Journal of Cybersecurity Advance Access published December 1, 2015 Journal of Cybersecurity, 0(0), 2015, 1–16 doi: 10.1093/cybsec/tyv004 Research Article Research Article Critical visualization: a case for rethinking how we visualize risk and security Peter Hall1,* Claude Heath2 and Lizzie Coles-Kemp2 1Central St Martins University of the Arts London, 1 Granary Square, London N1C 4AA and 2Royal Holloway University of London, Surrey, TW200EX, UK Downloaded from *Correspondence address. Royal Holloway University of London, Surrey TW200EX, UK. Tel: þ44(0)1784434455; E-mail:
[email protected] Received 29 May 2015; accepted 28 September 2015 Abstract http://cybersecurity.oxfordjournals.org/ In an era of high-profile hacks, information leaks and cybercrime, cybersecurity is the focus of much corporate and state-funded research. Data visualization is regarded as an important tool in the detection and prediction of risk and vulnerability in cybersecurity, but discussion tends to remain at the level of the usability of visualization tools and how to reduce the cognitive load on the consumers of the visualizations. This focus is rooted in a desire to simplify the complexity of cybersecurity. This article argues that while usability and simplification are important goals for the designers of visualizations, there is a much wider discussion that needs to take place about the underlying narratives upon which these visualizations are based. The authors take the position that the narratives on which cybersecurity visualizations are based ignore important aspects of cyberse- curity and that their visual form causes the producers and users of these visualizations to focus too by guest on December 8, 2015 narrowly on adversarial security issues, ignoring important aspects of social and community-based security.