Back to Blogs

Foundations of Cybersecurity: Introduction to cybersecurity

Introduction to cybersecurity

2026-07-22
LearningCybersecurity

What do security analysts do?

Security analysts are responsible for monitoring and protecting information and systems.

Security analyst responsibilities

  • Protecting computer and network systems
    • Protecting computer and network systems requires an analyst to monitor an organization’s internal network. If a threat is detected, then an analyst is generally the first to respond.
    • For example, a security analyst may contribute to penetration testing or ethical hacking. The goal is to penetrate or hack their own organization’s internal network to identify vulnerabilities and suggest ways to strengthen their security measures
  • Installing prevention software
    • Analysts may also be involved in software and hardware development. They’ll often work with development teams to support product securiry by setting up appropriate processes and systems to meet the organization’s data protection needs.
  • Conducting periodic security audits
    • A security audit is a review of an organization’s security records, activities, and other related documents
    • For example, an analyst may examine in-house security issues such as making sure that confidential information, like individual computer passwords, isn’t available to all employees.

Key cybersecurity terms and concepts

Compliance is the process of adhering to internal standards and external regulations and enables organizations to avoid fines nd security breaches.

Security frameworks are guidelines used for building plans to help mitigate risks and threats to data and privacy.

Security controls are safeguards designed to reduce specific security risks. They are used with security frameworks to establish a strong security posture.

Security posture is an organization’s ability to manage its defense of critical assets and data and react to change. A strong security posture leads to lower rish for the organization.

A threat actor, or malicious attacker, is any person or group who presents a security risk. This risk can relate to computers, applications, networks, and data.

An internal threat can be a current or former employee, an external vendor, or a trusted parner who poses a security risk. At times, an internal threat is accidental. For example, an employee who accidentally clicks on a malicious email link would be considered an accidental threat. Other times, the internal threat actor intentionally engages in risky activities, such as unauthorized data access.

Cloud security is the process of ensuring that assets stored in the cloud are properly configured, or set up correctly, and access to those assets is limited to authorized users. The cloud is a network made up of a collection of servers or computers that store resources and data in remote physical locations known as data centers that can be accessed via the internet. Cloud security is a growing subfield of cybersecurity that specifically focuses on the protection of data, applications, and infrastructure in the cloud.

Programming is a process that can be used to create a specific set of instructions for a computer to execute tasks. These tasks can include:

  • Automation of repetitive tasks (e.g., searching a list of malicious domains)
  • Reviewing web traffic
  • Alerting suspicious activity

Feedback for this post

What do you think about "Foundations of Cybersecurity: Introduction to cybersecurity"? Leave your feedback below!

Email

hoangminhtri.ngo@gmail.com

Address

Ho Chi Minh City, Vietnam