What Is Cyber Security?

As a regular commentator on the cyber security industry, I am frequently surprised at the seeming lack of understanding of what cyber security is and how it can be used by an organisation to truly mitigate the growing risk of cyber attack. This is often demonstrated by the incorrect (and annoying) use of the terms, ‘threat’, ‘vulnerability’ and ‘risk’.  Threats and vulnerabilities although related, are not the same thing and it remains frustrating to see the words used interchangeably by authors describing products from companies that include Microsoft, IBM and Sophos.

A good definition of cyber security is:

 

Cyber security refers to the body of technologies, processes, and practices designed to protect networks, devices, programs, and data from attack, damage, or unauthorised access.

Digital Guardian

 

Cyber security – the digital child of internet security

It is important to remember that cyber security is closely related to physical security and both disciplines together are the central building blocks of information security. Information security pre-dates cyber security by many decades. Long before the internet was invented, organisations were just as concerned about the security of their paper-based confidential documents. The role played by people as they interact with technology is also critical to understanding cyber security. The phrase ‘people, process, technology’ clearly sums up the nature of cyber risks and their associated security counter-measures (controls).

 

The CIA Triad – it’s a gang of three

To gain a true understanding of cyber security, it is essential to understand how people in an organisation use information to fulfil their own job role or to ensure the privacy of others.

The CIA Triad model defines the need for the following:

  • Confidentiality – information is not disclosed to unauthorised individuals
  • Integrity – ensuring accuracy and completeness of data
  • Availability – users must have information when they need it

The CIA Triad is a central tenant of ISO/IEC 27001:2013 (ISO 27001), the international standard that describes best practice for an ISMS (information security management system). ISO 27001 neatly summarises Information security as the maintenance of confidentially, availability and integrity of the confidential assets of an organisation.

 

What is cyber risk?

One of the best definitions of cyber risk is:

 

Risk is the probability that a (a person or thing that is likely to cause damage) exploiting a vulnerability (a flaw, feature or user error) that causes a negative impact to an asset.

Alan Calder, Steve G Watkins

You will note that this definition defines a threat and a vulnerability and relates them to the risk (negative impact) to the organisation. This relationship is at the heart of an effective risk management programme and applies to large and small organisations located anywhere in the world.

I urge all owners of business assets to consider this definition and then ask the following questions:

What are my key information assets?

What happens if they are stolen or lost? (the impact)

What are my main threats?

What are my main vulnerabilities?

What countermeasures (controls) are needed to mitigate the risks

What is the cost/benefit for each control (focus on high priority risks first)?

Start at the beginning of your business

I always strongly recommend a basic cyber risk management approach to owners of start-up or early stages businesses. With limited resources (capital and expertise), early strategic decisions made about cyber security are crucial to the success and growth of any company. i.e. one good cyber attack can put you out of business within days (or sometimes hours).

 

——————–

 

As an experienced cyber security consultancy, Wizard Cyber is committed to helping SME businesses identify their cyber threats and vulnerabilities. Our cyber audit and penetration testing services are specially designed to evaluate the security status of people, process and technology. Armed with this information, we then recommend and implement countermeasures that mitigate the risks associated with cyber attack and fully support the CIA Triad.

CIA

Abdallah Alhajeid

WordPress Developer

WIZARD CYBER
Headquarters
Providing enterprises with bespoke & powerful managed solutions to protect against all forms of cybercrime
OUR LOCATIONS
Where to find us?
world map
GET IN TOUCH
Latest Updates
Stay up to date with the latest news from Wizard Cyber and the cybersecurity industry
https://wizardcyber.com/wp-content/uploads/2026/04/ISO-QSL-Cert-ISO-27001-scaled.png
https://wizardcyber.com/wp-content/uploads/2026/04/ISO-QSL-Cert-ISO-9001-scaled.png
WIZARD CYBER
Headquarters
Providing enterprises with bespoke & powerful managed solutions to protect against all forms of cybercrime
OUR LOCATIONS
Where to find us?
world map
GET IN TOUCH
Latest Updates
Stay up to date with the latest news from Wizard Cyber and the cybersecurity industry

Copyright by Wizard Cyber. All rights reserved.

Copyright by Wizard Cyber. All rights reserved.

Contact Us
×
Contact Us
Need Cybersecurity Guidance? Get in touch with us!

Our experts are ready to help with your cybersecurity questions—book a conversation with us by clicking the button.

Book a Meeting
Funded Workshops
×
Funded Workshops
Explore Our Funded Microsoft Security Workshops

Click to learn more about each Microsoft-supported engagement

Book a Consultation