Cybersecurity Basics, Explained in Plain English

27 concepts · 2 comparisons · 27 updated this month

Cybersecurity basics in plain English: the CIA triad, common threats, core controls, encryption, identity and frameworks, with tables and a learning path.

NIST 800-63the MFA standard
AES-256the cipher everything uses
3factors: know, have, are
90 daysthe old password rule, now retired
In this guide

Cybersecurity basics, from the threat to the control that stops it

Cybersecurity basics are the small set of ideas behind every security decision: what you are protecting, who might attack it and how, and which controls stand in the way. The tools change every year.

The logic underneath them has barely moved, which is why a person who understands the basics can evaluate a product, a policy or an incident without being told what to think.

This guide covers IT security basics in the order they build on each other: what cybersecurity is, the CIA triad, the types of cybersecurity, the common threats and attacks, the core security controls, encryption, identity and access, the frameworks worth knowing, and what to do when something goes wrong. Each section links to a full page in this library.

DefinitionWhat is cybersecurity?

Cybersecurity is the practice of protecting computers, networks, software and data from unauthorized access, damage and disruption. Information security is the wider term, covering information in any form, including paper; cybersecurity is the part that deals with digital systems.

Network security is narrower again: it protects the traffic and the devices on a network. The cyber security vs network security page draws the line between them.

Three words are used loosely and mean different things:

  • Vulnerability: a weakness, such as an unpatched flaw, a default password or an open port.
  • Threat: someone or something that could exploit a weakness, such as a criminal group, a careless employee or a power failure.
  • Risk: the chance that a threat exploits a vulnerability, multiplied by the damage if it does. Security work is risk reduction, not the pursuit of zero.

Known vulnerabilities are cataloged publicly, each with a CVE identifier and a severity score, in the National Vulnerability Database.

StakesWhy cybersecurity matters

Every organization holds sensitive information that someone else can turn into money: customer records, payment details, payroll, email, contracts and the credentials that unlock all of it. Cyber criminals do not need a famous target. Most attacks are automated and opportunistic, which means small organizations are hit precisely because they are easier, not because anyone chose them.

The cost of an incident is rarely the ransom. It is the days of downtime, the recovery work, the legal duty to notify the people whose information was exposed, and the customers who leave.

Good cybersecurity practices help an organization in a second way as well: insurers, large customers and regulators increasingly ask for proof of them before they will do business.

GoalsThe CIA triad: what security is trying to protect

Every security control serves at least one of three goals, known as the CIA triad. Asking which goal a control serves is the fastest way to tell whether it is worth having.

GoalMeansBroken byProtected by
ConfidentialityOnly authorized people can read the dataData theft, eavesdropping, a lost laptopEncryption, access control, MFA
IntegrityThe data is accurate and has not been alteredTampering, malware, a silent corruptionHashing, digital signatures, change control
AvailabilitySystems and data are there when neededRansomware, denial of service, hardware failureBackups, redundancy, patching

The three pull against each other. A system locked down so tightly that nobody can use it is confidential and useless, which is why security decisions are trade-offs and not a checklist.

DomainsTypes of cybersecurity

The field divides by what is being protected. A small organization needs something from each of these, even when one person covers them all.

  • Network security: controlling what traffic may enter, leave and cross the network, with a firewall, segmentation and intrusion detection and prevention.
  • Endpoint security: protecting laptops, servers and phones with business antivirus, disk encryption and patching.
  • Identity and access management: proving who a user is and limiting what they can reach, with MFA and conditional access.
  • Application security: finding and fixing flaws in software, and shielding web applications with a web application firewall.
  • Cloud security: securing workloads and configuration in a cloud platform, covered in cloud security architecture, CWPP and posture management.
  • Data security: encryption, backup and control over where sensitive data lives.
  • Security operations: monitoring, detection and response, the work of a security operations center. See SOC vs NOC.

ThreatsCommon cyber threats and attacks

Most incidents come from a short list of attack types. Knowing how each one works is what makes the matching defense obvious.

AttackHow it worksMain defense
PhishingA message impersonates someone trusted to steal a password or deliver malwareMFA, email filtering, user training
MalwareMalicious software such as a virus, trojan or spyware runs on a deviceEndpoint protection, patching, least privilege
RansomwareMalware encrypts files and demands payment for the keyOffline or immutable backups, patching, segmentation
Credential attacksStolen or guessed passwords are tried against many accountsMFA, unique passwords, lockout policy
Denial of service (DoS, DDoS)A flood of traffic makes a service unavailableUpstream filtering, rate limiting, capacity
Man in the middleAn attacker intercepts traffic between two partiesEncryption in transit, certificate validation
InjectionCrafted input makes an application run the attacker's commands, as in SQL injectionInput validation, a WAF, secure coding
Insider threatA person with legitimate access misuses it, by malice or by mistakeLeast privilege, logging, offboarding
Zero-day exploitAn attack on a flaw that has no patch yetDefense in depth, segmentation, detection

Cyber threats also differ by who is behind them, because motive predicts method:

  • Cyber criminals want money, and account for most attacks on businesses: ransomware, payment fraud and stolen data for resale.
  • Nation-state groups want information or disruption, and have the patience and resources to stay hidden.
  • Hacktivists want attention for a cause, usually through defacement or denial of service.
  • Insiders already have access, and cause harm through a grudge or, far more often, a mistake.

Social engineering sits behind most of them. It is usually easier to persuade a person to open the door than to break the lock, which is why MFA and training appear in the defense column so often.

DefensesCore security controls and best practices

No single control stops everything, so they are layered. The principle is called defense in depth: an attacker who beats one layer meets another. The basic cybersecurity best practices for any organization are these:

  1. Turn on multi-factor authentication everywhere it is offered, starting with email and remote access. See what MFA is.
  2. Patch promptly. Most successful attacks use a vulnerability that already had a fix. See patch management.
  3. Back up, and test the restore. Follow the 3-2-1 backup rule and keep one copy that malware cannot reach.
  4. Apply least privilege. Every account gets only the access its job needs, and administrators use a separate account for administration.
  5. Default to deny. A firewall should block everything that is not explicitly allowed, the rule known as implicit deny.
  6. Segment the network so that one infected device cannot reach every server. VLANs are the usual tool.
  7. Encrypt devices and traffic. Full-disk encryption on every laptop, HTTPS and a VPN for remote access.
  8. Log and monitor. An attack nobody sees cannot be stopped. Collect logs centrally and review the alerts.
  9. Train people, briefly and regularly, on phishing and on reporting without blame.

The zero trust model takes least privilege to its conclusion: no user or device is trusted because of where it sits on the network, and every request is verified. Zero trust explained covers how that works in practice.

HabitsCyber hygiene: secure habits for every user

Technology covers only part of the problem. The everyday habits of the people using it, often called cyber hygiene, decide the rest. These are the practices worth teaching everyone, at work and at home:

  • Use a password manager and a different password for every account, so one stolen password opens one door.
  • Turn on MFA for email, banking and anything that holds sensitive information.
  • Install updates when they are offered, on computers, phones and home routers alike.
  • Think before you click. Be suspicious of urgency, of unexpected attachments and of any message asking you to sign in.
  • Verify payment changes by phone, using a number you already have, not one in the message.
  • Use secure Wi-Fi, and a VPN on public networks.
  • Lock your screen and encrypt your devices, so a lost laptop is an expense and not a breach.
  • Report mistakes immediately. An organization that punishes reports learns about incidents last.

Free guidance written for small organizations is published by CISA and by NIST, and both are worth bookmarking as learning resources.

CryptographyEncryption basics

Encryption turns readable data into ciphertext that only someone with the key can turn back. It protects data in two states: at rest, on a disk, and in transit, crossing a network.

  • Symmetric encryption uses one shared key for both directions. It is fast, so it encrypts the actual data. AES is the standard.
  • Asymmetric encryption uses a public key and a private key. It is slower, so it is used to exchange keys and to sign. RSA and elliptic curve are the common forms, and Diffie-Hellman key exchange shows how two parties agree on a secret over an open line.
  • Hashing is one-way: it produces a fixed fingerprint of the data and cannot be reversed. It proves integrity and stores passwords safely. See hash functions.

The encryption algorithms page compares the ones in use. On endpoints, disk encryption means BitLocker on Windows and FileVault on a Mac; the pages on the BitLocker recovery key and FileVault disk encryption cover the part that goes wrong, which is losing the key. On Wi-Fi, WPA2-PSK explains what the shared password actually protects.

IdentityIdentity and access management

With staff working from anywhere, identity has replaced the office network as the security boundary. Three steps are involved every time someone signs in:

  • Identification: the user claims an identity, usually a username.
  • Authentication: the user proves it, with something they know (a password), something they have (a phone or key) or something they are (a fingerprint). MFA requires two of those.
  • Authorization: the system decides what that identity may do, ideally by role and by least privilege.

Privileged accounts and application secrets need stronger handling than ordinary logins. CyberArk vs HashiCorp Vault and KMS vs Secrets Manager compare the tools that do it.

FrameworksCybersecurity frameworks worth knowing

A framework is a structured list of what a security program should cover, so nothing is missed and progress can be measured.

  • NIST Cybersecurity Framework (CSF): organizes security into six functions: Govern, Identify, Protect, Detect, Respond and Recover. It is free, widely used, and scales down to a small business.
  • CIS Critical Security Controls: a prioritized list of concrete actions, a practical starting point when the question is what to do first.
  • ISO/IEC 27001: the international standard for an information security management system, against which an organization can be certified.
  • Sector rules: PCI DSS for card payments, HIPAA for US health data, and similar regulations set minimum controls for specific data.

ResponseIncident response basics

Prevention fails eventually, so the plan for that day matters as much as the defenses. The standard incident response cycle has four phases:

  1. Preparation: know who decides, who to call, where the backups are and how to reach people when email is down.
  2. Detection and analysis: confirm what happened and how far it spread, from logs and alerts.
  3. Containment, eradication and recovery: isolate affected systems, remove the attacker's access, restore from clean backups, and change credentials.
  4. Post-incident review: record what happened and fix the cause, without blame.

A small company that cannot staff this around the clock usually buys it as a service. What an MSSP is explains what a managed security provider does, and the cybersecurity services directory lists providers by city.

Reading orderCybersecurity for beginners: a learning path

For someone new to the field, these pages in this order cover the cybersecurity basics without gaps:

  1. Cyber security vs network security: the map of the field.
  2. Firewalls and implicit deny: the first control on any network.
  3. MFA and conditional access: protecting identity.
  4. Encryption algorithms and hash functions: how data is protected.
  5. IDS vs IPS and WAF: detecting and blocking attacks.
  6. Zero trust: the model that ties it together.

GlossaryCybersecurity terms worth knowing

  • Attack surface: every point where an attacker could try to get in. Reducing it is the cheapest security there is.
  • Exploit: code or a technique that takes advantage of a vulnerability.
  • Patch: an update that fixes a vulnerability.
  • Least privilege: giving each account only the access its job needs.
  • Defense in depth: layering controls so that one failure is not a breach.
  • SIEM: a system that collects logs from many sources and raises alerts on suspicious patterns.
  • EDR: endpoint detection and response, software that watches devices for malicious behavior and can isolate them.
  • Penetration test: an authorized attack on your own systems to find weaknesses before someone else does.

Every security concept, by topic

27 pages

Cryptography6 pages

Network security9 pages

Cloud security2 pages

Identity and access5 pages

Security operations2 pages

Cloud and data security1 pages

Vulnerability management1 pages

Wireless security1 pages

How to read the security silo

Cybersecurity basics in plain English: the CIA triad, common threats, core controls, encryption, identity and frameworks, with tables and a learning path.

  • Start with the concepts at the top, in order. They take about an hour together and everything else refers back to them.
  • Use the index by topic. Each group maps to a chapter of the common certification outlines.
  • Go straight to the troubleshooting group. Each page has a checklist at the top.
  • The comparison pages end with a decision chooser and link to the companies listed in the directory that deploy them.

Security questions we get most

Short answers here, full pages one click away.

What are the basics of cybersecurity?

Know what you are protecting, keep it patched, require multi-factor authentication, give each account only the access it needs, back up and test the restore, encrypt devices and traffic, and watch the logs. Behind all of it sits the CIA triad: confidentiality, integrity and availability.

What is the CIA triad?

The three goals of security. Confidentiality means only authorized people can read data, integrity means the data has not been altered, and availability means systems are there when needed. Every control serves at least one of them.

What is the difference between cybersecurity and information security?

Information security protects information in any form, including paper and spoken word. Cybersecurity is the part of it that protects digital systems, networks and data. Network security is narrower still and covers the network and its traffic.

What are the most common cyber attacks?

Phishing, malware and ransomware, stolen or guessed credentials, denial of service, and attacks on unpatched software. Most of them begin with a person being tricked or with a fix that was never installed.

Do I need a hardware firewall or is the one in Windows enough?

Both. The host firewall protects the device wherever it goes. A network firewall protects everything behind it and gives you one place to see and control traffic. The firewall page explains where each one fails.

Is SMS-based MFA still acceptable?

It is better than a password alone and worse than an authenticator app or a hardware key. SIM swap attacks and SS7 weaknesses are why most frameworks now steer administrators toward phishing-resistant methods.

What does zero trust actually change?

It removes the assumption that anything inside the network is safe. Every request is authenticated and authorized on identity, device health and context, whether it comes from the office LAN or a cafe.

What is the difference between a vulnerability, a threat and a risk?

A vulnerability is a weakness. A threat is someone or something that could exploit it. Risk is the likelihood of that happening combined with the damage it would cause, and it is the thing security work tries to reduce.

What is the difference between encryption and hashing?

Encryption is reversible with the right key, so it protects data you need to read again. Hashing is one-way and produces a fixed fingerprint, so it is used to check integrity and to store passwords without storing the password itself.

How often should security patches be applied?

Critical patches for internet-facing systems within days, and everything else on a regular monthly cycle. The patch management page covers how to test and roll out updates without breaking production.

What is the NIST Cybersecurity Framework?

A free framework from the US National Institute of Standards and Technology that organizes security work into six functions: Govern, Identify, Protect, Detect, Respond and Recover. It is a common starting point because it scales from a small business to a large enterprise.

What should a small business do first for security?

Turn on MFA for email and remote access, make sure backups exist and restore, patch automatically, remove administrator rights from daily accounts, and encrypt laptops. Those five close the doors that most attacks on small companies use.

Other silos

One packet a weekA short, illustrated explainer every Tuesday. No vendor pitches, unsubscribe in one click.