What is cybersecurity?
Cybersecurity means protecting computers, phones, networks and data from attack, damage or theft. It has three goals, called the CIA triad:
- Confidentiality: only allowed people can see the data.
- Integrity: the data is correct and nobody has changed it secretly.
- Availability: systems and data work when people need them.
Privacy is about your right to control your personal data. Good security protects privacy. For personal online safety (cyberbullying, safe browsing, reporting), see Cyber safety.
Common cyber threats
- Malware (malicious software): a virus attaches to files and spreads when they run; a worm spreads by itself over networks; a trojan hides inside a program that looks useful; spyware secretly watches you; ransomware locks your files and asks for money.
- Social engineering: tricking people rather than machines. Phishing uses fake emails or messages; shouldering means watching someone type a PIN; pretexting means inventing a story to get information.
- Brute-force attack: trying every possible password until one works.
- Denial of service (DoS): flooding a server with requests so real users cannot get in. A DDoS uses thousands of hacked devices at once.
- Weak points: unpatched software, default passwords, open network ports, and smart (IoT) devices like cameras that are never updated.
Authentication and access control
Authentication checks that you really are who you say. There are three kinds of factors:
- Something you know: password, PIN.
- Something you have: phone code (OTP), security key.
- Something you are: fingerprint, face (biometrics).
Using two different kinds is two-factor authentication (2FA). A strong password is long and mixes letters, numbers and symbols. With 26 small letters, a 4-letter password has 26⁴ = 456,976 choices, but an 8-letter one has 26⁸ ≈ 208 billion. Access control gives each user only the rights they need (a student can read results; only the teacher can change them). Locking accounts after a few wrong tries and CAPTCHAs slow down brute force.
Encryption
Encryption turns readable plain text into scrambled cipher text using a key. Only someone with the right key can decrypt it back.
The Caesar cipher is an old, simple example: shift every letter by the key. With key 3, A → D, B → E, and SAFE → VDIH. It is easy to break because there are only 25 possible keys. Modern encryption (like AES) uses keys so long that trying them all would take longer than the age of the universe.
- Symmetric encryption uses the same key to lock and unlock.
- Public-key (asymmetric) encryption uses a public key to lock and a private key to unlock. The padlock and
httpsin a browser use it.
Firewalls, anti-malware, updates and backups
- Firewall: software or hardware that checks data packets coming in and going out, and blocks those that break its rules.
- Anti-malware: scans files and compares them with known malware patterns; it also watches for strange behaviour.
- Updates (patches): fix security holes. Turn on automatic updates, including on routers and smart devices; change default passwords.
- Backups: copies of data. The 3-2-1 rule: 3 copies, on 2 kinds of storage, 1 kept off-site (for example in the cloud).
- Penetration testing: companies pay experts to attack their own systems (with permission) to find weak points first.
- People: training users to spot phishing is one of the best defences.
Try it: build a strong passphrase
Pick four random, unrelated words, for example mango-river-lamp-seven (do not use this one!). Count the characters. Compare it with a short password like raj123. Which is easier to remember and harder to guess? Then use the 3D free play: encrypt a word with the Caesar cipher and ask a friend to decrypt it using the key.
Key formulas and definitions
- CIA triad: Confidentiality, Integrity, Availability
- Number of passwords = (characters available)^(length), e.g. 26⁸
- Caesar cipher: cipher letter = plain letter shifted by the key (wraps Z → A)
- 3-2-1 backup: 3 copies, 2 media, 1 off-site
Worked examples
1. Encrypt CAT with a Caesar key of 3.
C → F, A → D, T → W. Cipher text: FDW.
2. Decrypt KHOOR, which used key 3.
Shift each letter back 3: K → H, H → E, O → L, O → L, R → O. Plain text: HELLO.
3. How many 3-digit PINs (0–9) are there?
10 × 10 × 10 = 10³ = 1,000.
4. A message says: "Your bank account is blocked. Click here and enter your PIN within 1 hour." What attack is this, and what should you do?
Phishing (social engineering). Do not click. Check by opening the bank's official app or calling its official number, then report the message.
5. A school's result server is flooded with fake requests and nobody can open it. Which part of CIA is attacked?
Availability. This is a denial of service attack.
6. Which factor types are used when you log in with a password and a fingerprint?
Something you know (password) and something you are (fingerprint): two-factor authentication.
Common mistakes
- Thinking a firewall removes viruses. A firewall filters network traffic; anti-malware finds and removes malware.
- Using the same password on many sites. One leak then opens every account.
- Believing that encryption hides that a message was sent. It hides the content, not the fact of sending.
- Keeping the only backup on the same computer. If the computer is stolen or locked by ransomware, the backup is lost too.