Threat Spotter
Define cyber security like the mark scheme wants. Then spot the weakness in real scenarios and learn what penetration testing is for.
Work it through together, step by step
A free interactive activity that works the method through with a class, step by step.
Start revising freeWhat you'll cover
Threat Spotter
Systems get attacked because they leave a door open. Your job on this case: know what **cyber security** actually means, learn the everyday weaknesses attackers exploit, and spot them in real situations. First, the definition. Because it is worth easy marks if you state it precisely.
What is cyber security?
**Cyber security** is the processes and practices designed to **protect** computer systems, networks and **data** from **attack, damage or unauthorised access**.
Define it precisely
For one mark, which is the best definition of **cyber security**?
- Protecting computer systems and data from attack or unauthorised access
- A type of antivirus software you install
- Keeping computers safe
- Choosing strong passwords
Where the doors are left open
Most breaches exploit ordinary, avoidable weaknesses. These four are the ones the spec names, so learn them by their exam wording.
Why is each a risk?
- Weak / default passwords
- Misconfigured access rights
- Removable media
- Unpatched software
- Easily guessed, letting attackers log straight in
- Users can reach data they should not
- Can carry malware in, or sensitive data out
- Known security holes are left open
Spot the weakness: the USB
Staff routinely bring in USB sticks from home to move work files between office PCs. Which weakness is that?
- Removable media
- Weak passwords
- Unpatched software
- Misconfigured access rights
Read the audit note
Three of these findings are good practice. Tap the ONE that describes a security weakness.
- Audit notes:
- backups run nightly to an off-site server
- ,
- the Wi-Fi router still uses the login it shipped with, admin and admin
- ,
- all workstations installed last month's security updates
- , and
- staff completed phishing-awareness training in April
Fix the weaknesses
A charity finds that all its staff share one login, and that its servers have not been updated for two years. Pick the TWO actions that directly fix those weaknesses.
- Give every member of staff their own account with a unique password
- Apply the outstanding security updates and keep them current
- Ask staff to make the shared password considerably longer
- Put tape over the webcam on every laptop in the building
- Move the office printer away from the reception desk
Audit the studio
You are auditing a small design studio. Work through what you find, and choose the weakness AND the fix each time.
- Every machine signs in with the same account. The password is `studio2020` and has not changed since the studio opened.
- The studio runs a design package the vendor stopped supporting three years ago.
- The new intern can open the payroll folder on their first morning.
- You have listed the weaknesses you could see. What should the studio do next to be confident none were missed?
Testing your own defences
How does an organisation find these weaknesses before criminals do? **Penetration testing**, or pen testing. Testers deliberately **simulate an attack** on the system, probing it the way a real attacker would, to **find the vulnerabilities** so they can be fixed before they are exploited for real.
Say what it does
Penetration testing simulates an _____ on a system to find its _____ before a real attacker can exploit them.
Why pay for it?
A bank hires an outside firm to try to break into its online banking system, with permission, and report everything it finds. Why is that worth paying for?
- It exposes the vulnerabilities the bank has, so they can be fixed before criminals find them
- It guarantees the system can never be broken into again afterwards
- It makes the online banking system respond faster for its customers
- It removes the bank's legal duty to protect its customers' data
In the exam
Case closed. Grade-9 habits for cyber security fundamentals: • **Define precisely**: cyber security = protecting systems and data from attack / unauthorised access. • Know the **four common weaknesses**: weak/default passwords, misconfigured access rights, removable media, unpatched software, and match a scenario to the right one. • **Penetration testing** = simulate an attack to find vulnerabilities before real attackers do.
Write it up
A small school runs its office PCs on software that stopped receiving updates last year, and every member of staff signs in with the same password. Name the TWO weaknesses this shows, explain the risk of each, and state what penetration testing would add.
- Name each weakness in the spec wording, not as a description of the situation.
- For each one, say what an attacker could actually DO as a result. That is the risk.
- Say what penetration testing IS: a deliberately simulated attack.
- Then say what it is FOR: finding vulnerabilities before real attackers exploit them.
- If you use the term cyber security, define it precisely: protecting systems and data from attack or unauthorised access.