Cybersecurity What Is It? Cybersecurity is the protection of resources operated and/or accessed via the internet from cyber threats. These threats include unauthorized access to, or attack on, systems, websites, and other cyber resources.
Success in cybersecurity hinges on a robust system that consists of technology, best practices, and policies, coupled with a workforce that is sensitized on cyber risks.
The goal of cybersecurity is to protect to the extent possible the security of digital information (confidentiality) and to ensure that the information and systems are available and functioning as intended.
Cybersecurity protects the interest of the client and the organization in cyberspace.
It allows an organization to conduct business online without the fear of customers’ personal information being compromised.
Just like the security system of a building, cybersecurity employs a combination of several controls and measures to safeguard digital information.
These include but are not limited to the use of encryption to obfuscate data and access controls.
What is Cybersecurity?
The aim of cybersecurity is to safeguard digital systems and the information therein from unauthorized alteration, destruction or disruption as well as access and theft.
It is the function that protects a company’s online representation and operations.
Cybersecurity is akin to risk management. Multiple layers of controls are required to mitigate risks posed by cyber threats.
Importance of Cyber Security
The use of technology has become pervasive in both our personal and professional lives. The ubiquitous nature of computers, connectivity and the cloud have revolutionized the modern workplace.
Negative impacts of cyber attacks can include:
- Identity Theft and Fraud
- Loss of Control of your Finances
- Control of your Online Accounts by Unauthorized Persons
- Denial of Access to your Online Accounts
- Interruption of your Business
- Loss of Access to your Data
- Loss of your Data
- Loss of your Customers’ Trust
- Unplanned Expenses
Protection of your customers’ data may also be a requirement imposed by the law. A cybersecurity incident can also occur despite best efforts. Protecting confidential data of customers is imperative to win and retain customers’ trust.
Why do Cisco, Microsoft and IBM view Cybersecurity in a similar light? Because Cybersecurity is critical in protecting the systems, data and the employees of an organization. Like the employees, the data and systems of an organization are also crucial to the success of a business. The systems, data and the employees should be protected from digital threats.
Protection of Digital Assets
The following are examples of digital assets:
1. Data
Personal information of employees, customers and business partners. Financial information. Proprietary Information.
2. Devices
Computers (fixed and portable), peripheral devices, printers.
3. Networks
4. Applications
Websites, Software and other IT Infrastructure.
Organizations are moving their applications and data to cloud environments. Security of such environments encompasses security of the underlying cloud infrastructure and services, as well as workloads, applications, and data.
User accounts provide access to various services and resources, and as such are often targets of various attacks. Control of access to various services and resources is governed by various identity and access controls.
The term CIA Triad represents the foundation of security of an organization and comprises of the following elements.
- Confidentiality
- Integrity
- Availability
Confidentiality defines security of information and oversees that information is accessible only to authorized entities.
Integrity of information ensures that information is not altered by unauthorized entities.
Availability represents the ability of an entity to provide service to authorized entities.
Downtime of an online retail store to process orders represents a failure of availability.
The prevention of unauthorized access and interference with the operations of the retail store represents integrity.
Considering the needs of the online retail store, the principles of cyber security are largely comprised of availability and integrity. Confidentiality, however, plays a major role in the security of cloud and other information technology services.
Cybersecurity covers numerous domains of protection. Endpoint and network security cover protection at the edges of the network and within the network, respectively.
Some examples of this include:
- Computers (desktops and laptops)
- Telephones (landlines and smartphones)
- Tablets
Endpoints are protected through a variety of controls including antivirus software, EDR software, management software, and others.
3. Application Security
This area concentrates on the security of software. This includes everything from the development of secure software through to the testing and verification of software security.
It encompasses the security of Application Programming Interfaces (APIs), software updates and modifications (patching), and testing of software security.
Software contains a variety of security vulnerabilities and flaws. These may provide attackers with an avenue to access a computer system or data.
4. Cloud Security
Cloud Computing provides many advantages to organizations, including flexibility and cost savings. However, for the security of information and data stored in the cloud, additional controls and countermeasures may be necessary.
5. Information Security
The objective of information security is to ensure the integrity of information, and to protect information from being disclosed to, or altered by, unauthorized persons.
In the field of cybersecurity, information security merges with other domains of cybersecurity. The difference between the two is the scope of coverage.
6. Identity and Access Management
Controls in this domain regulate who can access a system, and the level of access granted.
It is based on the principle that access to information and systems should be provided only to those with a business need to know.
7. Data Security
Data security is concerned with the protection of information.
Protection and security of data may be accomplished through encryption. Other techniques may include the secure removal of data and the ongoing monitoring of data.
8. Critical Infrastructure Security
The security of facilities, systems, and services that are essential to the functioning of a society is also protected.
9. Mobile Security
The threats to the data residing on and accessed through mobile devices are similar to those of other computing devices. However, additional risks, threats and vulnerabilities are introduced by the use of wireless networks and mobile technologies.
10. AI Security
The adoption of artificial intelligence (AI) by organizations will require adjustments to include AI in the risk management and security frameworks of organizations.
NIST has identified potential threats to AI systems, including threats to the confidentiality, integrity and availability of AI systems and the data (e.g. training data, output data) used to develop and/or provide the AI system. NIST is also conducting research on attacks and threats to the AI field, including adversarial machine learning.
The most common types of cybersecurity threats and attacks include malware, phishing, and password attacks.
Malware is defined as any software designed to compromise a system, including:
- Viruses
- Trojan Horse programs (Trojans)
- Worms
- Spyware
Ransomware is a type of malware that infects a system and/or data and prevents legitimate users from accessing the system and/or data until an attacker’s demand for payment is satisfied.
In addition to prevention controls, incident response and business resumption plans are key elements of an organization’s cybersecurity resilience.
Messages that include a request for sensitive information or that direct the user to visit a fraudulent website to enter sensitive information are known as phishing attacks. Phishing messages may appear to come from:
- Banks
- Courier and delivery services
- Government entities
- Friends or colleagues
- Social media or online platforms
- Other software or online services
Phishing is the most common type of cyber attack, according to Microsoft.
Passwords are often protected and attacked using a variety of techniques, including:
- Password spraying
- Credential stuffing
- Brute force attacks
- Phishing
Preventing accounts from being compromised can be achieved through the use of unique passwords and MFA.
Denial-of-Service Attacks
An attack that makes resources unavailable to their intended users is called a denial-of-service (DoS) attack.
An attack that intends to do the same as a DoS attack but uses a larger number of systems to create the attack traffic is called a distributed denial-of-service (DDoS) attack.
Social Engineering
Attacks that depend on social skills of the attacker to trick people and gain illegal access to data are social engineering attacks.
Attackers may dress up as employees and call for help in interpreting system access and usage restrictions to gain system access.
Data Breaches
Any incident where access to data is gained by unauthorized entities is called a data breach.
Data breaches happen because of a variety of reasons which may include insider activities, system and application vulnerabilities, and mischief caused by external entities and other unforeseen circumstances.
How Does Cybersecurity Work?
To achieve adequate cyber security, a combination of methods is used.
Although the methods may vary, the goal is to secure data and resources from unauthorized access.
The methods include trainings for employees to help them understand the threats, use of encryption to protect data, and use of firewalls to restrict access to data and resources.
The methods may also include using monitoring and detection solutions to identify suspicious activities and respond to security incidents.
What is Described Above is The Workings of The NIST Cybersecurity Framework 2.0
The framework is made of six components:
- Govern – Set direction and objectives for managing cybersecurity risk.
- Identify – Understand and define the resources within the organization’s control that are to be protected.
- Protect – Reduce risk to an acceptable level.
- Detect – Identify activities that may impact cybersecurity.
- Respond – Preserve, protect and restore services.
- Recover – Restore and make changes to reduce the possibility of reoccurrence.
NIST CSF 2.0
The new edition of NIST CSF positions Govern as a core function to communicate the importance of integrating cybersecurity risk management in all levels of business strategy and decision-making.
What Is Zero Trust?
The key concept of Zero Trust is that any person or device, including those located within the trusted network, must be manually authenticated to gain access to the organization’s resources.
In 2017, NIST released a publication that offered guidance on designing a Zero Trust architecture. The publication outlined that an organization must integrate strong authentication and access control mechanisms to safeguard the organization’s resources.
An example of a traditional approach to architecture and a Zero Trust approach to architecture are described below.
A traditional approach to architecture usually employs a “trust but verify” approach, for instance, “This user is located in our organization, therefore we can trust this user.”
In a Zero Trust approach, architecture evaluates access and grants access to resources only if it confirms that the access is permitted and requested by the user, the resource owner and the resource itself. An example of a Zero Trust approach to the traditional case above is as follows, “This user is located in our organization, however, this user does not have the right to access this resource. Therefore, this user must not be granted access to this resource.”
What are the Benefits of Zero Trust Architecture?
Zero Trust architecture can be beneficial to an organization that utilizes distributed workforce, outsourced and/or cloud services.
In 2025, NIST released a guidebook that provides 19 example Zero Trust architectures.
Cybersecurity in the Real World
It is important to understand that “cybersecurity awareness” focuses on behavior, and not on the skills to identify 100% of phishing emails or other threats. In general, people should not feel obligated to click on a link that they believe may compromise the security of their account.
If passwords have already been entered, change your password and follow your organization’s process for handling compromised credentials.
This illustrates an important point:
Cybersecurity encompasses many different things, including but not limited to, technology and software. Human behavior and choice are critical to security.
What can the General Public do to improve Cybersecurity?
It is easier than you think to increase your cybersecurity.
You can utilize stronger and more unique passwords.
Password managers can help you generate and store stronger and more unique passwords.
Additionally, you can enable two-step verification.
Keep your software and apps up to date to ensure you have the latest and most secure version.
Think twice before you click.
Be skeptical of anything, including links and attachments from companies you think you can trust.
If you are planning to be online, protect your Wi-Fi.
You should always secure your router’s firmware.
Think carefully about which apps you give permission to.
You can significantly improve your safety and security by learning how to recognize and spot scams and frauds.
What can Companies do to improve Cybersecurity?
There are more things a company can do to improve its Cybersecurity. This includes properly securing and managing user access to the company’s data and information. A company should consider creating and implementing a structured Cybersecurity plan.
At a minimum, your organization should:
- Document critical IT assets
- Identify sensitive data
- Enable MFA
- Implement least privilege
- Keep up-to-date software releases
- Protect endpoints
- Secure the cloud
- Independently monitor critical assets
- Educate the workforce
- Retain backups and
- Respond to incidents
- Regularly benchmark supplier risks
- Write cybersecurity policy
NIST’s Cybersecurity Framework 2.0, allows organizations to manipulate cyber risk in a way that is meaningful to their business.
Cybersecurity and Information Security: What’s the Difference?
While the two concepts overlap and often figure jointly in a sentence, there is a difference.
Cybersecurity concentrates on measures and procedures adopted to safeguard digital information and systems from threat actors.
Protection of information across all domains (i.e. Digital, Physical and Cognitive) is termed as information security.
Protecting information and systems hosted on the Cloud from unauthorized access is a cybersecurity concern. Protecting a hardware token from unauthorized possession is an information security concern.
Is Cybersecurity Limited to Large Companies?
No.
Cybersecurity concerns are pertinent to all (e.g. Individuals, small businesses, large enterprises, nonprofit organizations, etc.).
A small business may have valuable information and systems, for example, customer email addresses and credit card numbers, employee bank account information and records, and software and systems administration accounts and credentials.
Factors such as the size and complexity of the business and available financial and human resources would dictate the security controls implemented by a business.
What is the Direction of the Cybersecurity Trend?
There is no looking back. Expect change.
The following topics are of growing interest:
Artificial Intelligence (AI)
Along with enhancing processes relating to security analysis, automation and recognition, the use of AI creates security concerns. Both IBM and NIST have published or updated research regarding the relationship between AI and security.
Cloud Security
With business applications and data residing in different locations, security systems have to keep pace with the telescoping perimeter of the organization.
Identity
The ongoing use of compromised credentials by attackers mandates the use of proper identity controls, along with MFA and least privilege.
Zero Trust
This security model is applicable to situations where assets and users are located in multiple, and possibly, untrusted locations.
Resilience
Security systems and procedures must be designed to preserve business operations, and protect the safety and health of employees and the general public.
What is Cyber Security?
Frequently Asked Questions
Cybersecurity is the protection of the “Crown Jewels” of an organization. While there are varying definitions, most include the protection of information systems, networks, and data.
The CIA Triad is comprised of the Confidentiality, Integrity and Availability of systems, processes and information. While they are always in balance, generally one is the primary focus and the others are supported.
The major areas of cybersecurity include, but are not limited to, network, application, and endpoint security. Other rapidly emerging areas include, but are not limited to, the security of the cloud, data, and mobile systems and platforms.
What are the implications of cyber insecurity?
Data, systems and processes of a business can be disrupted or compromised due to various cyber threats. This includes loss of business information and reputation.
What is the difference between Cyber Security and Information Security?
Cyber Security is focused on the usage control of digital flow of information while Information Security is focused on the overall protection of information in all forms.
What is a Zero Trust model?
Zero Trust model of security verifies and enforces security for all access requests. In this model, trust is not given to any user.
What measures can be taken to improve cyber security?
Use of unique and strong passwords, enabling MFA, securing backups, updating software, limiting access controls, and awareness on different types of threats and frauds can improve cyber security.
What is your understanding of cyber security?
Basic cyber security measures include the use of MFA and updating of software.
What should be the approach of an organization towards cyber security?
Organizations should ensure that access to their critical information and systems is protected. This should include taking measures to prevent threats, detecting and handling incidents, and restoring normal business operations.








