Make Your Point: Crafting Compelling Cyber Narratives
Joe Nay (Pentester | Storyteller | Solutions Architect at Horizon3.ai)
SAINTCON 2025 · Day 3 · Main Track 1
Overview
In the fast-paced and technically complex world of cybersecurity, the ability to uncover vulnerabilities and identify threats is paramount. However, as Joe Nay, a seasoned pentester and solutions architect at Horizon3.ai, argues in his SAINTCON talk, "Make Your Point: Crafting Compelling Cyber Narratives," the true value of technical expertise remains unrealized without effective communication. This presentation delves into the often-overlooked art and science of storytelling within cybersecurity, emphasizing its critical role in translating complex technical findings into actionable insights for diverse audiences, from fellow technical practitioners to non-technical executives.

Key moments
- 1:15 The pentest where communication failed
- 2:15 Narrative transforms issues into compelling stories
- 2:50 Storytelling defined: when facts meet context
- 3:20 Demonstrating contextual impact for a CISO
- 4:10 Why human brains are wired for stories
- 6:00 Storytelling: an art with discoverable rules
- 7:35 Essential "Tell Them" theory for clarity
Make Your Point: Crafting Compelling Cyber Narratives
Speakers: Joe Nay, Pentester | Storyteller | Solutions Architect at Horizon3.ai
Conference: SAINTCON
YouTube: https://www.youtube.com/watch?v=25MAqTDbd0w
Overview
In the fast-paced and technically complex world of cybersecurity, the ability to uncover vulnerabilities and identify threats is paramount. However, as Joe Nay, a seasoned pentester and solutions architect at Horizon3.ai, argues in his SAINTCON talk, "Make Your Point: Crafting Compelling Cyber Narratives," the true value of technical expertise remains unrealized without effective communication. This presentation delves into the often-overlooked art and science of storytelling within cybersecurity, emphasizing its critical role in translating complex technical findings into actionable insights for diverse audiences, from fellow technical practitioners to non-technical executives.
Nay's talk is a direct response to a common frustration experienced by many cybersecurity professionals: the failure of critical findings to drive organizational change, despite their technical merit. Drawing from his extensive experience on both red and blue teams, including a pivotal early penetration test where his detailed debrief failed to prompt any action, Nay highlights the communication gap that frequently exists. He posits that merely presenting a "laundry list of issues" is insufficient; instead, cybersecurity professionals must learn to craft compelling narratives that captivate attention, foster understanding, and ultimately inspire necessary security improvements.
This article explores Nay's framework for effective cybersecurity storytelling, dissecting his "Tell Them Theory," the crucial distinction between plot summaries and synopses, and the power of incorporating protagonists into technical discussions. It provides a detailed look at how these principles can transform dry technical reports into engaging stories that resonate with stakeholders, enabling organizations to move beyond simply identifying problems to actively implementing solutions, thereby enhancing their overall security posture and mitigating significant business risks.
Background
▶ Watch: The pentest where communication failed (1:15)
The genesis of Joe Nay's passion for storytelling in cybersecurity stems from a deeply personal and common professional dilemma. Early in his career as a penetration tester, Nay successfully achieved domain admin privileges during a network pentest, uncovering numerous critical vulnerabilities. He meticulously documented these findings and presented them during a debrief, confident that the sheer technical weight of his discoveries would compel the client to act. To his dismay, "they didn't do a dang thing." This experience served as a profound realization: while technical professionals are often brilliant at their craft, communication can be a significant shortfall.
This communication gap is not unique to Nay. It's a pervasive problem across the industry, where highly skilled individuals struggle to convey the gravity and implications of their work to those who hold the power to implement change. The consequence is often a cascade of unaddressed vulnerabilities, escalating risks, and a perception that cybersecurity is a cost center rather than a strategic imperative. Nay argues that this isn't due to a lack of importance in the technical findings themselves, but rather a failure to present them in a way that truly connects with the audience.
Nay defines storytelling not as mere entertainment, but as "when facts meet context"—the art and science of convincing, and a fundamental form of information exchange essential to human evolution. Our brains, he explains, are inherently wired for narratives. This wiring serves several crucial functions:
- Survival Skill: Historically, the ability to explain where to find food or how to collaborate effectively was vital for survival.
- Memory Booster: Narratives stick in our minds far better than raw facts or statistics. Nay humorously contrasts remembering Admiral Akbar's home planet (Moncala) with forgetting his own anniversary, illustrating how stories embed information more deeply.
- Simulation Engine: Stories allow us to mentally simulate situations, practicing responses and understanding potential outcomes without direct experience. This "what would I do in that situation?" aspect is invaluable for preparing for cyber incidents or understanding the impact of vulnerabilities.
The problem, therefore, isn't a lack of facts, but a deficit of context and an inability to leverage the brain's natural inclination towards narrative. Nay's background, spanning manual penetration testing and now automated solutions at Horizon3.ai, further underscores the need for effective communication, as even the most advanced tools require clear articulation of their findings to deliver real-world value. His personal journey from a frustrated pentester to a solutions architect advocating for storytelling highlights the industry's critical need to transform "laundry lists of issues" into compelling calls to action.
Key Findings
▶ Watch: Storytelling defined: when facts meet context (2:50)
Joe Nay’s talk outlines several key principles for crafting compelling cyber narratives, transforming the abstract art of storytelling into a more structured, scientific approach applicable to technical communication:
- The "Tell Them Theory": This foundational principle is presented as a crucial framework for structuring any presentation or report. It comprises three stages:
- Tell them what you're going to tell them: Begin by clearly introducing the topic and setting expectations. This prevents the audience from feeling dropped into a mid-conversation.
- Tell them what you promised you would tell them: Deliver the core message and details as promised in the introduction.
- Tell them what you told them again: Conclude with a recap, reiterating the main points and, crucially, providing the specific perspective or takeaway you want the audience to retain. This final step solidifies understanding and reinforces the desired message. Nay stresses that context is paramount, and this structure should be adapted to the audience (e.g., non-technical executive vs. fellow sysadmin) and the available time.
- Synopsis vs. Plot Summary: Nay distinguishes between these two forms of explanation, emphasizing that a synopsis is often more effective for initial engagement. A plot summary details every step of a story, which can be overwhelming or spoil the experience. In contrast, a synopsis provides just enough context and intrigue to make the audience want to hear more, setting expectations without revealing every detail. He uses the example of the movie Everything Everywhere All at Once, which he struggled to get into until a friend provided a brief, compelling synopsis ("cool multiversal story, but it's really about a family relationship... funny, action-packed"). For cybersecurity, this means offering a high-level overview of the impact and relevance of a finding before diving into the granular technical steps.
- The Power of a Protagonist: A story without a character, Nay asserts, is merely a report. Introducing a protagonist—a person or even a persona—into a technical narrative immediately creates emotional impact and makes the information relatable. He illustrates this with an image of a locked computer screen; while technically informative, it gains emotional weight when a person is added to the frame, evoking empathy. In the context of automated penetration testing at Horizon3.ai, he explains how describing the impact on "Mary in accounting" or "John in sales" after clicking a phishing link makes the security risk tangible and personal, driving home the need for change.
- Pacing and Specificity: Effective storytelling requires dynamic pacing, which is not simply speaking slowly. It involves varying the speed of delivery—speeding up to build excitement and transition between points, and slowing down or even pausing to emphasize critical information and allow it to sink in. Coupled with pacing, specificity and concreteness are vital. Generic statements are easily dismissed; vivid, detailed examples, even if hypothetical, make a narrative memorable and impactful. Nay references a Bill Burr comedy bit about kicking a baby to illustrate how extreme specificity can transform a potentially offensive scenario into something hilarious and highly imaginative, proving that concrete details immerse the listener. For cybersecurity, this means moving beyond "this is a problem" to "this specific misconfiguration could lead to domain compromise, costing millions in operational downtime and brand damage."
These findings collectively form a practical guide for cybersecurity professionals to transform their technical reports and presentations from dry recitations of facts into persuasive narratives that compel action and foster a deeper understanding of security risks.
Technical Deep Dive
▶ Watch: Demonstrating contextual impact for a CISO (3:20)
While Joe Nay's talk focuses on communication rather than specific cybersecurity vulnerabilities or exploits, its "technical deep dive" lies in dissecting the mechanics of effective information exchange in a technical field. The "science" aspect of storytelling, as Nay frames it, involves understanding how human brains process information and leveraging those cognitive pathways to ensure technical messages are not just heard but understood and acted upon.
Nay illustrates the power of narrative by contrasting bland technical statements with compelling, context-rich stories. He provides a series of examples related to penetration test results:
- Initial, Ineffective Presentation: "Here are your network pentest results. We found legacy name resolution protocols that's default and it's a problem. We found SMB signing that was disabled and not required. That's also a problem. And also ESC1 misconfigurations on with the Active Directory Certificate Services that could lead to domain compromise and we were able to get domain compromise there. So that's a problem. You should fix it." This approach, a common pitfall, presents technical facts as a "laundry list" without establishing their broader significance.
- Effective, Narrative-Driven Presentation: Nay reworks this scenario to demonstrate a superior approach: "These are your network pentest results. All of these issues, most of them are going to be default configuration. Specifically, the legacy name resolution protocols and the SMB signing disabled. These are default and we need to make sure that these are fixed in the environment because without these, it's going to lead to not just domain compromise—and we were able to achieve that—but it's going to cost the company potentially millions of dollars. It's going to lead to operational downtime. It's going to lead to brand reputation damage. It's going to lead to ransomware exposure. All of these things are concrete results of what could happen because we're sitting like an open duck. So my question to you is, is this acceptable business risk or should we adjust priorities to resolve this?"
This transformed narrative leverages several technical storytelling principles:
- Contextualization of Technical Details: Instead of merely stating "legacy name resolution protocols" or "SMB signing disabled" are problems, Nay immediately links them to their default configuration status, implying ease of exploitation and widespread risk. He highlights ESC1 misconfigurations on Active Directory Certificate Services as a critical vector, explicitly stating it "could lead to domain compromise" and that they "were able to achieve that." This provides technical validation of the severity.
- Impact Quantification: The most significant shift is the articulation of consequences. The technical findings are directly tied to business-critical impacts: "millions of dollars," "operational downtime," "brand reputation damage," and "ransomware exposure." These are terms that resonate directly with business leaders and decision-makers, translating abstract technical vulnerabilities into concrete financial and operational risks.
- Call to Action as a Business Decision: The concluding question, "is this acceptable business risk or should we adjust priorities to resolve this?" is a masterstroke. It reframes the technical problem as a strategic business decision. By forcing the audience to acknowledge the potential consequences and explicitly accept or reject the risk, it pushes for commitment and accountability, making it much harder to ignore the findings.
Nay also touches upon the technical implementation of his storytelling principles through the example of Horizon3.ai's autonomous penetration testing. When discussing a phishing pentest that integrates with phishing simulation tools, he describes how clicking a malicious link initiates a pentest with that user's privileges. The key insight is how to communicate this: instead of a dry technical explanation, he suggests telling the story from the perspective of "Mary in accounting" or "John in sales" who clicked the link. This is a technical process (automated pentest execution based on user interaction) made relatable through a protagonist, demonstrating how technical systems can be understood through human-centric narratives.
In essence, the "technical deep dive" in Nay's talk is not about the what of cybersecurity threats, but the how of communicating them effectively. It's about taking the raw, complex data from tools and assessments and processing it through a narrative filter that emphasizes impact, context, and human relevance, ultimately making the technical message stick and drive tangible security improvements.
Demo / Proof of Concept
▶ Watch: Storytelling: an art with discoverable rules (6:00)
While Joe Nay's talk does not feature a live technical demonstration of an exploit or a security tool, it effectively employs several "proofs of concept" in the form of illustrative examples to demonstrate the power and impact of storytelling principles. These examples serve as mini-demos, allowing the audience to experience the difference between poor and effective communication firsthand.
One of the most engaging examples Nay uses is a YouTube video that parodies a meeting with J.R.R. Tolkien, where he attempts to describe The Lord of the Rings. The video brilliantly contrasts a synopsis with a plot summary. In the video, Tolkien initially gives an exciting synopsis: "It's about a magic ring... given to an heir... who must destroy all evil... on a magic quest." The room is captivated. Then, he switches to a plot summary, detailing every mundane step: "They walk, walk, walk, walk. Somebody's following them. Walk, walk, hide. Walk, walk, walk. And steal some mushrooms. Get on the boat. Walk. Oh, for the first time. Wow. Walk, walk. Nighttime walk, walk, walk. Attacked by Tweed." Nay plays only the first 30 seconds of this video, which has over 1.5 million views, to highlight how quickly a compelling narrative can devolve into a tedious list of events, losing the audience's attention. This serves as a powerful demonstration of why a concise, impactful synopsis is crucial for initial engagement in cybersecurity communications, reserving the detailed plot summary for those who need or request it.
Another crucial demonstration involves his own pentest debrief example, which he presents in three iterations to show progressive improvement:
- Terrible Story (Beginning, Middle, End disjointed): Nay starts with "These are your network pentest results," then moves to a separate "push this button" example, and ends with a "Jack was almost eaten by the giant" snippet. This disjointed presentation demonstrates how a lack of structure and purpose renders communication ineffective.
- Better Story (Structured, but lacking impact): He then presents a more structured list of pentest findings (legacy name resolution, SMB signing disabled, ESC1 misconfigurations leading to domain compromise) and simply concludes with "That's a problem. You should fix it." This shows that while the facts are presented, the lack of context, impact, and a clear call to action still falls short of driving change. He also uses a "Here's a sandwich" example to illustrate a bland, uninspired presentation.
- Compelling Story (Full Narrative Arc): Finally, Nay presents the revised pentest debrief, as detailed in the "Technical Deep Dive" section. This version explicitly links technical vulnerabilities (legacy name resolution, SMB signing, ESC1 Active Directory Certificate Services misconfigurations) to their business impact (millions of dollars, operational downtime, brand damage, ransomware exposure) and concludes with a direct question about acceptable business risk. This "demo" effectively illustrates how combining structure, context, impact, and a clear call to action transforms a technical report into a powerful, change-driving narrative.
Through these carefully chosen examples, Nay provides tangible "proofs of concept" for his storytelling principles, allowing the audience to viscerally understand the difference between merely presenting facts and crafting a narrative that truly makes a point and inspires action.
Defensive Implications
▶ Watch: Essential "Tell Them" theory for clarity (7:35)
The insights from Joe Nay's talk have profound defensive implications for cybersecurity professionals across all roles. The core message is that even the most sophisticated defensive measures, threat intelligence, or vulnerability remediation efforts are futile if their importance and impact cannot be effectively communicated to the right stakeholders.
Here's how defenders can leverage storytelling:
- Justifying Budget and Resources: CISOs and security managers constantly face the challenge of securing budget for new tools, personnel, and training. Instead of presenting raw statistics on threat landscapes or vulnerability counts, defenders can craft narratives around specific attack scenarios that could impact their organization. For example, instead of saying, "We need $500,000 for an EDR solution," a defender could tell a story: "Imagine Mary in accounting receives a phishing email. She clicks it, and within hours, our systems are encrypted by ransomware, leading to weeks of operational downtime, millions in lost revenue, and severe brand reputation damage. This EDR solution is our best defense against that specific narrative, allowing us to detect and contain such threats before they escalate."
- Prioritizing Vulnerability Remediation: When presenting vulnerability scan results or penetration test findings, defenders should move beyond a simple list of CVEs and CVSS scores. Nay's example of the pentest debrief is a direct blueprint. For vulnerabilities like legacy name resolution protocols, disabled SMB signing, or ESC1 misconfigurations on Active Directory Certificate Services leading to domain compromise, the narrative should clearly articulate:
- The Threat Actor: Who might exploit this? (e.g., an opportunistic attacker, a nation-state actor).
- The Attack Path: How would they exploit it, step-by-step (without overwhelming detail)?
- The Business Impact: What would be the tangible consequences for the organization (operational downtime, data breach, financial loss, regulatory fines, brand damage)?
- The Call to Action: Frame it as a business risk decision: "Is this acceptable business risk, or should we prioritize remediation?"
- Improving Incident Response Communication: During an active incident, clear and concise communication is paramount. Storytelling can help cut through the noise. Rather than providing a minute-by-minute technical log, an incident response lead can craft a narrative for executives that covers:
- The Current State: What is happening now?
- The Impact: Who is affected, and how?
- The Action Being Taken: What are we doing about it?
- The Next Steps/Expected Outcome: What can they expect?
This allows leadership to grasp the situation quickly and make informed decisions without getting bogged down in technical jargon.
- Enhancing Security Awareness Training: The "protagonist" principle is invaluable here. Instead of dry policy reviews, security awareness training can use stories about "Mary in accounting" or "John in sales" falling victim to phishing or social engineering. These relatable narratives make the risks personal and memorable, significantly increasing the likelihood of employees adopting secure behaviors.
- Reporting Threat Intelligence: When sharing threat intelligence, simply listing IOCs (Indicators of Compromise) is insufficient. A compelling narrative would explain:
- The Adversary: Who is this group? What are their motivations?
- Their Tactics, Techniques, and Procedures (TTPs): How do they operate?
- Their Targets: Are we a likely target?
- The Potential Impact: What could happen if they succeed?
- Defensive Recommendations: What specific actions should we take based on this intelligence?
By embracing storytelling, defenders can transform their role from merely identifying problems to actively driving solutions, ensuring that their critical work translates into tangible improvements in an organization's security posture.
Key Takeaways
- Storytelling is a Critical Cybersecurity Skill: Beyond technical expertise, the ability to craft compelling narratives is essential for translating complex cybersecurity findings into actionable insights and driving organizational change.
- Leverage the "Tell Them Theory": Structure your communications by first stating what you'll say, then delivering the message, and finally recapping what you've said, ensuring clarity and retention for your audience.
- Prioritize Synopsis Over Plot Summary: For initial engagement, provide a concise, high-level synopsis that sparks interest and sets expectations, rather than overwhelming your audience with a detailed plot summary of technical steps.
- Introduce a Protagonist for Impact: Humanize your technical narratives by introducing a relatable character (e.g., "Mary in accounting") to illustrate the personal and business impact of security incidents or vulnerabilities, fostering emotional connection and urgency.
- Master Pacing and Be Specific: Vary your delivery speed to maintain engagement and emphasize critical points. Always be specific and concrete with examples, linking technical vulnerabilities to tangible business consequences like "millions of dollars in operational downtime" or "ransomware exposure."
- Frame Issues as Business Risks: Transform technical problems into strategic business decisions by clearly articulating the potential impact and asking stakeholders if the identified risk is "acceptable business risk," thereby compelling them to take ownership and action.
About the Speaker(s)
Joe Nay is a dynamic cybersecurity professional with eight years of diverse experience across both offensive (red team) and defensive (blue team) security disciplines. He spent several years as a dedicated penetration tester, gaining firsthand experience in uncovering critical vulnerabilities and understanding the challenges of communicating their impact. Currently, Nay serves as a Solutions Architect at Horizon3.ai, a company specializing in automated penetration testing, a role that bridges his manual testing background with cutting-edge autonomous security solutions. Beyond his cyber career, Joe Nay is also the host of "Once Upon a Podcast," a non-cyber-related podcast dedicated to fairy tales, which underscores his deep-seated passion for storytelling and narrative structures. This unique combination of technical prowess and a profound understanding of narrative informs his belief that effective communication is the linchpin for driving meaningful change in cybersecurity.