Cybersecurity covers the protection of networks, devices, and data from unauthorized access, guided by the principles of confidentiality, integrity, and availability. While definitions vary across sources, the field centers on securing technology and the information that depends on it.
Defining Cyber Security
There's a few different perspectives on what cybersecurity actually means, so let's fully define what cybersecurity is, the different perspectives there are on what cybersecurity is, and what cybersecurity will mean for this course.
We're actually first going to define what security means. Security means free from danger or threat. So whatever organization you're working for, if you're part of the cybersecurity program, your goal is to make sure that the company or the organization is free from danger or threat.
Now let's talk about cyber and what the definition of cyber is. Essentially, cyber is something that's either related to computers or related to computer networks, so it's this digital world that we're talking about here.
So now we bring those two words together: cybersecurity, which means cyber, computers and computer networks, and security, free from danger or threat. So it's really free from danger or threat to our technology and things that are related to our technology.
If we look at the official definition from CISA, it says cybersecurity is the art of protecting networks, devices and data from unauthorized access or criminal use, and the practice of ensuring confidentiality, integrity and availability of information.
Depending on who you ask or what resource you're looking at, cybersecurity can actually have some different perspectives. So what is the scope of cybersecurity? Technically, if we were to look at this, cyber means computer or computer networks or some sort of technology, so it's security around the technology.
But we also have this term information security. There's information that falls outside the cyber world. What happens when we print off a document? It is now in paper form. We throw it into the trash, it has sensitive information on it, and that information gets exposed. So that document falls outside of cybersecurity, but it's still something that we need to be concerned about.
There are also terms such as data security and network security, and depending on how you define this, they're all going to look a little different out there. This model that I'm showing you right here looks different on different sites. I would even argue that there are things that fall outside of information security and cybersecurity and data security. One of the things you want to do is protect everything by making sure you're hiring the right people and doing background checks. That was one of the jobs that I had to do, to turn in reports about whether we are performing the proper background checks before we're hiring people. So there's things that fall outside this bound of cybersecurity and what cybersecurity is.
So how are we going to define it for our course? Mainly we're going to be talking about cybersecurity from a technology perspective, so that is the main purpose of this course. But there are other aspects that we're going to be talking about that do occasionally fall outside of that realm of cybersecurity and within information security, or maybe even broader than that.
So then we ask the question: who is responsible for cybersecurity, or the security of the company? The simple answer to this is that everyone in the company is responsible for playing their role, their part, in cybersecurity and making sure that things are secure. That is a true statement, but the problem with that statement is it doesn't have any kind of accountability from a global perspective. So we do need somebody to take the lead on cybersecurity, to establish the goals and establish what cybersecurity is going to look like for that company.
In many big businesses that is a department. There is a security department that's in charge of overseeing all of that, and that's a great way to set it up, so that way there's checks and balances with everything and there's no conflict of interest. But many small businesses don't have the resources to throw a department at security, let alone a single person at security. So often what happens is it defaults to the IT people within the company to tackle cybersecurity, which makes sense: there's a cyber component to it. There is some conflict of interest to it, but often the IT department is responsible for cybersecurity.
So if cybersecurity falls to the IT department in smaller companies, which makes a lot of sense because it's technology, there is a bit of conflict of interest in it. But if it falls to IT to do that, then they are setting policies and they are organizing all of the security around the technology. And because there's this need that goes beyond just cybersecurity, that often also gets put on the IT department, to make sure security is set for the whole company outside of even the cybersecurity realm. Which is one of the reasons why we're defining cybersecurity for this course as being a little bit more expanded, so we think about other areas as well.
The definition and scope of what cybersecurity is can vary a little bit depending on who you're talking to or what resource you're looking at, but essentially cybersecurity has to deal with security around the technology. And since it's around technology, in smaller companies it usually falls to the IT department to create policies and procedures around cybersecurity. And because there are missing gaps in that, and there are other security concerns that need to be addressed and there's no security department to address them, a lot of times that gets put under the scope of cybersecurity and for the IT department to manage. So you'd often find, a lot of times nowadays, that IT departments are managing things, managing policies and procedures that wouldn't typically or traditionally have been something you would have seen the IT department manage. So things have changed a little bit.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →