Home
Glossary
Cybersecurity
Table of contents
5 min
H2 title on one or more lines.
Share
Updated on
August 14, 2026

What is cybersecurity?

Cybersecurity is the practice of protecting systems, networks, applications, and data from attack, unauthorized access, and disruption. It combines technology, processes, and people: tools that prevent and detect malicious activity, procedures that define how an organization responds when something happens, and the judgment of the people who operate both. The purpose isn't to eliminate risk, which isn't achievable, but to reduce it to a level the organization can live with and to be able to recover when prevention fails. The word covers an unusually wide field, from securing a laptop to defending national infrastructure, which is why definitions of it tend toward the abstract. This page is deliberately structured as a starting point: it sets out what cybersecurity covers, the threats it addresses, how organizations actually practise it, why prevention alone has stopped being sufficient, and how European regulation shapes what's expected. Each area links onward to a fuller explanation elsewhere in this glossary.

Key takeaways

  • Cybersecurity is people, process, and technology together. Tools alone don't produce security, and neither do policies nobody follows.
  • It spans several domains. Network, endpoint, identity, cloud, application, and data security each address a different part of the same problem.
  • The goal is managed risk, not zero risk. No organization is unbreachable, so the realistic aim is to reduce likelihood and limit impact.
  • Prevention alone is no longer enough. Attackers increasingly use valid credentials and legitimate tools, which means detection and response have become essential rather than optional.
  • Regulation now sets a floor. In Europe in particular, obligations around incident reporting, resilience, and data protection have turned parts of cybersecurity from good practice into legal requirement.

What cybersecurity covers

The field is usually divided into domains, less because the boundaries are sharp than because organizations need to allocate responsibility. Most real incidents cross several of them.

Cybersecurity domains
Domain What it covers
Network security Protects traffic, network devices, segmentation, remote access, and the services exposed to or reachable from the network.
Endpoint security Protects laptops, servers, mobile devices, and other endpoints with controls such as EDR, antivirus, and device management.
Identity and access security Controls who can access which systems and under what conditions, using capabilities such as IAM, MFA, privileged access management, and ZTNA.
Cloud security Protects cloud infrastructure, workloads, containers, SaaS applications, and the identities and configurations that control them.
Application security Builds security into software development and protects applications from vulnerabilities, insecure configurations, and supply chain attacks.
Data security Protects data through classification, encryption, access controls, loss prevention, retention, and secure deletion.
Operational technology security Protects industrial control systems, connected machinery, and SCADA environments where availability and safety are as important as confidentiality.

Two areas cut across all of them. Governance and risk management decide what gets protected and to what standard, and security operations provide the continuous monitoring, detection, and response that keep the rest honest.

The threats cybersecurity addresses

The threat landscape is broad but the recurring categories are limited enough to be worth knowing:

  • Malware, software built to do harm, including information stealers, loaders, and remote access tools that give an attacker control of a system.
  • Ransomware, which encrypts systems and increasingly steals data first, so that the pressure to pay survives a successful restore.
  • Phishing and social engineering, which target people rather than software and remain the most common route into an organization.
  • Credential theft and account takeover, where an attacker uses valid credentials, producing activity that looks legitimate to most controls.
  • Vulnerability exploitation, particularly of internet-facing systems, which lets an intrusion begin without anyone in the organization doing anything.
  • Insider risk, covering both deliberate misuse and the far more common case of someone making a mistake with access they legitimately hold.
  • State-linked espionage, conducted by well-resourced groups pursuing intelligence rather than money, and generally patient enough to be hard to notice.
  • Denial of service, which attacks availability rather than data, sometimes accompanied by extortion.

What most of these have in common is that they don't rely on defeating strong technology. They rely on finding something unpatched, someone willing to help, or a credential that still works.

How organizations practise cybersecurity

In practice a security programme rests on three things that have to work together, and it fails when one is treated as a substitute for the others.

People. Skilled staff to run detection and response, and a wider workforce that recognizes the techniques aimed at them. The shortage of experienced security practitioners is a genuine constraint, which is why many organizations rely on external providers for round-the-clock coverage.

Process. Documented procedures for handling incidents, patching, granting and revoking access, and recovering from disruption. Processes decided in advance are what allow a team to act quickly rather than improvise under pressure, and untested procedures tend not to survive contact with a real incident.

Technology. Preventive controls that reduce the attack surface, and detective capability that surfaces what gets through. A security operations centre, or SOC, is the function that brings this together, combining monitoring platforms with the analysts who investigate what those platforms surface. It's worth being precise here, because the terms get muddled: a SOC is a team and a function, while a security information and event management platform, or SIEM, is one of the tools that team uses.

Why prevention alone is no longer enough

For a long time cybersecurity was understood mainly as keeping attackers out: a strong perimeter, patched systems, filtered email. Those controls still matter and still stop a great deal. What's changed is the proportion of intrusions they don't stop.

A growing share of attacks involve no malicious file and no exploited vulnerability. An attacker with a stolen password logs in and looks like an employee. An attacker using tools already installed on a system generates activity that resembles administration. An attacker who has persuaded someone to install remote access software has been helped rather than resisted. Preventive controls are designed to make judgments about whether something is permitted, and in each of these cases the answer they arrive at is yes.

That's why detection and response have moved from advanced practice to baseline requirement. The relevant question stops being whether an action is allowed and becomes whether it makes sense: whether this account normally behaves this way, whether this process should be running here, whether this data should be moving now. Answering that requires visibility across the whole environment rather than at its edges, and it requires knowing how attackers currently operate, which is the function of cyber threat intelligence.

Cybersecurity and European regulation

For organizations operating in Europe, a significant part of what cybersecurity now requires is set out in law rather than in best practice, and this is one of the areas where the picture differs meaningfully from the one described by most large vendors.

The NIS2 Directive substantially widened the range of sectors expected to meet baseline security requirements and to report significant incidents within defined timeframes, and it attached management accountability to those obligations. The General Data Protection Regulation, which is a data protection instrument rather than a security one, nonetheless imposes security expectations on personal data and its own breach notification duties. In financial services, the Digital Operational Resilience Act sets requirements around operational resilience and third-party risk, reflecting a concern with continuity rather than confidentiality alone. And the Cyber Resilience Act extends obligations to the security of products with digital elements, shifting some responsibility toward manufacturers.

Two practical consequences follow. Incident detection and reporting capability is now a compliance matter as well as a security one, because an obligation to report within a fixed period presupposes the ability to notice. And where data is processed and stored has become a live question, which is the substance behind the interest in data sovereignty rather than a marketing theme.

Why cybersecurity is an operational discipline rather than a purchase

The most common structural mistake in cybersecurity is treating it as a procurement problem. Tools get bought, deployed, and assumed to be working, and the organization discovers during an incident that alerts were going somewhere nobody read, that a control had been disabled during a project, or that the backup nobody had restored from didn't work. Security isn't a state a business reaches by acquiring the right products. It's a set of activities somebody has to keep performing.

Sekoia is a European cybersecurity vendor, and the way it approaches this is worth stating plainly because it follows from the argument above rather than from a product roadmap. Its AI SOC platform brings detection, native cyber threat intelligence produced by an in-house Threat Detection & Research (TDR) team, and automated response into one place, with detection built on behaviour mapped to the MITRE ATT&CK framework rather than on recognizing known files. The reason for that design is the one described earlier: an attacker using valid credentials and legitimate tools leaves behaviour to detect but not much else. As a European vendor, Sekoia also processes that telemetry under European jurisdiction, which matters more to organizations subject to the regulations above than it did a few years ago.

For anyone starting from this page, the useful next step isn't a list of products. It's to work out which of the domains above your organization can actually see into, what would happen if a credential were stolen tomorrow, and who would notice. Those three questions locate most of the gap between a security programme that exists on paper and one that works.