What is Cybersecurity in Simple Words?
Cybersecurity consists of all the technologies and practices that keep computer systems and electronic data safe. And, in a world where more and more of our business and social lives are online, there are many types of cybersecurity roles to consider.
“Cybersecurity aims to protect devices, networks, software and data from external cyberthreats,” said Rodney Royster, a cybersecurity adjunct instructor at Southern New Hampshire University (SNHU) with more than 20 years of information security experience in both the federal and private sectors. “This (protection) is accomplished with the use of practices and tools that can mitigate or reduce the impact of these threats.”
Then What is Information Security?
Information security is broader, according to Royster, and it considers encryption, endpoint security and physical security. “(It) ensures the overall protection of data, including its confidentiality, integrity and availability, across various environments,” Royster said.
Everything is connected by computers and the internet, including communication, entertainment, transportation, shopping, medicine and more. A copious amount of personal information is stored among these various services and apps, which is why both cybersecurity and information security are critical.
Read more: What is Information Security?
Why is Cybersecurity So Important?

Getting hacked isn’t just a direct threat to the confidential data companies need. It can also ruin their relationships with customers and even place them in significant legal jeopardy. With new technology, from self-driving cars to internet-enabled home security systems, the dangers of cybercrime become even more serious.
So, it’s no wonder that international research and advisory firm Gartner predicts worldwide security spending will hit $184 billion in 2024. Gartner also predicts the market will reach $294 billion by 2028.
These days, the need to protect confidential information is a pressing concern at the highest levels of government and industry. State secrets can be stolen from the other side of the world. Companies whose whole business models depend on control of customer data can find their databases compromised. In just one high-profile 2017 case, personal information for 147 million people was compromised in a breach of a credit reporting company, according to the Federal Trade Commission (FTC).
What Are Cyberattacks?
A cyberattack is a malicious effort to access computer systems without authorization with the intent to steal, expose, modify, disable or eradicate information, according to International Business Machines (IBM).
There could be many reasons behind a cyberattack, according to Royster, including political motivations or revenge. “But I believe the main one is financial gain because an attacker could gain a tremendous amount of money during these attacks,” he said.
What Are Some Types of Cyberattacks and Threats?
Cyberattacks can be carried out in a variety of ways. Three of the most common types Royster sees include phishing, ransomware and social engineering.
Phishing
“Phishing is a type of cyberattack where victims are lured or tricked into something malicious,” Royster said.
He said these attacks often involve fraudulent links and can be done through a variety of channels, such as email, text, social media and websites. The goal of the attack may be for a victim to download viruses or malware (short for malicious software) onto their devices.
Read more: Types of Phishing: Tips to Prevent, Spot, Report Scam Emails
Ransomware
Ransomware involves the encryption of an individual or organization’s data through malware, according to Royster, which restricts access to their own files, systems or networks.
“It is called ransomware because the attacker will request a ransom in order for the company to get their data back,” he said. Even riskier, paying the ransom does not necessarily mean you’ll get your data back.
According to security organization Astra, ransomware attacks have increased 13% in the last five years, with an average cost of $1.85 million per incident. In addition, 13% of small and medium businesses reported a ransomware attack in the past year, with 24% of respondents reporting at least one attack ever, according to security software provider Datto (PDF Source).
Social Engineering
Social engineering often involves impersonation. “(It) is an attack to retrieve sensitive information by deceiving users,” Royster said. “This could be by an attacker calling you on the phone, pretending to be someone else, such as an IT person from your mobile company, wanting your password.”
Who is Behind Cyberattacks?
Attacks against enterprises can come from a variety of sources, such as criminal organizations, state actors and private persons, according to IBM. An easy way to classify these attacks is by outsider versus insider threats.
Outsider or external threats include organized criminals, professional hackers and amateur hackers, IBM reported.
Insider threats are typically those who have authorized access to a company’s assets and abuse them deliberately or accidentally, according to IBM, and these threats include employees who are careless of security procedures, disgruntled current or former employees, and business partners or clients with system access.
Developing Cyber Awareness
With so many types of cyberthreats and attackers, it’s important for individuals and organizations to take security measures to protect themselves and their data.
“One concept I like is the ‘defense in depth’ method where you are applying multiple layers of security in order to protect your assets from attackers,” Royster said. Just as you might take multiple precautions to protect your physical valuables, you can use security tools to protect yourself in the cyber world, according to Royster.
Some of these tools include:
- Antivirus software
- Encryption
- Firewalls
- Intrusion detection systems (IDS)
- Intrusion prevention systems (IPS)
You can also take preventative measures by creating strong passwords with a variety of upper and lowercase letters, characters and numbers. “Along with this, you should regularly change your password every 60 to 90 days, use multi-factoring authentication and use an antivirus product,” Royster said.
And if you do find yourself a victim of a cybercrime, report it. Royster said you can report a variety of concerns through the FTC, including:
- Fraud
- Identity theft
- Ransomware
- Unwanted phone calls
There are also many resources relating to cybersecurity awareness readily available on the Cybersecurity and Infrastructure Security Agency (CISA) government website based on your needs.
What Are the Types of Cybersecurity?

Here are some common types of cybersecurity available:
- Cloud Security: Cloud security encompasses the collection of technologies and strategies designed to protect business security from both internal and external sources while balancing productivity and security, according to IBM.
- Infrastructure Security: Critical infrastructure security describes the physical and cyber systems that are so vital to society that their incapacity would have a debilitating impact on our physical, economic or public health and safety, according to CISA.
- Internet of Things (IoT) Security: IoT is the concept of connecting any device to the internet and other connected devices. The IoT is a network of connected things and people, all of which share data about the way they are used and their environments, reports IBM. These devices include appliances, sensors, televisions, routers, printers and countless other home network devices.
- Network Security: Network security is the protection of network infrastructure from unauthorized access, abuse or theft, according to CISCO, and these security systems involve creating a secure infrastructure for devices, applications and users to work together.
What Does a Cybersecurity Professional Do?
Kamyck said cybersecurity professionals could play a wide range of roles in a modern company. For example, some small businesses may hire a single person to handle all kinds of work protecting data. Others contract with consultants who can offer a variety of targeted services. Meanwhile, larger firms may have whole departments dedicated to protecting information and chasing down threats.
While companies define roles related to information security in a variety of ways, Kamyck said there are some specific tasks that these employees are commonly called on to do. In many cases, they must analyze threats and gather information from a company’s servers, cloud services and employee computers and mobile devices.
“An analyst’s job is to find meaning in all of that data, see what’s concerning,” he said. “Is there a breach? Is someone violating a policy?”
Kamyck said security specialists often work with other information technology (IT) professionals to ensure a company’s systems are secure.
But breaches don’t just take the form of someone hacking into a server. They can also involve customer lists sent through unencrypted email, a password written on a sticky note in a cubicle or a company laptop stolen from an employee’s car.
Depending on their specific role, cybersecurity professionals must also think strategically. In many industries, companies rely on employees having quick access to highly sensitive data, such as medical records or bank account information.
“The goal is to balance the needs of the company or the organization you’re working for with the need to protect the confidentiality of customer data and trade secrets,” Kamyck said.
Kamyck said people who do well in these jobs tend to be curious, competitive and willing to keep learning to stay up to date with rapidly changing technology. The work draws on multidisciplinary knowledge, and people who continue with the work find there are a variety of directions they can take in their careers.
For example, Kamyck said if you’re interested in the business side, you might become a manager or run audits that let companies know where they need to improve to meet compliance. If you love the adversarial part of the job, you might become a penetration tester, essentially an “ethical hacker” who tests for system vulnerabilities by trying to get through them.
