1.1 Why “secure” always means secure against something
Security isn’t a single switch you flip on. Every system is secure against some threats and exposed to others, and the job of a security practitioner is to be explicit about which is which. The standard starting vocabulary for that conversation is the CIA triad:
- Confidentiality — only the people who should see data can see it.
- Integrity — data and systems aren’t altered without authorization, and you can tell if they are.
- Availability — the system is there and working when legitimate users need it.
Most real incidents compromise more than one of these at once. A ransomware attack hits availability (systems are locked) and often confidentiality too (data is exfiltrated before encryption).
1.2 Threat, vulnerability, risk — not the same word
These three get used interchangeably in casual conversation, but in this course they mean specific things:
- A vulnerability is a weakness — a flaw in software, a misconfiguration, a gap in a process.
- A threat is someone or something that could exploit that weakness — an attacker, a piece of malware, even a careless insider.
- Risk is the combination: the likelihood a given threat exploits a given vulnerability, multiplied by the impact if it does.
An unpatched server with no internet access has a vulnerability but very little realistic threat exposure, so the risk is low. The same server facing the public internet is a very different story.
# Check what you're actually running before you reason about its exposure
uname -a
1.3 Why attackers attack
Motivation shapes behavior, and behavior is what you detect. The three you’ll see referenced most:
- Financial — ransomware, fraud, data theft for resale. By far the most common motivation for the incidents you’ll study this semester.
- Ideological / political — hacktivism, nation-state espionage, disruption as a message.
- Curiosity / opportunity — not every compromise starts with a plan; plenty start because a door was left open.