1.
Components of Cybersecurity: Cybersecurity is the practice of
protecting computers, networks, systems, and data from cyber threats,
unauthorized access, malware, and cyberattacks. It uses different
security measures to ensure the Confidentiality, Integrity, and
Availability (CIA) of information.
1. Network Security: Network Security is the process of protecting a
computer network from unauthorized access, misuse, attacks, and
data theft. It uses hardware, software, and security policies to ensure
that only authorized users can access the network.
Objectives of Network Security: Protect network devices. Protect
confidential data. Prevent unauthorized access. Detect and stop
cyberattacks. Ensure secure communication.
Why is Network Security Important? Network Security is important
because it protects valuable information from hackers and
cybercriminals. Without network security, attackers can steal
confidential data, damage systems, or interrupt business operations.
Importance: Prevents unauthorized access. Protects sensitive and
valuable data. Reduces cyberattacks. Prevents identity theft. Protects
business reputation. Ensures secure communication between users.
If hackers gain access to sensitive data, they can cause asset theft,
identity theft, and reputational damage.
Importance of Protecting Networks: Protecting networks helps
organizations reduce different types of risks.
Category Description Example
Theft of assets such as Hackers steal a
Financial
source code, research company's source code,
Risks
data, or designs can lead which may be replicated
(Intellectual
to financial loss and loss of by competitors,
Property)
competitive advantage. reducing revenue.
Cyberattacks can disrupt
A Ransomware attack
business operations,
Operational locks company systems,
making systems
Risks halting operations until
unavailable and stopping
recovery.
daily activities.
Failure to protect data A company violates the
Regulatory
may violate legal and General Data Protection
Issues
regulatory requirements, Regulation (GDPR) after
resulting in fines and legal a data breach and faces
action. penalties.
Exposure of Personally
Customer data (CNIC,
Identifiable Information
Financial email, bank details) is
(PII) can lead to identity
Risks (PII) stolen and used for
theft, fraud, and financial
fraudulent transactions.
damage.
How Does Network Security Work? Network Security works by using
different hardware devices, software tools, and security policies to
monitor and protect network traffic. Its main objective is to stop
unauthorized access and malicious communication.
Working Process: 1. Users request access to the network.
2. Authentication verifies the user's identity. 3. Firewalls inspect
incoming and outgoing traffic. 4. Security tools detect suspicious
activities. 5. Unauthorized traffic is blocked. 6. Authorized users can
safely access network resources.
A security team creates security policies, and all users must follow
them.
Types of Network Security Network Security uses different
technologies to protect systems.
1. Email Security: Email Security protects email accounts and email
communication from spam, phishing, malware, and unauthorized
access.
Example: Gmail automatically moves spam emails to the Spam Folder.
2. Anti-virus & Anti-malware Software: Anti-virus and Anti-malware
software detect, prevent, and remove viruses, worms, ransomware,
spyware, and other malicious software.
Example: Windows Defender scans a computer and removes viruses
automatically.
3. Network Segmentation: Network Segmentation divides a large
network into smaller sections (segments) to improve security and
performance.
Example: A university separates the Student Network and Faculty
Network.
4. Data Loss Prevention (DLP) Data Loss Prevention (DLP) protects
confidential information from being lost, leaked, or stolen.
Example A company blocks employees from sending customer data
through personal email.
5. Mobile Device Security Mobile Device Security protects
smartphones, tablets, and other mobile devices from cyber threats.
Example Using fingerprint lock and encryption on a smartphone.
6. Virtual Private Network (VPN) A VPN (Virtual Private Network)
creates a secure and encrypted connection between a user and the
internet.
Example Employees use a VPN to securely access office systems from
home.
7. Security Information & Event Management (SIEM): SIEM is a
security system that collects, monitors, and analyzes security events
from different devices and applications.
Example SIEM detects multiple failed login attempts and alerts the
security team.
8. Intrusion Detection System (IDS) An Intrusion Detection System
(IDS) monitors network traffic and detects suspicious or malicious
activities.
Example IDS detects a hacker attempting to access a server illegally.
9. Sandboxing: Sandboxing is a security technique that runs
unknown files or applications in an isolated environment to check
whether they are safe.
Example A suspicious email attachment is opened inside a sandbox
before allowing users to access it.
10. Software Defined Perimeter (SDP) Software Defined Perimeter
(SDP) hides network resources from unauthorized users and allows
access only after proper authentication.
Example Only authenticated employees can access the company's
internal applications.
11. Workload Security Workload Security protects applications,
virtual machines, servers, and cloud workloads from cyber threats.
Example A cloud server is continuously monitored to detect malware
attacks.
12. Wireless Security: Wireless Security protects Wi-Fi networks from
unauthorized users and cyberattacks.
Example Using a strong WPA2/WPA3 password on a home Wi-Fi
network.
13. Web Security Web Security protects websites, web applications,
and users from online threats such as hacking, malware, and phishing
attacks.
Example An e-commerce website uses HTTPS (SSL Certificate) to
secure online transactions.
Benefits of Network Security: Protecting Sensitive Data from
Unauthorized Access. Guarding Your Competitive Edge Meeting Legal
and Regulatory Requirements. Keeping Systems Running. Increases
customer trust. Improves network performance.
Challenges to Network Security
Remote & Mobile Access: Expands the attack surface because users
operate outside the traditional protected network
User Adherence: Technology alone cannot secure a network, Users
must also follow secure practices consistently
Third Party Partners: An organization’s security is only as strong as
the security of its connected partners and suppliers
Evolving Network Attack Actors: Cyber attackers continuously
adapt, so organizations must continuously update and improve their
security
2. End-User (Endpoint) Security: Endpoint Security (also called End-
User Security) is the process of protecting endpoint devices such as
computers, laptops, smartphones, tablets, and servers from cyber
threats. It helps prevent malware, ransomware, viruses, and
unauthorized access by securing every device connected to the
network.
Objective of Endpoint Security The main objectives of Endpoint
Security are: Protect endpoint devices from cyberattacks. Prevent
unauthorized access. Detect and remove malware. Secure sensitive
data. Ensure safe communication between devices.
1. What is an Endpoint? An Endpoint is any physical device that
connects to a computer network. Since these devices communicate
with the network, they can become entry points for cyberattacks if they
are not properly protected.
2. What is Considered an Endpoint? Any device connected to a
certain network is considered an endpoint.
Desktop PCs, Laptops, Mobile Phones, Tablets, Servers, Virtual
Machines, IoT Devices (Smart Cameras, Smart TVs, Sensors), POS
Devices, Wearables, Coud Based Apps (PAAS) Printers. Network
Devices
3. Importance of Endpoint Security Endpoint Security is important
because cybercriminals often target endpoint devices to gain access to
an organization's network. Protecting every endpoint reduces the risk
of malware infections, data breaches, and unauthorized access.
Importance: Protects sensitive information. Prevents malware and
ransomware. Stops unauthorized users. Reduces data breaches.
Secures remote workers. Improves overall network security.
Example: If a company's employee opens a malicious email
attachment, Endpoint Security can detect and block the malware
before it spreads across the network.
4. How Endpoint Security Works Endpoint Security works by
continuously monitoring endpoint devices for suspicious activities. It
scans files, checks applications, blocks malicious software, and reports
security incidents to administrators.
Working Process: 1. Device connects to the network. 2. Endpoint
Security Agent is installed. 3. Device is continuously monitored. 4.
Suspicious files or activities are detected. 5. Malware is blocked or
removed. 6. Security alerts are sent to the administrator.
5. Endpoint Protection Platform (EPP) An Endpoint Protection
Platform (EPP) is a security solution that protects endpoint devices
using antivirus, anti-malware, firewall, encryption, and threat
detection technologies.
5.1 Traditional or Legacy EPP Traditional EPP stores security
software and management tools on local servers inside the
organization.
Features: Installed on local servers. Managed by the organization.
Suitable for on-premises environments.
5.2 Cloud-Based EPP Cloud-Based EPP stores security services in the
cloud, allowing devices to be protected from anywhere with an internet
connection.
Features: Cloud management. Easy updates. Supports remote users.
Scalable security.
5.3 Hybrid EPP Hybrid EPP combines both Traditional and Cloud-
Based protection to provide flexible security management.
Features Local + Cloud management. Better flexibility. Improved
protection. Suitable for large organizations.
6. Components of Endpoint Security are the different security
technologies that work together to protect endpoint devices such as
laptops, desktops, servers, and mobile devices from cyber threats.
1. Machine Learning Classification Machine Learning automatically
analyzes files and user behavior to quickly detect new and unknown
cyber threats.
Example Machine Learning detects a new ransomware that has never
been seen before.
2. Advanced Anti-virus & Anti-malware Software Advanced Anti-
virus and Anti-malware software protects endpoint devices from
viruses, malware, spyware, ransomware, and other malicious
programs.
Example Windows Defender detects and removes a Trojan virus.
3. Active Web Security Active Web Security protects users while
browsing the internet by blocking malicious websites and harmful
downloads.
Example Google Chrome warns users before opening a dangerous
website.
4. Data Classification & Data Loss Prevention (DLP) Data
Classification organizes sensitive information, while Data Loss
Prevention (DLP) prevents confidential data from being leaked, copied,
or stolen.
Example A company blocks employees from copying customer records
to a USB drive.
5. Built-in Firewall A Built-in Firewall monitors and filters incoming
and outgoing network traffic to block malicious network attacks.
Example Windows Firewall blocks an unauthorized connection from
the internet.
6. Email Gateway An Email Gateway filters incoming and outgoing
emails to block spam, phishing emails, and malicious attachments
before they reach users.
Example An email containing a malicious attachment is automatically
quarantined.
7. Centralized Endpoint Management Platform A Centralized
Endpoint Management Platform allows administrators to monitor and
manage all endpoint devices from one central location.
Example An IT administrator updates antivirus software on all
company computers from one dashboard.
8. Protection from Insider Threats This component protects the
organization from malicious or careless actions performed by
employees or authorized users.
Example An employee tries to copy confidential files to a personal USB
device, and the system blocks the action.
9. Endpoint, Email & Disk Encryption Encryption protects endpoint
devices, emails, and stored data by converting information into
unreadable form. Only authorized users with the correct key can
access the original data.
Example If a company laptop is stolen, encrypted files cannot be read
without the encryption key.
7. Difference Between EPP and Antivirus
Feature Antivirus EPP (Endpoint Protection
Platform)
Visibility Protects only Provides centralized visibility of
one device all endpoints
Administration Managed Managed from one central console
individually
Protection Detects viruses Protects against viruses,
only ransomware, malware, and
advanced threats
8. Core Functionality of Endpoint Security
8.1 Next-Generation Antivirus (NGAV): NGAV is an advanced
antivirus solution that detects both known and unknown threats using
intelligent detection techniques.
Functions Malware Detection, Ransomware Protection, Behavioral
Analysis, Real-time Protection
8.2 Endpoint Detection and Response (EDR) EDR continuously
monitors endpoint devices, detects suspicious activities, and helps
security teams investigate and respond to cyber threats.
Functions Continuous Monitoring, Threat Detection, Incident
Investigation, Response to Attacks
8.3 Managed Threat Hunting Managed Threat Hunting is a proactive
security service where security experts continuously search for hidden
threats before they cause damage.
Benefits Early Threat Detection, Reduced Security Risks, Continuous
Monitoring
8.4 Threat Intelligence Integration Threat Intelligence Integration
collects and uses information about the latest cyber threats to improve
endpoint protection.
Benefits Detects new attacks. Improves security decisions. Updates
protection against emerging threats.
3. Operational Security (OPSEC) Operational Security (OPSEC) is a
security process used to protect sensitive information from
unauthorized access. It helps organizations identify critical
information, analyze possible threats, and take preventive measures to
reduce security risks.
Objective of OPSEC The main objectives of Operational Security are:
Protect sensitive information. Prevent data leakage. Identify security
risks. Reduce cyber threats. Improve organizational security.
Importance of Operational Security Operational Security is
important because it helps organizations protect valuable information
from hackers, competitors, and unauthorized users. A good OPSEC
program reduces the chances of cyberattacks and improves overall
security.
Importance Protects confidential information. Prevents data breaches.
Reduces cyber risks. Improves business continuity. Supports secure
decision-making. Protects an organization's reputation.
Five Steps to Create an Operational Security (OPSEC) Plan
An effective OPSEC plan consists of five main steps:
Step 1: Identify Information Assets The first step is to identify the
important information and assets that need protection. These assets
are valuable to the organization and must be kept secure.
Examples of Information Assets Customer Data, Employee Records,
Financial Information, Business Documents, Passwords, Research
Data, Intellectual Property
Why It Is Important Identifies critical information. Helps prioritize
security. Reduces the risk of data loss.
Step 2: Recognize Threats After identifying important assets, the
next step is to recognize the threats that may harm those assets.
Common Threats Hackers, Malware, Phishing Attacks, Insider
Threats, Ransomware, Natural Disasters
Why It Is Important Helps understand possible attacks. Improves
security planning. Reduces future risks.
Step 3: Identify Vulnerabilities A vulnerability is a weakness in a
system that attackers can exploit. Identifying vulnerabilities helps
organizations fix security weaknesses before they are abused.
Examples of Vulnerabilities Weak Passwords, Outdated Software,
Unpatched Systems, Poor Access Control, Misconfigured Devices
Why It Is Important Prevents security breaches. Improves system
protection. Reduces attack opportunities.
Step 4: Analysis In this step, organizations analyze the identified
threats and vulnerabilities to determine the level of risk. This helps
decide which security issues should be addressed first.
Purpose of Analysis Evaluate risks. Identify high-risk assets.
Prioritize security measures. Support decision-making.
Example If customer data is stored on an outdated server, the
organization may classify it as a high-risk asset and upgrade its
security.
Step 5: Mitigation: Mitigation means taking actions to reduce or
eliminate identified risks. Organizations implement security controls to
protect their assets from threats.
Mitigation Techniques Install Firewalls. Update Software. Use Strong
Passwords. Enable Multi-Factor Authentication (MFA). Encrypt
Sensitive Data. Train Employees.
Purpose Reduce cyber risks. Protect information assets. Improve
overall security.
Security Plan A Security Plan is a document that describes how an
organization will protect its information, systems, and network. It
outlines security policies, responsibilities, and procedures to reduce
cyber risks.
Contents of a Security Plan Security Policies, Risk Assessment,
Incident Response Procedures, Access Control Rules, Backup and
Recovery Plan, Employee Responsibilities
Benefits Improves security management. Provides clear security
guidelines. Helps respond to security incidents. Ensures business
continuity.
Best Practices of OPSEC: Organizations should follow these best
practices to improve Operational Security: Use strong and unique
passwords. Regularly update software. Encrypt sensitive data. Limit
access to important information. Train employees on cybersecurity
awareness. Perform regular security audits. Monitor systems
continuously. Create regular backups.
4. Disaster Recovery Planning (DRP) Disaster Recovery Planning
(DRP) is a process that helps an organization recover its data, systems,
and network after a disaster or cyberattack. It ensures that business
operations can continue with minimum downtime and data loss.
Objectives of Disaster Recovery Planning Recover important data.
Restore IT systems quickly. Reduce business downtime. Protect
business operations. Minimize financial losses.
Importance of Disaster Recovery Planning Disaster Recovery
Planning is important because unexpected disasters such as
cyberattacks, hardware failures, floods, or fires can damage computer
systems. A proper recovery plan helps organizations restore services
quickly and continue normal operations.
Importance Protects business continuity. Reduces data loss.
Minimizes downtime. Saves recovery costs. Improves customer trust.
1. How Does Disaster Recovery Planning Work? Disaster Recovery
Planning works by preparing a recovery strategy before a disaster
occurs. The organization regularly creates backups, identifies critical
systems, and develops procedures to restore services after an incident.
Working Process 1. Identify critical systems and data. 2. Create
regular backups. 3. Detect the disaster. 4. Activate the Disaster
Recovery Plan. 5. Restore systems and data. 6. Resume normal
business operations.
Example A company experiences a ransomware attack that encrypts
all files. The organization: Restores data from backups. Reinstalls
affected systems. Resumes business operations.
2. Elements of a Disaster Recovery Plan A Disaster Recovery Plan
includes several important elements.
Disaster Recovery Team A group of employees responsible for
managing recovery after a disaster.
Risk Assessment Identifies possible threats and evaluates their
impact.
Data Backup Regularly stores copies of important data for future
recovery.
Recovery Procedures Step-by-step instructions to restore systems
and services.
Communication Plan Defines how employees, customers, and
management will communicate during a disaster.
Testing and Maintenance Regular testing ensures that the recovery
plan works effectively.
3. How to Build a Disaster Recovery Plan? A Disaster Recovery Plan
(DRP) is built by organizing different teams and assigning specific
responsibilities to recover business operations after a disaster.
Step 1: Crisis Management The Crisis Management Team initiates
the recovery plan, coordinates all recovery activities, and resolves any
problems or delays during the recovery process.
Responsibilities Initiates the recovery plan. Coordinates recovery
activities. Solves problems and delays. Ensures smooth recovery.
Step 2: Business Continuity The Business Continuity Team ensures
that the recovery plan aligns with the organization's business needs
based on the Business Impact Analysis (BIA).
Responsibilities Maintain business operations. Support business
continuity. Prioritize critical business services. Reduce business
downtime.
Step 3: Impact Assessment & Recovery The Impact Assessment &
Recovery Team evaluates the impact of the disaster and restores the
organization's IT infrastructure, including servers, databases, storage,
and networks.
Responsibilities Assess disaster impact. Recover servers. Recover
databases. Recover storage systems. Restore network services.
Step 4: IT Applications The IT Applications Team restores and
monitors application services according to the recovery plan. It also
ensures application integration, configuration, and data consistency.
Responsibilities Restore applications. Monitor application services.
Configure applications. Maintain data consistency. Verify application
integration.
4. Types of Disaster Recovery Different organizations use different
disaster recovery methods.
1. Backups are copies of important data stored in a secure location so
that information can be restored if the original data is lost or damaged.
Example A company backs up its customer database every day to
recover data after a system failure.
2. Cold Site is a backup location with basic facilities but without
running systems. Hardware and software must be installed before it
can be used.
Example A company rents an empty office as a backup site and
installs servers only after a disaster occurs.
3. Hot Site is a fully operational backup site with servers, software,
and network connections ready for immediate use after a disaster.
Example If the main data center fails, business operations
immediately continue from the Hot Site.
4. Backup as a Service (BaaS) is a cloud-based service that
automatically stores data backups on remote servers managed by a
service provider.
Example A company stores all its files on cloud backup services such
as Microsoft Azure or Google Cloud.
5. Disaster Recovery as a Service (DRaaS) is a cloud service that
allows organizations to recover their entire IT infrastructure after a
disaster without managing recovery systems themselves.
Example After a ransomware attack, a company restores its complete
cloud environment using DRaaS.
6. Point-in-Time Copy restores data to a specific date and time before
a disaster or cyberattack occurred.
Example If files are deleted today, the system restores them from
yesterday's backup.
7. Virtualization creates virtual versions of servers and systems,
allowing applications to be restored quickly on virtual machines after a
disaster.
Example A virtual server is started immediately when the physical
server fails.
8. Instant Recovery allows organizations to restore systems and
applications immediately with very little downtime.
Example A company's database becomes available within a few
minutes after a server crash.
5. Key Cybercrime Statistics Cybercrime continues to increase every
year and affects organizations worldwide.
Common Facts Cyberattacks are increasing rapidly. Ransomware
attacks target businesses of all sizes. Data breaches cause financial
losses. Phishing is one of the most common cyber threats.
Organizations invest heavily in cybersecurity and disaster recovery.
Important Statistics
1. Human Error: 95% of cybersecurity breaches are caused due to
human error.
2. Average Data Breach Cost: As of 2022, the United States (US) has
the highest average data breach cost. Average Cost = $9.44 Million per
attack.
3. Business Resources: 51% of businesses claim they lack the
resources to respond to a cyberattack.
Cybercrime Statistics You Should Know
Devices Most Vulnerable to Cybercrime
Device Percentage
Desktops & Laptops 70%
Smartphones 61% Leading Malware Carriers
Tablets 53% Carrier Percentage
Wireless Access Points 50% Email 92.4%
Servers & Server Rooms 50% Web 6.3%
Routers & Switches 47% Others 1.3%
5. Cyber Attack is an attempt by hackers or cybercriminals to gain
unauthorized access to a computer system, network, or data. The
main purpose of a cyberattack is to steal information, damage
systems, interrupt services, or demand money from victims.
Objectives of Cyber Attacks Steal sensitive information. Disrupt
business operations. Damage computer systems. Gain unauthorized
access. Earn financial benefits.
1. Who is Behind Cyber Attacks? Cyber-attacks can be carried out
by criminal groups, state entities, and individuals. According to the
slide, the risks of cyber-attacks are divided into two main categories.
1. Outsider Threats are attacks performed by people outside the
organization who do not have authorized access to the system.
Examples Hackers, Cybercriminals, Criminal Groups, State Entities
(Nation-State Attackers)
Purpose Steal sensitive data. Damage systems. Disrupt business
operations. Commit financial fraud.
2. Insider Threats Insider Threats are attacks caused by people inside
the organization, such as employees, contractors, or former staff who
have authorized access.
Examples Employee negligence, Malicious employees, Contractors,
Former employees
Purpose Steal confidential information. Leak company data. Misuse
authorized access.
2. Who is Behind Data Breaches? A Data Breach occurs when
confidential information is accessed, stolen, or disclosed without
authorization. According to the slide, the main causes of data breaches
are shown below.
Main Causes of Data Breaches
Cause Percentage
Employee Negligence or Internal Threat 66%
External Threat 18%
Other 9%
Social Engineering 3%
Cyber Extortion 2%
Network Business Interruption 2%
1. Employee Negligence or Internal Threat (66%) Employees
accidentally or intentionally expose confidential information.
Example: An employee shares sensitive company files with an
unauthorized person.
2. External Threat (18%) Hackers or cybercriminals attack an
organization's systems to steal information.
Example: A hacker gains unauthorized access to a company's
database.
3. Other (9%) Other unexpected reasons that lead to data breaches.
4. Social Engineering (3%) Attackers manipulate people into
revealing confidential information.
Example: A phishing email tricks a user into sharing a password.
5. Cyber Extortion (2%) Attackers demand money by threatening to
release or destroy data.
Example: A ransomware attack asks for payment to unlock encrypted
files.
6. Network Business Interruption (2%) Network failures or cyber
incidents interrupt business operations and may result in data loss.
Example: A DDoS attack causes network downtime and disrupts
company services.
3. What Do Cyber Attackers Want? Cyber attackers target
corporations, governments, private organizations, and individuals to
steal valuable information for financial gain, espionage, or other
malicious purposes.
Main Objectives Financial gain. Personal information. Banking
information. Business secrets. Intellectual Property. Customer
databases. Passwords and login credentials. System disruption.
Political or military information.
Example A ransomware attacker encrypts company files and demands
money to restore access.
4. Complete Impact of Cybercrime on Business Cybercrime can
have serious financial, operational, and reputational effects on a
business. The impact includes both direct costs and hidden costs.
A. Well-Known Cyber Incident Costs These are direct costs that
organizations pay after a cyber incident.
Technical Investigation, Breach Warning to Customers, Regulatory
Compliance, Legal Fees, Customer Protection Post-breach, Public
Relations, Cybersecurity Improvements
B. Hidden Costs These are indirect losses that affect business
performance over time.
Increase in Insurance Premium, Operational Disruption, Loss in
Revenue, Reputational Damage, Stolen Intellectual Property, Impact on
Client Relations
Impact of Cybercrime on Business
1. Increased Costs Cybercrime increases business expenses due to
system recovery, security improvements, legal fees, and investigation
costs. Organizations also spend more money on preventing future
attacks.
2. Changed Business Practices After a cyberattack, organizations
often change their security policies, business processes, and employee
training to improve cybersecurity and reduce future risks.
3. Operational Disruption Cyberattacks can interrupt daily business
operations by making systems, applications, or networks unavailable.
This reduces productivity and delays important business activities.
4. Loss of Revenue When business operations stop or customers lose
trust, organizations may lose sales and income. Recovery from
cyberattacks can also increase financial losses.
5. Reputational Damage A cyberattack can damage a company's
reputation and reduce customer confidence. Customers may stop
using the organization's products or services.
6. Stolen Intellectual Property Cybercriminals may steal valuable
business assets such as source code, product designs, research data,
or trade secrets. This can reduce the company's competitive
advantage.
5. What is Spam? Spam is unwanted or unsolicited messages sent in
large numbers through email, SMS, or other communication
platforms. Spam messages are usually used for advertising, fraud, or
spreading malware.
Characteristics of Spam Unwanted messages. Sent to many users.
May contain advertisements. May include malicious links. May spread
malware.
Examples of Spam Promotional Emails. Fake Lottery Messages.
Unwanted Advertisements. Bulk SMS Messages.
Problems Caused by Spam Wastes time. Fills email inboxes. Spreads
malware. Increases phishing attacks. Reduces productivity.
Difference Between Cyber Attack and Data Breach
Cyber Attack Data Breach
Attempt to attack a system or Unauthorized access to
network confidential data
May not always succeed Data is successfully exposed or
stolen
Can include malware, Focuses mainly on stolen
ransomware, DDoS information
6. Phishing Attack is a type of cyberattack in which attackers pretend
to be a trusted person or organization to trick users into revealing
sensitive information such as usernames, passwords, bank details, or
credit card information.
Objectives of Phishing Steal usernames and passwords. Obtain
banking information. Steal personal data. Install malware. Commit
financial fraud.
1. Phishing is one of the most common cyberattacks used by
cybercriminals. Attackers send fake emails, messages, or websites that
look genuine to fool users into sharing confidential information.
Example A user receives an email that appears to be from a bank
asking them to verify their account. The email contains a fake login
page. After entering the username and password, the attacker steals
the information.
2. How Do Phishing and Spam Work?
How Spam Works Spam is the process of sending unwanted messages
to many users.
Working Bulk emails are sent. Promotional or fake messages are
delivered. Some messages contain harmful links. Users may
accidentally open them.
How Phishing Works Phishing follows these steps: 1. The attacker
creates a fake email or website. 2. The message appears to come from
a trusted source. 3. The victim clicks the provided link. 4. The victim
enters confidential information. 5. The attacker steals the information.
Example Fake Email → Click Link → Fake Login Page → Enter
Password → Attacker Steals Information
3. Spam vs Phishing
Spam Phishing
Unwanted messages Fraudulent messages
Mainly advertising Mainly data theft
Sent in bulk Sent to trick users
May not always be harmful Usually malicious
Objective: Promotion Objective: Steal information
4. Types of Phishing Attacks There are different types of phishing
attacks.
1. Spear Phishing is a targeted phishing attack aimed at a specific
person or organization. Attackers use personal information to make
the fake message appear genuine.
Example: A fake email sent to a company employee pretending to be
from the manager.
2. Whaling is a phishing attack that targets high-profile individuals
such as CEOs, directors, and senior executives. The goal is to steal
confidential business information or money.
Example: A fake email sent to a CEO requesting a financial
transaction.
3. Vishing (Voice Phishing) is a phishing attack carried out through
phone calls. Attackers pretend to be bank officials or trusted
organizations to steal sensitive information.
Example: A fake bank representative asks for your ATM PIN or OTP.
4. Smishing (SMS Phishing) uses fake text messages to trick users
into clicking malicious links or sharing personal information.
Example: An SMS saying, "You have won a prize. Click here to claim it."
5. Email Phishing is the most common type of phishing attack.
Attackers send fake emails that appear to come from trusted
organizations to steal usernames, passwords, or financial information.
Example: A fake PayPal or Gmail security email asking you to verify
your account.
6. Search Engine Phishing involves creating fake websites that
appear in search engine results. Users visit these fake sites and
unknowingly provide their personal information.
Example: A fake online banking website appearing in Google search
results.
5. How to Prevent Phishing
1. Conduct Regular Training Conduct regular training to train
employees to recognize phishing attacks and malicious emails or links.
2. Set Up a Spam Filter Set up a spam filter to prevent suspicious
emails from reaching employees.
3. Keep Secure Passwords Keep secure passwords with special
characters and change these from time to time.
4. Deploy Multi-Factor Authentication (MFA) Deploy Multi-Factor
Authentication (MFA) on critical business applications to provide an
extra layer of security.
5. Install and Regularly Update Security Patches Install and
regularly update security patches to protect systems against
vulnerabilities.
Example Before clicking any banking email, verify the official website
instead of opening the provided link.
Problem with Symmetric Encryption Symmetric Encryption uses the
same secret key for both encryption and decryption. Although it is fast,
it has several problems in modern digital communication.
Problems with Symmetric Encryption
1. Key Distribution Problem The biggest problem is that the same
secret key must be shared securely between the sender and receiver. If
the key is intercepted, the communication becomes insecure.
2. Difficult Key Management In a large network with many users,
every sender and receiver needs a different secret key. Managing and
storing so many keys becomes difficult.
3. Scalability Problem In many-to-one, one-to-many, and many-to-
many communication, billions of secret key pairs may be required,
making the system difficult to manage.
4. Communication Space Problem As the number of users increases,
the communication space also grows. This creates problems in storing
and managing all the required secret keys.
5. Not Suitable for Large Networks Because millions of users
communicate over the Internet, using only symmetric keys is
impractical. Modern systems use public-key encryption to exchange
keys and symmetric encryption to send data efficiently.
6. Solution To solve the key distribution problem, modern systems
use Public-Key Cryptography (Asymmetric Encryption). After
exchanging keys securely, Symmetric Encryption is used for fast data
transmission (e.g., HTTPS).
Asymmetric Encryption Algorithms Asymmetric Encryption uses
two different keys: Public Key → Used for Encryption & Private Key
→ Used for Decryption. It solves the key distribution problem and
provides secure communication.
Types of Asymmetric Encryption Algorithms
1. RSA (Rivest–Shamir–Adleman) uses two very large prime numbers
to generate secure keys. It is widely used by web browsers to establish
secure connections.
Uses: Secure websites (HTTPS), SSL/TLS.
2. Diffie–Hellman (DH) is used to securely exchange secret keys
between two parties over a public network.
Uses: SSL, TLS, SSH, IPSec.
3. ElGamal is an asymmetric encryption algorithm mainly used for
digital signatures. It is free to use because it is not protected by a
patent.
4. Elliptic Curve Cryptography (ECC) uses mathematical elliptic
curves to provide strong security with smaller key sizes. It is widely
used for digital signatures and key exchange.
Difference Between Symmetric and Asymmetric Encryption
Symmetric Encryption Asymmetric Encryption
Also called Shared-Secret Key Also called Public Key Algorithm
Algorithm
Uses one secret key Uses Public Key and Private Key
Key length: 80–256 bits Key length: 512–4096 bits
Sender and receiver share the Sender and receiver do not
same key share a secret key
Fast because of simple Slower because of complex
mathematical operations mathematical operations
Examples: DES, 3DES, AES, IDEA, Examples: RSA, ElGamal, ECC,
RC2/4/5/6, Blowfish Diffie–Hellman
Applications of Symmetric Encryption: Electronic payment industry
uses 3DES. Operating systems use DES to protect files. Most file
encryption systems (such as NTFS) use AES.
Applications of Asymmetric Encryption: IKE (Internet Key
Exchange) – Used in IPSec VPNs. SSL (Secure Socket Layer) – Secures
web browsers. SSH (Secure Shell) – Provides secure remote access.
PGP (Pretty Good Privacy) – Secures email communication.