Core security concepts—assets, threats, threat agents, vulnerabilities, exploits, exposure, and risk—form the foundation of any effective cybersecurity strategy. Understanding how these terms relate to one another is essential for assessing and reducing organizational risk.
Key Security Concepts
An asset is something of value. If the company has things that are of value, those are assets for the company. An example of it would be a building; a building is an asset for the company. Straight out cash is obviously value for the company, if the company has a lot of cash on hand. The data that it stores could be an asset for the company that it can use. If that data is customer data, if it has a list of customers, whether potential customers or their own customers, that is an asset that the company has. The people: if you have really great people working for you, those people are assets to the company. If you have some sort of program or code, that code itself could be an asset for the company. If the company has a really strong reputation that's out there, a great reputation, then that reputation is an asset for the company.
So an asset is anything of value for the company that, if the company were to lose that resource, would be devastating to the company or would hinder the company from growing. Those are assets.
Whatever could happen to that asset is a threat. An example right here is, let's say we have data that we are storing and that data is considered an asset for the company. That asset could be stolen. It could be copied. It could be altered. It could be deleted. So something could happen to that asset that would hurt the company.
When we look at the security triad, deleted means that it's no longer available. When we see that it's altered, that's the integrity of the data. And when we see that it's stolen or copied, that's the confidentiality of that data. So it fits within that security triad.
When it comes to threats, then we have the threat agent. The agent is what is actually causing the threat for this data. So in this example right here, we have a hacker that is trying to steal or alter this data right here. And so the hacker is the threat agent in this example.
We obviously want to protect our data, and so what we're going to do is put things up to protect that data. In this example right here, we're putting a fence up with a gate on it to protect that data so that a hacker cannot get to it. So that's mitigation. Mitigation is to lessen the threat of something happening.
Then we have vulnerability. To be vulnerable means that it's open for attack or harm. Before, our data was sitting out and could be accessed by anyone because we didn't have it protected. That is what it means to be vulnerable. So what we did is we put a wall around it and we put a gate around it to protect the data so that a hacker would not be able to get to the data.
But the problem is that even these technologies that we put around it, a wall or a gate, have different vulnerabilities in themselves. There's ways to get through this. For instance, in this case right here, perhaps through this gate people still need to access this data. So this gate has some sort of lock on it so you can open it up and access that data. Well, that lock is probably a weak point. There's probably some way a hacker might be able to pick that lock and get into the gate. Or the gate is also not quite as strong as the rest of the wall, so perhaps there's something that can break that gate down so it can access the data.
So these are vulnerabilities of these different technologies that we implemented, and things that we will need to do mitigating with. We've already mitigated against it being out in the open, but there's still things that we need to tackle to see if we can solve for, to make sure that we're reducing the amount of threats there are to this data and reducing the vulnerability that it has.
An exploitation is when a hacker is going to exploit a vulnerability. So an example that we gave was there's a lock on this gate, and so maybe this hacker knows how to pick that particular lock that is on the gate. And so what that hacker is doing is exploiting a weakness in this technology to get to the data, and so that is exploitation.
Exposure is when one of your assets is then put out there and exposed to these different threats. An example that I have right here is, let's say this person right here needs to access the data, but after they leave they forget to close the gate. And so now the data is open for anybody to come and grab it. And so now that is an exposure that's happening, that this data then is exposed to the outside world.
What we really want to do on our networks is take an approach of defense in depth. What that means is that we realize whatever we're going to put out there is susceptible to some sort of vulnerability. So we put a gate up there, but the lock can be picked, or maybe it's left open for somebody to walk in and grab that data. And so what we do is, instead of just relying on the gate, maybe we also put a guard out in front of that gate to protect that data. Or perhaps we encrypt the data that's on there, so even if it is stolen, they can't do anything with the data because it's all encrypted and you need the keys to that encryption. Maybe we put a camera so that if it is stolen, we're able to see who stole it and go and grab it and get it back.
So the idea behind this is we put in multiple layers. Any one of these layers could fail, and probably will fail at some point in time, because that's how technology goes. So we put in multiple layers, multiple lines of defense, so that we make sure that there is no exposure of the data.
When we implement all of these mitigation steps to ensure the security of our data, we're reducing the amount of risk. Risk is the chances that something is going to happen, and it also factors in, there's actually an equation for it. Risk equals the probability of something happening, how probable is it, times the impact that it's going to have to the company.
So as we take all of these steps to secure this data, what are the chances now that this hacker is going to be able to break into the system and get this data? And if they were to get that data, how impactful would it be to the business, and how devastating would it be to the business? That is the amount of risk, and the risk is going to determine how many steps we're going to take to actually protect this data.
We have an asset that needs to be protected. So that is the asset. It is prone to some sort of threat. For instance, the data could be stolen, so the threat is the fact that it could be stolen. We have a threat agent, that is the who, whatever is going to be the perpetrator, whoever is going to steal the data. So in this case, we've got the hacker right there.
We take steps to mitigate the risk. So we put things in place to mitigate this risk and lessen the likelihood that this is going to be a problem. Each one of these things that we implement and put into place has some sort of vulnerability to it. For instance, the lock on the gate is a vulnerability because it's a single point that can fail or can be picked, or something that we can use to leverage that weak point to get into here.
If we were to leverage that vulnerability, that means that we're exploiting that vulnerability, so that we can hack this. If for some reason data gets out and this information is stolen, that's an exposure. Or if somebody leaves the gate open, that's an exposure. So we expose the data to the outside world.
We have then this idea of risk, the probability that this is going to happen and what the impact would be to the company. And then defense in depth. Defense in depth is the idea that we're going to put multiple safeguards on here to protect this data, realizing that each one of those safeguards that we put out there is going to help but has its own vulnerabilities that can be leveraged. So we are going to put in multiple walls and multiple steps in here to guard this data.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →