
Cybersecurity did not begin with computers.
This is inconvenient, because computers like to think that everything is all about them.[1]
To understand cybersecurity in depth, we must go back well beyond the invention of the modern computer.
Images in this article are generated by

EU AI Act Regulation 2024/1689
Long before anyone was patching servers, arguing about password rotation, losing USB sticks or pretending that “AI-powered” meant “not just a spreadsheet with opinions”, people were already trying to protect information. They wrapped messages round sticks. They hid meaning in diplomatic letters. They broke ciphers, abused networks, forged trust, exploited habits, built machines, wrote laws, and discovered, repeatedly and with admirable stubbornness, that secrecy is never just about secrecy.
This series is a history of cybersecurity told through 128 artefacts: 2⁷ of them, because powers of two are soothing, even to people disguised in suits, and because 128 gives the story room to breathe. The artefacts are not all objects you could put in a glass case. Some are machines, papers, laws, protocols, incidents, standards, practices, failures, or ideas that changed what security meant and how it was understood. That is deliberate. Cybersecurity is a long argument between information, power, trust, mathematics, human weakness, bureaucracy, money, law, and the cheerful optimism of people connecting things to other things.
The artefacts are arranged broadly chronologically. The order is not a ranking. History is not a leaderboard, despite what several empires and most vendors appear to believe. Some artefacts overlap. Some contradict each other. Some represent breakthroughs; others represent failures so instructive that not including them would frankly be rude.
The 128 artefacts are arranged in sixteen octets of eight entries each. They begin with the scytale and end, for now, among post-quantum standards, supply-chain provenance and AI-agent security.
Each artefact gets its own short article: not an academic paper, not a certification manual, and definitely not a vendor white paper pretending not to be a sales pitch. The aim is to tell a story: what the artefact was, why it mattered, what it reveals about security, and why it still echoes in the systems we use now.
A few themes will keep returning, because civilisation is slow at marking its own homework.
Security is not just technology. A cipher can fail because of a courier. A machine can fail because of an operator habit. A protocol can fail because trust was put in the wrong place. A supply chain can fail because everyone assumed that someone else was checking. A regulation can matter because incentives matter. A vulnerability can become historic not because it was clever, but because it exposed how much of the world was quietly depending on something nobody had funded, understood, or properly considered.
This history is also not only the history of famous men having famous thoughts under flattering lighting. The record is full of omissions. Women, people of colour, other marginalised groups, clerks, operators, maintainers, messengers, technicians, analysts, researchers, users and communities have often been ignored, hidden behind institutions, or treated as supporting scenery while someone else got the recognition, the plaque, or even the footnote. Where named credit is due, I try to give it. Where the sources are silent, I try not to mistake silence for absence.
That matters because cybersecurity has always been collective. It is craft, labour, mathematics, engineering, law, administration, politics and culture. It is also memory. Forgetting who did the work is itself a kind of vulnerability.
This is not a definitive history. Definitive histories are suspicious objects. This is a curated journey through 128 selected moments, devices, documents, scandals, ideas and habits that help explain how we got from secret messages on leather strips to a world where software updates, identity systems, cloud platforms, ransomware crews and machine-learning agents all sit inside the same threat model, glaring at one another.
This series will unfold over the coming months. Evil plots do not hatch themselves, nor do articles like these write themselves. Blaise Pascal once apologised for making a letter long because he had not had time to make it shorter. Mark Twain is often given the credit, because accurate attribution is apparently difficult even when nobody is actively trying to conceal it.
It is comparatively easy to write at length. Writing short, focussed, connected articles that form a coherent arc through this fascinating history, and draw out its often-overlooked lessons, takes rather longer.
The first artefact is the scytale: a strip of writing that only makes sense when wrapped around the right staff.
Which is ridiculous.
And elegant.
And, unfortunately, still rather familiar.

00000000 NUL
Footnotes
[1] I should not really personify computers. They hate that.
Tables of Contents
Below you can find the list of artefacts in their octets and jump directly to any one. Follow the link for an octet to read about how the artefacts are linked and understand the overall thinking behind it.
Octet the first
Interception and open design
| No | Date or Era | Artefact and Type | Title & Why? |
|---|---|---|---|
| 001 | c. 5th century BCE | Scytale Cipher device | Scytale: When the Key Was a Stick Important because it frames security as authorised reading. |
| 002 | c. 1st century BCE | Caesar cipher Cipher | Caesar Cipher: When the Key Was Three A useful teaching artefact because it introduces keys, brute force, substitution, and the recurring failure of security by obscurity. |
| 003 | c. 9th century | Al-Kindī & frequency analysis Cryptanalysis | Al-Kindī and Frequency Analysis: When the Letters Gave Themselves Away This is one of the birth moments of cryptanalysis: defence and offence become an evidence-based arms race rather than a contest of clever secrets. |
| 004 | 16th century | Vigenère cipher Cipher | The Vigenère Cipher: Many Caesars in a Trench Coat Once treated as unusually resistant to attack, its eventual defeat showed how repetition betrays structure. |
| 005 | 1507-1532 | Catherine of Aragon’s Tudor cipher Royal cryptography | Catherine of Aragon’s Tudor Cipher: When Secrecy Was Agency Ciphered correspondence during a period when diplomacy, dynastic survival and personal agency were entangled. |
| 006 | 1586 | Mary, Queen of Scots’ Babington cipher Nomenclator and interception | Mary, Queen of Scots’ Babington Cipher: When the Channel Was the Trap An early, brutally consequential example of communications security failure. Confidentiality, authenticity, chain of custody, informants and forged or manipulated message handling all appear in recognisable form centuries before the word “cyber” existed. |
| 007 | 1834 | Blanc brothers semaphore telegraph fraud Network abuse | Blanc Brothers Semaphore Telegraph Fraud: When the Error Was the Message Insider help, protocol manipulation, covert signalling, financial motives and legal uncertainty. |
| 008 | 1883 | Kerckhoffs’ principle Security principle | Kerckhoffs’ Principle: When the Enemy Gets the Manual A cryptosystem should remain secure even if everything except the key is public. The antidote to secret proprietary magic. Assume the attacker learns the design, then make the design survive anyway. |
Octet the second
Cryptography becomes machinery, intelligence and profession
| No | Date or Era | Artefact and Type | Title & Why? |
|---|---|---|---|
| 009 | 1917 | Vernam teleprinter cipher Machine cryptography | Gilbert Vernam’s paper tapes: When cryptography learns to type for itself Vernam’s teleprinter cipher mechanised encryption by combining message text with a key stream. It points towards stream ciphers, automated communications security and the modern habit of securing machines talking to machines. Cryptography has to become both operational and scalable. |
| 010 | 1917 to 1919 | One-time pad Cryptographic ideal | Perfect secrecy, paid for in advance The one-time pad gives perfect secrecy when its key material is truly random, as long as the key is used once, kept secret and is as long as the message. Those conditions are wildly inconvenient, which is why humans invented logistics and then complained about them. Its value is as the high-water mark against which practical cryptography is judged. |
| 011 | 1917 | Zimmermann Telegram Signals intelligence and diplomacy | The secret that needed a cover story The Zimmermann Telegram was an encrypted German diplomatic message proposing a Mexican alliance against the United States. British cryptanalysts recovered enough of its content to turn a secret cable into a strategic public event. Its significance is not only the cryptanalysis. It shows the whole intelligence lifecycle: interception, decryption, source protection, disclosure strategy and political effect. Modern cyber operations still face the same awkward question: when you know something secretly, how do you use it without burning how you know it? |
| 012 | 1920s to 1945 | Enigma Cryptographic system | Breaking the machine was only half the secret. And the smaller half by far Enigma made encryption electromechanical, portable and routine for military communications. Its defeat was not one magic trick: captured material, operator habits, procedural errors, traffic analysis, mathematics, machines and disciplined organisation all mattered. That is why Enigma belongs in a cybersecurity history rather than just a cryptography history. It shows that the security of a system includes training, workflow, key discipline, maintenance, configuration and the small human shortcuts that adversaries patiently collect. |
| 013 | 1920s to 1940s | Elizebeth Friedman’s rumrunner and spy ciphers Law-enforcement cryptanalysis | The woman who read everyone else’s secrets, then vanished from the story Elizebeth Smith Friedman broke thousands of encrypted messages used by rumrunners and smugglers, built cryptanalytic capability for the US Coast Guard and later worked against German espionage communications in South America. Her work shows cryptanalysis as law-enforcement tradecraft, not only as military codebreaking. She is an essential overlooked figure because much of her credit was displaced onto institutions and men around her. This artefact links cryptography to prosecution, expert testimony, intelligence analysis and the unpleasant human habit of forgetting who actually did the work. |
| 014 | 1920s to 1940s | Agnes Meyer Driscoll’s naval codebreaking Naval cryptanalysis | The woman who trained the men history remembered Agnes Meyer Driscoll, often called the First Lady of Naval Cryptology, attacked Japanese naval systems and trained many later US Navy cryptanalysts. She also pushed early machine assistance for cryptanalysis, which matters because scale was already becoming part of the problem. Her artefact is not one cipher but a professional lineage. Cybersecurity often worships single exploits; Driscoll represents deep skill, mentoring, continuity and institutional memory, which are less glamorous than a logoed vulnerability but far more useful. |
| 015 | 1932 to 1940 | Polish bomba, Zygalski sheets, and the British Bombe Cryptanalytic machinery | The head start that became a lifeline The Polish Cipher Bureau did not merely inspire later Enigma work; it gave Britain a running start. Marian Rejewski, Jerzy Rozycki and Henryk Zygalski turned Enigma into an engineering and mathematical problem, and Zygalski sheets and the bomba showed that machinery could be used to industrialise cryptanalysis. The later British Bombe, shaped by Alan Turing, Gordon Welchman and many others, scaled that idea inside a wartime intelligence factory. The artefact also opens the door to the often-hidden labour of women operators and clerical specialists who kept the machines, menus and punched records moving. |
| 016 | 1940s to 1960s | The software patch Maintenance concept | The small repair that became a permanent way of life Patching is a superbly literal term. Early programs on paper tape or punched cards could be corrected by covering, replacing or splicing the faulty part, and the word survived the move from physical media to code updates. Cybersecurity inherited the term and turned it into a permanent ritual: vulnerability appears, fix is issued, estate refuses to comply. Rinse, repeat ad nauseum. |
Octet the third
What Systems Reveal
| No | Date or Era | Artefact and Type | Title & Why? |
|---|---|---|---|
| 017 | 1940 | Genevieve Grotjan Feinstein and PURPLE Diplomatic cryptanalysis | When the Pattern Revealed the Machine Genevieve Grotjan Feinstein spotted the pattern that broke open the Japanese diplomatic cipher machine known to the US as PURPLE. That insight enabled the construction of an analogue machine and the exploitation of diplomatic traffic during the Second World War. She later contributed to Venona, including work around recognising key reuse. The artefact is a reminder that cryptanalytic breakthroughs often begin as disciplined attention to a faint pattern others had not yet recognised, not as cinematic genius glowing under one convenient desk lamp. |
| 018 | 1940 to 1941 | Enigma cillies and operator keying habits Operational-security failure | When Randomness Became Routine A cilly was a guessable Enigma message setting: something pronounceable, patterned, related to an indicator, or otherwise born from operator habit rather than randomness. Bletchley Park exploited these human shortcuts alongside cribs, Herivel-type insights and machine assistance. The often-retold “girlfriend name” examples should be handled carefully, but they point to a real lesson: users create patterns when systems demand tedious randomness. Mavis Lever, later Mavis Batey, is rightly associated with spotting lazy Enigma usage in Italian and Abwehr work; the wider artefact is operational security collapsing under human convenience. |
| 019 | 1940 to 1945 | Joan Clarke, Banburismus and Hut 8 Cryptanalytic method | The Mathematics Before the Machine Joan Clarke was one of the few senior female cryptanalysts at Bletchley Park and the longest-serving member of Hut 8, which attacked German naval Enigma. Her work on Banburismus and related methods helped reduce the search space for naval keys. This artefact matters because naval Enigma was operationally critical and technically stubborn. Clarke also exposes a familiar security problem with historical record-keeping: when secrecy and sexism work together, attribution becomes a casualty. |
| 020 | 1942 | Hedy Lamarr and George Antheil frequency hopping patent Anti-jamming communications | The Signal That Would Not Sit Still Hedy Lamarr and George Antheil patented a frequency-hopping idea during the Second World War to make radio-controlled torpedoes harder to jam or intercept. It was not deployed in that wartime form, but it anticipated spread-spectrum thinking used in later secure and resilient wireless communications. It is not cybersecurity in the narrow compliance-checklist sense, mercifully. It belongs because communications security includes resistance to interception, jamming and traffic manipulation, and because Lamarr is one of the clearest examples of technical invention being dismissed when it came from the wrong sort of person. |
| 021 | 1944 | Colossus Codebreaking computer | The Computer Britain Pretended It Had Never Built Colossus was built at Bletchley Park to help attack the Lorenz cipher, not Enigma, and it is central to both computing and cybersecurity history. It linked electronics, probability, intercepted traffic and operational intelligence at a scale pencil-and-paper work could not have matched. Its secrecy delayed public recognition for decades, while the broader workforce around it was also under-credited. Colossus is an artefact of high-end security as collective engineering: mathematicians, engineers, operators, intercept stations and intelligence analysts all formed the system. |
| 022 | 1947 | Harvard Mark II moth and the visible bug Debugging artefact | When the Bug Was Visible The famous moth taped into the Harvard Mark II logbook did not invent the word bug, which predates electronic computers. It did, however, help make debugging visible: a fault was observed, preserved, labelled and folded into the culture of computing. The common Grace Hopper version of the story is useful but needs care. Hopper helped popularise the story and cement the bug in computing folklore, but the artefact itself matters because it turns security-adjacent fault finding into a disciplined habit: evidence rather than folklore. |
| 023 | 1949 | Shannon’s Communication Theory of Secrecy Systems Cryptographic theory | Unique does not mean easy. Ambiguous does not mean secret Claude Shannon made secrecy mathematical. His work linked cryptography to information theory, defined concepts such as perfect secrecy and helped move the field from craft to science. For cybersecurity, it is a founding text because it asks what can be proved about secrecy rather than what merely feels hard to guess. |
| 024 | 1950s onward | TEMPEST and emissions security Side channel | The Cipher Worked. Yet the Secret Escaped. TEMPEST work showed that systems can leak information through electromagnetic emissions and other physical side channels. This widens cybersecurity beyond software and passwords: a secure computation may still radiate clues. The idea later echoes in power analysis, acoustic leakage, cache timing attacks and the general misery that physics keeps joining the threat model. |
Octet the fourth
Shared machines need security architecture
| No | Date or Era | Artefact and Type | Title & Why? |
|---|---|---|---|
| 025 | |||
| 026 | |||
| 027 | |||
| 028 | |||
| 029 | |||
| 030 | |||
| 031 | |||
| 032 |
Octet the FIFTH
Modern foundations: principles, public key, standards and hidden trust
| No | Date or Era | Artefact and Type | Title & Why? |
|---|---|---|---|
| 033 | |||
| 034 | |||
| 035 | |||
| 036 | |||
| 037 | |||
| 038 | |||
| 039 | |||
| 040 |
Octet the SIXTH
Networks become defended territory
| No | Date or Era | Artefact and Type | Title & Why? |
|---|---|---|---|
| 041 | |||
| 042 | |||
| 043 | |||
| 044 | |||
| 045 | |||
| 046 | |||
| 047 | |||
| 048 |
Octet the SEVENTH
The public Internet inherits politics, privacy and exploitation
| No | Date or Era | Artefact and Type | Title & Why? |
|---|---|---|---|
| 049 | |||
| 050 | |||
| 051 | |||
| 052 | |||
| 053 | |||
| 054 | |||
| 055 | |||
| 056 |
Octet the EIGHTH
Visibility, hardening, naming and human-amplified malware
| No | Date or Era | Artefact and Type | Title & Why? |
|---|---|---|---|
| 057 | |||
| 058 | |||
| 059 | |||
| 060 | |||
| 061 | |||
| 062 | |||
| 063 | |||
| 064 |
Octet the Ninth
Internet-scale failure forces engineering discipline
| No | Date or Era | Artefact and Type | Title & Why? |
|---|---|---|---|
| 065 | |||
| 066 | |||
| 067 | |||
| 068 | |||
| 069 | |||
| 070 | |||
| 071 | |||
| 072 |
Octet the Tenth
Governance, cloud, botnets, APTs and the cyber-physical turn
| No | Date or Era | Artefact and Type | Title & Why? |
|---|---|---|---|
| 073 | |||
| 074 | |||
| 075 | |||
| 076 | |||
| 077 | |||
| 078 | |||
| 079 | |||
| 080 |
Octet the Eleventh
Trust breaks: CAs, states, suppliers, privacy and open source
| No | Date or Era | Artefact and Type | Title & Why? |
|---|---|---|---|
| 081 | |||
| 082 | |||
| 083 | |||
| 084 | |||
| 085 | |||
| 086 | |||
| 087 | |||
| 088 |
Octet the Twelfth
Baselines meet cloud-native, critical infrastructure and IoT reality
| No | Date or Era | Artefact and Type | Title & Why? |
|---|---|---|---|
| 089 | |||
| 090 | |||
| 091 | |||
| 092 | |||
| 093 | |||
| 094 | |||
| 095 | |||
| 096 |
Octet the Thirteenth
Blast radius, governance failure and ransomware economics
| No | Date or Era | Artefact and Type | Title & Why? |
|---|---|---|---|
| 097 | |||
| 098 | |||
| 099 | |||
| 100 | |||
| 101 | |||
| 102 | |||
| 103 | |||
| 104 |
Octet the Fourteenth
Identity, supply chain and threat-informed triage
| No | Date or Era | Artefact and Type | Title & Why? |
|---|---|---|---|
| 105 | |||
| 106 | |||
| 107 | |||
| 108 | |||
| 109 | |||
| 110 | |||
| 111 | |||
| 112 |
Octet the Fifteenth
The dependency stack starts wobbling in public
| No | Date or Era | Artefact and Type | Title & Why? |
|---|---|---|---|
| 113 | |||
| 114 | |||
| 115 | |||
| 116 | |||
| 117 | |||
| 118 | |||
| 119 | |||
| 120 |
Octet the Sixteenth
The response: design responsibility, governance, quantum and AI agents
| No | Date or Era | Artefact and Type | Title & Why? |
|---|---|---|---|
| 121 | |||
| 122 | |||
| 123 | |||
| 124 | |||
| 125 | |||
| 126 | |||
| 127 | |||
| 128 |
