What is Cybersecurity?

Cybersecurity is the practice of protecting computer systems, networks, programmes, and data from unauthorised access, attack, or damage. It encompasses a wide range of technologies, processes, and practices designed to create a secure digital environment.

The CIA Triad

The foundation of cybersecurity rests on three pillars, known as the CIA triad:

  • Confidentiality: Ensuring that sensitive information is accessible only to those authorised to view it. This is achieved through encryption, access controls, and authentication mechanisms.
  • Integrity: Maintaining the accuracy and completeness of data throughout its lifecycle. Hash functions, digital signatures, and version control help preserve integrity.
  • Availability: Guaranteeing that systems and data are accessible when needed. Redundancy, backup systems, and disaster recovery plans support availability.

Common Threat Types

Malware

Malicious software designed to damage, disrupt, or gain unauthorised access to systems. Types include viruses, worms, trojans, ransomware, and spyware.

Phishing

Social engineering attacks that trick users into revealing sensitive information or downloading malware through deceptive emails, websites, or messages.

Man-in-the-Middle (MitM)

An attacker secretly intercepts communication between two parties to eavesdrop or modify the data being exchanged.

Denial of Service (DoS)

Overwhelming a system or network with traffic to make it unavailable to legitimate users.

Basic Protection Strategies

  1. Keep software updated: Regular updates patch known vulnerabilities
  2. Use strong passwords: Long, complex passwords or passphrases reduce brute-force risk
  3. Enable multi-factor authentication (MFA): Adds an extra layer of security beyond just a password
  4. Back up data regularly: Maintain recent backups to recover from ransomware or data loss
  5. Train staff: Human error is a leading cause of security breaches

Hong Kong operator checklist

  1. Confirm whether the systems, vendors, or practices described apply to your estate.
  2. Assign an owner and a review date — do not leave findings as unread newsletter content.
  3. Capture evidence (configs, tickets, screenshots) if you later enter a Trust Review.
  4. Brief leadership with a dated one-page note when residual risk remains high.

What “good” looks like

  • Controls are operated, not only documented
  • Privileged access uses phishing-resistant MFA where feasible
  • Detection and response paths are exercised at least annually
  • Third-party dependencies have an owner and an exit plan

Sources and further reading

Editorial note

This page is published by the Hong Kong Information Security Group (HKISG) for educational and early-warning purposes. It is not a substitute for legal advice, formal audit opinions, or national CERT coordination.

Frequently asked questions

Who should read this?

Security, IT, and risk owners in Hong Kong organisations who need practical context rather than marketing claims.

Does this change any public HKISG rating?

No. TrustScores are produced only through the published Trust Review / Awards process. Reading this page does not alter scores.

How often is this content reviewed?

HKISG dates publications and retains corrections under our editorial standards. Check the updated field in the page header when present.