DAVID GAME COLLEGE
BTEC RQF HNC/D ASSESSMENT BRIEF
Course BTEC Level 5 HND in Digital Technology
Academic Year 2025-2026
Unit Number & Unit Title Unit 3: Cyber Security
Assignment Author Koushik Modak
Assessors Koushik Modak
Assignment Title Security risks, challenges and Solutions
Date issued 29.09.2025 IV Name and Date Kezban Alpan: 30.09.2025
Formative Submission Deadline Summative (Final) Submission Deadline
Group Deadline Group Deadline
CDM25 & ADM25 Task 1 – 03.11.2025 CDM25 & ADM25 Task 1 – 01.12.2025
CDS25 & ADS25 Task 2 – 07.11.2025 CDS25 & ADS25 Task 2 – 05.12.2025
Good Academic Practice
DGHE considers an act of academic misconduct when a student attempts to benefit either for themselves
or for another person by unfair or improper methods, regardless of it being intentional or unintentional.
Examples include:
• Purchasing work and presenting it as your own.
• Plagiarism is passing off someone else’s work as your own such as:
o Using quotes without the use of quotation marks.
o Using images produced by another person without acknowledgement.
o Using data or ideas without acknowledgement.
o Copying another person’s work.
o Getting someone to help you write parts of your submission as if it were your own.
• Collusion is when two or more students working together without prior authorisation from the
academic member of staff concerned (e.g. programme leader, lecturer etc.) to produce the same or
similar piece of work and then attempting to present this entirely as their own individual submission.
It is important that you are clear about what you need to do for each assignment and how you can do it. If
you are not sure about any rules regarding academic writing and referencing, guidance is available from
many DGHE sources including Moodle, our Library and Study Skills Support teams and from your module
leaders/personal tutor.
ASSIGNMENT BRIEF AND GUIDANCE
Purpose of this assessment
The purpose of Unit 3: This unit has been designed to overview and outline a comprehensive approach
to Cyber security, blending theoretical understanding with practical application. Students are expected to
explore:
• Demonstrate knowledge, skills and ability to protect an organisation’s assets — including its
people, information, hardware, and network infrastructure
• Demonstrate a solid understanding of preventive security methods, including vulnerability
assessments and the development of effective security policies.
• Show knowledge of detection techniques used to identify, assess, and respond to security
breaches.
• Effectively respond to incidents through the implementation of contingency plans that support
business continuity.
• Identify, evaluate, and mitigate risks that could potentially impact or interrupt operational
processes.
• Develop and apply contingency strategies to maintain essential functions during and after a
security incident.
• Show understanding of access control mechanisms to ensure that only authorised users can access
sensitive systems and data.
• Monitor and manage the use of organisational systems and data to prevent misuse and ensure
compliance.
• Design and implement security policies that align with the specific needs and structure of the
organisation.
• Develop and enforce compliance procedures to ensure security policies are followed and
accountability is maintained.
• Evaluate the legal and ethical responsibilities involved in enforcing security policies and managing
data access.
• Demonstrate knowledge of threat and vulnerability detection practices across areas such as
physical security, IT systems, and overall threat management.
• Show a comprehensive understanding of network security architecture and operational practices,
including design and implementation.
• Understand the processes involved in securing remote access, conducting vulnerability scans, and
carrying out security audits for compliance testing.
• Apply strong skills in communication, critical thinking, analytical reasoning, and interpretation
when assessing and addressing security-related challenges.
Scenario
You work as a Trainee Cyber Security Specialist for a leading Cyber consultancy firm named CyberHelp
Ltd. The company provides support to a local medical centre named HealthFirst, which has recently
experienced a Ransomware Attack on their central Data Centre. A ransomware variant infiltrated the data
centre via a phishing email clicked by an agency staff member. Within minutes, critical patient records,
financial systems, and clinic schedules are encrypted. The impact includes loss of access to all patient
2
data globally, patient treatment delays and cancellations, potential breach of UK GDPR due to data loss,
operational and reputational damage. As a response strategy you have been instructed by your firm to-
• Activate incident response plan
• Disconnect affected systems from the network
• Notify ICO (Information Commissioner’s Office) within 72 hours
• Restore data from offline backups
• Conduct root cause analysis and retrain staff on phishing awareness
As part of your role, your line manager has also asked you to write a detailed report and an engaging
presentation to help train the junior IT staffs of your organisation.
Task 1
Written Report for the junior IT staffs
Your line manager has asked you to write a report on the nature of cybercrime and cyber threat along with
the associated hazards.
Your report must include the following points.
➢ Review types of malicious and/or criminal cyber activity.
➢ Investigate the potential targets of cybercrime.
➢ Describe security threats and hazards to a system or service or process.
➢ Investigate common attack techniques and recommend how to defend against them.
Your report may also include (but not restricted to) the following points.
➢ Analyse the concept of digital systems as ‘targets’ and ‘tools’ as related to cyber security, giving
real-world examples.
➢ Assess the role of threat intelligence when defending against common attack techniques.
➢ Evaluate types of malicious cyber activity and the action that can be taken to neutralise cyber
threat actors.
Task 1 provides evidence for LO1 and LO2
Submission Format
The assignment submission is in the form of:
A formal report aimed to explore IT security risks and solutions.
• The recommended word limit is minimum 1,500 and 2,000 words maximum.
• The use of Harvard Academic Referencing is a must.
• The report must be prepared on the Overleaf platform. The format to be used is available
in the link below.
[Link]
template/myxmhdsbzkyd
• Submissions prepared outside the specified format will not be accepted.
3
Task 2
After having completed your report on different aspects of Cyber Security, you need to prepare a 10–
15-minute oral presentation that discusses the effectiveness of information assurance concepts applied
to ICT infrastructure and further investigation on incident response methods to cyber security threats. You
should support your arguments with examples of well-chosen evidence from your research. The
presentation template provided on Moodle must be used. Presentations prepared using
another template will not be accepted. You need to present your work to train junior staff members
at your organisation.
Your presentation must include the following points.
➢ Explain how information assurance concepts can mitigate threats and vulnerabilities in ICT
infrastructure, giving examples.
➢ Describe security standards, regulations and their consequences across at least two sectors.
➢ Examine the types of response that have been implemented in response to cyber security threats
Your presentation may also include (but not restricted to) the following points.
➢ Assess how information assurance could enhance the cyber resilience of ICT infrastructure.
➢ Analyse the role of criminal and other law in deterring cybercrime.
➢ Evaluate the responses that have been implemented by different organisations in response to
cyber security threats.
Task 2 provides evidence for LO3 and LO4
Formative Task
You have the opportunity to receive formative feedback by submitting a draft to the relevant ‘Formative
task’ submission points on Moodle. To get the most useful feedback, you should aim to have completed
around 60% of each task before submission. Your draft will not be graded but will provide guidance to
help you complete the final assessment.
The Assignment Brief covers the following Learning Outcomes and Assessment Criteria
Pass Merit Distinction
LO1 Explore the nature of cybercrime and cyber threat
actors
P1 Review types of malicious M1 Analyse the concept of digital D1 Evaluate types of malicious
and/or criminal cyber activity. systems as ‘targets’ and ‘tools’ as cyber activity and the action that
P2 Investigate the potential related to cyber security, giving can be taken to neutralise cyber
targets of cybercrime. real-world examples. threat actors.
LO2 Investigate cyber security threats and hazards
4
P3 Describe security threats and M2 Assess the role of threat
hazards to a system or service or intelligence when defending
process. against common attack
P4 Investigate common attack techniques.
techniques and recommend how to
defend against them.
Pass Merit Distinction
LO3 Examine the effectiveness of information assurance concepts
applied to ICT infrastructure
P5 Explain how information M3 Assess how information
assurance concepts can assurance could enhance the cyber D2 Evaluate the responses that have
mitigate threats and resilience of ICT infrastructure. been implemented by different
vulnerabilities in ICT organisations in response to cyber
infrastructure, giving examples. security threats.
LO4 Investigate incident response methods to cyber security threats
P6 Describe security standards, M4 Analyse the role of criminal and
regulations and their other law in deterring cybercrime.
consequences across at least
two sectors.
P7 Examine the types of
response that have been
implemented in response to
cyber security threats.
Student Achievements and Assessor Feedback
Student achievement and Assessor feedback for both formative and summative submissions will be
recorded within Grade mark Turnitin via Moodle and will be available for students to view as notified on
Turnitin. Please use exclusively the grade classification below.
Assessment Grading Scale
Grade Classification Grade Listed as
Distinction D
Merit M
Pass P
Unclassified/ Referred U
Alleged Academic Misconduct SAM
Student submission declaration
5
The following declaration will be inserted in the Turnitin link for both formative and summative
submissions:
‘I certify that by submitting the work for this assessment on Moodle (and via Turnitin) it is my own work
and all research sources are fully acknowledged using the Harvard system of references. I certify that
there are no personal or mitigating circumstances that have affected my work.’
By submitting such document, you acknowledge that your work is your own, and abides by the DGHE
code of conduct, and Pearson regulations.
Please note that in case of academic malpractice DGHE reserves the right to decline to accept the work
for assessment purposes, and/or conduct an investigation, which might result in an oral presentation,
oral or written exam, or any other appropriate form of examination. Further information can be found in
the academic integrity and misconduct policy, the assessment policy, and the student handbook.
Understanding what a command verb is
Your assignment will always have a series of questions or points that you will need to address. The first
step in successfully addressing your assignment questions is by understanding what your lecturer wants
from you, and this means understanding the command verb of the question.
What is a command verb?
This is constituted by an imperative verb that gives you a specific instruction.
What are the common command verbs your assignment has and what they mean?
The following is not a complete list however, it can help you to understand what is expected of you.
Explain = to describe a situation in detail or present relevant facts. E.g. To say it’s a chair, it’s descriptive
but not explanatory, to say it’s a wooden chair, made of mango woods, that has four legs, and an arm
rest, is to explain.
Assess = to evaluate the relevance of something. For example, stating that digital transformation is
important in healthcare is factual but not evaluative. However, saying that the introduction of AI-driven
data analysis in CAAB's collaboration with the NHS could potentially improve early diagnosis in patients
but may face challenges due to data privacy concerns, provides a more evaluative perspective by
discussing both the benefits and potential obstacles.
Compare = to measure how similar or different something is. For example, stating that data collection
and data analysis are different processes is factual. However, comparing manual data collection by
healthcare workers with automated AI-driven analysis provides a deeper insight: manual data collection
relies on human input and is more prone to error, while AI-driven analysis is more accurate and faster
but depends on the quality of the input data. This distinction illustrates how both methods contribute
differently to improving patient outcomes.
Analyse = to examine something in detail. Saying that CAAB's digital transformation is innovative is too
simplistic. However, analysing how CAAB's AI Unit processes NHS data to predict patient outcomes by
using machine learning involves detailing how this technology helps in identifying early-stage diseases
like cancer. Exploring the interaction between CAAB’s data collection teams, quality control unit, and the
AI Unit, and how each contributes to more effective patient care, provides a thorough analysis of the
entire digital process. Further analysis might include potential challenges in scaling these solutions across
all NHS hospitals while maintaining data security and compliance with healthcare regulations.
Don’t forget you can always refer to your lecturer for other verbs not included here or your study skills
tutor.