In this guide
- What is cybersecurity?
- Why cybersecurity matters
- The CIA triad: what security is trying to protect
- Types of cybersecurity
- Common cyber threats and attacks
- Core security controls and best practices
- Cyber hygiene: secure habits for every user
- Encryption basics
- Identity and access management
- Cybersecurity frameworks worth knowing
- Incident response basics
- Cybersecurity for beginners: a learning path
- Cybersecurity terms worth knowing
- FAQ
Cybersecurity basics, from the threat to the control that stops it
Cybersecurity basics are the small set of ideas behind every security decision: what you are protecting, who might attack it and how, and which controls stand in the way. The tools change every year.
The logic underneath them has barely moved, which is why a person who understands the basics can evaluate a product, a policy or an incident without being told what to think.
This guide covers IT security basics in the order they build on each other: what cybersecurity is, the CIA triad, the types of cybersecurity, the common threats and attacks, the core security controls, encryption, identity and access, the frameworks worth knowing, and what to do when something goes wrong. Each section links to a full page in this library.
DefinitionWhat is cybersecurity?
Cybersecurity is the practice of protecting computers, networks, software and data from unauthorized access, damage and disruption. Information security is the wider term, covering information in any form, including paper; cybersecurity is the part that deals with digital systems.
Network security is narrower again: it protects the traffic and the devices on a network. The cyber security vs network security page draws the line between them.
Three words are used loosely and mean different things:
- Vulnerability: a weakness, such as an unpatched flaw, a default password or an open port.
- Threat: someone or something that could exploit a weakness, such as a criminal group, a careless employee or a power failure.
- Risk: the chance that a threat exploits a vulnerability, multiplied by the damage if it does. Security work is risk reduction, not the pursuit of zero.
Known vulnerabilities are cataloged publicly, each with a CVE identifier and a severity score, in the National Vulnerability Database.
StakesWhy cybersecurity matters
Every organization holds sensitive information that someone else can turn into money: customer records, payment details, payroll, email, contracts and the credentials that unlock all of it. Cyber criminals do not need a famous target. Most attacks are automated and opportunistic, which means small organizations are hit precisely because they are easier, not because anyone chose them.
The cost of an incident is rarely the ransom. It is the days of downtime, the recovery work, the legal duty to notify the people whose information was exposed, and the customers who leave.
Good cybersecurity practices help an organization in a second way as well: insurers, large customers and regulators increasingly ask for proof of them before they will do business.
GoalsThe CIA triad: what security is trying to protect
Every security control serves at least one of three goals, known as the CIA triad. Asking which goal a control serves is the fastest way to tell whether it is worth having.
| Goal | Means | Broken by | Protected by |
|---|---|---|---|
| Confidentiality | Only authorized people can read the data | Data theft, eavesdropping, a lost laptop | Encryption, access control, MFA |
| Integrity | The data is accurate and has not been altered | Tampering, malware, a silent corruption | Hashing, digital signatures, change control |
| Availability | Systems and data are there when needed | Ransomware, denial of service, hardware failure | Backups, redundancy, patching |
The three pull against each other. A system locked down so tightly that nobody can use it is confidential and useless, which is why security decisions are trade-offs and not a checklist.
DomainsTypes of cybersecurity
The field divides by what is being protected. A small organization needs something from each of these, even when one person covers them all.
- Network security: controlling what traffic may enter, leave and cross the network, with a firewall, segmentation and intrusion detection and prevention.
- Endpoint security: protecting laptops, servers and phones with business antivirus, disk encryption and patching.
- Identity and access management: proving who a user is and limiting what they can reach, with MFA and conditional access.
- Application security: finding and fixing flaws in software, and shielding web applications with a web application firewall.
- Cloud security: securing workloads and configuration in a cloud platform, covered in cloud security architecture, CWPP and posture management.
- Data security: encryption, backup and control over where sensitive data lives.
- Security operations: monitoring, detection and response, the work of a security operations center. See SOC vs NOC.
ThreatsCommon cyber threats and attacks
Most incidents come from a short list of attack types. Knowing how each one works is what makes the matching defense obvious.
| Attack | How it works | Main defense |
|---|---|---|
| Phishing | A message impersonates someone trusted to steal a password or deliver malware | MFA, email filtering, user training |
| Malware | Malicious software such as a virus, trojan or spyware runs on a device | Endpoint protection, patching, least privilege |
| Ransomware | Malware encrypts files and demands payment for the key | Offline or immutable backups, patching, segmentation |
| Credential attacks | Stolen or guessed passwords are tried against many accounts | MFA, unique passwords, lockout policy |
| Denial of service (DoS, DDoS) | A flood of traffic makes a service unavailable | Upstream filtering, rate limiting, capacity |
| Man in the middle | An attacker intercepts traffic between two parties | Encryption in transit, certificate validation |
| Injection | Crafted input makes an application run the attacker's commands, as in SQL injection | Input validation, a WAF, secure coding |
| Insider threat | A person with legitimate access misuses it, by malice or by mistake | Least privilege, logging, offboarding |
| Zero-day exploit | An attack on a flaw that has no patch yet | Defense in depth, segmentation, detection |
Cyber threats also differ by who is behind them, because motive predicts method:
- Cyber criminals want money, and account for most attacks on businesses: ransomware, payment fraud and stolen data for resale.
- Nation-state groups want information or disruption, and have the patience and resources to stay hidden.
- Hacktivists want attention for a cause, usually through defacement or denial of service.
- Insiders already have access, and cause harm through a grudge or, far more often, a mistake.
Social engineering sits behind most of them. It is usually easier to persuade a person to open the door than to break the lock, which is why MFA and training appear in the defense column so often.
DefensesCore security controls and best practices
No single control stops everything, so they are layered. The principle is called defense in depth: an attacker who beats one layer meets another. The basic cybersecurity best practices for any organization are these:
- Turn on multi-factor authentication everywhere it is offered, starting with email and remote access. See what MFA is.
- Patch promptly. Most successful attacks use a vulnerability that already had a fix. See patch management.
- Back up, and test the restore. Follow the 3-2-1 backup rule and keep one copy that malware cannot reach.
- Apply least privilege. Every account gets only the access its job needs, and administrators use a separate account for administration.
- Default to deny. A firewall should block everything that is not explicitly allowed, the rule known as implicit deny.
- Segment the network so that one infected device cannot reach every server. VLANs are the usual tool.
- Encrypt devices and traffic. Full-disk encryption on every laptop, HTTPS and a VPN for remote access.
- Log and monitor. An attack nobody sees cannot be stopped. Collect logs centrally and review the alerts.
- Train people, briefly and regularly, on phishing and on reporting without blame.
The zero trust model takes least privilege to its conclusion: no user or device is trusted because of where it sits on the network, and every request is verified. Zero trust explained covers how that works in practice.
HabitsCyber hygiene: secure habits for every user
Technology covers only part of the problem. The everyday habits of the people using it, often called cyber hygiene, decide the rest. These are the practices worth teaching everyone, at work and at home:
- Use a password manager and a different password for every account, so one stolen password opens one door.
- Turn on MFA for email, banking and anything that holds sensitive information.
- Install updates when they are offered, on computers, phones and home routers alike.
- Think before you click. Be suspicious of urgency, of unexpected attachments and of any message asking you to sign in.
- Verify payment changes by phone, using a number you already have, not one in the message.
- Use secure Wi-Fi, and a VPN on public networks.
- Lock your screen and encrypt your devices, so a lost laptop is an expense and not a breach.
- Report mistakes immediately. An organization that punishes reports learns about incidents last.
Free guidance written for small organizations is published by CISA and by NIST, and both are worth bookmarking as learning resources.
CryptographyEncryption basics
Encryption turns readable data into ciphertext that only someone with the key can turn back. It protects data in two states: at rest, on a disk, and in transit, crossing a network.
- Symmetric encryption uses one shared key for both directions. It is fast, so it encrypts the actual data. AES is the standard.
- Asymmetric encryption uses a public key and a private key. It is slower, so it is used to exchange keys and to sign. RSA and elliptic curve are the common forms, and Diffie-Hellman key exchange shows how two parties agree on a secret over an open line.
- Hashing is one-way: it produces a fixed fingerprint of the data and cannot be reversed. It proves integrity and stores passwords safely. See hash functions.
The encryption algorithms page compares the ones in use. On endpoints, disk encryption means BitLocker on Windows and FileVault on a Mac; the pages on the BitLocker recovery key and FileVault disk encryption cover the part that goes wrong, which is losing the key. On Wi-Fi, WPA2-PSK explains what the shared password actually protects.
IdentityIdentity and access management
With staff working from anywhere, identity has replaced the office network as the security boundary. Three steps are involved every time someone signs in:
- Identification: the user claims an identity, usually a username.
- Authentication: the user proves it, with something they know (a password), something they have (a phone or key) or something they are (a fingerprint). MFA requires two of those.
- Authorization: the system decides what that identity may do, ideally by role and by least privilege.
Privileged accounts and application secrets need stronger handling than ordinary logins. CyberArk vs HashiCorp Vault and KMS vs Secrets Manager compare the tools that do it.
FrameworksCybersecurity frameworks worth knowing
A framework is a structured list of what a security program should cover, so nothing is missed and progress can be measured.
- NIST Cybersecurity Framework (CSF): organizes security into six functions: Govern, Identify, Protect, Detect, Respond and Recover. It is free, widely used, and scales down to a small business.
- CIS Critical Security Controls: a prioritized list of concrete actions, a practical starting point when the question is what to do first.
- ISO/IEC 27001: the international standard for an information security management system, against which an organization can be certified.
- Sector rules: PCI DSS for card payments, HIPAA for US health data, and similar regulations set minimum controls for specific data.
ResponseIncident response basics
Prevention fails eventually, so the plan for that day matters as much as the defenses. The standard incident response cycle has four phases:
- Preparation: know who decides, who to call, where the backups are and how to reach people when email is down.
- Detection and analysis: confirm what happened and how far it spread, from logs and alerts.
- Containment, eradication and recovery: isolate affected systems, remove the attacker's access, restore from clean backups, and change credentials.
- Post-incident review: record what happened and fix the cause, without blame.
A small company that cannot staff this around the clock usually buys it as a service. What an MSSP is explains what a managed security provider does, and the cybersecurity services directory lists providers by city.
Reading orderCybersecurity for beginners: a learning path
For someone new to the field, these pages in this order cover the cybersecurity basics without gaps:
- Cyber security vs network security: the map of the field.
- Firewalls and implicit deny: the first control on any network.
- MFA and conditional access: protecting identity.
- Encryption algorithms and hash functions: how data is protected.
- IDS vs IPS and WAF: detecting and blocking attacks.
- Zero trust: the model that ties it together.
GlossaryCybersecurity terms worth knowing
- Attack surface: every point where an attacker could try to get in. Reducing it is the cheapest security there is.
- Exploit: code or a technique that takes advantage of a vulnerability.
- Patch: an update that fixes a vulnerability.
- Least privilege: giving each account only the access its job needs.
- Defense in depth: layering controls so that one failure is not a breach.
- SIEM: a system that collects logs from many sources and raises alerts on suspicious patterns.
- EDR: endpoint detection and response, software that watches devices for malicious behavior and can isolate them.
- Penetration test: an authorized attack on your own systems to find weaknesses before someone else does.
