Cybersecurity Gets Lost in Translation: Security Risk in Multilingual and Multinational Technology Programs

A cybersecurity term can be translated correctly and still be misunderstood. In multinational programs, shared meaning is part of risk management.

By John Keenan, CISSP

A correct translation can still produce the wrong decision

Global technology programs routinely cross languages, but cybersecurity frameworks are often discussed as if everyone shares the same professional vocabulary and institutional assumptions.

They do not.

“Zero trust” is not simply a statement that nobody should be trusted. “Risk acceptance” does not mean ignoring a vulnerability. “Authorization” can describe different processes depending on the environment. “Secure by design” is not a checklist applied just before release.

Each phrase can be translated accurately at the word level while the underlying concept remains misaligned. That becomes a cybersecurity problem when teams believe they have reached agreement and then build different assumptions into the system.

Security language is institutional language

Cybersecurity vocabulary develops inside organizations and professional communities. Defense organizations, healthcare systems, commercial software companies, startups, and multinational firms may use similar words while operating under different incentives, authorities, and risk tolerances.

Working with international stakeholders in Spanish has made this particularly visible to me. Explaining a security concept often requires more than translating the term. It may require explaining the institutional reason behind it.

Take “secure-by-design”. A literal rendering can communicate the words. A useful explanation connects those words to architecture decisions, customer expectations, lifecycle cost, vulnerability management, and responsibility for security outcomes.

That is not merely a linguistic distinction. It changes how a product team behaves.

Miscommunication becomes architectural debt

The consequences can persist long after the meeting ends.

A team may choose a component without recognizing the customer's supply-chain concerns. It may design an identity model around a trust relationship that the target environment will not permit. It may retain data because no one recognized minimization as an objective. It may depend on continuous cloud connectivity without considering an environment in which communications are degraded or prohibited.

Those are technical problems, but some begin as communication failures.

Once the assumption is embedded in hardware, software, contracts, or operational processes, correcting it becomes architectural debt. The cost of clarification rises dramatically.

AI raises the stakes for shared terminology

NIST's adversarial machine learning work has an instructive feature: it deliberately establishes a common taxonomy and terminology for AI attacks and mitigations. That is not incidental. A rapidly developing technical field becomes harder to secure when practitioners use the same words differently.

AI adds concepts such as poisoning, evasion, model privacy, misuse, retrieval-augmented generation, model provenance, and prompt-related attacks to an already dense cybersecurity vocabulary. Multinational teams must align not only on translations but on what those concepts mean operationally.

NIST's AI RMF similarly emphasizes context, governance, documentation, affected actors, and risk communication. Those ideas support treating multilingual communication as part of the operating context rather than an administrative detail.

Treat terminology as a control surface

Organizations can manage this risk deliberately.

Maintain bilingual glossaries for consequential terms. Pair definitions with examples and non-examples. Use architecture diagrams to reduce dependence on verbal explanations. Record assumptions. Distinguish formal customer requirements from advisory interpretation. When a decision matters, ask participants to explain the decision back in their own words rather than simply asking whether everyone agrees.

Most importantly, involve multilingual security professionals or qualified language professionals early when language could affect architecture, compliance, or risk decisions. The goal is not perfect linguistic elegance. It is shared technical understanding.

Cybersecurity professionals routinely identify trust boundaries between systems. Multinational programs have human trust boundaries as well. Information crosses them through language, professional culture, and institutional experience.

When that transfer fails, risk can enter the program before an attacker ever does.

For organizations building connected or AI-enabled technologies across borders, accurate cybersecurity communication is therefore not a soft skill sitting outside the security program. It is part of the mechanism by which the program makes sound security decisions.

Sources

·       NIST AI RMF

·       NIST AML 2025

·       CISA Secure AI

Next
Next

Security by Design for AI-Enabled Defense Systems: Lessons from Cross-Border Technology Development