Your messages, your photos, your bank balance, and your school or work records all live on computers you will never see. Cybersecurity is the work of keeping that information, and the systems that hold it, out of the wrong hands and working when people need them.
This primer is the first step in our cybersecurity basics learning path. It assumes no background. By the end you will know what security protects, what it protects against, and the core ideas that professionals use to reason about risk.
What security protects: the CIA triad
Security professionals describe their goals with three words, often called the CIA triad. It has nothing to do with the intelligence agency.
- Confidentiality. Only the right people can see the information. Your medical records should be visible to you and your doctor, not to everyone at the clinic, and certainly not to strangers on the internet.
- Integrity. The information is accurate and has not been changed by someone who should not change it. A bank balance that an attacker can edit is worthless, even if no one else can read it.
- Availability. The system works when people need it. A hospital system that is perfectly private but offline during an emergency has failed at security too.
Almost every security problem breaks at least one of the three. When you hear about a "data breach", confidentiality failed. When ransomware locks a company's files, availability failed. When someone alters grades in a school system, integrity failed.
Threats, vulnerabilities, and risk
Three words come up constantly, and they mean different things.
- A threat is anything that could cause harm: a criminal group, a careless employee, a flood in the data center.
- A vulnerability is a weakness that a threat could use: a reused password, a program that trusts input it should check, a door left unlocked.
- Risk is the combination: how likely it is that a threat will use a vulnerability, and how bad the result would be.
A house with a broken lock on the back door has a vulnerability. Whether that is a high risk depends on the threats around it and what is inside. Security teams spend most of their effort deciding which risks matter most, because no organization can fix everything at once. That way of thinking, ranking by likelihood and impact, is the same one professional testers use to decide what to test first.
Who attacks, and why
It helps to know why people attack systems, because motive shapes method.
- Money. Most attacks are crimes for profit: stealing card numbers, holding files for ransom, or tricking someone into sending a payment.
- Information. Some attackers want secrets: designs, plans, or personal data they can sell or use.
- Disruption. Some want to knock a service offline or embarrass an organization.
- Opportunity. Many attacks are automated. Programs scan the internet around the clock for any system with a known weakness. Being small or uninteresting is not protection.
Attackers also include insiders: people who already have access and misuse it, sometimes on purpose and often by accident.
People, process, and technology
New learners often picture security as purely technical: firewalls, encryption, antivirus. Those matter, but most incidents involve people and process as well.
- People click links, choose passwords, and decide whom to trust. Training and good habits reduce mistakes.
- Process decides who gets access, how changes are reviewed, how quickly updates are installed, and what happens when something goes wrong.
- Technology enforces the rules: sign-in systems, encryption, monitoring, and backups.
A strong lock (technology) does not help if the key is taped to the door (people) and nobody checks (process).
Defense in depth
No single protection is perfect, so professionals stack several, each one catching what the last one missed. This is called defense in depth.
Picture a building: a fence, then a locked front door, then a badge reader on the office floor, then a locked cabinet for the most sensitive files, and cameras throughout. An intruder who climbs the fence still faces the door. In software, the layers might be strong sign-in, permissions that limit what each account can do, encryption of stored data, monitoring that spots unusual activity, and backups that let the organization recover.
Defense in depth is also why security is never "done". Each layer needs to be tested, maintained, and updated as systems and attackers change.
Security is everyone's job
Security is a profession, with roles in security engineering, incident response, penetration testing, and governance. It is also part of every other technical job. Developers write code that resists attack. Testers check that it does. Administrators keep systems patched. Everyone who uses a computer makes choices that make attacks easier or harder.
That is good news for anyone starting out. You can contribute to security from almost any role, and the habits you build now protect you and the people around you.
Try it yourself
Pick an app you use every day, such as a messaging app, a game, or a school portal. Write down one example of each:
- What would a confidentiality failure look like in that app?
- What would an integrity failure look like?
- What would an availability failure look like?
- For one of those, name a threat, a vulnerability it could use, and how bad the result would be.
The next step in this path turns these ideas into everyday habits: passwords, multi-factor sign-in, spotting phishing, and keeping devices updated. Look up any unfamiliar term in our glossary.