Cybersecurity is the practice of protecting systems, networks, programs and data from unauthorised access, disruption, theft or destruction. It is not a product you buy, and it is not a department you hire once. It is a set of layered controls maintained continuously against opponents who adapt.
Two facts frame everything that follows. Attacks are overwhelmingly automated and indiscriminate — you are not being targeted, you are being scanned. And the overwhelming majority of successful breaches exploit something that was known and had a patch available, or a credential that was reused.
The three objectives
Everything in the field resolves to the CIA triad:
| Goal | Meaning | Failure looks like |
|---|---|---|
| Confidentiality | Data seen only by authorised people | Data breach, exposure of personal records |
| Integrity | Data and systems are accurate and unaltered | Tampered records, altered logs, fraudulent transactions |
| Availability | Systems accessible when needed | Ransomware, denial-of-service, outage |
Most controls trade one against another. Encryption reduces convenience to protect confidentiality; strict access controls protect confidentiality at the cost of availability when someone legitimately needs the data at 3am. Security is the art of choosing where to sit on those trade-offs deliberately rather than by accident.
The main categories of threat
1. Social engineering
Manipulating people rather than breaking software. It is the dominant initial access vector because it bypasses technical controls entirely. Phishing, smishing, vishing, pretexting, business email compromise and tailgating all belong here. Phishing is covered in depth in our dedicated phishing guide — including the nine variants and what to do after clicking.
2. Malware
Malicious software, in several flavours: viruses (attach to a host file), worms (self-propagate across networks without a host), trojans (disguised as legitimate software), spyware and keyloggers (capture input), rootkits (hide their own presence at kernel level), and adware.
3. Ransomware
Encrypts data and demands payment. Modern variants practice double extortion — exfiltrating data first, then threatening publication, so paying for decryption still leaves a breach to disclose. The 2017 WannaCry outbreak exploited a Windows SMB flaw for which Microsoft had released a patch a month earlier.
The operational answer is not payment. It is immutable, tested backups.
4. Denial of service
Overwhelming a service with traffic so legitimate users cannot reach it. DDoS distributes the attack across a botnet of compromised devices — the 2016 Mirai botnet recruited poorly secured cameras and routers. Volumetric, protocol and application-layer attacks differ in mechanism; the objective is availability.
5. Man-in-the-middle
Intercepting communication between two parties who think they are talking directly. Risks on public Wi-Fi include ARP spoofing; at internet scale, BGP hijacking redirects routing. TLS and certificate validation are the primary defence, which is why a padlock you did not verify tells you nothing about who you reached — see how to check whether a website is safe.
6. Injection and application flaws
SQL injection, cross-site scripting, command injection and path traversal all share one root cause: untrusted input being interpreted as code or commands. Parameterised queries and output encoding eliminate the entire class. Injection remains in the OWASP Top 10 year after year.
7. Zero-day exploits
Attacks against vulnerabilities the vendor does not yet know about — hence “zero days” of patch availability. Because there is no patch, defence falls back on layers: segmentation, endpoint detection, application allowlisting, and behavioural monitoring rather than signature matching.
8. Supply chain compromise
Attacking targets through a trusted upstream — a software update, a library dependency, a service provider. The 2020 SolarWinds compromise injected malicious code into a routine update signed by the vendor itself. Trust in an update channel is a real and quantifiable attack surface.
9. Insider threat
Employees, contractors or administrators — malicious, or simply negligent. Credentials that work are not flagged as attacks. Defences are least privilege, separation of duties, logging, and making the secure path the easy path.
10. Password and credential attacks
Credential stuffing — taking username/password pairs from one breached site and trying them everywhere, which works because people reuse credentials. Brute force, password spraying (common passwords against many accounts), and rainbow tables against unsalted hashes. All are defeated by unique credentials plus multi-factor authentication.
The defences that actually work
Defence in depth
The core principle: no single control is sufficient, so layers are stacked so that failure of one does not mean compromise. Perimeter, network, host, application, data and human layers each independently raise cost to the attacker.
Identity
- Unique passwords for every site, generated by a password manager. This single measure neutralises credential stuffing
- Multi-factor authentication everywhere — blocks the majority of account takeover
- Phishing-resistant MFA — passkeys and FIDO2 hardware tokens are bound to the domain, so a convincing fake site cannot complete authentication
- Least privilege — nobody holds access they do not need, including administrators
Patching
The single highest-yield technical control. Known vulnerabilities with available patches account for a large share of successful intrusions. Automated, tested, and prioritised by exposure — an internet-facing service with an active exploit gets done today.
Encryption
- In transit — TLS, so intercepted traffic is unreadable
- At rest — full-disk and database encryption, so stolen hardware is a paperweight
- Passwords — never stored encrypted and never stored plain. They are hashed with a slow algorithm such as Argon2 or bcrypt, plus a per-user salt. MD5 and unsalted SHA-1 are inadequate — a leaked database of unsalted hashes falls quickly
Backups — the ransomware answer
The 3-2-1 rule: three copies of the data, on two different media types, with one offsite. Add a fourth consideration now — immutable or offline, so the backup cannot be encrypted along with the source. And a backup you have never restored is a hypothesis, not a backup: test recovery regularly.
Network and endpoint
- Firewalls and segmentation — limit lateral movement. A compromised marketing workstation should not reach the database
- Zero trust — “never trust, always verify”. Authenticate and authorise every request regardless of network location, because the perimeter no longer contains the workforce
- EDR / endpoint detection — behavioural monitoring on endpoints rather than signature-only antivirus
- SIEM and logging — you cannot detect what you did not record. Retention matters: logs deleted after 24 hours cannot reconstruct a breach discovered on day five
The shared responsibility model
This is the most commonly misunderstood idea in modern security. For cloud services, the provider secures the cloud; you secure what is put in it. The infrastructure is maintained by the vendor. Misconfigured storage buckets, over-permissive identities, unencrypted databases and missing logging are customer-side failures — and they account for a large share of cloud breaches. The platform was secure; the configuration was not. This is why our cloud computing guide treats configuration as the main cloud risk.
Frameworks and how organisations structure this
NIST Cybersecurity Framework 2.0 organises activity into six functions: Govern, Identify, Protect, Detect, Respond, Recover. ISO 27001 is the certifiable management-system standard. CIS Controls provide an prioritised implementation list. MITRE ATT&CK catalogs attacker behaviours so detections can be mapped against real adversary technique.
Incident response follows a recognised sequence: Preparation → Identification → Containment → Eradication → Recovery → Lessons learned. The step most often skipped is the last one, and it is the one that prevents recurrence.
Risk is conventionally expressed as likelihood × impact, assessed against an organisation’s risk appetite. No organisation is secure against everything; the discipline is choosing what to accept deliberately.
Common myths
- “I’m not a target.” Automated scanning does not care who you are. Ransomware operators want any payable victim; credential stuffing tests any account it finds
- “A VPN makes me anonymous.” It encrypts the connection to the VPN provider and hides traffic from your local network. The provider can see everything, and it does not prevent entering credentials on a fake site. Its genuine uses are public Wi-Fi and location privacy — see what a VPN actually does
- “I have antivirus, so I’m covered.” One layer, and one that signature-based tools handle poorly against zero-days and social engineering
- “Mac/Linux don’t get malware.” Market share changes targeting economics, not capability
- “Incognito mode makes me private.” It stops local history being saved on the device. It does not hide anything from your network, employer or the sites you visit
Where an individual should start
- Password manager and unique credentials everywhere
- MFA on everything that supports it, passkeys where offered
- Update operating systems, browser, and applications — enable automatic updates
- Back up anything you would be unable to reconstruct
- Recognise phishing — our phishing guide covers the specific markers
- Check for breaches — services that report whether your credentials have appeared in known leaks, then change reused passwords
- Encrypt the device and use a strong screen lock
- Use a VPN on public Wi-Fi
Frequently asked questions about cybersecurity
Is paying a ransom ever the right decision?
Law enforcement consistently advises against it, for three reasons: there is no guarantee of decryption (a substantial minority of ransomware strains have broken decryptors or operational failures); payment funds and incentivises further attacks; and payment may breach sanctions rules. The alternatives are tested backups, incident response planning, and early reporting to authorities. Organisations that plan for the decision in advance make it far better than those deciding under pressure.
Can cybersecurity ever be fully achieved?
No, and any vendor claiming otherwise is selling something. The goal is reducing risk to an acceptable level at a justifiable cost, and raising the attacker’s cost above the value of attacking you. Security is a continuous process of reassessment — attackers change their methods, and so must the controls.
Do small businesses need this, or is it an enterprise concern?
Small businesses are frequently targeted precisely because they are less likely to have defences — and because they are often a route into the larger customers they supply. The cost-effective basics are disproportionately effective: patching, multi-factor authentication, backups, staff awareness and basic logging would prevent a large share of incidents at any size of organisation.
Is machine learning solving cybersecurity?
It helps on detection — spotting anomalous behaviour across high-volume logs would be impossible to do manually. It also cuts both ways: attackers use it to write convincing phishing at scale, to automate vulnerability discovery, and to generate deepfakes for voice-based social engineering. Expect an ongoing trade rather than a resolution. See our machine learning explainer for how these systems work.
How do I know if I have already been compromised?
Signs include password reset notifications you did not initiate, unfamiliar sessions or devices in account settings, unexpected email rules or forwarding addresses, colleagues receiving messages you did not send, and transaction alerts for activity you do not recognise. The absence of signs is not evidence of safety — most compromise is detected by third parties. Regularly reviewing active sessions and connected applications is a habit worth building.
This article explains general technology concepts and is not a substitute for advice from your IT or security team.















