Cybersecurity
In short: The part of IT security that concentrates specifically on protection against digital/network-based attacks — i.e. threats that come via the internet or a network.
In more detail: While “security” also covers physical and organisational aspects, cybersecurity specifically means defending against malware, DDoS attacks, spoofing and similar network-based threats. In practice, the two terms are often used synonymously in German.
In Depth
Cybersecurity is often structured along the so-called CIA triad — the three central protection goals of confidentiality, integrity and availability. An attack almost always violates at least one of these goals: DDoS attacks availability, malware such as spyware attacks confidentiality, a manipulated software update attacks integrity.
Typical categories in the cybersecurity field, with example terms from this glossary:
Network security - firewall, VPN, IPSec
Endpoint security - antivirus, malware detection
Application security - SQLi protection, authentication
Cryptography - encryption, hashing, certificates
Offensive security - Nmap, Wireshark, Hydra (pentesting tools)
In practice, a distinction is made between defensive security (building protective measures such as firewalls and encryption) and offensive security (actively searching for vulnerabilities, e.g. through penetration tests with tools such as Nmap or Wireshark). Both approaches complement each other: offensive security uncovers gaps before real attackers find them — ideally with the explicit permission of the system operator (otherwise it’s no longer legal security research but an attack in itself).
Blue team, red team, purple team
In larger organisations the offensive/defensive split is often formalised: the “red team” simulates real attackers (penetration tests, social engineering, physical access attempts), the “blue team” defends and monitors the system in live operation (monitoring, incident response). “Purple team” exercises actively bring both sides together — instead of working separately, attackers and defenders share insights in real time in order to improve the defence faster than a classic pentest report evaluated afterwards would allow.
The human factor
An often underestimated aspect: the overwhelming majority of successful cyberattacks don’t begin with a sophisticated technical vulnerability, but with social engineering — phishing emails that trick employees into revealing credentials, or calls pretending to be IT support. That’s why professional cybersecurity management always also includes security awareness training for employees, not just technical protective measures — the strongest firewall is of little use if an employee voluntarily hands their password to a supposed support employee.
Well-known frameworks and standards
Several international frameworks have become established for structuring cybersecurity measures: the NIST Cybersecurity Framework (USA) organises measures into the five core functions identify, protect, detect, respond, recover. ISO/IEC 27001 is an internationally recognised certification standard for information security management systems, which many companies in the B2B environment require of their service providers. The MITRE ATT&CK framework catalogues real attacker tactics and techniques and serves both defenders (what do I need to be able to detect?) and red teams (which realistic techniques do I simulate?) as a common reference.
Cost of cyberattacks
The economic damage caused by cybercrime is estimated internationally at several trillion US dollars a year (studies such as the Cybersecurity Ventures report assume well over 10 trillion USD worldwide) — a central reason why cybersecurity is no longer treated as a pure IT topic but as a business risk at board level. Often the most expensive part isn’t the immediate recovery cost, but the consequential damage: loss of reputation, contractual penalties for breached SLAs, regulatory fines (e.g. under the GDPR) and lost revenue due to downtime.