
𝗢𝗰𝘁𝗲𝘁 𝘁𝗵𝗲 First
Cybersecurity did not begin with computers.
It began when one person had information, another had reason to protect it, and a third realised that the message had to travel through a world full of hands, eyes, habits, mistakes, incentives, and enemies.
Images in this article are generated by

EU AI Act Regulation 2024/1689
The first eight artefacts in this series span more than two thousand years, from an ancient strip of writing wrapped around a stick to Auguste Kerckhoffs’ remarkably modern insistence that a secure system should survive even when the enemy understands how it works.
That sounds like a journey through increasingly clever ciphers.
It is really a journey through increasingly uncomfortable questions.
The scytale begins with the simplest one: who is allowed to understand this? The writing itself can be plainly visible, yet useless without the right physical context. But even this apparently simple device already exposes most of the wider security problem. The courier can be intercepted. The strip reveals that communication exists. Its length, route, sender, and recipient may all reveal something. The system depends on people, procedures, shared objects, and assumptions about the adversary. The first artefact therefore already contains the seeds of modern threat modelling, albeit with substantially more leather and fewer architecture diagrams.
The Caesar cipher moves the secret from a physical staff into a rule and a small key. That immediately exposes another distinction which will matter throughout the series: the algorithm is not the key. If an adversary discovers how the system works and there are only a handful of possible keys, mystery evaporates rather quickly. Security by “nobody will know how this works” turns out to have ancient pedigree, unfortunately without becoming wiser with age.
Then al-Kindī changes the nature of the contest.
Instead of guessing, he counts.
Language has structure. Common letters remain common even when their names change. Enough ciphertext becomes evidence, and cryptanalysis becomes an empirical discipline: measure, compare, form hypotheses, test them, and let the supposedly concealed message betray itself statistically. It is one of the points at which codebreaking stops looking like clever puzzle-solving and starts looking recognisably like security analysis.
The Vigenère-style cipher responds exactly as security systems still do: it is designed to defeat the attack that worked last time. Instead of one alphabet, use several. Frequency analysis becomes much harder.
And then the key repeats.
Repetition creates rhythm. Rhythm creates evidence. The defence against one attack manufactures the structure required for another. The important lesson is not that Vigenère was foolish; it was an ingenious improvement. The lesson is that a stronger mechanism can still create a new attack surface of its own.
With Catherine of Aragon, the octet deliberately moves away from treating cryptography as an abstract contest between algorithms.
Cipher becomes agency.
Catherine used confidential communication in diplomacy, politics, dynastic conflict, and survival. Her correspondence exposes the machinery around encryption: who writes, who enciphers, who carries, who waits, who is trusted, who is ill, who is under pressure, and who has to get the message away before the courier leaves. Security is not a box marked cipher. It is a workflow conducted by human beings with competing needs and imperfect circumstances.
Mary, Queen of Scots, supplies the brutal counterpart.
Mary believed that she possessed a secret communications channel. In reality, her adversary controlled it. Her correspondence could be intercepted, read, copied, altered, resealed, and forwarded. Thomas Phelippes could not merely decipher messages; he could add text in the same cipher. Confidentiality failed, then integrity and authentication failed with it. The cipher protected against outsiders while the attacker had quietly become part of the system itself.
The Blanc brothers then dispense with cryptanalysis almost entirely.
They abused France’s Chappe optical telegraph by hiding private financial information in deliberate errors which the network faithfully transmitted and then corrected out of the official record. The authorised message arrived intact. The covert message arrived first.
That is protocol abuse, an insider threat, a covert channel, and an observability failure nearly two centuries before anyone thought of putting those phrases onto a conference slide. The dangerous information existed in the gap between what the system did and what the system recorded.
And then the octet arrives at Kerckhoffs.
Suppose the enemy gets the manual.
Not merely the ciphertext. The design. The device. The protocol. The training material. The implementation.
Does the system still stand?
Kerckhoffs’ famous principle says that long-term secrecy of the design should not be what keeps a cryptosystem secure. The mechanism should be capable of inspection and even capture; the smaller, replaceable key is what must remain secret.
That principle does not sit awkwardly at the end of these first eight artefacts.
It is what they have been approaching all along.
The scytale can be intercepted.
Caesar’s method can be discovered.
Language leaks statistical structure.
Repeated keys reveal rhythm.
Real cryptography lives inside human workflows.
A secure-looking channel may belong to the adversary.
A network may carry information its own records erase.
The answer cannot simply be “keep the trick secret.”
The first octet therefore begins with a stick and ends with an assumption:
The attacker gets the method.
Design for that world.
Because eventually the manual leaks, the equipment is captured, the protocol is reverse-engineered, the insider talks, the researcher gets curious, or somebody simply notices the pattern you hoped nobody would notice.
That is not the failure of secrecy.
It is the environment in which security has to work.

I
Octet the FIRST – Contents
Cryptography becomes machinery, intelligence and profession
| No | Date or Era | Artefact and Type | Title & Why? |
|---|---|---|---|
| 001 | c. 5th century BCE | Scytale Cipher device | Scytale: When the Key Was a Stick Important because it frames security as authorised reading. |
| 002 | c. 1st century BCE | Caesar cipher Cipher | Caesar Cipher: When the Key Was Three A useful teaching artefact because it introduces keys, brute force, substitution, and the recurring failure of security by obscurity. |
| 003 | c. 9th century | Al-Kindī & frequency analysis Cryptanalysis | Al-Kindī and Frequency Analysis: When the Letters Gave Themselves Away This is one of the birth moments of cryptanalysis: defence and offence become an evidence-based arms race rather than a contest of clever secrets. |
| 004 | 16th century | Vigenère cipher Cipher | The Vigenère Cipher: Many Caesars in a Trench Coat Once treated as unusually resistant to attack, its eventual defeat showed how repetition betrays structure. |
| 005 | 1507-1532 | Catherine of Aragon’s Tudor cipher Royal cryptography | Catherine of Aragon’s Tudor Cipher: When Secrecy Was Agency Ciphered correspondence during a period when diplomacy, dynastic survival and personal agency were entangled. |
| 006 | 1586 | Mary, Queen of Scots’ Babington cipher Nomenclator and interception | Mary, Queen of Scots’ Babington Cipher: When the Channel Was the Trap An early, brutally consequential example of communications security failure. Confidentiality, authenticity, chain of custody, informants and forged or manipulated message handling all appear in recognisable form centuries before the word “cyber” existed. |
| 007 | 1834 | Blanc brothers semaphore telegraph fraud Network abuse | Blanc Brothers Semaphore Telegraph Fraud: When the Error Was the Message Insider help, protocol manipulation, covert signalling, financial motives and legal uncertainty. |
| 008 | 1883 | Kerckhoffs’ principle Security principle | Kerckhoffs’ Principle: When the Enemy Gets the Manual A cryptosystem should remain secure even if everything except the key is public. The antidote to secret proprietary magic. Assume the attacker learns the design, then make the design survive anyway. |
