Skip to content
Glossary

What is cybersecurity?

Cybersecurity encompasses all technologies, strategies, processes, and measures aimed at protecting IT systems, networks, devices, data, and users from digital threats. In a world where digital transformation is advancing, cybersecurity is crucial for ensuring the confidentiality, integrity, and availability of sensitive information and for safeguarding the continuity of business operations.

In light of increasingly decentralized and mobile work environments (New Work) as well as the migration of critical infrastructure and data to the cloud, cybercriminals’ attack vectors have evolved. Modern threats increasingly target the human factor, with phishing attacks and targeted attacks on executives with broad access privileges posing a particular danger.

Cybersecurity is no longer just a technical challenge but a company-wide responsibility that affects every area of a business. An effective, holistic security approach integrates both technological solutions and employee training to ward off both external and internal threats.

1. What types of cyber threats are there?

Malware includes harmful software such as viruses, worms, Trojans, ransomware, and spyware, which are designed to disrupt or damage IT systems or steal data. Often, all it takes is one careless click on an email attachment for the malware to enter the system.

Phishing refers to attempts to deceive users—often via email—in order to steal sensitive information. The attacker poses as a trustworthy entity. Using clever social engineering techniques—such as an email purporting to be from a boss or a bank—attackers put pressure on the target and attempt to force them to disclose login credentials such as PINs, passwords, or similar information. Phishing emails are often sent in large numbers, and even if only a small percentage of the targets fall for the scam, the damage is enormous.

Man-in-the-middle attacks are eavesdropping attacks that insert themselves between two systems or communication partners to listen in on or read the communication. In the process, valuable information may be obtained that helps prepare and carry out an attack on the involved IT systems.

Denial-of-Service (DoS) and Distributed Denial-of-Service (DDoS) attacks aim to overload a system or network with a massive volume of requests, rendering it inoperable and causing it to crash. Often, millions of access attempts and requests are carried out automatically in rapid succession. The goal is to push systems to their capacity limits and paralyze them.

Zero-day exploits are security vulnerabilities in software systems that are still unknown to—or have not yet been detected by—the software vendors and operators. Zero-day exploits are highly sought after and are traded and resold in relevant darknet forums.

Ransomware attacks —cyberattackers gain access to a company’s IT infrastructure and use cryptographic algorithms to encrypt a large portion or all of the company’s data and systems. The entire IT infrastructure fails, and business operations come to a standstill; this results in financial losses and damage to the company’s reputation. In exchange for a ransom payment, the attackers promise to decrypt the data. Often, sensitive corporate information is also stolen, and the attackers threaten to publish it, which puts additional pressure on the targeted companies.

SQL injection is an attack technique that uses manipulated commands in the SQL query language to gain unauthorized access to an IT system. The first step usually involves triggering malfunctions to circumvent security mechanisms.

Botnets are hijacked computers or PCs over which cybercriminals have gained control without the users and owners of the devices having noticed the loss of control so far. Botnets can comprise thousands or even tens of thousands of computers. Cybercriminals exploit the combined computing power of botnets to carry out attacks against companies, such as DoS or DDoS attacks.

2. Why has cybersecurity become important?

As PCs, computers, servers, and devices such as smartphones become increasingly interconnected, the number of potential entry points that cybercriminals can exploit for their attacks has risen significantly. The digital world has become more vulnerable and must be protected accordingly. Attackers exploit vulnerabilities to gain financial, political, and ideological advantages.

3. What are the key components of a comprehensive cybersecurity strategy?

The first step in developing a comprehensive cybersecurity strategy is to conduct a status quo analysis and a risk assessment. The risk profile varies slightly for each company depending on its industry, market, and business activities. The purpose of the risk assessment is to identify potential vulnerabilities that cybercriminals could exploit for attacks and to evaluate them based on their threat potential.

Access control ensures that only authorized individuals—based on their job, role, and function within the company—are granted access to specific data, information, and systems. Access is protected from unauthorized users through security mechanisms such as passwords, double opt-ins, and other access controls.

An incident or emergency response plan specifies which guidelines apply and how to proceed in the event of an attack. This enables a quick and efficient response in the event of an attack, as everyone knows what to do.

Regular audits and tests put the IT infrastructure to the test, verifying that all security systems are still functioning properly and that no new vulnerabilities or risks have emerged in the meantime against which the implemented security measures can no longer provide reliable protection.

Security training raises employees’ awareness of threats, such as those posed by phishing emails. A mindful and responsible approach is essential. Untrained employees are among the greatest security risks for companies.

Regular updates and patches should actually be a given, but in practice they are often overlooked. Software vendors use updates and patches to close security vulnerabilities that have arisen, so installing them is mandatory.

Backups and Recovery – Regularly performed backups help companies restore data that has become unusable following a technical failure, a security breach, or a ransomware attack. This largely prevents prolonged business disruptions and associated costs. Backups should be performed at regular intervals and stored in a secure location separate from the company network.

Darknet Monitoring – On the darknet, the part of the World Wide Web that isn’t readily accessible, cybercriminals offer stolen security and access codes, PINs, and passwords and sell them to the highest bidder. The buyer then carries out the actual attack. Darknet monitoring can therefore provide important clues about impending attacks. The targeted victim has enough time to take countermeasures and close security gaps.

Proprietary Encryption – To prevent sensitive information from being stolen and misused, companies can encrypt their files and grant access only to a select group of individuals. Although attackers can steal the encrypted data, they cannot read or reuse it. It is of no value to cybercriminals.

The issue of IT security presents companies and public administrations with ever-greater challenges and threats. valantic has been providing companies with expert and comprehensive consulting services for many years.

4. What are some current examples of cybersecurity threats?

Cyberattacks on a hospital in Israel and Kuwait’s Ministry of Finance, a DDoS attack on the Berlin city government’s website, and a cyberattack on an electronics company in Japan are recent examples. Over the past decade, the Stuxnet computer worm, among other incidents, has caused quite a stir. Stuxnet was able to spread undetected via USB drives for several years and infected hundreds of thousands of computers worldwide.

The WannaCry ransomware triggered an epidemic wave of extortion and crippled more than 200,000 computers in 150 countries within four days. Victims included factories, businesses, and critical infrastructure such as hospitals, where medical devices were encrypted and thus rendered inoperable.

The Emotet banking Trojan was discovered in 2014. Emotet initially specialized in intercepting online banking credentials but was quickly able to carry out many other malicious functions. The attacks primarily targeted banks and businesses.

Currently, attempts at deception using artificial intelligence (AI)—so-called “deep fakes”—are on the rise. AI creates fake videos or audio clips that appear deceptively real. Cybercriminals use these to manipulate their victims and trick them into acting recklessly. Attacks on supply chain management and supplier networks can also severely impact companies and cause significant damage.

5. What are the emerging cybersecurity threats in the digital world?

Edge computing and the Internet of Things (IoT) are current trends in information technology and business. In this context, intelligence is decentralized and shifted to “outposts” because decision-making authority is greater there—and decision-making processes are more streamlined—than in a centralized structure. Since this means that devices are constantly connected to the Internet and corporate networks, it also creates an ever-increasing number of potential entry points for cybercriminals.

Lightning-fast quantum computers have the potential and computing power to crack conventional access codes for banks, critical infrastructure, and even weapons systems much faster than is possible, for example, with today’s already highly powerful supercomputers. Researchers and corporations are preparing for this and working on quantum-cryptographic protection mechanisms.

AI-driven cyberattacks are on the rise, partly due to recent advances (see also deepfakes). AI is being used to improve the efficiency and sophistication of these attacks.

6. What security tips are available for businesses and individuals to protect themselves against cyberattacks?

Multi-factor authentication is an effective security measure for security-sensitive connections and data. Simply entering a username and password is not enough to gain access. Additional verification is required via another device, such as a personal smartphone, and/or a code from a specially configured authentication app. Multi-factor authentication already provides significantly greater protection against attacks.

Firewalls and antivirus software from well-known vendors should be updated and kept current, because cybercriminals’ attack vectors change and new security vulnerabilities are frequently discovered.

Regular backups, stored separately from the network in multiple secure locations, offer a high level of protection. In the event of technical failures or ransomware attacks, businesses and individuals can quickly recover data that has been stolen or rendered unusable.

Last but not least: Staying informed about new developments and exercising caution with suspicious emails and attachments from unknown senders (phishing emails) is already a simple and effective preventive measure.

7. What role do artificial intelligence and machine learning play in cybersecurity?

With the help of AI and machine learning, banks, insurance companies, institutions, and businesses can detect suspicious patterns that deviate from their customers’ usual behavior. If a suspicious, anomalous pattern is detected—such as frequent account debits from different locations—this may be an indication of fraudulent activity.

Predictive analytics, powered by AI, can more accurately forecast future threats, such as burglaries in cities. Police and security forces are already using AI models to predict and combat crime.

AI and machine learning can also be used to improve user authentication and make it more secure by incorporating biometric and behavior-based methods.

8. What does a cybersecurity consultant do?

Cybersecurity consultants advise companies and organizations on how best to protect their data and infrastructure against cyber threats. They identify and evaluate vulnerabilities, recommend appropriate security measures, develop a roadmap, and coordinate the implementation of security solutions. If an attack has already occurred, security consultants—known as breach coaches —provide valuable assistance in minimizing and mitigating the damage. The goal is to maintain business operations or restore them as quickly as possible.

9. What are the latest trends in cybersecurity?

Zero-Trust Architectures: Today’s digital world is more interconnected than ever. Zero-Trust approaches aim to ensure security through appropriate measures at every point in the network. Zero Trust uses technologies such as network segmentation to prevent the spread of malware within an IT system.

Security Orchestration, Automation, and Response (SOAR): Security orchestration and automation refers to a set of cybersecurity technologies that enable an organization to respond to security incidents quickly, efficiently, and automatically.

Extended Detection and Response (XDR): XDR is a security technology that monitors, collects, and analyzes data from various network points such as servers, email, cloud workloads, and endpoints. Threats are categorized and prioritized to help cybersecurity teams evaluate incidents and remediate vulnerabilities.