FirstHack Learn
Log in Sign up free
Lessons in this course 0/6 All courses Cyber Security Fundamentals

Cyber Security

Progress0 / 6 lessons
  1. 1. What security actually means
  2. 2. How passwords are stored
  3. 3. Authentication, MFA and sessions
  4. 4. Social engineering and phishing
  5. 5. Securing your own accounts and devices
  6. 6. Security careers and certifications in India

Courses › Cyber Security Fundamentals

What security actually means

The CIA triad explained with college examples instead of jargon.

9 min read · Lesson 1 of 6 · Free

Security is not "hacking"

Most students meet this subject through movies. A person in a hoodie types fast, a green screen fills up, and a bank falls over. That is not the job.

Security is a boring, useful question asked again and again: what could go wrong here, and what does it cost us? You ask it about a login form, a college result portal, a USB pen drive, a WhatsApp message from an unknown number. Then you fix the cheap problems first.

If you learn one framework in this course, learn this one.

The CIA triad

Every security control on earth is protecting one of three things.

Confidentiality — only the right people can read the data. Your semester marks should be visible to you and the exam cell, not to the whole class.

Integrity — the data has not been changed by the wrong people. Your marks say 78. Nobody, including you, should be able to quietly turn that into 87.

Availability — the system works when it is needed. The result portal that crashes on result day has failed at security, even though nothing was stolen and nothing was changed.

Property Question it answers Example failure
Confidentiality Who can read it? Marksheet database leaked online
Integrity Who can change it? Attendance edited from 41% to 76%
Availability Is it up? Portal down during counselling
ℹ️

These three pull against each other. The most confidential server is one with no network cable, but then nobody can use it. Security is always a trade, never a maximum.

Threat, vulnerability, risk

Students mix these three words in vivas. Keep them separate.

A threat is who or what might hurt you. A bored classmate. A criminal group. A power cut.

A vulnerability is the weakness they would use. A password written on the lab whiteboard. Software that has not been updated in two years.

Risk is the combination, weighted by how much you would lose. Risk goes up when the threat is capable and the vulnerability is open and the data is valuable.

An example. Threat: someone in your hostel wants your Wi-Fi. Vulnerability: your router still uses the default password printed on its sticker. Risk: moderate, because the loss is bandwidth and possibly your identity on that connection. Changing one password removes the vulnerability, and the threat becomes irrelevant.

The AAA of every login screen

Three more words, and now you can read most security documentation.

Authentication — proving who you are. Password, OTP, fingerprint. Authorisation — what you are allowed to do once you are in. A student logs in and sees their own marks. A faculty account logs in and can enter marks for a section. Accounting (also called auditing) — the record of what happened. Who logged in, from where, at what time, and what they changed.

⚠️

Students constantly write "authentication" when they mean "authorisation". In an interview this is an immediate red flag. Authentication is who are you. Authorisation is what may you do. A working login with broken authorisation is how most real data leaks happen: user 1041 changes the URL to user 1042 and sees somebody else's data.

Defence in depth

No single control holds. Passwords get reused. Firewalls get misconfigured. People click things.

So real systems stack controls that fail independently. The database is on a private network, and the app uses a limited database account, and passwords are hashed, and logins are logged, and backups exist offline. Break one layer and the attacker has still gained very little.

This is why "we have antivirus" is not a security answer. It is one layer.

Least privilege

Give every account and every program the smallest set of permissions that lets it do its job, and nothing more.

Your college app does not need a database user that can drop tables. Your own laptop does not need you logged in as administrator all day. The mini-project team member who only writes the front end does not need production database credentials.

Least privilege does not stop a mistake from happening. It limits the blast radius when the mistake happens.

What to take away

  • Security is risk management, not tricks.
  • Every control serves confidentiality, integrity or availability.
  • Authentication and authorisation are different words for different jobs.
  • Layer your defences; assume each one will fail some day.
  • Give the least access that still works.

The next lesson opens up the single most misunderstood piece of all of this: what actually happens to your password after you type it.