Last reviewed 16 Sept 2026 · Facts as of 16 Sept 2026 · 10 min read
Cyber security
Cyber security — protection of computers, networks, programs and data from unauthorised access, attacks, damage or theft.
Goals — the CIA triad and more
| Principle | Meaning | Example measures |
|---|---|---|
| Confidentiality | Only authorised people can access information | Encryption, access control, passwords |
| Integrity | Information is accurate and not altered improperly | Hashing, checksums, digital signatures, version control |
| Availability | Systems and data are accessible when needed | Backups, redundancy, DDoS protection, power backup |
| Authentication | Verifying identity | Passwords, OTP, biometrics, certificates |
| Authorisation | Granting rights to authenticated users | Role-based permissions |
| Non-repudiation | Sender cannot deny having sent a message/transaction | Digital signatures, audit logs |
Cyber threats
Malware (malicious software)
| Malware | Characteristics |
|---|---|
| Virus | Attaches itself to files/programs; needs a host and user action to spread; corrupts or deletes data |
| Worm | Self-replicating, spreads across networks without user action or host file; consumes bandwidth |
| Trojan horse | Disguised as legitimate software; creates backdoors or steals data; does not self-replicate |
| Ransomware | Encrypts files and demands ransom (often cryptocurrency) for decryption |
| Spyware | Secretly monitors activities and collects information |
| Keylogger | Records keystrokes to steal passwords and card details |
| Adware | Displays unwanted advertisements; may track users |
| Rootkit | Hides deep in the system to maintain privileged access and conceal other malware |
| Botnet | Network of infected computers (bots/zombies) controlled remotely — used for DDoS and spam |
| Logic bomb / time bomb | Malicious code triggered by a condition or date |
| Fileless malware | Operates in memory using legitimate tools |
Social engineering attacks
Manipulating people rather than technology.
| Attack | Description |
|---|---|
| Phishing | Fraudulent emails/websites imitating trusted organisations to steal credentials or install malware |
| Spear phishing | Targeted phishing at a specific person/organisation; whaling targets senior executives |
| Vishing | Voice phishing — fraudulent phone calls (e.g. fake bank officials asking for OTP) |
| Smishing | SMS/messaging phishing with malicious links |
| Pretexting | Creating a false scenario to obtain information |
| Baiting | Leaving infected USB drives or offering free downloads |
| Tailgating | Following an authorised person into a restricted area |
| QR code scams | Fake QR codes that trigger payments instead of receiving money |
Network and application attacks
| Attack | Description |
|---|---|
| Denial of Service (DoS) / Distributed DoS (DDoS) | Flooding a server/network with traffic to make it unavailable |
| Man-in-the-middle (MITM) | Intercepting communication between two parties (e.g. on unsecured public Wi-Fi) |
| SQL injection | Inserting malicious SQL code into input fields to access/modify databases |
| Cross-site scripting (XSS) | Injecting malicious scripts into web pages viewed by others |
| Password attacks | Brute force (trying all combinations), dictionary attacks, credential stuffing (reusing leaked passwords) |
| Spoofing | Faking email addresses, caller IDs, IP addresses or websites |
| Zero-day exploit | Attack using a vulnerability unknown to the vendor/unpatched |
| Session hijacking, DNS spoofing, eavesdropping (sniffing) | Taking over sessions, redirecting to fake sites, capturing traffic |
Cyber crimes against individuals
Identity theft, cyberstalking and harassment, cyberbullying, online financial fraud (fake KYC updates, lottery scams, fake customer care numbers, SIM swap, fake investment and job offers), sextortion, data breaches, fake news/misinformation, software piracy, hacking of social media accounts.
Security measures
Technical controls
| Measure | Function |
|---|---|
| Antivirus / anti-malware | Detects and removes malware (signature- and behaviour-based); keep updated |
| Firewall | Hardware or software that monitors and filters network traffic based on rules — blocks unauthorised access |
| Intrusion detection/prevention systems (IDS/IPS) | Detect/block suspicious activity |
| Encryption | Converts plaintext into ciphertext so only authorised parties with keys can read it |
| Hashing | One-way function producing a fixed-length digest (SHA-256) — verifies integrity, stores passwords securely |
| Digital signature | Created with the sender's private key, verified with the public key — ensures authenticity, integrity, non-repudiation |
| Digital certificates | Issued by Certificate Authorities — bind public keys to identities (used in HTTPS) |
| HTTPS / TLS | Encrypted web communication; padlock icon; check correct domain |
| VPN (Virtual Private Network) | Encrypted tunnel over public networks |
| Multi-factor authentication (MFA/2FA) | Two or more factors: something you know (password/PIN), something you have (OTP, phone, token), something you are (biometric) |
| Access control | Least privilege, role-based access, strong authentication |
| Patching and updates | Fix vulnerabilities in OS and applications |
| Backups | Protect against ransomware and data loss |
| CAPTCHA | Distinguishes humans from bots |
Encryption types
| Type | Keys | Features / examples |
|---|---|---|
| Symmetric | Same key for encryption and decryption | Fast; key sharing problem — AES, DES (old) |
| Asymmetric (public-key) | Public key encrypts, private key decrypts (or vice versa for signatures) | Solves key distribution; slower — RSA, ECC; used in digital signatures and TLS key exchange |
Password best practices
- Long passphrases with mix of characters; unique for each account.
- Use a password manager; enable MFA.
- Never share passwords, PINs or OTPs (banks never ask for them).
- Change default passwords of routers and devices.
Backup strategy — 3-2-1 rule
Keep 3 copies of data, on 2 different media, with 1 copy offsite (or offline/cloud) — protects against ransomware and disasters.