Cybersecurity
and Data
Protection
Learning Target
● Define cybersecurity and its importance to society
through a crossword puzzle
● Identify common types of cyber threats and
attacks
● Understand the basic principles of data protection
by making a security awareness poster design.
Cybersecurity and data protection are words that people tend
to use interchangeably. While they have similarities and often
overlap, it’s kind of like discussing a rectangle and a square
where both have four sides but are distinct shapes.
In a digital world, your cybersecurity posture directly
impacts your data protection and privacy initiatives.
Cybersecurity and
its Importance to
Society
Cybersecurity - refers to the practice of protecting computer
systems, networks, and digital data from unauthorized
access, damage, theft, or disruption.
● It involves implementing measures to prevent, detect,
and respond to cyber threats and attacks.
● The main objective of cybersecurity is to ensure the
confidentiality, integrity, and availability of information
and systems.
In today's digitally-driven world, safeguarding your data and ensuring
strong cybersecurity is not just a choice; it is a necessity. Here's why it is
crucial:
1. Data's Importance:
Data is the lifeblood of the digital age, and protecting it is synonymous with
safeguarding the future of your business or organization.
2. Ever-Changing Threats:
Cyber threats are constantly evolving, requiring constant vigilance and
adaptability to stay ahead and protect against potential attacks.
3. Remote Work Realities:
The shift to remote work has expanded our digital presence. Securing this
broader landscape is of utmost importance.
In today's digitally-driven world, safeguarding your data and ensuring
strong cybersecurity is not just a choice; it is a necessity. Here's why it is
crucial:
4. Trust and Reputation:
Reputation and trust are hard-earned but easily damaged. Protecting data
helps maintain the trust of customers, clients, and partners.
5. Embracing Innovation: Cybersecurity tools and strategies are advancing.
Cutting-edge technologies are reshaping our ability to combat cyber threats
effectively.
6. Human Element: People remain a significant factor in security breaches.
Training and awareness are fundamental in mitigating risks associated with
human error.
7. Continuous Vigilance: Cybersecurity is not a one-time effort but an ongoing
journey. Regular monitoring and updates are key to maintaining a secure
environment.
What is a
Cyberattack
?
A cyberattack refers to a
malicious attempt to
compromise, damage, or
disrupt computer networks and
systems. These attacks can be
categorized into two main
types: insider threats and
outsider threats.
● Insider threats involve individuals who have
authorized access to an organization's
network, such as employees or contractors,
and may exploit system vulnerabilities either
intentionally or unintentionally. This can be
driven by personal grievances or negligence.
● Outsider threats come from individuals or
groups without legitimate access to the
targeted systems. These attackers, often
associated with criminal organizations or
independent hackers, aim to breach the
organization's network from outside.
The Most Common Cyber
Threats and Attacks
1. Malware: Programs or code created to harm a computer, network, or server.
2. Denial-of-Service (DoS) Attacks: Floods a network with false requests to disrupt operations.
3. Phishing: Uses emails, SMS, social media to trick victims into sharing sensitive information.
4. Spoofing: Disguises as a trusted source to steal information or install malware.
5. Identity-Based Attacks: Masquerades as a valid user to evade detection.
6. Code Injection Attacks: Injects malicious code into vulnerable systems to alter their actions.
7. Supply Chain Attacks: Targets trusted vendors to infect all users of an app.
8. Social Engineering Attacks: Manipulates people into taking actions through psychological tactics.
9. Insider Threats: Internal actors who pose a danger due to access to sensitive data.
10. DNS Tunneling: Uses DNS queries to transmit data within a network.
11. IoT-Based Attacks: Targets IoT devices to steal data or launch attacks.
12. AI-Powered Attacks: Utilizes AI and ML technology to access networks or steal information.
To prevent cyber attacks, follow
these key practices
● Use Strong Passwords ● Back Up Data
● Keep Systems Updated ● Enable Two-Factor
● Install Antivirus Authentication
● Network Security ● Secure Wi-Fi
● Beware of Phishing ● Protect Mobile Devices
● Use VPNs
The Basic
Principles
of Data
Protection
Data privacy - focuses specifically on the
protection of personal and sensitive
information.
● It involves the proper handling, storage,
and usage of personal data in
accordance with legal and ethical
standards.
● Data privacy aims to safeguard
individuals' right to control their
personal information and ensures that
data is collected, processed, and shared
The General Data Protection Regulation (GDPR) outlines key principles that
form the foundation of the data protection regime. Compliance with these
principles is crucial for controllers to fulfill their obligations under the
GDPR.
1. Lawfulness, fairness, and transparency:
○ Process personal data lawfully, with a valid legal basis like user consent.
○ Ensure fair processing that aligns with individuals' interests and expectations.
○ Communicate clearly and transparently about the data processing methods and purposes.
2. Purpose limitation:
○ Only process personal data for the intended purpose stated at the time of collection.
○ Avoid reusing data for other purposes without obtaining additional consent.
3. Data minimisation:
○ Collect and process only the necessary personal data required for the specific purpose.
○ Avoid unnecessary data collection and storage, minimizing compliance risks and data
breach impact.
4. Accuracy:
○ Maintain accurate, up-to-date, and relevant personal data.
○ Take reasonable measures to ensure data accuracy, especially when it is crucial for
the individual.
5. Storage limitations:
○ Delete personal data that is no longer necessary for the original purpose.
○ Implement secure data destruction processes to remove obsolete data and mitigate
security risks.
6. Integrity and confidentiality:
○ Ensure data integrity by preventing unauthorized manipulation or alteration.
○ Maintain data confidentiality by limiting access to authorized individuals and
protecting against cyber threats.
7. Accountability:
○ Take responsibility for proper data processing and GDPR compliance.
○ Document data processing activities, consent mechanisms, and organizational
measures to demonstrate accountability.
Reese Miller Sandra Haro Helene Paquet
Activity
Activity
Thank
you