Knowledge That Moves You Forward - ElimBora

Tuesday, 18 August 2026

INTRODUCTION TO CYBER SECURITY | FORM TWO FULL NOTES

 

The concept of cybersecurity centres on the term cyber. Cyber is a word that relate to computer systems, digital technology and the internet or online world.

It can be used to explain things that are connected to online activities, networks and virtual environments such as cyberspace and cybercrime.

By definition the term cybersecurity refers to the practice of keeping computer systems, networks and data safe from hackers or other unauthorized access. It involves the use of technology, rules and safety measures to prevent cyber-attacks. The main goal of cybersecurity is to protect computer systems, networks, applications and data from unauthorized access, damage or disruption. Example protecting your computer or mobile phone using password or PIN so as to prevent unauthorized people to open your computer or mobile phone.

Cyberspace is the virtual world created by computers, the internet and the digital networks. It is where online activities such as communication, social media and online banking take place.

Cybercrime is a crime committed using computers, the internet or other digital devices.

Other Terms used in Cybersecurity:

A. Cybersecurity ethics; it involves applying moral principles to digital networks and data security, emphasizing integrity, confidentiality and privacy.

B. Security; Is the state of being protected against or safe from danger or threat.

In computer security, it focuses on protecting computer software, systems and networks from threats that can lead to unauthorized disclosure of information, theft or damage to hardware, software or data.

C. Privacy; is the fundamental right of an individual to control their personal information, determining how it is collected, used, stored and shared by organizations. Ensuring its handled ethically and with consent.

KEY AREAS OF CYBERSECURITY

i. Network security; Protecting computer networks from intruders.

ii. Application security; Securing software and devices from threats

iii. Information security; Protecting data privacy and integrity, in storage and transit

iv. Operational security; Managing processes for handling and protecting data assets

IMPORTANCES OF CYBERSECURITY

i. It helps to protect sensitive information; for example, personally identifiable information and government data

ii. It helps to prevent financial loss and fraud

iii. It helps to maintain business continuity

iv. It building trust to customers, partners and other stakeholders by securing their data

v. It also teaches us on how to protect our devices and systems from hackers and damage

COMPONENTS OF CYBERSECURITY

These are the key elements that work together with cybersecurity; thus, the components of cybersecurity are;

i. Confidentiality; Is about preventing the disclosure of data to unauthorized parties.

 It ensures sensitive data or information is only accessed by authorized individuals.

Standard measures to establish confidentiality include

· Data encryption

· Twa factor authentications

· Biometric verification

· Security tokens

ii. Authentication; means to verify the identity of users or devices so as to prevent unauthorised access.

iii. Availability; Means to ensures information is available when needed without being disrupted by attacks.

Standard measures to guarantee availability include

· Backing up data to external drives

· Implementing firewall

· Having backup power supplies

· Data redundancy

iv. Integrity; refers to protecting information from being modified by unauthorized parties.

Standard measures to guarantee integrity include;

· Cryptographic checksums

· Using file permissions

· Uninterrupted power supplies

· Data backups

v. Access control; means to restrict access to systems and data based on the user’s roles and permission

vi. Network security; it ensures safe data transmission

vii. Application security; it ensures that software and applications are free from vulnerabilities and are secure.

viii. Incident response; means to develop a plan on how to respond and recover from cybersecurity incidents like breaches and attacks, for example deceptive messages

sent through email that need to still some personal information can be ignored and stop clinking the link or follow their instructions.

CYBER THREAT

Refers to any malicious act that seeks to damage data, steal sensitive information, or disrupt digital life by gaining unauthorized access to networks, devices or systems.

It is a potential risk or possibility of a cyberattack occurring rather than the attack itself.

TYPES OF CYBERTHREAT

There are two main categories of cyber threats;

Natural Threats; 

these re environmental or physical events like natural disasters, that can disrupt or damage information systems, infrastructure and data affecting cybersecurity.

Examples of natural threats include the followings;

i. Natural disasters such as earthquakes, floods, it can damage hardware through heat and water leading to data loss.

ii. Lightning strikes, it can cause power surges that may damage or destroy computer hardware

iii. Dust and humidity, it can clog internal cooling systems and lead to overheating

Measures to protect computers from natural cyber threats

i. Back up data

ii. Install computers in secure locations

iii. Install protective electrical devices

iv. Insulate computer from fire

v. Maintain appropriate temperature or humidity

Manmade Threats;

These are threats result from malicious human actors and accidental human errors pose various risks to computer systems and networks. It includes intentional actions like theft, viruses, spyware and unintentional actions like accidental data deletion and hardware damage.

Measures to protect computers from Manmade cyber threats

i. Store data safely

ii. Encrypt data; it is a method that translate data into a code or ciphertext that can only be read by people with access to a secret key or password.

iii. Install antivirus and antispyware programs

iv. Install firewall; A firewall is network security system that monitors and controls incoming and outgoing network traffic based on the configurable security rules.

v. Back up data

vi. Keep computer in safe environment.

CYBER ATTACK

Is a Malicious and deliberate attempt by an individual or organization to breach the information system of another to steal, alter, expose, destroy data or to disable network.

Cyber-attack can target both physical infrastructure and software systems.

TYPES OF CYBER ATTACKS:

A. Physical based attacks:

Is the attack that involve gaining physical access to devices or equipment to steal data or install malicious tools.

Examples of common physical attacks;

· Device theft, for example to stole a laptop with students record

· Keylogging devices; installing a device that records every keystroke

· Shoulder surfing; watching over someone shoulder to gain their credentials

· Dumpster diving; searching discarded/dumped materials for sensitive information

· Power interference attacks; for example, to read a typed data based on electrical fluctuations.

B. Software based attacks:

Is the attack that exploit software, networks, or user behaviour access, steal or damage information.

Common software-based cyberattacks or threats

1. Malware (Malicious Software)

Malware is any software intentionally designed to damage, disrupt or gain unauthorized access to computer systems.

Examples of Malware;

· Virus; attaches itself to legitimate files and spreads when the file is executed.

· Worm; self-replicates and spreads across networks without user interaction

· Trojan horse; disguises itself as legitimate software but performs malicious actions once installed.

· Spyware; secretly monitor user activities and collect sensitive information.

· Adware; displays unwanted advertisements and may track user behaviour.

Impacts of Malware

· Data loss or corruption

· System slowdown or crashes

· Theft of personal or organizational data

Security measures against Malware

i. User should install antivirus

ii. Keep systems updated

iii. Avoid suspicious links

iv. Use strong cybersecurity practices.

2. Phishing attacks

Phishing is a social engineering attack where attackers trick users into revealing sensitive information by pretending to be a trusted entity.

Examples of phishing;

· Email phishing; fake email requesting login credentials or personal data

· SMS phishing; Malicious messages sent via text

· Voice phishing; fraudulent phone call impersonating officials or companies.

             Impacts of phishing:

· Stolen usernames and passwords

· Financial fraud

· Identity theft

Security measures against Phishing:

i. Always check sender’s email

ii. Avoid clicking on unknown links

iii. Never share personal details with untrusted sources

3. Ransomware;

Is a type of malware that encrypts a victim’s files and demands payment to restore access. It can spread through phishing emails with malicious attachments, infected websites or fake software updates, USB drives and unsecured networks

Impacts:

· Loss of access to critical data

· Business or service disruption

· Financial loss due to ransom payments

Security measures against Ransomware

i. Backups and data recovery

ii. Endpoint protection

iii. Network security.

4. Weak password attacks;

Attackers exploit weak or reused passwords to gain unauthorized access.

Common methods:

· Brute force attacks: trying many password combinations.

· Dictionary attack: using common words or leaked passwords

· Credential stuffing; using stolen credentials from one site to access another.

            Impacts:

· Account takeover

· Unauthorized system access

· Data breaches

5. Man-in-the-middle attacks (MitM)

It occurs when an attacker secretly intercepts communication between two parties. For example, by using unsecured public Wi-Fi, face Wi-Fi hotspots and compromised router.

Impacts:

· Stolen login credentials

· Altered or monitored communications

· Financial Fraud

6. Denial of service (DoS ) attacks and distributed of Denial of Service (DDoS)

It aims to make a system or website unavailable by overwhelming it with traffic. For example, website stops working because of too many fake visitors.

DoS Attack from a single source while DDoS attack from multiple compromised systems (botnets).

Impact:

· Website downtime

· Loss of business and reputation.

· Disruption of online services

 

7. DNS spoofing;

Redirecting you to fake websites, for example, you think you are on your bank ‘s website but its fake.

8. Spamming; sending lots of unwanted emails, example getting fake emails about prize or offers.

9. Social engineering;

Means tricking people into giving information. For example, someone pretending to be IT support asking for your password.

10. Hacking:

Is the act of gaining unauthorized access to computer systems, networks or data by exploiting security weaknesses.

Hacker is an individual with advanced computer skills who navigates, manipulates or breaches computer systems, networks or software.

ANTIVRUS:

Is a software that protects a device from harmful programs, such as viruses, malware and spyware. It is important software to keep your devices and data safe.

How it works:

i. It scans for threats and blocks them

ii. It also updates regularly to fight new types of attacks

 

 

 

 

Differences between Cyber threats and cyber-Attacks

 

Cyber threats

Cyber attacks

1.

Refers to any malicious act that seeks to damage data, steal sensitive information, or disrupt digital life by gaining unauthorized access to networks, devices or systems.

 

Is a Malicious and deliberate attempt by an individual or organization to breach the information system of another to steal, alter, expose, destroy data or to disable network

2.

Threats are often constant and passive possibilities.

Attacks are immediate, active and time-bound events.

3.

For example, phishing emails in an inbox and system vulnerabilities

For example, a live SQL injection and authorized access

4.

It may or may not lead to an incident.

Results in tangible impacts such a data breaches or financial loss.

 

CYBER SECURITY THREATS COUNTER MEASURES/ CONTROL

i. Use strong, unique passwords and passphrases; for example, create at least 14 characters long password, mixing letters, numbers and symbols.

ii. Enable Multi-factor Authentication (MFA); This helps to adds a critical second layer of security by requiring an additional form of verification such as one time code sent to your phone or a biometric scan.

iii. Keep software and devices updated; Enable automatic updates for your operating systems, applications and antivirus software to ensure you have the latest security patches because cybercriminals often exploit vulnerability in an outdated software.

iv. Be cautious with links and attachments; think before you click on links or open attachments in suspicious emails or messages, especially those from unknown senders or with urgent language.

v. Secure your network: use a secure, password protected wi-fi network and change the default router password. Avoid accessing sensitive information like online banking on public wi-fi networks.

vi. Back up your data; regularly backup your important files to external hard drive or secure cloud storage. This ensures you can restore your data in the event of a ransomware attack or system failure.

vii. Limit personal information Online; Be aware of what you share on social media as this information can be used by attacker for social engineering or identity theft.

viii. Install firewall and end point protection: deploy network firewall and endpoint security software like antivirus on all devices to create a robust defence barrier.

Hacking:

Is the act of gaining unauthorized access to computer systems, networks or data by exploiting security weaknesses.

Hacker is an individual with advanced computer skills who navigates, manipulates or breaches computer systems, networks or software.

TYPES OF HACKERS

i. Black hat hackers; these are the bad hackers who can break into systems with malicious intent, such as stealing data or causing harm

ii. White hat hackers; these are ethical hackers who work to improve security by identifying and fixing vulnerabilities.

iii. Grey hat hackers; these are hackers that fall in between, sometimes hacking without permission but with no malicious intent.

Ways hacker exploit Vulnerabilities:

i. Exploit weak password

ii. Exploit Outdated software

iii. Attack public wi-fi

iv. Spread virus and ransomware

CYBERCRIME

Is the use of computers or digital devices to carry out illegal or harmful activities online. It includes actions like hacking, online scams and cyberbullying.

It affects individuals, business or community by stealing information, money or causing emotional or physical harm.

Types of cybercrime

Cybercrimes can be classified based on the target and method used.

i. Against individuals; it involves identity theft, phishing and online scams that target personal data or finances

ii. Against organizations; Targets business through data breaches, ransomware and system disruption.

iii. Against government and national security: This includes cyberterrorism, hacking government systems and cyber warfare which threaten national safety and critical services.

iv. Against property; Involves intellectual property theft, financial fraud and malware attacks like virus and trojans.

v. Against society; affects the public through child exploitation, misinformation and online trafficking.

Catalyst of cybercrimes

i. Financial gain

ii. Anonymity; The internet allows criminals to hide their identity and operate across borders

iii. Political and ideological motives: Some cyberattacks are done to protest or disrupt governments and corporations.

iv. Revenge

v. Curiosity and challenge; some commit crimes for fun or recognition

vi. Weak cybersecurity.

vii. Ineffective law enforcement;

CASE STUDY 01;

Wanna Cry Ransomware attack 2017

v Attack type: ransomware

v Target: Computers running Microsoft windows

v Impact: affected of 200,000 Computers in 150 countries, including hospitals, banks and business.

v Lesson: Keeping software updated and using backups can prevent such attacks.

APPLYING BASIC CYBERSECURITY MEASURES:

A. AUTHENTICATION

Is the process of conforming that a person is truly who they claim to be before allowing access to sensitive systems, data or accounts.

It serves as security check point where credentials or identity proofs must be presented and verified.

Common authentications methods include:

i. Username and password

ii. Biometrics: it involves the use of unique physical characteristics like fingerprints or facial features for identity confirmation

iii. Two-factor authentication (2FA); it adds an extra layer by requiring not only a password but also second verification method.

         PASSWORD

Is a secret string of characters used to verify a user’s identity and authorize access to a computer system, online account or digital resource, acting as the key to unlock protected information and services.

Characteristics of a strong password

i. Be at least 12 characters long

ii. Contain uppercase and lowercase letters

iii. Include numbers and special symbols

iv. Avoid personal information (name, phone number, date of birth)

v. Be unique for each device and account.

Password Management Best Practices

i. Never share your password with anyone

ii. Change password regularly

iii. Do not write password where others can see them

iv. Use Mult-Factor authentication where available

v. Use a password manager for complex passwords.

HOW TO SET A PASSWORD ON A PC (COMPUTER)

i. Step 01: Open settings

v Click the start menu

v Select settings

v Click accounts

ii. Access sign-in Options

v Choose sign-in options from the left panel

v Under password, click Add (or change if already set)

iii. Create a password

v Enter a new password

v Re-enter the password to confirm

v Add a password hint (do not make it obvious)

iv. Save settings

v Click next, then finish

PASSWORD SETTING ON A MOBILE PHONE

Setting a password on an android phone

i. Step 1: Open settings

v Go to settings

v Select security or security and privacy

 

ii. Step 2: Choose screen lock;

v Tap screen lock

v Select password (more secure than PIN or Pattern)

iii. Step 3: Create Password

v Enter a strong password

v Confirm the password

iv. Step 4: enable auto-lock

v Set Auto-lock time, example 30 seconds

v Optional security enhancements

v Enable fingerprint or face unlock

v Activate find my device

DIGITAL SIGNATURE

Is a method of providing that a message, document, or online transaction is genuine and has not been altered. It functions like a handwritten signature but in digital form.

Digital signature helps to prevent fraud and protect the integrity of information.

Steps to create a digital signature

i. Open your emails client’s settings or options

ii. Look for sections related to security, certificates or digital signatures

iii. Import or select the digital certificate you obtained.

iv. Within the email client’s security settings, enable the option to sign emails digitally.

v. You may have option to sign all ongoing emails or sign emails individually.

Other terms used in cyber-security:

A. FIREWALL

Is a security tool that helps protect your computer network from harmful attacks by blocking unwanted traffic and controlling what come in and out of your network.

Steps to configure window firewall

· Click start

· Click the control panel

· Choose a system and security

· Click windows and firewall

· Click turn On or off and do other necessary security actions.

B. Netiquette

Means good behaviour when using internet. It includes

i.  Being kind and respectful when chatting, posting or commenting online.

ii. Avoid using rude language

iii. Avoid spreading false information

iv. Respecting people privacy

Good netiquette helps create a safe and friendly online environment for everyone.

C. Computer forensics

Is a process of investigating digital devices to find evidence of cybercrimes like hacking, fraud, and identity theft.

Computer forensics play a key role in maintaining cyber-security and ensuring justice in the digital world.

Steps to conduct computer forensics:

i. Identification; Detect and identify digital devices and data that may contain evidence of cybercrime.

ii. Preservation; secure the devices and prevent any changes to the data by making forensic copies.

iii. Collection; gather all relevant digital evidence, including files, emails, using specialized forensic tools

iv. Examination; analyse the collected data to find important clues such as sign of hacking or unauthorized access.

v. Analysis; study the evidence carefully to understand how the crime happened and its impact.

vi. Documentation; record all findings, including screenshots, reports and logs to create a forensic report for legal purposes.

vii. Presentation; present the findings to law enforcement., organizations or in court as evidence

viii. Incident response and prevention; provide recommendation on how to improve security and prevent future cybercrimes.

D. Safe browsing:

Means using the internet in a way that protects your personal information and keeps you safe from online threats.

BEST PRACTICES FOR SAFE BROWSING

i. Verify website legitimacy before browsing; for example, check if the website URL starts with https:// and not http

ii. Avoid clicking unknown or suspicious links;

It helps to prevents malware downloads and phishing attacks.

iii. Download software only from trusted sources.

Use only official app stores like google play store or app le app store, this helps to prevents malware, spyware and ransomware infections.

iv. Keep browser and systems updated.

Use the latest version of browser and operating systems and enable automatic updates. It helps to closes security vulnerabilities that attackers exploit.

v. Use strong authentication while browsing:

Use strong, unique passwords for each website and enable multi-factor authentication (MFA).

vi. Be cautious when using public Wi-fi.

It can be easily monitored and insecure.

Avoid logging into banking or sensitive accounts on public wi-fi.

Use a Virtual Private Network (VPN)

It helps to prevent Man-in-the-Middle attacks.

vii. Limit Personal information shared on Public Wi-fi

Avoid over sharing personal or confidential information to reduce risk of identity theft and social engineering attacks.

viii. Use security tools and browser features.

Enable browser pop-up blockers and use reputable antivirus and anti-malware software aim to block malicious websites and harmful downloads.

ix. Monitor Online activity and accounts

Review account login history and regularly check for unusual behaviour, this allows early detection of security breaches.

USING ENCRYPTION TECHNIQUE

The term Encryption refers to a cyber security technique that converts readable information (plaintext) into an unreadable format (ciphertext) using a mathematical algorithm and a secret value called a key.

Only authorized users who possess the correct decryption key can convert the ciphertext back into readable information.

Purposes of Encryption in cybersecurity

i. To protect confidentiality of data

ii. Prevent unauthorized access

iii. Secure data transmission over networks

iv. Safeguard stored data

v. Ensure data integrity and trust

Limitations of Encryption

i. Weak passwords can expose encryption keys

ii. Poor key management reduces effectiveness

iii. Encryption does not protect against phishing or social engineering

iv. Encrypted data can still be deleted or corrupted

USES OF BIOMETRICS

Biometric refers to the use of unique physical or behavioural characteristics of an individual to verify or identify their identity for security purposes.

Unlike passwords or PIN, biometrics are inherent to a person, making them harder to steal, forget or share.

Purposes of biometrics in cyber security

i. Strengthen authentication and access control

ii. Reduce reliance on passwords

iii. Prevent unauthorized access

iv. Improve user convenience while maintaining security

v. Support multi-factor authentication (MFA)

Common types of Biometric Technologies

A. Fingerprint recognition

How it works:

A scanner captures the fingerprint pattern and compares it with a stored template.

Uses:

i. Unlocking smartphones and laptops

ii. Access control systems

iii. Time and attendance systems

Security benefit:

 it ensures only authorized individuals can access device and systems

B. Facial Recognition

How it works:

The system analyses facial features such as eye distance, nose shape and jawline.

Uses:

i. Phone and computer login

ii. Surveillance and identity verification

iii. Secure access to facilities

Security benefit:

 it enables contactless and fast authentication.

C. Iris and Retina Scanning

How it works:

The system scans unique patterns in the eye.

Uses:

i. High security environments (airports, research lab)

ii. Border control systems

Security benefit:

 Extremely accurate and difficult to forge.

D. Voice recognition

How it works:

Analyses voice patterns, tone and pitch.

Uses:

i. Call center authentication

ii. Voice-controlled systems

Security benefit:

Adds identity verification without physical contact.

E. Behavioural Biometrics

How it works:

Analyses user behaviour such as typing speed, mouse movement or walking style.

Uses:

i. Continuous authentication

ii. Fraud detection

Security benefit: Detects unauthorized users even after login.

CLOUD SECURITY

The term cloud refers to the network of remote servers that provide computing services when needed. Companies like google, Microsoft and Amazon offer cloud services. It allows users to access their data from anywhere via the internet using devices like smartphone, tablets or laptops.

Cloud security refers to the cybersecurity practices, controls and technologies used to secure applications, data, and secure applications, data and infrastructure in cloud environments.

Advantages of cloud security

i. Data security

ii. Business continuity

iii. Compliance; ensuring data adheres to legal, industry and regional regulations

iv. Accessibility

           Security challenges in cloud Environments

i. Data breaches and loss

ii. Unauthorized access

iii. Insider threats: Employee can mis use cloud resources

iv. Compliance and legal issues

v. Denial of service (DoS) attacks

 

 

Best Practices for cloud Security

i. Use strong password and Multi-factor Authentication

ii. Keep software updated

iii. Limit access

iv. Monitor activity

v. Back up data

vi. Shared responsibility: users must secure their data while providers handle the infrastructure.

CYBER SECURITY ETHICS:

Cyber security ethics are moral principles that guide the safe and responsible use of technology and the internet.

Key practices for cyber security ethics includes:

i. Respecting others online

ii. Giving credit to original creators

iii. Avoid cyberbullying and false information

iv. Not accessing or using others data without permission

v. Avoiding illegal activities like piracy or fraud.

No comments:

Post a Comment

FORM ONE HOME PACKAGE 2026

Popular Posts