needing more training to comply with other increasingly
complex responsibilities (Clark, 2016), the important question is why would L2 instructors be
interested in leveraging their content for cybersecurity educational purposes? To ignore teachers
“in any discussion of educational change … is to doom that discussion to failure” (Handsfield,
2002, p. 553). I thus suggest that recruiting the support of L2 professionals is vital, and for those
aiming to win over hearts and minds in the field of L2 learning, I propose that there are several
points worth emphasizing. Here, I address some potential benefits related to L2 programs,
pedagogy, teachers, and students in the context of exploiting L2 learning content to engage
learners with security mindset fundamentals.
Support for L2 Programs. Partnering with cybersecurity education efforts may have the
potential to bring more resources to both FL and ELL programs. L2 programs in the U.S. have
been beset by challenges associated with trends in funding and enrollment. The need for ELL
programs in K-12 public schools has been expanding while budgets and staffing have not always
kept up (Najarro, 2023; Porter et al., 2023; Sugarman, 2016; Villegas, 2023). At the same time,
the Modern Language Association (MLA, 2023) found that colleges and universities have been
reporting lower FL enrollment and a significant drop in reported number of programs. Fischer
(2023) called higher education’s 30 percent decline in FL enrollment since 2009 “a stunning
reversal” (para. 3) given that FL enrollment “over the previous 30 years … had been on a steady
upward trajectory” (para. 3). What current successful FL programs often have in common is
“ample funding, support from administrative offices and other departments, a willingness to
prioritize studying the cultural component of language, and a focus on applying language
learning in real-life contexts” (MLA, 2023, p. 3). To the point of “ample funding” (MLA, 2023,
p. 3), which is essential for “keeping language programs afloat,” (Lusin et al., 2023, p. 3), it is
thus worth bearing in mind that such collaboration may open up new sources of expertise and
revenue earmarked for cybersecurity educational efforts.
Ease of Alignment with L2 Pedagogical Goals and Best Practices. Best practices for
fostering security thinking and L2 learning—rather than working at cross-purposes—may enrich
and invigorate one another. Recommendations in the cybersecurity literature align in important
ways with best practices and recommendations within the field of L2 instruction:
•Incorporating real world content—the MLA (2023) reported that successful FL programs
have tended to “focus on applying language learning in real-life contexts” (p. 3). Multiple
calls for hands-on, real-world approaches in cybersecurity (e.g., Jethwani et al., 2017;
Luse and Burkman, 2021; Tioh et al., 2019) may therefore be in harmony with already
existing efforts to enhance L2 learning through real-world language and topics. Jethwani
et al.’s (2017) support for “embedding educational practice in the contexts of real-world
problems” (p. 20) in cybersecurity echoes statements in the L2 resources I examined
expressing the importance of including “everyday … authentic … relevant” (Azar &
Hagen, 2022, p. xi) content and “using another language in a real world context”
(Mondloch, as found in Valette & Valette, 2013, p. T55);
•Developing learners’ analytical capacities—another example of how recommendations in
the cybersecurity education literature may align with L2 pedagogical knowledge has to
do with the understanding that it is important to develop learners’ analytical knowledge
and capacities because these support other knowledge and capacities in the domain (see
Hamman & Hopkinson, 2016; Valette & Valette, 2013);
•Supporting creativity—the Partnership for 21st Century Skills (as found in Valette &
Valette, 2023) set a goal to develop L2 “students as creators and innovators [who]
respond to new and diverse perspectives” (p. T54) and “use language in imaginative and
original ways to make useful contributions” (p. T54). Likewise, cybersecurity educational
thinkers have emphasized the necessity of finding ways to support unique perspectives
and creative innovation (e.g., Hamman & Hopkinson, 2016; Severance, 2016);
•Using open-ended tasks—additional recommendations in the cybersecurity literature for
“develop[ing] the security mindset” (Severance, 2016, p. 8) have focused on exposing
students to open-ended tasks to support both creativity and real-world strategic
capacities.
Grome et al., (2020), who was writing about strategic thinking from a military
perspective, likewise asserted that “for the purpose of inquiry, deeper understanding, and
reflective thinking, open-ended questions are the best choice” (p. 55). Open-ended tasks
have also been found to benefit L2 learning: Tavoosy and Jelvah (2019) called for more
open-ended questions and interactive communication exchanges in L2 instruction while
Lee (2020) investigated the impact of open-ended writing tasks and found that these
“elicit[ed] greater lexical diversity than closed tasks” (Abstract);
•Capitalizing on errors—other types of instructional experiences have also been put forth
as useful for promoting security thinking, such as permitting students “to be exposed to
the ramifications of writing insecure code and designing vulnerable networks” (Kaza, in
Siraj et al., 2021, p. 336). L2 students can benefit from the practical experience of failure,
too (Guzmán-Muñoz, 2020). As one L2 learner stated in a study of L2 learner
engagement, there may be a sense of “getting everything wrong” (Teravainen-Goff, 2022,
p. 10). The silver living is that when students in one study were given opportunities to
make mistakes in an L2, they were found to demonstrate superior L2 acquisition
(Guzmán-Muñoz, 2020); and
•Organizing content—with respect to a more general aspects of instruction, Kaza (as
found in Siraj et al., 2021) proposed a spiral approach for teaching “security principles”
(p. 2) to “be repeated and enhanced in subsequent courses” (p. 2). Likewise, “a spiral
syllabus” (Abstract) in L2 learning has been proposed as an efficient way to “build a
richer schematic network and consequently strengthen long-term memory” (Crowley,
2022, Abstract).
These points listed above demonstrate important areas of compatibility between proposals for
effective cybersecurity instruction and recommended practices in L2 pedagogy. More than
simply aligning with L2 pedagogy, however, the introduction of security as an underlying theme
may be attractive to L2 instructors in other ways, discussed next.
Benefits for L2 Instructors. Leveraging L2 content to engage students with security
mindset fundamentals could also enrich L2 proficiency objectives by offering learners another
compelling pathway to treat real-world problems, to ask what it means to be an effective
communicator, and to be confronted with alternative patterns of being—connecting these
questions not only to potential cybersecurity career pathways but also to more responsible and
secure ways of thinking.
For FL instructors, this opportunity to “reframe the conversation” (McAllister, 2024, para.
10) with respect to the benefits of L2 learning could be significant. Given the advent of online
language-learning apps, increasingly sophisticated translation software tools, and dropoffs in FL
enrollment—FL teachers may face an existential crisis if their FL programs continue to operate
in ways that do nothing to set themselves apart from other available options. An exhortation
issued to FL practitioners by Klímová (as found in Ro, 2023) was that "technology is here to stay,
and we have to face it and reconsider our teaching methods and assessments” (para.
31).
ELL instructors may find that there are also important benefits associated with supporting
student engagement with cybersecurity fundamentals. While ELL programs may find their
continuation slightly less precarious given federal mandates, ELL teachers themselves may still
be challenged by devaluation of their “expertise and instructional roles” (Harper et al., 2008,
Abstract) and marginalization or isolation in their places of work (Harper et al., 2008; Lafond,
2023; Liggett, 2010). Liggett (2010) suggested that collaboration with teachers of other subjects
would help to mitigate this. While Liggett (2010) was writing about collaboration with general
education teachers, ELL instructors pursuing interdisciplinary and multidisciplinary
cybersecurity education efforts could find themselves better positioned to take part in a larger
conversations about security with more diverse cross sections of colleagues and administrators.
The potential to leverage L2 content to engage learners with security mindset
fundamentals may also be of interest to the many ELL instructors who take their role seriously as
an advocate for their students (see Linville, 2016). In a pivotal article titled “The Hidden
Curriculum of Survival ESL,” Auerbach and Burgess (1985) demonstrated that ELL curricula
often carried messages about predominantly subservient career pathways available to ELL
students. They urged practitioners to reflect on how ELL textbooks presented reality, portrayed
social roles, encouraged creative participation, and fostered critical thinking (Auerbach &
Burgess, 1985). Since then, scholars have picked up the torch and continued to call for critical
awareness with respect to ELL learning (e.g., Hayik, 2016; McBain, 2011; Sayedayn, 2019).
Camps (2016) even criticized overarching ELL legislation. She argued that existing ELL policy
goals that aimed for student employability and self-sufficiency—otherwise laudable objectives—
came at the expense of other practices and objectives that could promote self-determination,
which she saw as truly preferable for ELL learners (Camps, 2016). In this context, it is of interest
that raising ELL learners’ cybersecurity awareness could empower them with the building blocks
and opportunities to flex critical, creative, practical, and situational capacities while
simultaneously exposing them to viable pathways for education and employment in
cybersecurity and related fields. Eisner (2001) poignantly captured the tremendous importance of
this to the educational mission writ large, writing that “it’s what students do with what they learn
when they can do what they want to do that is the real measure of educational achievement” (p.
370). Below, I elaborate on opportunities for empowerment along with other benefits for both
ELL and FL students.
L2 Learners. Leveraging L2 content to engage students with security mindset
fundamentals could be beneficial to learners in a number of ways:
•Learner empowerment. Schoenmaker et al.’s (2023) recommendation for students to
“develop the skills and motivation to exercise the security mindset by freely exploring,
discovering, and investigating security challenges that are accessible at their current level
of skill” (p. 11) suggests that learner autonomy may be part and parcel of engaging
learners meaningfully with security thinking. This points to a kind of educational
empowerment with respect to the learning process itself, but personal empowerment can
come as a result of the learning process, too: Jarjoui (2023) framed the development of
end-users’ security awareness as a step toward “the empowerment of individuals to take
ownership of their destiny in cyberspace” (Abstract) and “to make conscious decisions in
intertwined digital environments” (p. 2);
•Genuine social connection. Dutton (2017) asserted that security mindsets were
“supported socially, such as through the social influence of friends and fellow users, and
sources of information chosen by users” (p. 5) and explained that “it arises from the
interaction of peers—bottom up—rather than from sanctions or directions from above”
(p. 5). This view was shared by Lezhikova (2022), who expressed the value of providing
safe spaces for people to share vulnerable experiences with one another as a means to
build their security mindset knowledge without having it “forc[ed] on them” (38:49). In
broaching security themes in meaningful ways, learners may face content-supported
opportunities to lean into social interactions with their peers. Takkaç Tulgar (2018)
argued that it was important for learners’ L2 acquisition to leverage “the unbreakable
cycle between social and cultural interactions and curiosity” (p. 69);
•Stimulating learners’ curiosity. Takkaç Tulgar (2018) saw curiosity as “the force keeping
the minds of people open to novel things, increasing their social, cultural and pragmatic
knowledge and competence” (p. 62). However, popular ELL textbooks marketed to a
wide audience have sometimes been accused of supporting “mundane methodologies”
(Porcaro, 2004, p. 40) and “vanilla content” (p. 39). It is relevant, then, that security
contexts involving adversaries “trying to thwart you at every turn” (p. 7) add interest and
excitement. At the same time that security can make L2 learning more interesting, L2
learning can make security more interesting: de Bruijn and Janssen (2017) maintained
that “there are always issues that stimulate people much more than cybersecurity, but that
are also interwoven with cybersecurity” (p. 7). Such issues “can be used to gather support
for the fight against cybercrime” (de Bruijn & Janssen, 2017, p. 7). It is possible to see
here how L2 learners’ curiosity with respect to security may be piqued by interweaving
these with powerful issues in language;
•Compelling problems. Sternberg and Lubart (1991) recommended “the use of serious
problems in a variety of disciplines” (p. 614) because “trivial problems” (p. 614) such as
identifying unorthodox ways of using a paper clip were less likely to support the transfer
of creative capacities between domains. “Better to ask students to think of unusual ways
to solve world problems … than to ask them to think of unusual ways to use a paper
clip!” they argued (Sternberg & Lubart, 1991, p. 614). Even better is when learners
themselves are able to pose the problems to be solved (Eisner, 2001; Freire, 1968/2017;
Sternberg & Lubart, 1991), and I submit that in joining L2 learning and security mindset
fundamentals, learners could find themselves eventually grappling with the problem of
balancing a particular short-term security goal with long-term security outcomes, or
openness with security, for example; and
•Engagement with citizenship themes. The introduction of security mindset fundamentals
may also be able to position L2 learning experiences within narratives of care,
connection, and integrity that invite L2 learners to go beyond measurable goals tied to
language proficiency. Schneier (2023) took the position that “defending society’s systems
against hacking isn’t just an issue for the designers of a particular system. It’s an issue for
society itself, and for those who care about social change and progress more generally”
(p. 68). Given the intensely interpersonal nature of communicative language, I submit
that in leveraging L2 content for security mindset purposes, there may be meaningful
inroads for learners to treat cybersecurity themes both “as a problem of the individual or
as a problem of society” (de Bruijn & Janssen, 2017, p. 4).
Above, I have offered recommendations for future action, which included the
development of supporting curricular materials built on further research and interdisciplinary
collaboration. I also proposed the need to garner the support of L2 educators. To that end, I
suggested raising awareness of how a deliberate effort to engage L2 learners with security
mindset fundamentals could potentially benefit L2 programs, pedagogy, teachers, and students.
Recommendations for Future Reflection
The benefits described above depend on successful collaboration and thoughtful
execution in leveraging L2 content for cybersecurity educational purposes; these benefits are by
no means guaranteed. In recommending ways to move forward, I propose that future actions be
accompanied by purposeful consideration of larger questions at the heart of cybersecurity,
language, and education. This is important so that undesirable outcomes might be avoided, and
learners might be offered truly compelling visions of security.
Avoiding Undesirable Outcomes. It is important to consider how an introduction of
security mindset fundamentals to L2 learners could lead to unwanted educational outcomes. One
concern is that such efforts might foster “a culture of fear” (Dutton, 2017, p. 6) among L2
learners. Although healthy security mindsets can be a “valuable alternative to creating a culture
of fear,” (p. 6), Dutton (2017) cautioned against unbalanced security mindsets fixated on “putting
security above all or most other considerations” (p. 6). Eisner (2001) observed that it “is not easy
when what the outcome is going to be is a function not only of what is introduced in the situation
but also of what a student makes of what has been introduced” (p. 368). It is thus vital for
educators to provide learners with the tools to navigate such unpredictability rather than be afraid
of it.
If L2 learning materials and practitioners were to overlook learners’ potential for growth
—and overemphasize vulnerability and threats when broaching the question of how things can
fail—this could come at the expense of students’ willingness to engage with and “explore the
beautiful and messy horizons of human connection” (Blanken-Webb et al., in press) arguably at
the heart of authentic L2 learning experiences. I submit that the aim of L2 learning ought never
to be the creation of cynical, fearful, or jaded interlocutors. Such an outcome for any introduction
to cybersecurity would be an educational tragedy.
Instead of encouraging students to cut themselves off from other humans, L2 settings
could frame security as endeavors to harden, monitor, and defend spaces ultimately to support
acts of communication and creation. L2 learners are, after all, working toward another “Hello,
World!” (Bonjour, le monde !) moment in their lives; their newfound capacity for expression and
connection in another language introduces both new advantages and vulnerabilities. Helping L2
learners navigate this complexity in productive ways may require nothing less than an
interdisciplinary caucus and the subsequent adoption of certain conceptions of cybersecurity over
others to inform the instructional process.
Developing L2 learners’ capacity for skepticism and mistrust is not in itself something to
be avoided, however. Wariness may, in fact, be indispensable to genuine interaction: Bonhoeffer
(1951/2005) affirmed that while “trust will always be one of the greatest, rarest, and happiest
blessings of … life in community. … it can emerge only on the dark background of a necessary
mistrust” (p. 278). The problem, rather, is if L2 content were leveraged to nurture only mistrust.
This could rob L2 learners of opportunities to grapple with the idea that trust is what “enables us
to really live and work” (Bonhoeffer, 1951/2005, p. 278) and that it means “learn[ing] to put our
very lives in the hands of others” (p. 278). Writing from an educational point of view, Sizer and
Sizer (1999) warned that “we’re selling our children short when we believe that grappling is
beyond them. In fact, most of them are engaging in dilemmas of intense seriousness while we’re
looking the other way” (p. 187). In attending to risk and mitigation in something as quotidian as
language use, my hope is that foundational understandings may be laid for how to support safer
and more genuine interactions between strangers wanting to communicate.
If educators or materials were to fail to strike a balance in introducing cybersecurity,
students might become fearful, or they could become disempowered. De Bruijn and Janssen
(2017) wrote that “Hell does not sell” (p. 6). They cautioned that:
It … feeds the idea that we are out of control—that the problem can no longer be
resolved … What impact does the message that you are never safe and the risks are
immense actually have on people? Instead of creating a sense of urgency, it might result
in denial. (p. 6)
They appreciated the enormity and complexity of cybersecurity; while it was important to try to
present cybersecurity in ways that were “clear and easy to explain” (de Bruijn & Janssen, 2017,
p. 5; see also Jarjoui, 2023), they recognized that “relevant issues might be omitted” (p. 5) as a
result. De Bruijn and Janssen (2017) therefore offered a helpful guide for how to avoid both
unbalanced (i.e., “utopian and dystopian” [p. 7]) portrayals of cybersecurity. Their advice for
people seeking to communicate more productively vis-à-vis cybersecurity issues was: 1) do
not exacerbate cybersecurity, 2) make it clear who the villains are, 3) give cybersecurity a face
by putting the heroes in the spotlight, 4) connect cybersecurity to values other than security
alone, 5) personalize the message for easy recognition and 6) connect to other tangible and
clear issues. (de Bruijn & Janssen, 2017, p. 7) In exploiting L2 learning tasks and topics to
familiarize students with the fundamentals of security thinking, this may be helpful counsel. I
submit that in any effort involving themes of security, it is vital to offer hope to students “that
good can prevail over evil, that morality can topple immorality” (Ornstein, as found in
Ornstein et al., 2015, p. 79).
Offer Learners a Compelling Vision of Security. For all who would take on the
challenge of leveraging L2 learning content to engage L2 learners with cybersecurity mindset
fundamentals, I point to a critical need to offer learners a compelling vision of security in L2
learning settings. For the purposes of interdisciplinary collaboration, this may involve generating
a loose consensus about what cybersecurity even is first.114 I suggest that in educational fields
that often prioritize learning-by-doing—such as cybersecurity and L2 learning—it is important
not to overlook the necessity of grappling with and synthesizing underlying ideas and how
students see themselves in relation to such ideas.
Just as language can and should be approached as more than “an abstract … set of rules
… that exists independently of situated action in the world” (Hodges et al., 2012, p. 500), so
security can and should be, too. While both security and language can be viewed as a set of
abstract technical principles, it is perhaps much easier in communicative human settings to be
reminded of the incompleteness of such a view. Owing to language’s technical and social
aspects, security issues considered in the context of language can be both the object of
mechanical and procedural analyses while remaining grounded in the human sphere.
For this reason, practitioners and scholars would do well to leverage these connections to
the human sphere, reflecting on the capacity for language’s compelling ideas and security’s
compelling ideas to invigorate each other. Language can afford speakers an opportunity to attend
to things which have been largely rendered automatic and forgotten (Hudes, 2016). “How many
114 Craigen et al. (2014) explained that:
Cybersecurity is a broadly used term, whose definitions are highly variable, often subjective, and at times,
uninformative. The absence of a concise, broadly acceptable definition that captures the
multidimensionality of cybersecurity impedes technological and scientific advances by reinforcing the
predominantly technical view of cybersecurity while separating disciplines that should be acting in concert
to resolve complex cybersecurity challenges. (Abstract)
times have we driven to the office and gone, ‘Wait, did I unplug the iron? Did I turn off the
coffee maker? Did I leave the keys in the door?’...We run on autopilot and proceed as if
sleepwalking,”
Hudes (2016, p. 90) alleged. As a playwright, Hudes (2016) observed how the stage could
“startl[e] us out of our sleepwalking” (p. 90) but, significantly, she also added:
I don’t think the arts are singular in their capacity to wake us up. Language as a study and
practice, “the interpretive and expressive skills” … , the deep investigation of how to
listen and articulate, voice where there has been silence, also helps us “recover the
sensation of life.” (Hudes, 2016, p. 90)
At the heart of rich educative experiences is the notion of hidden things brought into the light,
and language largely makes this possible. Language’s capacity to make things explicit can also
enhance security thinking; Bellovin (2013) contended that ignorance is not always bliss when it
comes to cybersecurity. He argued that “The real underlying issue is that too many of our
security mechanisms are based on assumptions. Implicit assumptions. And these are not
recognized as assumptions even by the architect of the security mechanism” (Bellovin (2013,
20:13-20:28). Technology and behaviors change over time, but if these assumptions haven’t been
made explicit, “we don’t know to look for danger and we don’t know when we need to change
the security advice, except incrementally several years too late” (Bellovin, 2013, 20:29-20:42).
Helping students (re)connect themselves to their lives is integral to their education, because
“unless we show students why what they are learning should matter to them, we cannot expect
them to retain what they are taught” (Sternberg & Lubart, 1991, p. 610).
Noddings (1995), too, recognized the importance of helping learners connect with
compelling themes in the classroom. In offering an example with respect to teaching about the
topic of crime—whether in a math, science, or English course—she argued for the value of
repeatedly reminding students “that the topic is part of a larger theme of caring for strangers and
fellow citizens” (p. 677). Whatever compelling ideas or objectives are selected for emphasis,
developing them need not take much instructional time to have an impact (Noddings, 1995;
Sternberg & Lubart, 1991). Noddings (1995) held that “it takes only a few minutes to talk about
what it means to live in safety, to trust one's neighbors, to feel secure in greeting strangers” (p.
677).
The question of security in greeting strangers may be particularly apropos when seeking
to offer learners a compelling vision of security. “Hello, World!” moments in L2 learning
represent students’ attempts to use a new language that can ultimately connect them with
strangers in unfamiliar surroundings. Such a situation is arguably characterized by vulnerability
and yet—because communicative endeavors are unescapably bound up with connection—visions
of security offered in L2 learning contexts will need to take seriously the challenge of how to
secure spaces for safe and secure conversational exchanges.
Consider the Scope. In seeking to provide learners with a compelling vision of security
and why it matters, collaborative L2-cybersecuity efforts would do well to consider the scale of
ideas and problems to which security mindsets can potentially be applied. These may range from
granular analyses of detecting potential security bugs in lines of code to monitoring the influence
that online platforms algorithms might have on end-users’ behaviors and attitudes (see Amer &
Noujaim, 2019). The question that might be posed, therefore, is if searching for coding errors—
or seeking to understand online “psychological weapon[s] of mass destruction” (Wylie, 2019, p.
17) and the societal impact of “curated realities” (Blanken-Webb et al., in press) nurtured in
cyberspaces—could both be appropriate topics to broach in introducing L2 learners to
foundational aspects of security thinking. What, if anything, lies outside the scope of
foundational security thinking? Where are the limits of security mindsets with respect to
cybersecurity? These is an important issue to sort out because the question “How can this fail?”
can conceivably be applied to low-level and high-level problems of vastly different scale in the
L2 classroom. What are the consequences for message integrity, for example, if learners
misapply a certain morphological ending? Should learners also be encouraged to consider what
the security consequences may be if a critical mass of people in a society fails to seek out the
perspective of others? Such considerations are beyond what is widely seen as the scope of
cybersecurity, yet both granular and wider perspectives may be needed to strengthen overall
cybersecurity efforts to promote genuine and safe interactions. Certainly, an introduction to
cybersecurity mindsets through L2 content could be restricted to a laser-like focus, but “Dewey
made the point that ‘thinking deprived of its normal course takes refuge in academic specialism’”
(Greene, 1995, p. 380). This, I submit, ought to be studiously avoided if the intent is to go
beyond narrow technical introductions to security thinking to train up students also accustomed
to investigating the exquisitely intractable “human side of the problem” (Greitzer, 2019, p. 1).
Limitations
I set out to investigate if and how L2 content might support opportunities for engaging L2
learners with security mindset fundamentals. In what follows, I present various limitations
associated with theoretical, methodological, and analytical aspects of this investigation.
Theoretical Limitations
To move the investigation forward, I created a framework for security mindset
fundamentals which blended conceptions of situational awareness (see Endsley, 1995;
Horneman, 2019) with Hamman and Hopkinson’s (2016) framework for adversarial thinking
based on Sternberg’s (1988) Triarchic Theory of Intelligence (TTI). My hope was that by
focusing on building blocks making up security thinking, I could avoid implying that security
mindsets were somehow monolithic or uniformly attained. Dutton (2017), for example, held that
“different actors, such as cybersecurity experts versus end-users, will manifest a cyber security
mindset in very different ways” (p. 6). Intelligence theorists such as Gottfredson (2003) have
been critical of the dearth of empirical evidence supporting TTI’s claims, pointing to—among
other things—challenges associated with reliably measuring some of the components of
intelligence that Sternberg (1988) specified. This critique notwithstanding, TTI’s various aspects
of intelligence (and the knowledge and capacities associated with them) nevertheless provided an
effective practical foundation for my study’s coding frame.
However, Padmos (2018) proposed a framework that also underscores different aspects
associated with security thinking. Padmos (2018) aligned various attitudes, skills, and tasks with
five “archetypal” (p. 14) cybersecurity roles: security analysts, engineers, forecasters, architects,
and managers. Using Padmos’s (2018) framework, I might have more explicitly investigated the
potential role L2 learning programs could play in the nation’s cybersecurity workforce pipeline.
To focus more on end-users, I could have alternatively selected a “holistic socio-technical
approach” (p. 2) presented by Jarjoui (2023), who proposed exploiting the various benefits
associated with mindfulness “as the first line of defense in cyberspace” (p. 11). Mindfulness
training may contribute to “a deliberate effort … to empower each person to take responsibility
for cybersecurity and become a human firewall” (Jarjoui, 2023, p. 9). It is not difficult to see how
Jarjoui’s (2023) language—e.g., “blueprint for empowering individuals” (p. 2); “cultivating
… resilience” (p. 4); “responsibility” (p. 10); “community-based collaboration, commitment, and
individuals’ engagement and accountability” (p. 11)—might be perceived by educators as more
compatible with traditional K12+ educational goals, in contrast with phrases such as adversarial
thinking, threat modelling, zero-trust architecture, or attack surfaces. The latter group of terms, at
present, may be potentially less well-understood and have less currency in general education
settings.
In the end, it has been said that “nothing is as practical as a good theory” (Sternberg &
Lubart, 1991, p. 609). Therefore, I submit that any theoretical limitations of the framework used
in this study were not enough to outweigh the practical advantages they offered in terms of
moving the investigation forward and contributing to validity. The categories and subcategories
that TTI and situational awareness generated for my coding frame allowed me to “capture what I
set out to capture” (Schreier, 2012, p. 175).
Methodological Limitations
This study was based on a small sample size, which included content from three L2
resources. Although great care was taken to select these resources which varied in language,
approach, and format, three resources cannot represent the quantity, quality, or diversity of the
many available L2 learning resources today. Moreover, I only examined the very beginning
portions of these resources—extremely basic content that learners would encounter in their very
first week or month of L2 learning. My investigation, however, was not concerned with
generalizability but rather possibility; in a very exploratory way, I wanted to determine if L2
content could be leveraged to support efforts to engage students meaningfully with security
mindset fundamentals. That I identified possibilities in even basic, introductory material points to
the potential value of further research with respect to more sophisticated L2 content.
Analytical Limitations
The findings in this study were the product of what I, as one individual, saw as possible
and it is likely that anyone else evaluating these L2 resources would identify different (e.g.,
fewer, more, or other) connections to be leveraged for cybersecurity. Even as I sought to
strengthen reliability by implementing a wait period between my initial coding efforts and
revisiting the same material again later to check for the stability of my judgements over time (see
Schreier, 2012), I was still the only instrument in the study. However, it can be argued that the act
of naming and developing a connection may be enough to possibilize opportunities for
leveraging it, regardless of whether another person would have replicated the same finding on
their own. My study was concerned with what could be. The educational psychologist Bloom
was said to be “more interested in what is possible than in what is likely” (Walberg, 1990, p.
474). However, whereas Bloom “sought to find the limits of learning” (Walberg, 1990, p. 474), I
was only seeking to find the launch pad.
As the primary research instrument in this study, it is also significant that I am an L2
educator and not a cybersecurity specialist. This was a very important limitation of the study. As
such, I was only able to show where the potential inroads were in the L2 content for exploitation;
to exploit these inroads effectively, the expertise of cybersecurity professionals is needed. As
such, the findings here are presented in a genuine spirit of interdisciplinary collaboration.
Conclusion
As humans and machines teeter “right on the edge of a new security landscape”
(Williams, 2023, para. 7) that is rapidly evolving and understaffed, there is a need for a wide
range of academic disciplines to inform more diverse, human-centric cybersecurity efforts
(Craigen et al., 2014) along with the development of underlying, flexible security thinking
amongst cybersecurity personnel as well as end users (e.g., Dark, 2015; Dutton, 2017; Dutton et
al., 2019; Esteves et al., 2017; Jarjoui, 2023; Pournaghshband, 2013; Schneider, 2013;
Schoenmakers et al., 2023). In fact, “teaching the ‘security mindset’ [to all individuals who
design/develop/deploy/upkeep/use digital systems] might be one of the most important aspects”
(Siraj et al., 2021, p. 2) for cybersecurity educators today.
The objective of this study was to investigate in what ways K12+ L2 learning content
could potentially support the introduction of security mindset fundamentals to L2 learners. In my
QCA of content in three L2 resources, I practiced IV to explore if and how existing materials
could be connected to analytical, creative, practical, and situational knowledge and capacities
underlying security thinking. I imagined how these connections could be leveraged to engage L2
learners meaningfully with security mindset fundamentals. I also looked for ways that L2
textbook content could serve as a springboard for broaching more explicit security-related
questions and issues (e.g., phishing, confidentiality, integrity, and availability, etc.). As such, my
investigation focused on both security thinking and thinking about security.
The foundational aspects of security mindsets around which I organized my analysis were
drawn from Hamman and Hopkinson’s (2016) adaptation of Sternberg’s (1988) TTI for
adversarial thinking and conceptions of situational awareness (Endsley, 1995; Horneman, 2019).
The decision to examine existing L2 content was driven by my own desire to gain insight into
what might be reasonably achieved within the current curricular infrastructure of L2 learning
with already available curricular materials and—recognizing that these were not explicitly
designed with security principles in mind—to provide some indication about the level of need to
develop L2 learning materials more deliberately for cybersecurity educational purposes.
My analysis revealed that a wide variety of L2 content in the three resources that I
examined was amenable to providing opportunities for learners to engage with analytical,
creative, practical, and situational security mindset fundamentals. I also found L2 content in all
of the resources that could support the introduction of basic cybersecurity domain concepts and
knowledge. As many of the opportunities that I identified had to do with features inherent to
language or topics common to L2 learning, I concluded that other L2 resources might be
similarly leveraged.
That currently available L2 materials might serve as a basis for cybersecurity thinkers and
L2 educators to produce meaningful materials for introducing L2 learners to security mindset
fundamentals suggests that K12+ L2 learning programs are not so far off from being able to be
leveraged in this way. In K-12 school districts and higher educational institutions throughout the
United States, the requisite infrastructure already exists, including established
ELL and FL programs, existing leverageable content, and millions of currently enrolled students.
The potential impact of providing wider opportunities comes into focus when considering
that there are millions of FL and ELL learners at present in the United States. Enrollment in K-12
ELL programs has outpaced general K-12 enrollment (de Jong, 2013) and represents the
fastestgrowing population in K-12 (Long, 2022). With respect to FL, at least 23 U.S. states
identify FL study as a graduation requirement (Jimenez & Sargrad, 2018) and admission criteria
at many colleges and universities across the United States also require prior FL study for
matriculation (Jimenez & Sargrad, 2018). These facts suggest that a perennially large number of
students are in a position to engage with cybersecurity mindset fundamentals through L2 content
matter. In this way, L2 classrooms could help widen the gateway for students to technical,
creative, and practical subfields within cybersecurity, acting as an important recruitment pipeline
for cybersecurity education and training.
Collaborative efforts to exploit this infrastructure, however, cannot overlook one of the
most important aspects of this infrastructure: L2 instructors. To increase the likelihood that L2
professionals would support a novel effort such as this, I highlighted several potential benefits
and advocated for the development of supplementary materials to help L2 educators and learners
more meaningfully exploit these connections between security mindset fundamentals and L2
learning. Supported by an interdisciplinary effort and shaped by compelling visions of security
and language, security mindset education and L2 programs might benefit each other in myriad
ways through this partnership.
While this is a novel conception within L2 learning settings, it is by no means a lone call
in the scholarship for connecting cybersecurity concepts to non-traditional content areas. Ivy et
al. (2019) proposed an approach wherein teachers of any subject might become familiar with
computing and cybersecurity topics as a result of being met “in the comfort zone of their content
areas” (p. 2) to allow them to grapple with such topics. Widening the circle has important
consequences for cybersecurity education: Ivy et al. (2019) argued that “from the ranks of the
music teacher, the history teacher, or the math teacher” (p. 2), one might find the future
cybersecurity workforce’s “best computing teachers” (p. 2).
For this reason, I am hopeful that those who are interested in introducing flexible,
underlying security thinking will not immediately dismiss the unorthodox possibility to hack L2
learning settings for this purpose—and that they will not miss the potential integrity of such an
endeavor with robust security mindsets themselves. As one cybersecurity professional with a
strong security mindset proclaimed, “There’s nothing, there’s nothing better in my brain at all”
(Schoenmakers et al., 2023, p. 7) than “making any kind of connection between two things
people don’t normally make connections between” (p. 7). The connections made in this study can
be exploited to engage L2 learners with security mindset fundamentals. I have argued before that
this could potentially benefit both security thinking and L2 learning (see Kuiken, 2023). I now
think that these disciplines could “rehumaniz[e]” (Roemischer, 2013, p. 8) each other. Security
reminds people of the vitality of language; language reminds people of the necessity of human
connection; human connection reminds people of the value of security. L2 students developing
fundamental security thinking have boundless opportunities to consider questions of enduring
import, as both security and language deal with the whole of life, what it means to be human, and
how to live with others.