Harshpreet Singh
Over the first three weeks of this course my view of cybersecurity shifted a lot before I
mostly thought of it as having antivirus and good passwords but now, I see it as a whole
way of thinking about technology builds around ideas like CIA tried which is
confidentiality, integrity and availability as the three pillars of protecting information.
These three core pillars that guide me in how we protect data and system thinking in
terms of these three pillars helped me see that every security decision is about
balancing who can see information how trustworthy that information is and whether it is
accessible when needed or not. I also gained A clearer picture of the modern threats
including how social engineering malware and misconfiguration exploit human habit.
These ideas show in my everyday life more than I expected when I saw my phone for
banking social media, I catch myself asking what if ‘I lost access to this’ or ‘there's
somebody got into my account?’ That availability or confidentiality in real life and this
happened to me for my epic gaming account two years ago. I've started turning on
multifactor authentication. After that I can rely on Google password manager instead
of reusing the same few passwords everywhere even outside a pure IT job almost every
workplace around on shared system cloud services. So, in real life I understand these
basics which help me see how my choice is like how I handle my files e-mail and login
credentials the factor the bigger security picture at any organization or individual.
So, when we looked at examples like phishing that steals credentials (compromised on
confidentiality). Or ransomware that locks people out of the system and corrupts data
(availability and integrity). The framework suddenly felt very real instead of just theory. I
especially enjoyed any activity where we had to think a bit like an attacker first and then
design defense because it forced me to realize how small weaknesses can be
combined into a serious breach.
Harshpreet Singh
I struggled with all those different types of security controls to reduce preventive
defective corrective and the way they overlap with technical administrative and physical
control. To deal with that I started making some scenarios like logging into an account or
keeping a server online and labeling which controls protector confidentiality to protect
integrity and availability going back through the labs more slowly and writing short notes
next to each steps this is defective this sports availability if the main system fails has
helped me move away from a memorizing and toward actually understanding which
each piece is matter.
Looking ahead, I still have some big questions: one is about application security in the
real world when developers are under pressure to ship new features quickly. How to
team realistically keeps your coding testing and code reviews from being the first thing
dropped when deadline gets tight and how they do double check the security in that fast
phase environment. Another question is about AI security and clouds, how shared
responsibility model in the cloud really works in a practical and how new AI tool changes
both what attackers can do and what defenders can automate or detect and, I'm curious
how we can keep security simple enough that regular people follow good practices
instead of feeling overwhelmed. Even as technology and the threats keep getting more
complex.
Overall, these first three weeks have given me a solid foundation for how to think about
cybersecurity not just an IT stuff but as something that shows up in my daily habit and
future career choices the challenge now is to keep building on that by turning these
ideas into consistent behavior and staying curious about how security work as a system
and a threat keep evolving because everything in this modern era is based on the
networks and to protect those network we have a mind behind is called cybersecurity.