
Cybersecurity did not begin with computers.
This is inconvenient, because computers like to think that everything is all about them.[1]
To understand cybersecurity in depth, we must go back well beyond the invention of the modern computer.
Images in this article are generated by

EU AI Act Regulation 2024/1689
Long before anyone was patching servers, arguing about password rotation, losing USB sticks or pretending that “AI-powered” meant “not just a spreadsheet with opinions”, people were already trying to protect information. They wrapped messages round sticks. They hid meaning in diplomatic letters. They broke ciphers, abused networks, forged trust, exploited habits, built machines, wrote laws, and discovered, repeatedly and with admirable stubbornness, that secrecy is never just about secrecy.
This series is a history of cybersecurity told through 128 artefacts: 2⁷ of them, because powers of two are soothing, even to people disguised in suits, and because 128 gives the story room to breathe. The artefacts are not all objects you could put in a glass case. Some are machines, papers, laws, protocols, incidents, standards, practices, failures, or ideas that changed what security meant and how it was understood. That is deliberate. Cybersecurity is a long argument between information, power, trust, mathematics, human weakness, bureaucracy, money, law, and the cheerful optimism of people connecting things to other things.
The artefacts are arranged broadly chronologically. The order is not a ranking. History is not a leaderboard, despite what several empires and most vendors appear to believe. Some artefacts overlap. Some contradict each other. Some represent breakthroughs; others represent failures so instructive that not including them would frankly be rude.
The 128 artefacts are arranged in sixteen octets of eight entries each. They begin with the scytale and end, for now, among post-quantum standards, supply-chain provenance and AI-agent security.
Each artefact gets its own short article: not an academic paper, not a certification manual, and definitely not a vendor white paper pretending not to be a sales pitch. The aim is to tell a story: what the artefact was, why it mattered, what it reveals about security, and why it still echoes in the systems we use now.
A few themes will keep returning, because civilisation is slow at marking its own homework.
Security is not just technology. A cipher can fail because of a courier. A machine can fail because of an operator habit. A protocol can fail because trust was put in the wrong place. A supply chain can fail because everyone assumed that someone else was checking. A regulation can matter because incentives matter. A vulnerability can become historic not because it was clever, but because it exposed how much of the world was quietly depending on something nobody had funded, understood, or properly considered.
This history is also not only the history of famous men having famous thoughts under flattering lighting. The record is full of omissions. Women, people of colour, other marginalised groups, clerks, operators, maintainers, messengers, technicians, analysts, researchers, users and communities have often been ignored, hidden behind institutions, or treated as supporting scenery while someone else got the recognition, the plaque, or even the footnote. Where named credit is due, I try to give it. Where the sources are silent, I try not to mistake silence for absence.
That matters because cybersecurity has always been collective. It is craft, labour, mathematics, engineering, law, administration, politics and culture. It is also memory. Forgetting who did the work is itself a kind of vulnerability.
This is not a definitive history. Definitive histories are suspicious objects. This is a curated journey through 128 selected moments, devices, documents, scandals, ideas and habits that help explain how we got from secret messages on leather strips to a world where software updates, identity systems, cloud platforms, ransomware crews and machine-learning agents all sit inside the same threat model, glaring at one another.
This series will unfold over the coming months. Evil plots do not hatch themselves, nor do articles like these write themselves. Blaise Pascal once apologised for making a letter long because he had not had time to make it shorter. Mark Twain is often given the credit, because accurate attribution is apparently difficult even when nobody is actively trying to conceal it.
It is comparatively easy to write at length. Writing short, focussed, connected articles that form a coherent arc through this fascinating history, and draw out its often-overlooked lessons, takes rather longer.
The first artefact is the scytale: a strip of writing that only makes sense when wrapped around the right staff.
Which is ridiculous.
And elegant.
And, unfortunately, still rather familiar.

00000000
Footnotes
[1] I should not really personify computers. They hate that.
Tables of Contents
Octet the first
Interception and open design
| No | Date or Era | Artefact and Type | Title & Why? |
|---|---|---|---|
| 001 | c. 5th century BCE | Scytale Cipher device | Scytale: When the Key Was a Stick Important because it frames security as authorised reading. |
| 002 | c. 1st century BCE | Caesar cipher Cipher | Caesar Cipher: When the Key Was Three A useful teaching artefact because it introduces keys, brute force, substitution, and the recurring failure of security by obscurity. |
| 003 | c. 9th century | Al-Kindī & frequency analysis Cryptanalysis | Al-Kindī and Frequency Analysis: When the Letters Gave Themselves Away This is one of the birth moments of cryptanalysis: defence and offence become an evidence-based arms race rather than a contest of clever secrets. |
| 004 | 16th century | Vigenère cipher Cipher | The Vigenère Cipher: Many Caesars in a Trench Coat Once treated as unusually resistant to attack, its eventual defeat showed how repetition betrays structure. |
| 005 | 1507-1532 | Catherine of Aragon’s Tudor cipher Royal cryptography | Catherine of Aragon’s Tudor Cipher: When Secrecy Was Agency Ciphered correspondence during a period when diplomacy, dynastic survival and personal agency were entangled. |
| 006 | 1586 | Mary, Queen of Scots’ Babington cipher Nomenclator and interception | Mary, Queen of Scots’ Babington Cipher: When the Channel Was the Trap An early, brutally consequential example of communications security failure. Confidentiality, authenticity, chain of custody, informants and forged or manipulated message handling all appear in recognisable form centuries before the word “cyber” existed. |
| 007 | 1834 | Blanc brothers semaphore telegraph fraud Network abuse | Blanc Brothers Semaphore Telegraph Fraud: When the Error Was the Message Insider help, protocol manipulation, covert signalling, financial motives and legal uncertainty. |
| 008 | 1883 | Kerckhoffs’ principle Security principle | Kerckhoffs’ Principle: When the Enemy Gets the Manual A cryptosystem should remain secure even if everything except the key is public. The antidote to secret proprietary magic. Assume the attacker learns the design, then make the design survive anyway. |
Octet the second
Cryptography becomes machinery, intelligence and profession
Octet the third
Wartime habits become computer-security lessons
| No | Date or Era | Artefact and Type | Title & Why? |
|---|---|---|---|
| 017 | 1940 | Genevieve Grotjan Feinstein and PURPLE Diplomatic cryptanalysis | |
| 018 | 1940 to 1941 | Enigma Cillies and operator keying habits Operational-security failure | |
| 019 | 1940 to 1945 | Joan Clarke, Banburismus and Hut 8 Cryptanalytic method | |
| 020 | 1942 | Hedy Lamarr and George Antheil frequency hopping patent Anti-jamming communications | |
| 021 | 1944 | Colossus Codebreaking computer | |
| 022 | 1947 | Harvard Mark II moth and the visible bug Debugging artefact | |
| 023 | 1949 | Shannon’s Communication Theory of Secrecy Systems Cryptographic theory | |
| 024 | 1950s onward | TEMPEST and emissions security Side channel |
Octet the fourth
Shared machines need security architecture
| No | Date or Era | Artefact and Type | Title & Why? |
|---|---|---|---|
| 025 | |||
| 026 | |||
| 027 | |||
| 028 | |||
| 029 | |||
| 030 | |||
| 031 | |||
| 032 |
Octet the FIFTH
Modern foundations: principles, public key, standards and hidden trust
| No | Date or Era | Artefact and Type | Title & Why? |
|---|---|---|---|
| 033 | |||
| 034 | |||
| 035 | |||
| 036 | |||
| 037 | |||
| 038 | |||
| 039 | |||
| 040 |
Octet the SIXTH
Networks become defended territory
| No | Date or Era | Artefact and Type | Title & Why? |
|---|---|---|---|
| 041 | |||
| 042 | |||
| 043 | |||
| 044 | |||
| 045 | |||
| 046 | |||
| 047 | |||
| 048 |
Octet the SEVENTH
The public Internet inherits politics, privacy and exploitation
| No | Date or Era | Artefact and Type | Title & Why? |
|---|---|---|---|
| 049 | |||
| 050 | |||
| 051 | |||
| 052 | |||
| 053 | |||
| 054 | |||
| 055 | |||
| 056 |
Octet the EIGHTH
Visibility, hardening, naming and human-amplified malware
| No | Date or Era | Artefact and Type | Title & Why? |
|---|---|---|---|
| 057 | |||
| 058 | |||
| 059 | |||
| 060 | |||
| 061 | |||
| 062 | |||
| 063 | |||
| 064 |
Octet the Ninth
Internet-scale failure forces engineering discipline
| No | Date or Era | Artefact and Type | Title & Why? |
|---|---|---|---|
| 065 | |||
| 066 | |||
| 067 | |||
| 068 | |||
| 069 | |||
| 070 | |||
| 071 | |||
| 072 |
Octet the Tenth
Governance, cloud, botnets, APTs and the cyber-physical turn
| No | Date or Era | Artefact and Type | Title & Why? |
|---|---|---|---|
| 073 | |||
| 074 | |||
| 075 | |||
| 076 | |||
| 077 | |||
| 078 | |||
| 079 | |||
| 080 |
Octet the Eleventh
Trust breaks: CAs, states, suppliers, privacy and open source
| No | Date or Era | Artefact and Type | Title & Why? |
|---|---|---|---|
| 081 | |||
| 082 | |||
| 083 | |||
| 084 | |||
| 085 | |||
| 086 | |||
| 087 | |||
| 088 |
Octet the Twelfth
Baselines meet cloud-native, critical infrastructure and IoT reality
| No | Date or Era | Artefact and Type | Title & Why? |
|---|---|---|---|
| 089 | |||
| 090 | |||
| 091 | |||
| 092 | |||
| 093 | |||
| 094 | |||
| 095 | |||
| 096 |
Octet the Thirteenth
Blast radius, governance failure and ransomware economics
| No | Date or Era | Artefact and Type | Title & Why? |
|---|---|---|---|
| 097 | |||
| 098 | |||
| 099 | |||
| 100 | |||
| 101 | |||
| 102 | |||
| 103 | |||
| 104 |
Octet the Fourteenth
Identity, supply chain and threat-informed triage
| No | Date or Era | Artefact and Type | Title & Why? |
|---|---|---|---|
| 105 | |||
| 106 | |||
| 107 | |||
| 108 | |||
| 109 | |||
| 110 | |||
| 111 | |||
| 112 |
Octet the Fifteenth
The dependency stack starts wobbling in public
| No | Date or Era | Artefact and Type | Title & Why? |
|---|---|---|---|
| 113 | |||
| 114 | |||
| 115 | |||
| 116 | |||
| 117 | |||
| 118 | |||
| 119 | |||
| 120 |
Octet the Sixteenth
The response: design responsibility, governance, quantum and AI agents
| No | Date or Era | Artefact and Type | Title & Why? |
|---|---|---|---|
| 121 | |||
| 122 | |||
| 123 | |||
| 124 | |||
| 125 | |||
| 126 | |||
| 127 | |||
| 128 |
