Cyber Security Basics 📂 Slides · 1 of 11 34 min read

Introduction to Cybersecurity — CIA Triad & Threats Guide

A 15-slide interactive walkthrough of cybersecurity fundamentals — the CIA triad (Confidentiality, Integrity, Availability), the ten threat types every practitioner should recognise, an essential 17-term glossary, and the eight modern challenges reshaping the field (IoT, cloud, AI attacks, remote work, skills shortage, RaaS, regulation, supply chain). Features three custom animated SVG diagrams and the WannaCry case study.

🛡️

Introduction to Cybersecurity

The CIA Triad, common threats, essential terminology and the modern challenges every practitioner must know — the foundation on which everything else is built.
CIA Triad Threat Types Glossary Modern Challenges

Press Next → or use ← → arrow keys

Section 01

What is Cybersecurity?

Locks, curtains and cameras — for your digital life
Your home has locks on the doors, curtains on the windows and a camera at the entrance. Your phones, laptops and servers hold something just as valuable — bank details, photos, work files, medical records — and they need the same layered protection.

Cybersecurity is the discipline of protecting computers, servers, mobile devices, networks and data through a combination of technology, processes and people.
11sA cyberattack every…
82%Breaches involve humans
$4B+WannaCry alone
3.5MGlobal skills shortage
Section 02

The Three Pillars — People, Process, Technology

Cybersecurity is not just a set of tools. It stands on three interconnected pillars — and the weakest one decides the strength of the whole.

👥
People
the weakest link
Trained staff who spot phishing, use strong passwords and follow procedure. 82% of breaches trace back to human error. Awareness is your cheapest defence.
📋
Process
the playbook
Documented procedures for backups, access reviews, patch cycles and incident response. Without process, technology and people improvise — badly.
⚙️
Technology
the toolset
Firewalls, antivirus, encryption, MFA, intrusion detection. Necessary but never sufficient — technology without process and people is a locked door with the key under the mat.
🌐
Cyberspace vs Information Security vs Cybersecurity

Cyberspace is the borderless virtual world of computers, cables and satellites. Information Security protects all information — even locked filing cabinets. Cybersecurity is the digital branch of Info Security — protecting devices, networks and cloud within cyberspace.

Section 03

The CIA Triad — Cybersecurity's Foundation

C Confidentiality Only the right eyes see it I Integrity A Availability SECURITY GOALS break one → the whole triad collapses
🎯
Three Non-Negotiable Security Goals

Confidentiality — only authorised people see the data. Integrity — the data hasn't been silently changed. Availability — the system is up when it's needed. Break any one, and security has failed.

Section 03 · Details

CIA in Practice — Examples & Failures

🔒
Confidentiality
only the right eyes
How: encryption, passwords, access controls, VPNs.
Example: your bank balance only you can see.
Break it → data leaks, identity theft.
Integrity
nothing silently changed
How: checksums, digital signatures, version control.
Example: salary in payroll matches your contract.
Break it → falsified records, wrong balances.
Availability
reachable when needed
How: backups, redundant servers, DDoS protection.
Example: hospital systems working during emergencies.
Break it → outages, business stops.
Extended Model — AAA

Modern frameworks add Authentication (who are you?), Authorization (what may you do?), and Non-repudiation (you can't later deny you did it).

Section 04

How an Attack Reaches You

😈 Attacker crafts the exploit 🌐 Internet public transit 🛡️ Firewall filters & blocks 💻 Target your device 💥
🚨
The Attack Path

A threat starts with the attacker, rides across the internet, hits your firewall (which filters known-bad traffic), and — if it slips through — reaches your device. Every hop is an opportunity to detect and block.

Section 04 · Types

The Ten Threats You Must Know

🦠
Malware
viruses, worms, trojans
Malicious software hidden in downloads or attachments.
🔐
Ransomware
WannaCry, LockBit, Ryuk
Encrypts files, demands crypto for decryption keys.
🎣
Phishing
email / SMS / web
Fake messages tricking you into handing over credentials.
🌊
DoS / DDoS
traffic flood
Thousands of devices overwhelm a site until it collapses.
🕵️
Man-in-the-Middle
public Wi-Fi risk
Silently intercepts and can modify traffic between you and a site.
🎭
Social Engineering
hack the human
Impersonation and manipulation — no code required.
💉
SQL Injection
database attack
Malicious query in a login field to steal or delete records.
Zero-Day Exploit
no patch yet
Uses an unknown vulnerability before the vendor can fix it.
🕶️
Insider Threat
from within
Employees or contractors misusing legitimate access.
Section 05

The Terminology You'll Hear Every Day

TermWhat it meansExample
AssetSomething valuable that needs protectingCustomer DB, laptop, source code
ThreatA potential dangerA hacker planning to steal files
VulnerabilityA weakness that could be exploitedAn unpatched Windows machine
ExploitThe actual code that abuses a vulnerabilityA script that hits the unpatched machine
RiskProbability that harm occurs90% chance of infection without a patch
Attack VectorThe route the attacker usesPhishing email, infected USB
PayloadThe malicious content insideRansomware embedded in a PDF
MFA / 2FASecond factor beyond passwordPassword + SMS OTP
Incident vs BreachSuspected event vs confirmed loss100 failed logins → 10M records leaked
🧮
The Two Formulas to Remember

Risk = Threat × Vulnerability × Impact — reduce any factor, reduce the risk.
Defence in Depth = Layer 1 + Layer 2 + Layer 3 — no single control catches everything.

Section 05 · Defence

Defence in Depth — The Layered Model

🏢 PHYSICAL LAYER 🌐 NETWORK LAYER 🔒 APPLICATION LAYER DATA 💎
🛡️
Every Layer Adds Time

The attacker has to defeat every ring to reach the data. Physical (locked server rooms) → Network (firewalls, IDS) → Application (auth, input validation). Each layer buys defenders time to detect and respond.

Section 06 · Part 1

Modern Challenges — Part 1

📡
IoT Explosion
Smart TVs, doorbells, fridges — shipped with weak default passwords and rarely patched. Each is a doorway into your network.
☁️
Cloud Misconfiguration
A single wrong AWS / Azure / GCP setting can expose millions of records publicly — in seconds, with no attacker skill required.
🤖
AI-Powered Attacks
Flawless phishing in any language, voice cloning, and 24/7 automated vulnerability discovery. Grammar is no longer a red flag.
🏡
Remote / Hybrid Work
The office perimeter dissolved. Employees log in from homes, cafes, and personal devices — every one a new attack surface.
Section 06 · Part 2

Modern Challenges — Part 2

🎓
Skills Shortage
A global gap of ~3.5 million qualified cybersecurity professionals. Demand rising faster than the talent pipeline.
💼
Ransomware-as-a-Service
Criminal gangs run help desks, affiliate programs and payment systems. Attacker skill barrier: near zero.
⚖️
Regulatory Pressure
GDPR (EU), DPDP Act (India), HIPAA (US) — massive fines for security failures. Compliance is now a board-level topic.
🔗
Supply-Chain Attacks
Compromise one vendor, reach thousands. The 2020 SolarWinds breach hit 18,000 organisations via one signed update.
⚖️
The Fundamental Asymmetry

Defenders must protect every door, every hour, every day. An attacker needs to find one open door, once.

Section 07

Case Study — The WannaCry Hospital Attack

Ambulances diverted. Surgeries cancelled. One missed patch.
In a single weekend, WannaCry ransomware infected computers across 150+ countries. Britain's NHS was hit hard — ambulances rerouted, operations cancelled, patient records locked behind Bitcoin ransoms.

The killer detail? Microsoft had shipped the protective patch two months earlier. Infected hospitals simply hadn't installed it.

Total damage worldwide: over $4 billion.
💔
All Three CIA Goals Failed Simultaneously

Confidentiality gone — attackers accessed records. Integrity gone — files encrypted, unreadable. Availability gone — systems offline for days. One missed update collapsed the entire triad.

Section 08 · Part 1

The Eight Golden Rules — 1 to 4

🛡️ ESSENTIAL CYBER HYGIENE · RULES 1–4
1
Update everything, always. Enable automatic updates for OS, browsers, apps and router firmware. Most successful attacks — WannaCry included — exploit outdated software.
2
Use unique, strong passwords. A password manager generates and stores a distinct one for every account. Reuse means one breach compromises them all.
3
Enable Multi-Factor Authentication. Even if your password leaks, MFA blocks 99%+ of automated attacks. The single highest-value security switch you can flip today.
4
Think before you click. Hover over links to see the real URL. "Account closing in 24 hours!" is the attack itself, not a problem with your account.
Section 08 · Part 2

The Eight Golden Rules — 5 to 8

🛡️ ESSENTIAL CYBER HYGIENE · RULES 5–8
5
Back up your data — and test restore. Follow the 3-2-1 rule: 3 copies, on 2 media types, with 1 copy offsite. Untested backups are hopes, not plans.
6
Treat public Wi-Fi as hostile. Coffee shops and airports are trivial to sniff. Use a reputable VPN — or your mobile data — for banking and anything sensitive.
7
Grant least necessary access. Limit app permissions, staff privileges and personal-account powers to strict requirements. Ask why a photo app needs your contacts.
8
Learn, practise, repeat. Follow security blogs, complete annual training, share what you learn. Attackers evolve constantly — awareness is your cheapest defence.
FINAL

Cybersecurity Starts With Fundamentals

CIAThe three security goals
10Core threat types to know
17Terms in your vocabulary
8Modern challenges
8Golden rules to live by
99%+Attacks MFA blocks
🎯
The Foundation is Set

Everything else in cybersecurity — penetration testing, incident response, cryptography, cloud security — builds on what you just learned. The CIA triad, the threat vocabulary and the golden rules are the language of the entire field.

📚
Where To Go Next

Study each threat type in depth. Practise on TryHackMe and HackTheBox. Watch the Verizon DBIR annually. Consider certifications like CompTIA Security+ or (ISC)² CC to formalise your knowledge.

🛡️ End of tutorial · Press to review, or click Restart