6. Cybersecurity and Digital Safety
A practical guide to recognizing cybersecurity threats, protecting accounts and devices, and responding safely when information or systems may be compromised.
The Goals of and
protects the systems and information people use every day. applies those protections to ordinary decisions, such as checking a suspicious message, limiting shared personal information, and reporting a compromised account.
A useful framework has three goals:
Confidentiality: Only authorized people can view information.
Integrity: Information remains accurate and is not improperly changed.
Availability: Authorized users can access systems and data when needed.
An attack may affect one or more goals. For example, a primarily threatens confidentiality, while a primarily threatens availability. or unauthorized changes can threaten integrity.
Takeaway: Evaluate a security problem by asking which information or system resource is at risk: who can see it, whether it can be trusted, and whether authorized users can access it.
Common Threats
Threats differ in how they operate and what they target.
is harmful software. Viruses attach to files and spread when opened; worms replicate across networks; trojans disguise themselves as legitimate software; spyware secretly monitors activity; ransomware blocks access or encrypts files for payment; and botnet lets an attacker control an infected device as part of a larger network.
uses deceptive messages, links, attachments, login pages, or payment requests to trick people. Email , text-message (smishing), and voice (vishing) are common forms.
manipulates people through authority, urgency, fear, curiosity, rewards, trust, or familiarity. The attacker may pretend to be a supervisor, relative, bank employee, technology-support worker, or government official.
A exhausts the resources of a website, application, server, or network. A distributed denial-of-service attack uses many systems at once and can make a service slow, unreachable, or unable to process normal requests.
A exposes sensitive information without authorization. Exposed data may include passwords, payment-card numbers, health records, Social Security numbers, customer information, or business secrets.
uses another person’s personal or financial information without permission to make purchases, open accounts, obtain services, file fraudulent claims, or impersonate the victim.
Takeaway: Identify both the method of attack and its target. This helps determine whether the priority is protecting a person, device, account, data set, or service.
Basic Defensive Practices
Use several layers of defense rather than relying on one tool or habit.
Use strong, unique authentication. Create a long, difficult-to-guess password or passphrase for each important account. A password manager can generate and store unique passwords. Password reuse is dangerous because attackers may try credentials exposed in one breach on other services.
Enable . Use two or more types of evidence, such as something you know, something you have, or something you are. MFA makes stolen passwords less useful.
Keep software updated. Install updates for operating systems, browsers, applications, phones, routers, and security tools. Updates often repair vulnerabilities that attackers could exploit.
Think before clicking. Treat unexpected links, attachments, QR codes, login requests, and payment demands cautiously. Navigate to an organization’s website or app independently instead of using a suspicious message link.
Back up important data. Keep regular backups of documents, photographs, and school or work files. At least one backup should be protected from being changed or encrypted by , and backups should be tested periodically.
Use . protects readable data by converting it into ciphertext. Protect passwords and recovery keys as carefully as the encrypted data.
Secure devices and networks. Use screen locks, reputable security software, current wireless-security settings, and a strong router-administrator password. Avoid sensitive transactions on untrusted public networks unless the connection and device are properly secured.
Takeaway: Strong authentication, current software, cautious decisions, reliable backups, , and secure devices work together to reduce risk.
Recognizing and
A suspicious request should create a pause, not an automatic response. Warning signs include urgent or threatening language, unexpected requests for passwords or payment, unusual sender addresses, generic greetings, suspicious links, and pressure to bypass normal procedures.
When a message seems suspicious:
Do not use the phone number, link, attachment, or QR code supplied in the message.
Inspect the sender and destination without opening anything harmful.
Contact the organization through a known website, official app, or trusted phone number.
Never disclose a password, multifactor-authentication code, recovery key, or other sensitive information merely because a message appears official.
Report the message through the organization’s official reporting method.
For example, if a student receives a message claiming that a school account will be deleted unless the student signs in immediately, the student should pause, avoid the included link, open the school’s official website or app independently, contact the school’s technology office through a known channel, report the message, and delete it. If credentials were entered, the student should immediately change the password, change it anywhere else it was reused, enable MFA, and notify the school.
Takeaway: Independent verification is safer than reacting to urgency. A trusted channel should be found separately from the suspicious message.
Responding to Compromise and Security Incidents
Respond quickly, but use a controlled sequence so that the problem does not spread.
Disconnect the affected device from the network if is suspected, while avoiding actions that could destroy useful evidence.
Contact the organization through a known, official channel.
From a clean device, change compromised passwords and any reused passwords.
Enable MFA and review account-recovery settings.
Check financial accounts, credit reports, and important notifications.
Run updated security software or seek help from a trusted professional.
If identity information was exposed, use the recovery guidance at IdentityTheft.gov. Report cybercrime through the appropriate organizational or law-enforcement channel.
If a service reports a , first determine what information was exposed. Then change affected passwords, change reused passwords, enable MFA, monitor accounts and credit reports, and follow the organization’s instructions. A breach increases the risk of fraud and account compromise, but it does not necessarily mean that every exposed record has already been misused.
Organizations also reduce risk through traffic monitoring, rate limiting, redundant systems, filtering services, incident-response plans, secure backups, and coordination with internet-service and security providers. Individuals should report service disruptions and avoid downloading suspicious software that could turn a device into part of a botnet.
Takeaway: Prompt reporting and recovery actions limit damage. A no-blame reporting culture is important because hiding a mistake, such as clicking a link, can give an attacker more time to spread.
Putting Into Practice
is both a technical and human responsibility. Technology can filter threats, encrypt data, monitor traffic, and support recovery, but people must still verify unusual requests, protect authentication information, maintain backups, and report problems.
The central pattern is:
Protect confidentiality with access controls, unique authentication, MFA, , and careful sharing.
Protect integrity with updates, reputable security tools, cautious downloads, and verification of unexpected changes.
Protect availability with backups, resilient systems, monitoring, and preparation for denial-of-service attacks.
Recover from incidents by disconnecting affected systems when appropriate, contacting trusted organizations, changing credentials, monitoring accounts, and reporting promptly.
Final takeaway: Effective combines prevention, detection, independent verification, and fast recovery. No single practice eliminates every risk, but layered defenses make attacks less likely to succeed and reduce their impact when they occur.