Theory
From threats to defence
The previous unit catalogued the threats: hacking, malware, fraud, denial of service. This unit is about the defence: cyber security, the practice of protecting systems, networks, and data from all those attacks.
An online store faces every threat you studied, so it needs cyber security to survive and keep customers' trust. This opening lesson defines cyber security, the kinds of threats it defends against, and the concrete advantages it brings. It reframes everything from the previous unit as a problem to be solved, and this unit provides the tools and concepts to solve it.
Theory
What cyber security protects
Cyber security is protecting computers, networks, programs, and data from unauthorised access, attack, damage, or theft. Its goal is often summarised as the CIA triad:
- Confidentiality: data is seen only by those authorised (your card number stays private).
- Integrity: data is not improperly altered (your order and balance are accurate).
- Availability: systems and data are accessible when needed (the store stays online).
A good security posture preserves all three. An attack typically breaks one of them, stealing data (confidentiality), tampering with it (integrity), or knocking a service offline (availability), so defending all three is the core aim.
At a glance
| Threats to defend against | Advantages of cyber security |
|---|---|
| Malware (viruses, worms, trojans, ransomware) | Protects sensitive data and privacy |
| Phishing and social engineering | Builds and keeps customer trust |
| Denial of service (DoS/DDoS) | Ensures business continuity and uptime |
| Man-in-the-middle and password attacks | Prevents financial loss and reputational damage |
Theory
Threats and advantages
The threats cyber security defends against span everything from the last unit: malware (including ransomware, which locks data for ransom), phishing and social engineering, denial-of-service attacks, man-in-the-middle interception, insider threats, and password attacks.
The advantages of taking security seriously are concrete: it protects sensitive data and privacy, ensures business continuity (systems stay up), builds customer trust (people transact only where they feel safe), prevents financial loss and reputational damage, and helps meet legal/compliance obligations. For an online business, security is not a cost centre but a requirement for survival, one serious breach can destroy customer trust and the business with it.
Quiz
The 'CIA triad' that cyber security aims to preserve stands for which three properties?
- Central Intelligence Agency's three offices
- Confidentiality, Integrity, and Availability of data and systems
- Cost, Income, and Assets
- Computers, Internet, and Applications
Show the answer
Confidentiality, Integrity, and Availability of data and systems
In cyber security, the CIA triad stands for Confidentiality (data seen only by authorised parties), Integrity (data not improperly altered), and Availability (systems and data accessible when needed), the three core goals security aims to preserve. Option A is a play on the acronym but unrelated to the security concept. Options C and D are invented expansions with no basis. Most attacks break one leg of the triad, stealing data (confidentiality), tampering with it (integrity), or taking a service offline (availability), so defending all three is the heart of cyber security.
Think first
Why is cyber security a survival requirement for an online business, not just a nice-to-have?
Security costs time and money. Why is it essential rather than optional for e-commerce? Then tap.
Show the answer
Because a single serious breach can inflict damage so severe, financial, legal, and reputational, that it can destroy an online business outright, and e-commerce is exposed to constant attack precisely because it handles money and data over the open internet. Consider what is at stake. An online store holds customers' PAYMENT and PERSONAL data, which attackers actively hunt; if that data is stolen in a breach, the direct costs are huge (fraud losses, fines for failing to protect data, legal liability, the expense of investigating and fixing the breach), and the INDIRECT cost is often fatal: customers lose TRUST. People will not shop where they fear their card details will be stolen, so news of a breach can drive customers away permanently, and reputation, once lost, is extremely hard to rebuild. AVAILABILITY matters too: if attackers knock the store offline with a DDoS or ransomware locks its systems, sales stop entirely, and downtime for an online business is lost revenue by the minute. Meanwhile the store is a target 24/7, reachable by attackers anywhere in the world, so threats are not hypothetical but continuous. Against all this, the cost of security, authentication, encryption, monitoring, secure coding, is modest and, crucially, PREVENTIVE: it is far cheaper to defend than to recover from a breach. That is why security cannot be treated as an optional extra bolted on later; it must be built in, because the downside of neglecting it is not inconvenience but potentially the end of the business. For e-commerce, where trust and uptime ARE the business, security is foundational to survival. The stakes, real money, real data, real trust, under constant attack, make cyber security essential, not optional.
Summary
Key takeaways
- Cyber security is protecting computers, networks, programs, and data from unauthorised access, attack, damage, or theft.
- Its goals are the CIA triad: Confidentiality (only authorised access), Integrity (no improper alteration), Availability (accessible when needed).
- Threats it defends against include malware (including ransomware), phishing, denial of service, man-in-the-middle, insider, and password attacks.
- Most attacks break one leg of the triad: stealing data, tampering with it, or taking a service offline.
- Advantages: protecting data and privacy, ensuring business continuity, building trust, preventing financial and reputational loss, and compliance.
- For an online business, security is a survival requirement, since one breach can destroy customer trust.
- Memory hook: cyber security defends the CIA triad against a range of threats; it is essential for e-commerce, not optional.