Introduction to Cybersecurity
A structured cybersecurity foundation course covering core security concepts, risk, attack surfaces, threat actors, cybercrime, cyber warfare, security principles, domains and career roles. Ten study-note parts plus a 50-question final MCQ exam. Pass mark: 75%.
01Part 1 — What Is Cybersecurity & Information Security
Cybersecurity foundations, InfoSec comparison, objectives and importance.
STUDY NOTES
Part 1 — What Is Cybersecurity & Information Security
Cybersecurity foundations, InfoSec comparison, objectives and importance.
# 1. What is Cybersecurity? Cybersecurity is the practice of protecting **systems, networks, applications, devices, and data** from digital attacks, unauthorized access, damage, or disruption. It combines technology, processes, and people. ## Main areas it covers - Network security, endpoint security, application security - Cloud security, data security, identity and access management - Incident response and recovery # 2. Information Security vs Cybersecurity | Aspect | Information Security (InfoSec) | Cybersecurity | |---|---|---| | Scope | Protects information in **any form** (digital, paper, verbal) | Protects **digital assets** and cyberspace | | Focus | Data confidentiality, integrity, availability | Systems, networks, internet-connected devices | | Example | Locking physical files in a cabinet, shredding documents | Firewalls, antivirus, encryption of online data | | Relationship | The broader umbrella | A subset of InfoSec (though the terms are often used interchangeably) | # 3. Cybersecurity Objectives and Importance ## Objectives - Protect sensitive data from theft or exposure - Ensure systems run reliably without disruption - Prevent unauthorized access and misuse - Detect, respond to, and recover from incidents - Ensure regulatory compliance (GDPR, HIPAA, PCI-DSS, India's DPDP Act, etc.) - Maintain trust of customers and stakeholders ## Why it matters - **Financial impact:** breaches can create fines, lawsuits, downtime and recovery costs. - **Privacy:** personal data such as banking, health and identity information needs protection. - **Business continuity:** attacks such as ransomware can halt operations. - **National security:** critical infrastructure such as power grids, hospitals and banks depends on cyber resilience. - **Reputation:** loss of customer trust can be long-lasting. - **Growing attack surface:** cloud, IoT, remote work and mobile devices increase exposure.
02Part 2 — CIA Triad & Security Objectives
Confidentiality, integrity, availability and extended security properties.
STUDY NOTES
Part 2 — CIA Triad & Security Objectives
Confidentiality, integrity, availability and extended security properties.
# 4. The CIA Triad The CIA Triad is the foundation of information security. Every control aims to protect one or more of these properties. ## Confidentiality Only authorized people can access information. **Controls:** encryption, access control, MFA, data classification and VPNs. **Violation examples:** data breach, eavesdropping and shoulder surfing. ## Integrity Data remains accurate, complete and unaltered except by authorized parties. **Controls:** hashing (SHA-256), digital signatures, checksums, version control and audit logs. **Violation examples:** a hacker modifies bank balances or a file is tampered with in transit. ## Availability Systems and data are accessible when needed. **Controls:** redundancy, backups, load balancing, DDoS protection, disaster recovery plans and patching. **Violation examples:** DDoS attack, ransomware locking files or server failure. ## Extended concepts - **Authenticity:** verifying that an identity or source is genuine. - **Non-repudiation:** a party cannot deny having performed an action; digital signatures and logs can support it. - **Accountability:** actions can be traced to an entity. **Key examples:** encryption mainly supports confidentiality; hashing supports integrity; redundancy and backups support availability; digital signatures can support integrity and non-repudiation.
03Part 3 — Assets, Threats, Vulnerabilities, Exploits & Risk
Core risk vocabulary, relationships, zero-days and risk treatment.
STUDY NOTES
Part 3 — Assets, Threats, Vulnerabilities, Exploits & Risk
Core risk vocabulary, relationships, zero-days and risk treatment.
# 5. Threat, Vulnerability, Exploit, Risk and Impact | Term | Definition | Example | |---|---|---| | **Asset** | Anything of value to protect | Database, server, employee data | | **Threat** | Potential danger that could harm an asset | Hacker, malware, natural disaster, insider | | **Vulnerability** | A weakness that can be exploited | Unpatched software, weak password, misconfiguration | | **Exploit** | Code, technique or method that takes advantage of a vulnerability | SQL injection payload, buffer overflow script | | **Risk** | Likelihood that a threat exploits a vulnerability, combined with the resulting impact | High risk if a critical server is unpatched and internet-facing | | **Impact** | The consequence or damage if the risk materializes | Data loss, financial loss, downtime, legal penalties | ## Risk relationship A common simplified expression is **Risk = Threat × Vulnerability × Impact**; another common representation is **Likelihood × Impact**. Risk analysis should make clear which model is being used. **Relationship flow:** Threat actor → uses an exploit → against a vulnerability → in an asset → causing impact. ## Risk treatment options - **Mitigate:** apply controls. - **Accept:** tolerate the risk. - **Transfer:** use insurance or outsourcing. - **Avoid:** stop the risky activity. **Zero-day:** a vulnerability unknown to the vendor, with no patch available.
04Part 4 — Attack Surface & Attack Vectors
Digital, physical and human attack surfaces and common attack paths.
STUDY NOTES
Part 4 — Attack Surface & Attack Vectors
Digital, physical and human attack surfaces and common attack paths.
# 6. Attack Surface and Attack Vectors ## Attack Surface The **total sum of all points** where an attacker could try to enter or extract data. ### Types - **Digital:** open ports, APIs, web apps, cloud services, software and code. - **Physical:** USB ports, unlocked server rooms and stolen laptops. - **Human/social:** employees susceptible to phishing or manipulation. ### Reducing attack surface Disable unused services, close unnecessary ports, remove unneeded software, apply least privilege, segment networks and patch regularly. ## Attack Vector The **path or method** an attacker uses to reach the target. ### Common vectors - Phishing emails and malicious links or attachments - Compromised or weak credentials - Unpatched vulnerabilities - Malware such as drive-by downloads or infected USB devices - Misconfigured cloud storage - Insider threats - Man-in-the-middle attacks on public Wi-Fi - Supply chain compromise involving third-party software - Social engineering such as vishing and pretexting **Key difference:** attack surface = *where* you can be attacked; attack vector = *how* you are attacked.
05Part 5 — Threat Actors & Motivations
Threat actor categories, motivations and APT concepts.
STUDY NOTES
Part 5 — Threat Actors & Motivations
Threat actor categories, motivations and APT concepts.
# 7. Threat Actors and Their Motivations | Threat Actor | Description | Motivation | |---|---|---| | **Script kiddies** | Unskilled; use pre-made tools | Fun, curiosity, reputation | | **Hacktivists** | Ideologically driven groups | Political or social causes, protest | | **Cybercriminals** | Individuals or organized crime groups | Financial gain, ransomware, fraud, data theft | | **Nation-state / APT actors** | Government-backed, highly skilled, well-funded | Espionage, sabotage, geopolitical advantage | | **Insiders** | Employees or contractors, malicious or negligent | Revenge, money or accidental error | | **Competitors** | Rival businesses | Industrial espionage, trade secrets | | **Terrorist groups** | Extremist organizations | Fear, disruption, ideological goals | | **Organized crime** | Structured criminal syndicates | Large-scale profit | Common motivations include money, espionage, ideology, revenge, ego and recognition, coercion, curiosity and political or military advantage. **APT (Advanced Persistent Threat):** a prolonged, stealthy, targeted attack where an attacker maintains long-term access to a network.
06Part 6 — Hacker Types & Security Exercise Teams
White/black/grey hat terminology and red/blue/purple/white team roles.
STUDY NOTES
Part 6 — Hacker Types & Security Exercise Teams
White/black/grey hat terminology and red/blue/purple/white team roles.
# 8. Types of Hackers and Their Roles | Type | Description | Legal Status | |---|---|---| | **White Hat** | Ethical hackers; authorized to find vulnerabilities and report or fix them | Legal when properly authorized | | **Black Hat** | Malicious hackers who break in for personal gain or damage | Illegal | | **Grey Hat** | Hack without permission but usually without malicious intent; may disclose flaws afterward | Legally ambiguous or illegal | | **Blue Hat** | Outsiders invited to test software before launch, or a term sometimes used for revenge-driven hackers | Varies | | **Red Hat** | “Vigilantes” who aggressively target black hats | Often illegal | | **Green Hat** | Beginners eager to learn hacking | Depends on actions | | **Script Kiddie** | Uses others’ tools without understanding them | Illegal if used maliciously | | **Hacktivist** | Hacks for political or social causes | Illegal when unauthorized | | **State-sponsored** | Government employees or contractors conducting cyber operations | Varies by jurisdiction | ## Team roles in security exercises - **Red Team:** simulates attackers (offensive). - **Blue Team:** defends and detects (defensive). - **Purple Team:** red and blue collaborating to improve defenses. - **White Team:** referees and manages the exercise.
07Part 7 — Cybercrime
Cybercrime categories, examples, related concepts and legal examples.
STUDY NOTES
Part 7 — Cybercrime
Cybercrime categories, examples, related concepts and legal examples.
# 9. Cybercrime and Cyber Warfare Concepts ## Cybercrime Cybercrime is criminal activity that targets or uses computers, networks or digital devices. ### Categories and examples - **Financial:** online banking fraud, credit card theft, ransomware and business email compromise (BEC). - **Identity-related:** identity theft, phishing and account takeover. - **Data-related:** data breaches and corporate espionage. - **Content-related:** cyberbullying, cyberstalking and illegal content distribution. - **Attacks on systems:** hacking, DDoS and malware distribution. - **Intellectual property:** software piracy and copyright infringement. - **Cyber extortion:** ransomware and sextortion. ### Related concepts Dark web marketplaces, Ransomware-as-a-Service (RaaS) and cryptocurrency used for payments can be associated with cybercrime ecosystems. ### Laws and frameworks (examples) India’s IT Act 2000 and amendments, the CFAA in the USA, GDPR in the EU and the Budapest Convention on Cybercrime are examples of legal instruments relevant to cybercrime and digital activity. Applicability depends on jurisdiction and facts.
08Part 8 — Cyber Warfare & Notable Examples
Cyber warfare, nation-state operations, characteristics and examples.
STUDY NOTES
Part 8 — Cyber Warfare & Notable Examples
Cyber warfare, nation-state operations, characteristics and examples.
# Cyber Warfare Cyber warfare refers to use of cyberattacks by or on behalf of a nation-state to disrupt, damage or gain advantage over another state. ## Characteristics - Targets critical infrastructure such as power grids, water, banking and military systems. - Includes espionage, sabotage, propaganda and disinformation. - Attribution can be difficult because attackers may hide behind proxies or compromised infrastructure. ## Notable examples - **Stuxnet (2010):** malware that damaged Iranian nuclear centrifuges. - **Ukraine power grid attacks (2015–16).** - **NotPetya (2017):** destructive malware disguised as ransomware. - **SolarWinds (2020):** a supply-chain espionage campaign. Related terms include cyber espionage, cyber terrorism, information warfare and hybrid warfare. | Cybercrime | Cyber Warfare | |---|---| | Motive: profit or personal | Motive: political or military | | Actors: criminals | Actors: nation-states | | Targets: individuals and businesses | Targets: governments and critical infrastructure |
09Part 9 — Least Privilege, Defense in Depth & Zero Trust
Core security principles, control types and Zero Trust architecture.
STUDY NOTES
Part 9 — Least Privilege, Defense in Depth & Zero Trust
Core security principles, control types and Zero Trust architecture.
# 10. Security Principles ## Least Privilege Users, programs and systems get **only the minimum access** needed to do their job, and nothing more. **Benefits:** limits damage from compromised accounts, reduces insider risk and contains malware spread. **Implementation:** role-based access control (RBAC), just-in-time access, regular access reviews and separate admin/user accounts. Related concepts include need-to-know and separation of duties. ## Defense in Depth Defense in depth uses **multiple layers of security controls**, so if one fails, others still protect the asset—the “castle” model. ### Example layers 1. Policies and awareness: training and security policies 2. Physical: locks, CCTV and badges 3. Perimeter: firewalls and IPS/IDS 4. Network: segmentation, VLANs and VPNs 5. Host/Endpoint: antivirus/EDR, patching and hardening 6. Application: secure coding and WAF 7. Data: encryption, backups and DLP 8. Identity: MFA and strong authentication ### Control types Preventive, detective, corrective, deterrent, compensating and recovery. ### Control categories Administrative, technical and physical. ## Zero Trust A security model based on **“Never trust, always verify.”** No user or device is trusted by default, even inside the network perimeter. ### Core tenets - Verify explicitly. - Use least-privilege access. - Assume breach. - Continuously validate identity, device health and context. - Micro-segment networks. - Use strong identity management and MFA. - Continuously monitor and log. | Traditional perimeter model | Zero Trust | |---|---| | Trust inside, distrust outside | Trust no one by default | | Single perimeter defense | Verification at every access request | | Flat internal network | Micro-segmented network | Other important principles include separation of duties, fail-safe defaults (deny by default), economy of mechanism, open design, complete mediation, security by design and psychological acceptability (usable security).
010Part 10 — Cybersecurity Domains, Careers & Certifications
Major cybersecurity domains, career roles and common certifications.
STUDY NOTES
Part 10 — Cybersecurity Domains, Careers & Certifications
Major cybersecurity domains, career roles and common certifications.
# 11. Cybersecurity Domains and Career Roles ## Major Domains 1. **Network Security:** firewalls, IDS/IPS, VPNs, segmentation 2. **Application Security (AppSec):** secure development, code review, OWASP Top 10 3. **Cloud Security:** securing AWS, Azure and GCP environments 4. **Endpoint Security:** protecting laptops, servers and mobile devices 5. **Identity and Access Management (IAM):** authentication, authorization, SSO and MFA 6. **Data Security and Privacy:** encryption, DLP and compliance 7. **Security Operations (SOC):** monitoring, detection and SIEM 8. **Incident Response and Digital Forensics (DFIR):** investigating and containing breaches 9. **Threat Intelligence:** researching adversaries and tactics 10. **Offensive Security:** penetration testing, red teaming and vulnerability assessment 11. **Governance, Risk and Compliance (GRC):** policies, audits and standards such as ISO 27001 and NIST 12. **Malware Analysis and Reverse Engineering** 13. **IoT / OT / ICS Security:** industrial and embedded systems 14. **Cryptography** 15. **Physical and Human Security:** social engineering defense and awareness training ## Career Roles | Role | Responsibility | |---|---| | **SOC Analyst (L1/L2/L3)** | Monitors alerts, triages and investigates incidents | | **Security Analyst** | Analyzes threats and manages security tools | | **Penetration Tester / Ethical Hacker** | Simulates attacks to find weaknesses | | **Red Team Operator** | Advanced adversary simulation | | **Security Engineer / Architect** | Designs and implements secure systems | | **Incident Responder** | Handles and contains active security incidents | | **Digital Forensics Analyst** | Collects and analyzes digital evidence | | **Threat Hunter / Intel Analyst** | Proactively searches for hidden threats | | **Malware Analyst** | Dissects malicious software | | **GRC Analyst / Auditor** | Ensures compliance and manages risk | | **Cloud Security Engineer** | Secures cloud infrastructure | | **AppSec Engineer** | Reviews and secures application code | | **Security Consultant** | Advises organizations on security posture | | **CISO** | Leads the organization’s security strategy | ## Popular Certifications **Entry:** CompTIA Security+, CEH, Google Cybersecurity Certificate. **Intermediate/Advanced:** CISSP, CISM, OSCP, CompTIA CySA+, GIAC (GSEC, GCIH), CCSP, CISA. # Part 11 — Final MCQ Exam The final exam contains 50 questions. Passing requires **75%**. The maximum number of attempts is **5** before passing. Once passed, the exam cannot be retaken and the learner can claim a verified **Introduction to Cybersecurity** badge with a unique verification code.
Study progress is saved to your account. The final exam is Part 11.