Cybersecurity is a modern and essential field of our era, concerned with protecting everything that is digital. It covers various aspects such as information systems, people, companies and even the State. In this introduction, we will explore the different elements of computer security, the technologies involved, and how to protect yourself effectively against threats.

Security of everything digital
A global approach
The information system: Protecting data and the systems used to store and process it is crucial. For example, in 2017, the NotPetya attack paralyzed many companies by encrypting their data and making their systems inaccessible. Information systems must include regular backups, security updates, and robust firewalls.
People : Awareness and training to avoid human error are essential. For example, the phishing incident at Sony Pictures in 2014, where fraudulent emails led to a massive data leak, shows the importance of security training.
Companies : Companies must put security policies and procedures in place. For example, JPMorgan Chase invested more than 500 million dollars a year in cybersecurity after suffering a breach in 2014 that compromised the information of 76 million households and 7 million small businesses.
The State: States must regulate and create an infrastructure to protect national interests. For example, the General Data Protection Regulation (GDPR) in Europe imposes strict obligations on how companies must protect personal data.
The digital domain
Connected material assets
IoT (Internet of Things, that is, objects) devices are often poorly secured. In 2016, the DDoS attack on Dyn, a DNS provider, was carried out by the Mirai botnet, which compromised hundreds of thousands of IoT devices such as cameras and routers, disrupting access to major sites like Twitter and Netflix.
Data
Example: In 2013, the data breach at Target exposed the credit card information of 40 million customers, showing the importance of protecting sensitive data.
Information and Communication Technologies (ICT)
ICT covers the technologies used for communication and information management. They include networks, software, computer hardware, and internet services. Securing these technologies is essential to guarantee the confidentiality, integrity and availability of data.
Concrete examples
- Software: Flaws in software, such as the one exploited by the WannaCry malware in 2017, show the importance of regular security patches.
- Networks: Man-in-the-middle attacks, where an attacker intercepts and possibly modifies communications between two parties, show the need to encrypt network communications.
How to protect yourself
Detect and understand the threat
It is crucial to constantly monitor systems to detect anomalies and understand potential threats. For example, the use of intrusion detection systems (IDS) and prevention systems
intrusion prevention systems (IPS) can help identify suspicious behavior. In 2016, Yahoo revealed that a data breach had compromised 3 billion accounts. Proactive monitoring could have limited the impact of this attack.
Create a legal framework
Obligation
Example: The GDPR (General Data Protection Regulation) in Europe imposes strict obligations on how companies must protect the personal data of EU residents. Companies must obtain explicit consent to collect data, ensure the security of the data and report data breaches within 72 hours.
Sanction
Example: In the event of non-compliance with the GDPR, companies can be fined up to 4% of their annual worldwide turnover or 20 million euros, whichever is higher. British Airways was fined 183 million pounds sterling in 2019 for a data breach.
Establish a security policy
Organizational plan
Example: An organization can set up a team dedicated to computer security, such as an incident response team (IRT). After the 2013 attack, Target restructured its security team to include a chief information security officer (CISO) and increased its investment in employee training.
Technical plan
Example: Implement technical solutions such as multi-factor authentication (MFA). In 2016, Dropbox implemented MFA after suffering a data breach that affected 68 million users.
Roles and jobs in computer security
CISO (Chief Information Security Officer): Coordinates computer security activities. For example, at a large company like IBM, the CISO is responsible for the overall security strategy.
Security Analyst: Identifies and fixes vulnerabilities. For example, a security analyst may use tools like Nessus to scan networks for vulnerabilities.
Security Engineer: Designs and implements security solutions. For example, a security engineer may configure firewalls and intrusion detection systems.
Security Auditor: Assesses the effectiveness of security measures. For example, a security auditor may conduct penetration tests to evaluate the robustness of a company's security systems.
Train users
Training is essential so that users understand the risks and adopt secure behaviors. For example, after a phishing attack in 2017, Google launched a training campaign for its employees, reducing click rates on phishing links by 40%.
Motivations of cybercriminals
- Financial gain: Ransomware such as Ryuk has earned cybercriminals millions of dollars. In 2019, a Florida city paid a 600,000 dollar ransom after a Ryuk attack.
- The wish to cause harm: Groups such as Anonymous have launched DDoS attacks to protest against organizations or governments, as during Operation Payback in 2010.
- Espionage: The APT28 group, suspected of being linked to the Russian government, was involved in cyberattacks aimed at stealing confidential information from various governments.
- Other motivations: For example, LulzSec, a group of hackers, carried out attacks for the pleasure of demonstrating the weakness of security systems.
Concrete cases of cyberattacks
EternalBlue
In 2017, the EternalBlue vulnerability was exploited to spread WannaCry, a ransomware that affected systems in 150 countries, including hospitals in the United Kingdom, causing millions of dollars in damage.
WannaCry
The WannaCry ransomware encrypted data on infected systems, demanding a ransom in Bitcoin to decrypt the files. It affected companies such as FedEx and the British National Health Service (NHS).
Babar
Babar is a sophisticated malware attributed to a French intelligence agency. It was used to spy on specific targets by recording keystrokes, screenshots, and audio conversations.
Techniques used
Phishing
In 2016, a phishing attack against John Podesta, Hillary Clinton's campaign chairman, led to the disclosure of thousands of emails, affecting the presidential campaign.
Use of resources
Zombie computers, also called botnets, such as Conficker, compromised millions of computers, turning them into zombies used to launch DDoS attacks.
Address books / spam
Attackers use compromised address books to send spam or large-scale phishing attacks. In 2011, the data breach at Epsilon exposed the emails of millions of users, subsequently used for phishing campaigns.
Storage of illegal files
Compromised servers are often used to host and distribute pirated or illegal content, such as cases of hacked servers used to host pirated films.
Cryptomining
Example: Malware such as Coinhive exploits the resources of victims' computers to mine cryptocurrencies without their consent. In 2018, several government websites were compromised to host cryptomining scripts.
The omnipresence of cybercrime
Cybercrime is a constant and evolving threat. For example, in 2020, cyberattacks increased by 600% because of the COVID-19 pandemic, targeting individuals and organizations with health-related scams and ransomware.
The value of personal data and the money generated
Personal data has great value on the black market. For example, a credit card number can sell for 5 to 110 dollars, and a complete medical record can be worth up to 1,000 dollars. In 2018, data breaches cost an average of 3.86 million dollars per incident.
Conclusion: Cybersecurity concerns everyone
Cybersecurity is everyone's business. Whether you are an individual, a company or a government organization, it is crucial to take steps to protect your digital assets and your personal data. Awareness and proactive action are the keys to reducing risks and defending against cyberthreats. Adopting robust security measures and staying informed about the latest threats is essential to remain protected in an increasingly connected world.
