Cyber Security Basics 📂 Slides · 5 of 11 48 min read

Internet Architecture, Digital Transformation & Cybersecurity Standards

A 17-slide interactive walkthrough of how the internet is built, how organisations modernise on top of it, and the policies and standards that secure it. Covers the six-decade internet timeline, TCP/IP layered architecture, anatomy of a web request, six pillars of digital transformation, all major frameworks (ISO 27001, NIST CSF, PCI DSS, HIPAA, GDPR, DPDP, CIS, SOC 2, MITRE ATT&CK, OWASP), organisational policies and the People-Process-Technology golden triangle.

🏛️

Internet Architecture, Digital Transformation & Cybersecurity Standards

How the internet is built, how organisations modernise on top of it, and the policies and standards — ISO 27001, NIST CSF, GDPR, DPDP — that keep it all secure.
TCP/IP Layers Digital Transformation Policies Standards

Press Next → or use ← → arrow keys

Section 01

The Big Picture — Four Connected Pieces

A modern city has all four elements
A city's growth mirrors internet development. Its streets and utilities are the architecture. Businesses moving online is the digital transformation. And the traffic laws and building codes are the security policies.

You cannot understand one without the other three.
🕰️
Development
the origin
How the internet was built — ARPANET, TCP/IP, the web, mobile, cloud.
🏗️
Architecture
the mechanics
How data actually moves — layered protocols, packets, routing, DNS.
🚀
Transformation
the business
How organisations reinvent themselves — cloud, AI, mobile, IoT.
Section 02

Internet Development Timeline

🖥️ 1969 ARPANET 4 computers 🔗 1983 TCP/IP adopted common language 🌐 1991 World Wide Web HTTP + HTML 📱 2007 Smartphone Era always on ☁️ 2016 Cloud + IoT data centralised 🤖 2024+ AI + 5G/6G reshapes industry
🌐
From Lab Curiosity to Critical Infrastructure

In 55 years, the internet grew from 4 university computers to a global system with 30 billion devices — each era adding new capability and new attack surface.

Section 03

Internet Architecture — The TCP/IP Stack

1 · Application HTTP · DNS · SMTP · FTP what you see 2 · Transport TCP (reliable) · UDP (fast) segments & delivery 3 · Internet IP · ICMP · ARP addressing & routing 4 · Link / Physical Ethernet · Wi-Fi · 5G wires & waves SEND RECV Data flows DOWN the stack when sending, UP the stack when receiving
🧩
Each Layer Has One Job

Layers are independent — a Wi-Fi upgrade doesn't require rewriting your browser. When something breaks, identifying which layer owns the problem is 80% of the fix.

Section 03 · Support

The Supporting Infrastructure

📖
DNS
the phonebook
Translates human names (wikipedia.org) into numeric IPs (208.80.154.224). Every web request starts here.
🌉
ISPs
your on-ramp
Internet Service Providers connect you to the wider internet — Airtel, Jio, Comcast, Verizon.
🔀
IXPs
the junction
Internet Exchange Points let different ISPs swap traffic directly — faster & cheaper than going the long way round.
🏛️ Client–Server Model
Central server stores & delivers
Clients request, server responds
Examples: websites, Netflix, Gmail
✅ Simple to secure, single authority
❌ Single point of failure
🕸️ Peer-to-Peer (P2P)
No central authority — every device is equal
Direct device-to-device sharing
Examples: BitTorrent, blockchain, some VoIP
✅ Resilient, distributed
❌ Hard to regulate or shut down
Section 04

Anatomy of a Web Request

🌐 Browser "open example.com" 📖 DNS Lookup name → 93.184.216.34 🔐 TCP + TLS port 443 handshake 🛰️ Routers packets hop globally 🖥️ Web Server builds response GET 200 OK
All of this happens in under a second

Every page you open runs this 5-step journey — DNS lookup, TCP+TLS handshake, packets routed across continents, server response, browser render. Packet-switching is what makes it scale to billions of users.

Section 05

Six Pillars of Digital Transformation

"The shift from doing old things faster with technology, to doing entirely new things that were impossible before."

☁️
Cloud Computing
AWS · Azure · GCP
Rent servers on demand. Scale in minutes, not months. Pay only for what you use.
📊
Data & Analytics
insight from data
Turn raw operational data into decisions. Dashboards, ML models, business intelligence.
🧠
AI & Automation
ML · RPA · GenAI
Chatbots for support, robotic process automation for repeat tasks, generative AI for everything else.
📱
Mobile & UX
app-first design
Self-service on mobile, expected 24/7. If it's not on a phone, it may as well not exist.
🔌
IoT & Edge
sensors everywhere
Smart devices generate real-time data. Edge computing processes it near the source.
🛡️
Cybersecurity
secure by design
Bigger digital footprint = bigger attack surface. Security must be built in from day one.
Section 05 · Impact

Before vs After Digital Transformation

❌ Before DT
Paper records & manual data entry
Phone-based support with queues
Decisions on intuition
Multi-week product launches
Perimeter-only security
✅ After DT
Cloud databases & automated workflows
Self-service apps + 24/7 chatbots
Real-time data-driven analysis
Deployment in days
Integrated, layered security architecture
⚠️
The Golden Rule of Transformation

Digital expansion without matching security expansion just means bigger risk. Every new cloud service, mobile app or IoT sensor is a new door — and every door needs a lock.

Section 06

Policies — Three Levels of Documentation

📜 THE POLICY HIERARCHY
POLICY
What & Why — high-level rules approved by leadership.
e.g. "All employee laptops must be encrypted."
STANDARD
How Exactly — specific technical implementations.
e.g. "Use AES-256 full-disk encryption with TPM required."
PROCEDURE
Step by Step — the operational how-to.
e.g. "Enable BitLocker; store recovery key in the corporate vault."
🎯
Why Policies Matter

Clarity — no ambiguity about what's allowed. Accountability — everyone knows their role. Compliance — GDPR, DPDP, HIPAA all mandate documentation. Trust — shows customers and regulators you take security seriously.

Section 07

Major Cybersecurity Standards & Frameworks

StandardOwnerFocusWho Uses It
ISO/IEC 27001ISOISMS certificationGlobal enterprises
NIST CSFUS NISTIdentify → Protect → Detect → Respond → RecoverUS federal + worldwide
PCI DSSPCI SSCCredit card data protectionAnyone taking card payments
HIPAAUS HHSProtected health info (PHI)US healthcare
GDPREUEU citizen data · fines up to 4% revenueAnyone touching EU data
DPDP Act 2023IndiaIndian citizen personal dataAnyone touching Indian data
CIS Controls v8CIS18 prioritised practical controlsSMBs to enterprises
SOC 2AICPAService-provider trust reportingSaaS & cloud vendors
MITRE ATT&CKMITREAttacker tactics & techniques KBSOC / threat hunters
OWASP Top 10OWASPWeb application security risksWeb developers
🧭
Pick a Backbone

You don't adopt every standard. Pick one backbone — usually ISO 27001 or NIST CSF — then layer sector-specific rules on top (PCI DSS for payments, HIPAA for healthcare, DPDP for Indian citizen data).

Section 07 · NIST CSF

NIST CSF — The 5-Function Lifecycle

🔍 IDENTIFY assets · risks 🛡️ PROTECT controls training 📡 DETECT monitor alert 🚨 RESPOND contain remediate 🔄 RECOVER restore learn NIST CSF
🔁
Security Is a Cycle, Not a Project

Mature programs iterate through all five functions continuously. You never "finish" identifying, protecting, detecting, responding and recovering — the loop restarts the moment it ends.

Section 08

Governance — Policies Every Org Needs

📋
Acceptable Use
AUP
What employees may and may not do with company devices, email and internet.
🔑
Access Control
least privilege
Who gets access to what, how it's granted, reviewed and revoked.
🏷️
Data Classification
Public → Restricted
Categorises data, sets retention periods, mandates deletion timelines.
🚨
Incident Response
IR playbook
Standardised detect → report → contain → recover — no improvising under pressure.
💾
Backup & BCP
3-2-1 rule
Ensures recoverability. Business continuity when ransomware or disaster hits.
🔗
Vendor / Third-Party
supply chain
How you vet cloud providers, SaaS vendors and contractors before granting them access.
Section 08 · Formula

The Golden Formula — People + Process + Technology

👥 People training, awareness, culture 📋 Process ⚙️ Technology = REAL SECURITY remove any vertex → the whole triangle collapses
🎯
Defence in Depth

Layer your controls: Prevent → Detect → Respond → Recover. When one layer fails (and one always does), the next one still catches the attacker. Missing any of People, Process or Technology defeats every layer at once.

Section 09

Why Policies & Standards Fail

📚
Unread Policies
80-page PDFs nobody opens. Effective policies are short, plain-English, and reinforced by training.
Standards Lag Tech
Cloud, AI, quantum evolve monthly. Formal standards take years. Apply principles, not just checklists.
🌍
Cross-Border Conflicts
One app may need to satisfy DPDP + GDPR + US rules — sometimes contradictory.
Compliance ≠ Security
Passing an audit shows you followed rules on a specific date. Real security is 24/7 — a much higher bar.
👤
Humans Beat Tech
A single careless click can defeat millions in security spend. Culture matters as much as controls.
🏛️
Legacy Systems
Old software that can't be patched blocks modern policy enforcement. Migrating is painful but essential.
Section 10 · Part 1

Golden Rules — 1 to 4

🏆 KEY TAKEAWAYS · 1–4
1
Know the TCP/IP layers. Every network problem lives in one specific layer. Identify the layer, cut the debugging time in half.
2
Nobody owns the internet. Distributed ownership creates both resilience (no single kill switch) and complexity (no single defender).
3
Digital transformation is business strategy, not IT. Leadership, culture and process must transform alongside the technology — or the tech alone won't help.
4
Bake security in from day one. Retrofitting security is 10× more expensive than building it in. Secure-by-design isn't optional anymore.
Section 10 · Part 2

Golden Rules — 5 to 8

🏆 KEY TAKEAWAYS · 5–8
5
Pick one backbone framework. ISO 27001 or NIST CSF. Then layer PCI DSS / HIPAA / DPDP on top as your context demands. Multiple backbones = confusion.
6
Aim past compliance. Compliance is the floor, not the ceiling. Auditors check paperwork; attackers don't.
7
Keep policies readable. Annual review, plain language, one page where possible. Policies nobody reads deliver zero security.
8
Advance People, Process and Technology together. Miss any one and the golden triangle collapses. The best firewall in the world can't fix a bad culture.
FINAL

You Now Speak the Language of the Field

4TCP/IP layers
6Digital transformation pillars
5NIST CSF functions
10+Global standards mapped
3Policy · Standard · Procedure
PPTPeople + Process + Technology
🎯
The Foundation Is Complete

You understand how the internet is built, how organisations modernise on it, and the policies and standards — ISO 27001, NIST CSF, GDPR, DPDP — that keep it secure. Everything else in cybersecurity fits on top of this foundation.

📚
Where To Go Next

Deep-dive into your chosen backbone (ISO 27001 or NIST CSF). Study OWASP Top 10 and MITRE ATT&CK. Try practical labs on TryHackMe. Formalise with ISC2 CC, CompTIA Security+, or eventually CISSP.

🏛️ End of tutorial · Press to review, or click Restart