Cybersecurity is the practice of
protecting computer systems,
networks, programs, devices,
and data from digital threats,
damage, or unauthorized
access. It involves a combination
of technologies, processes, and
controls designed to reduce the
risk of cyberattacks and ensure the
confidentiality, integrity, and
availability of information.
What Does Cybersecurity Do?
Cybersecurity helps prevent unauthorized
access to data and organizational/personal
assets.
The goal of cybersecurity is to ensure that a
safe and secure environment is provided to
individuals and organizations where they are
not at risk from bad actors.
At the organizational level, cybersecurity aims
to protect computer systems, networks,
information, trade secrets from unauthorized
access and harm.
While at the individual level, cybersecurity
aims to protect the personal assets and
information of the individual.
Core Goals of Cybersecurity
Confidentiality:
Goal: To ensure that sensitive information is accessed,
used, or disclosed only by authorized individuals or
entities. It's about keeping secrets secret.
Why it's important: Prevents unauthorized viewing, theft,
or misuse of data, protecting privacy, intellectual
property, and competitive advantage.
Integrity:
Goal: To maintain the accuracy, completeness, and
trustworthiness of data and systems. It's about ensuring
data has not been altered or corrupted in an unauthorized
way.
Why it's important: Guarantees that information can be
relied upon, preventing fraud, errors, and system
malfunctions due to tampered data.
Availability:
Goal: To ensure that authorized users can reliably access
systems and data when needed. It's about keeping
services up and running.
Why it's important: Prevents disruption of business
operations, loss of productivity, and denial of critical
services.
The importance of cybersecurity
cannot be overstated in our modern, interconnected
world. It is no longer an optional add-on but a
fundamental necessity for individuals, businesses,
governments, and critical infrastructure.
Here's why cybersecurity is critically important:
• Protects Sensitive Data and Privacy
• Prevents Significant Financial Losses
• Maintains Trust and Reputation
• Ensures Operational Continuity and Resilience
• Protects Critical Infrastructure
• Safeguards National Security
• Compliance with Laws and Regulations
• Enables Digital Transformation and Innovation
Cybersecurity Benefits
Cybersecurity has become a need given our
dependencies on technology. If the general
public feels unsafe about browsing the
internet and having their devices infected or
data stolen, then it’ll be a huge problem.
Cybersecurity professionals help prevent this.
Here are the key benefits of robust
cybersecurity:
• Data Protection:
• Reputation and Trust Preservation:
• Financial Savings and Loss Prevention:
• Operational Continuity and Resilience:
• Compliance with Regulations and Legal
Requirements:
• Protection of Intellectual Property (IP) and
Trade Secrets:
• Enhanced Productivity:
• Competitive Advantage:
How Cybersecurity Works
Cybersecurity works by employing a combination
of technologies, processes, and people to
protect computer systems, networks, programs,
devices, applications and data from cyber threats.
Its core goal is to ensure the confidentiality,
integrity, and availability of digital information.
The approach is often described as "Defense in
Depth," which means using multiple, layered
security controls so that if one layer fails, another
is there to back it up.
Layer Focus Examples of Tools/Practices
Security awareness training
Educating people, as they (recognizing phishing), strong
Human Layer
are often the weakest link. password policies, Multi-Factor
Authentication (MFA).
Firewalls (acting as a digital
Controlling the traffic
barrier), Intrusion
Perimeter / between your internal
Detection/Prevention Systems
Network network and the outside
(IDS/IPS), Virtual Private Networks
internet.
(VPNs).
Key Principles Securing individual devices Antivirus/Anti-malware software,
and Layers of Endpoint that connect to the network Endpoint Detection and Response
Defense (laptops, phones, servers).
Protecting the software and
(EDR), regular software patching.
Secure coding practices, Web
Application services you use from being Application Firewalls (WAFs),
exploited. regular security testing.
A robust cybersecurity
strategy involves protecting Protecting the information
Encryption (making data
different areas of an Data itself, regardless of where it
unreadable without a key), Data
organization or individual's is stored or travels.
Loss Prevention (DLP) tools,
digital life: regular data backups.
Identity and Access Management
Identity & Managing who can access (IAM) systems, Principle of Least
Access what resources. Privilege (users only get the access
they need).
•Prevent : Implement controls like firewalls, strong passwords,
and employee training to stop attacks before they happen.
•Detect : Continuously monitor systems and networks to identify
suspicious activity or signs of a breach in real-time using tools like
security monitoring software.
The
•Respond : Have an Incident Response Plan ready to quickly
Cybersecurity contain the threat, eradicate the attacker's presence, and minimize
Process the damage.
Cybersecurity isn't just about •Recover : Restore systems and data back to normal operation,
static defenses; it's a often using secure backups, and conduct a post-incident review to
continuous, cyclical process: learn and improve defenses.
Cybersecurity
Domain
Common Cyber
Threats
Common Cyber
Defenses
Evolving Threat
Landscape
The cybersecurity threat
landscape is dynamic and
complex, characterized by rapid
changes in attacker tactics,
techniques, and procedures
(TTPs), as well as the emergence
of new vulnerabilities and attack
vectors. What was a primary
concern five years ago might still
be present, but now
overshadowed by more
sophisticated and pervasive
threats.
Emerging
Cybersecurity
Trends
The threat landscape is constantly
evolving, and so too are the
strategies and technologies used
to defend against it. Understanding
these trends is crucial for staying
ahead of future challenges.
Key Threat
Actors
The threat landscape is
constantly evolving, and so
too are the strategies and
technologies used to defend
against it. Understanding
these trends is crucial for
staying ahead of future
challenges.
Rank Cyber Threat Description Key Risk Factors
Highly sophisticated, complex, and Stealing classified information,
State-Sponsored persistent attacks conducted by intellectual property (especially in
1 Attacks / nation-state actors for strategic defense), disrupting critical
Espionage advantage, intelligence gathering, or national infrastructure, and
sabotage. undermining political processes.
Malicious software that blocks Operational disruption of
access to a system or encrypts data, essential public services
Ransomware &
2 demanding a ransom for release. (healthcare, local government),
Malware
Malware (viruses, worms, trojans) is massive financial loss, and data
Top Threats: the common delivery vehicle. exfiltration (double extortion).
Defence & PSUs Social
Attacks that manipulate individuals
(employees, contractors) into
Human error is the primary
weakness. Highly effective for initial
divulging confidential information,
The defense and public 3 Engineering &
downloading malware, or
access to well-defended networks,
sectors are prime targets for Phishing
performing actions that grant
often leading to ransomware or
cyber threats due to the highly attackers access.
espionage.
sensitive data they manage
and the critical services they Targeting third-party vendors,
provide. suppliers, or contractors with Exploiting trusted relationships to
weaker security to gain infiltrate multiple high-value
Supply Chain
4 unauthorized access to the main, targets simultaneously. A major
Compromise
more secure organization (e.g., a threat, especially in the defense
defense contractor or government industry's ecosystem.
agency).
Overwhelming a system, network, or
Disruption of public services and
website with a flood of malicious
Distributed communication channels,
traffic to make it unavailable to
5 Denial of Service particularly during major events or
legitimate users. Often politically or
Cyber Threat Description Key Risk Factors
Stealing classified information,
Highly sophisticated, complex, and
State-Sponsored intellectual property (especially in
persistent attacks conducted by nation-
Attacks / defense), disrupting critical national
state actors for strategic advantage,
Espionage infrastructure, and undermining
intelligence gathering, or sabotage.
political processes.
Malicious software that blocks access
Operational disruption of essential
to a system or encrypts data,
Ransomware & public services (healthcare, local
demanding a ransom for release.
Malware government), massive financial loss,
Malware (viruses, worms, trojans) is the
Technical Debt &
and data exfiltration (double extortion).
common delivery vehicle.
Legacy System Social
Attacks that manipulate individuals
(employees, contractors) into divulging
Human error is the primary weakness.
Challenge (TDLS) Engineering &
Phishing
confidential information, downloading
malware, or performing actions that
Highly effective for initial access to
well-defended networks, often leading
TDLS aren't just IT headaches; grant attackers access.
to ransomware or espionage.
they are a fundamental
cybersecurity risk multiplier Targeting third-party vendors, suppliers,
Exploiting trusted relationships to
in the Defense and Public or contractors with weaker security to
infiltrate multiple high-value targets
Sector. Due to underlying Supply Chain gain unauthorized access to the main,
simultaneously. A major threat,
vulnerability of Legacy Compromise more secure organization (e.g., a
especially in the defense industry's
System makes all other defense contractor or government
ecosystem.
threats more effective, more agency).
costly, and more dangerous. Overwhelming a system, network, or
Disruption of public services and
Distributed website with a flood of malicious traffic
communication channels, particularly
Denial of Service to make it unavailable to legitimate
during major events or conflicts,
(DDoS) Attacks users. Often politically or ideologically
undermining public confidence.
motivated by hacktivists.
Supply Chain
Risk
Supply Chain Risk in
Cybersecurity refers to
vulnerabilities introduced
through third-party vendors,
contractors, or software
components that
organizations rely on.
Zero Trust
Security
Traditional security operated
on a "castle-and-moat"
model: everything outside the
network perimeter (the
firewall) was untrusted, and
everything inside the network
was implicitly trusted.
Zero Trust Architecture (ZTA)
reverses this assumption: No
user, device, or application
is trusted by default,
regardless of its location.
Every single access request
must be explicitly and
continuously verified.
Zero Trust
Architecture
At its heart, Zero Trust
operates on the idea that
no entity (user, device,
application, network
segment) is inherently
trustworthy, regardless of
its location (inside or
outside the network
perimeter). Every access
request must be explicitly
verified.
Zero Trust: The
Five Pillars
While Zero Trust is a holistic
security strategy, it's often
broken down into "pillars"
to help organizations
understand and implement
its various components.
Different frameworks might
articulate these slightly
differently, but the core
areas remain consistent.
Zero Trust:
Why it matter
for Public
Sector
Zero Trust is crucial for the
public sector because it
provides a modern, robust
security framework
necessary to protect highly
sensitive data, critical
national infrastructure, and
an increasingly distributed
workforce.
Zero Trust:
Why it matter
for Public
Sector
Zero Trust is crucial for the
public sector because it
provides a modern, robust
security framework
necessary to protect highly
sensitive data, critical
national infrastructure, and
an increasingly distributed
workforce.
Data Security &
Classification
is foundational concept in
cybersecurity and compliance.
In essence, you can't truly
secure your data until you first
understand and categorize it.
Data Security &
Classification
is foundational concept in
cybersecurity and compliance.
In essence, you can't truly
secure your data until you first
understand and categorize it.
Identity & Access
Management
(IAM) Solution
is s a framework of policies,
processes, and technologies
that enables organizations to
manage digital identities and
control user access to
resources. Simply put, it
ensures that the right people
have the right access to the
right resources at the right
time – and that the wrong
people don't.
Endpoint
Security
Solution
An Endpoint Security
Solution is a
comprehensive
cybersecurity approach
designed to protect all
connected devices
(endpoints) within an
organization's network from
various cyber threats.
Network &
Perimeter
Solution
A Network & Perimeter
Solution refers to the
comprehensive set of security
measures, technologies, and
strategies designed to protect
the boundaries and internal
infrastructure of a computer
network.
Perimeter Security is the
castle wall, moat, and
gatehouse, controlling who
gets in and out.
Network Security includes
the internal defenses, patrols
within the castle, and
segmented areas to protect
different valuable assets
inside.
Web &
Application
Security
Web and Application Security
is the practice of protecting
websites, web applications,
and APIs from Internet-based
threats throughout their entire
lifecycle. The core aim is to
ensure the confidentiality,
integrity, and availability of
the application and its
sensitive data, safeguarding
both the business and its
users.
Operational
Technology
Security
Operational Technology (OT)
Security focuses on
protecting systems that
manage industrial operations
like industrial control systems
(ICS), supervisory control and
data acquisition (SCADA)
systems, and manufacturing,
energy, transportation, and
utilities. These systems differ
from traditional IT systems in
their priorities and
architecture. Unlike
traditional IT security, which
focuses on data
confidentiality, integrity, and
availability, OT security often
prioritizes the availability and
safety of physical processes.
Vulnerability
Management
(VM) & Patch
Management
(PM)
Vulnerability Management
(VM) and Patch Management
(PM) are two distinct but
intrinsically linked disciplines
that form the cornerstone of
effective cybersecurity.
Together, they create a
continuous cycle aimed at
reducing an organization's
overall risk exposure.
Threat
Intelligence (TI)
Integration
Threat Intelligence (TI)
Integration is the process of
incorporating relevant, timely,
and actionable information
about current and potential
threats into an organization's
existing security tools,
systems, and processes. It
moves an organization beyond
reactive defense to proactive
anticipation and prevention
of cyberattacks.
How Threat Intelligence is Integrated
Threat intelligence can be integrated across a wide array of security tools and functions:
Security Tool/Function How TI is Integrated Benefits
Automatically update blacklists of malicious IPs, Proactive blocking of known threats at
Firewalls & IDS/IPS
domains, and URLs. the network perimeter.
SIEM (Security Information & Correlate internal logs with threat indicators; Faster detection of sophisticated
Event Management) enrich alerts with threat context. attacks; reduced false positives.
Endpoint Detection & Response Scan endpoints for known malicious file hashes Detect advanced malware and insider
(EDR) (IoCs) or suspicious TTPs. threats on endpoints.
SOAR (Security Orchestration, Automate response actions (e.g., block IP, Rapid, consistent, and automated
Automation, & Response) quarantine host) based on TI. incident response.
Prioritize patching based on vulnerabilities Focus resources on the highest-risk
Vulnerability Management
actively exploited in the wild (as identified by TI). vulnerabilities.
Block emails from known malicious senders or Prevent phishing attacks and malware
Security Gateways (Email/Web)
access to known phishing sites. delivery.
Improve anomaly detection by understanding Identify stealthy attacks that bypass
Security Analytics
normal vs. threat actor behavior. traditional defenses.
Provide context, TTPs, and IoCs to guide Empower analysts to find threats faster
Human Analysts/Threat Hunters
investigations and proactive hunting. and understand adversary motives.
SIEM & SOAR
SIEM (Security Information
and Event Management) and
SOAR (Security
Orchestration, Automation,
and Response) are two
foundational technologies in a
modern Security Operations
Center (SOC). They work
together to handle the
massive volume of security
data and threats faced by
organizations today.
Simply put: SIEM detects the
threat, and SOAR
orchestrates the response.
The Integration: SIEM + SOAR
The true power is realized when SIEM and SOAR are integrated, creating a
virtuous cycle::
Technology in
Phase Example
Action
Detects an unusual login from a new country followed by file downloads
Detection SIEM
and generates an alert.
Receives the alert from the SIEM and initiates the "Compromised User"
Orchestration SOAR
playbook.
Automatically queries the Threat Intelligence feed to check the source
Automation SOAR IP. It then queries the EDR to get the process list from the endpoint and
creates a ticket in the ticketing system.
If the IP is malicious, the SOAR playbook automatically tells the firewall
Response SOAR
to block the IP and tells the EDR to isolate the affected endpoint.
A human analyst reviews the enriched case and closes the ticket, with
Resolution Analyst/SOAR
all actions fully documented by the SOAR platform.
Detection &
Analysis
Detection & Analysis are
fundamental, intertwined
processes within
cybersecurity that aim to
identify malicious or
anomalous activity and
understand its nature, scope,
and potential impact. These
capabilities are at the heart of
any effective Security
Operations Center (SOC) and
are crucial for minimizing the
time an adversary spends
undetected in a network
(dwell time).
Simply put: Detection
identifies that something is
happening, and Analysis
determines what it is, how
it's happening, and what to
do about it.
Containment &
Eradication
Strategy
Containment and Eradication
are two critical phases in the
Incident Response Lifecycle.
Once a security incident has
been detected and analyzed,
these phases focus on
stopping the spread of the
attack and thoroughly
removing the threat from the
environment. They are closely
linked, with effective
containment being a
prerequisite for successful
eradication.
Cyber Resilience
Cyber Resilience is an
organization's ability to
prepare for, respond to, and
recover from cyberattacks
and failures while
continuously delivering its
intended outcomes. It's about
more than just preventing
attacks; it's about building the
organizational fortitude to
withstand inevitable
disruptions and continue
operating effectively, even
when under duress.
In essence, Cyber Resilience
acknowledges that perfect
prevention is impossible.
Instead, it focuses on
minimizing the impact of
incidents, ensuring business
continuity, and quickly
returning to normal (or an
improved) state of operations.
Defence In
Depth
The Defense-in-Depth
Principle is a layered security
strategy designed to protect
systems and data by
implementing multiple
controls at different levels.