Computer Security Basics

Computers and mobile devices store important information such as:

  • Personal photographs
  • Passwords
  • Bank details
  • School or business documents
  • Emails
  • Contact information
  • Website data

If this information is stolen, changed, deleted or made unavailable, it can cause serious problems. Computer security protects devices, accounts, software and data from these dangers.

This is a pillar page that introduces the main computer-security topics. Each topic can be studied separately in more detail.

What Is Computer Security?

Computer security is the practice of protecting computers, software, accounts and data against:

  • Unauthorized access
  • Theft
  • Damage
  • Modification
  • Destruction
  • Disruption
  • Cyberattacks

NIST defines computer security as the measures and controls that protect the confidentiality, integrity and availability of information processed and stored by computers. (NIST Computer Security Glossary)

Simple Definition

Computer security means protecting a computer and its information from unauthorized access, damage, theft and misuse.

Real-Life Example of Computer Security

Think about how you protect your house.

House SecurityComputer Security
Door lockPassword
Second lockMulti-Factor Authentication
Security guardFirewall
CCTV cameraSecurity monitoring
Alarm systemAntivirus alerts
Repairing a broken windowInstalling a security update
Spare keyData backup
Locked cupboardEncryption
Permission to enter a roomAccess control

A house is not protected by only one lock. Similarly, a computer should use several layers of security.

flowchart TD
    A["Computer and data"]
    A --> B["Strong authentication"]
    B --> C["Updated software"]
    C --> D["Antivirus and firewall"]
    D --> E["Backups and recovery"]

Why Is Computer Security Important?

Computer security helps to:

  • Protect personal information
  • Stop account theft
  • Prevent financial loss
  • Protect business and school data
  • Keep systems working
  • Prevent malware infections
  • Maintain user privacy
  • Stop unauthorized changes
  • Protect an organization’s reputation
  • Recover from security incidents

Real-Life Example

Suppose a student stores all assignments on a laptop.

If ransomware locks the laptop and no backup exists, the student may lose months of work. Regular backups, updates and safe browsing can reduce this risk.

Main Goals of Computer Security

The three main goals of computer security are called the CIA Triad.

CIA stands for:

  1. Confidentiality
  2. Integrity
  3. Availability
flowchart TD
    A["Computer Security"]
    A --> B["Confidentiality"]
    A --> C["Integrity"]
    A --> D["Availability"]

NIST recognizes confidentiality, integrity and availability as the three central security properties. (NIST CSRC)

1. Confidentiality

Confidentiality means information should be accessed only by authorized people.

It can be protected using:

  • Passwords
  • Multi-Factor Authentication
  • Encryption
  • Access controls
  • File permissions
  • Screen locks

Real-Life Example

Your bank statement should be visible to you and authorized bank employees. It should not be available to strangers.

2. Integrity

Integrity means information should remain accurate, complete and trustworthy.

Data should not be changed without permission.

Integrity can be supported using:

  • File permissions
  • Digital signatures
  • Hashing
  • Change logs
  • Version history
  • Backups

Real-Life Example

If a student receives 85 marks, an unauthorized person should not be able to change the result to 35 or 95.

3. Availability

Availability means authorized users should be able to access systems and information when needed.

Availability can be supported using:

  • Regular backups
  • Reliable hardware
  • Security updates
  • Backup power
  • Multiple servers
  • Disaster-recovery plans
  • Protection against denial-of-service attacks

Real-Life Example

A hospital’s computer system should remain available when doctors need patient information during an emergency.

Threat, Vulnerability and Risk

These three terms are related but different.

TermMeaningReal-Life Example
AssetSomething valuable that needs protectionLaptop or personal files
ThreatSomething that could cause harmThief
VulnerabilityA weakness that could be exploitedUnlocked window
RiskPossibility and impact of the threat causing harmThief entering through the window
Security controlProtection that reduces riskLocking the window

NIST defines a vulnerability as a weakness that a threat source could exploit. Risk considers both the possible impact and likelihood of an unwanted event. (NIST Vulnerability Glossary, NIST Risk Glossary)

The basic relationship is:

flowchart LR
    A["Threat"] --> B["Exploits vulnerability"]
    B --> C["Creates security risk"]
    C --> D["Security controls reduce risk"]

Common Computer Security Threats

Malware

Malware means malicious software created to steal information, damage devices, spy on users or disrupt systems.

Common types include:

  • Virus
  • Worm
  • Trojan
  • Spyware
  • Adware
  • Ransomware
  • Rootkit
  • Keylogger

CISA describes malware as software used to gain unauthorized access, steal data, disrupt services or damage IT systems. (CISA)

Real-Life Example

A user downloads a “free game” from an unknown website. The file secretly installs spyware that records the user’s activity.

Computer Virus

A virus attaches itself to a file or program and spreads when that infected file is opened.

Real-Life Example

A student copies an infected file to a USB drive and opens it on another computer. The virus may then infect the second computer.

Computer Worm

A worm can copy itself and spread across networks without attaching itself to another file.

Real-Life Example

A worm finds an unpatched weakness in one office computer and automatically spreads to other computers on the same network.

Trojan Horse

A Trojan appears to be useful or harmless software but contains malicious code.

Real-Life Example

A program named “Free PDF Converter” works like a normal tool but secretly steals saved passwords.

Ransomware

Ransomware is malware that blocks access to files or systems, often by encrypting them, and demands payment.

CISA defines ransomware as malware designed to encrypt files and make the affected data or systems unusable. (CISA Stop Ransomware)

Real-Life Example

A business employee opens a malicious attachment. The ransomware encrypts company documents and demands money for a decryption key.

Phishing

Phishing is an attack in which criminals pretend to be a trusted person or organization.

Phishing can arrive through:

  • Email
  • Text message
  • Phone call
  • Social media
  • Fake website
  • QR code

Real-Life Example

A user receives a message saying:

“Your bank account will be blocked. Log in immediately.”

The link opens a fake banking page that steals the username and password.

Social Engineering

Social engineering means manipulating people into revealing information or performing an unsafe action.

An attacker may use:

  • Fear
  • Urgency
  • Curiosity
  • Authority
  • Trust
  • Greed

Real-Life Example

Someone calls an employee and says:

“I am from the IT department. Tell me your verification code so I can fix your account.”

The attacker is targeting the person rather than directly attacking the computer.

Password Attacks

Attackers may try to steal or guess passwords using:

  • Brute-force attacks
  • Dictionary attacks
  • Password spraying
  • Credential stuffing
  • Phishing
  • Keyloggers

Reusing one password across several accounts is dangerous. If one website suffers a breach, attackers may try the same password on email, banking and social-media accounts.

Software Vulnerabilities

A vulnerability is a weakness in software, hardware or configuration.

Attackers may exploit vulnerabilities to:

  • Run malicious code
  • Steal information
  • Take control of a device
  • Stop a service
  • Increase their access

Updates and security patches fix many known vulnerabilities. The UK NCSC recommends keeping devices and software updated to prevent known weaknesses from being exploited. (NCSC)

Unsafe Downloads and Websites

Files downloaded from untrusted sources may contain malware.

Dangerous downloads may appear as:

  • Free software
  • Cracked applications
  • Game modifications
  • Fake browser updates
  • Email attachments
  • Pirated films
  • Unknown mobile applications

Download software from official websites or trusted application stores whenever possible.

Network Attacks

Attackers may target a network to:

  • Intercept information
  • Access connected devices
  • Redirect traffic
  • Disrupt services
  • Spread malware

Weak Wi-Fi passwords, outdated router software and unsafe public networks can increase risk.

Denial-of-Service Attack

A Denial-of-Service attack attempts to make a system or service unavailable.

Real-Life Example

Imagine thousands of fake customers blocking the entrance to a shop. Genuine customers cannot enter.

Similarly, an attacker may send excessive traffic to a website so real users cannot access it.

Insider Threat and Human Error

Security incidents are not always caused by external hackers.

Problems can also result from:

  • Accidental deletion
  • Sending information to the wrong person
  • Weak passwords
  • Incorrect permissions
  • Lost devices
  • Malicious employees
  • Misconfigured systems

Real-Life Example

An employee accidentally sends a confidential salary file to the wrong email address.

Physical Threats

Computer security also includes physical protection.

Physical threats include:

  • Laptop theft
  • Fire
  • Flood
  • Power failure
  • Hardware damage
  • Unauthorized entry
  • Stolen USB drives

Security measures may include:

  • Door locks
  • CCTV
  • Device locks
  • Secure storage
  • Backup power
  • Off-site backups

Main Types of Computer Security

Security AreaWhat It Protects
Hardware securityPhysical computer components
Software securityOperating systems and applications
Data securityFiles, records and databases
Network securityNetworks, routers and network traffic
Endpoint securityLaptops, desktops and mobile devices
Internet securityOnline activity, browsing and communication
Application securityPrograms, websites and mobile applications
Cloud securityOnline storage and cloud services
Account securityUser identities and login credentials
Physical securityDevices, buildings and server rooms

Authentication and Authorization

Authentication and authorization are different security processes.

Authentication

Authentication checks who you are.

Examples:

  • Password
  • Fingerprint
  • Face recognition
  • Security key
  • One-time code

Authorization

Authorization decides what an authenticated user is allowed to do.

Examples:

  • Student can read a lesson.
  • Teacher can edit the lesson.
  • Administrator can manage users.

NIST defines authentication as verifying the identity of a user, process or device. Authorization refers to the permissions granted to access a resource. (NIST Authentication, NIST Authorization)

Real-Life Example

At an airport:

  • Showing your passport proves your identity: authentication.
  • Your boarding pass decides which flight you can enter: authorization.

Basic Computer Security Measures

Use Strong and Unique Passwords

A good password should be:

  • Long
  • Unique for every account
  • Difficult to guess
  • Stored securely

A password manager can create and store strong passwords.

Avoid using:

  • Your name
  • Date of birth
  • 123456
  • password
  • The same password everywhere

CISA recommends using long, random and unique passwords, preferably managed through a password manager. (CISA)

Enable Multi-Factor Authentication

Multi-Factor Authentication, or MFA, requires an additional verification method besides a password.

It may use:

  • Authenticator application
  • Passkey
  • Security key
  • Fingerprint
  • Face recognition
  • One-time code

Real-Life Example

A password is like the key to your house. MFA is like requiring both the key and a fingerprint before opening the door.

CISA recommends enabling MFA because it adds protection beyond a password. (CISA)

Install Security Updates

Updates may fix security weaknesses in:

  • Operating systems
  • Browsers
  • Applications
  • Mobile devices
  • Routers
  • Security software

Enable automatic updates when appropriate and install important updates promptly.

Use Antivirus or Endpoint Protection

Antivirus software can help:

  • Detect malware
  • Block suspicious files
  • Scan downloads
  • Quarantine infected files
  • Warn about known threats

Antivirus should be kept updated. It is useful, but it cannot protect against every threat or unsafe decision.

Use a Firewall

A firewall monitors and controls network traffic according to security rules.

It can help prevent unauthorized network connections.

Real-Life Example

A firewall is like a security guard at a building entrance. The guard checks traffic and decides who may enter or leave.

Back Up Important Data

A backup is a separate copy of important data.

You can back up information to:

  • External drive
  • Cloud storage
  • Another secure device
  • Organization’s backup system

At least one important backup should be separated from the main device so malware, theft or hardware failure does not destroy both copies.

The UK NCSC recommends backing up important data such as photographs and documents to an external drive or cloud storage. (NCSC)

Use Encryption

Encryption changes readable data into a protected form.

Only someone with the correct key should be able to read it.

Encryption can protect:

  • Stored files
  • Laptops and phones
  • Online communication
  • Messaging
  • Website traffic

Real-Life Example

Encryption is like placing a letter inside a locked box. Anyone may see the box, but only someone with the correct key can read the letter.

Use a Standard User Account

Avoid using an administrator account for every daily task.

An administrator can make major system changes. Malware running with administrator privileges may also cause greater damage.

Use the principle of least privilege:

Give users and programs only the access they need to complete their work.

Secure Wi-Fi and Routers

Basic Wi-Fi protection includes:

  • Use a strong Wi-Fi password.
  • Change default router administrator credentials.
  • Install router updates.
  • Use modern encryption settings.
  • Disable features you do not need.
  • Do not share the password unnecessarily.
  • Use care on public Wi-Fi.

Lock and Protect Devices

Use:

  • PIN or password
  • Automatic screen lock
  • Device encryption
  • Find-my-device features
  • Secure physical storage

Do not leave an unlocked laptop or phone unattended in a public place.

Check Links and Attachments

Before clicking:

  • Check the sender.
  • Read the real domain.
  • Look for spelling mistakes.
  • Be careful with urgent requests.
  • Do not open unexpected attachments.
  • Verify unusual payment requests separately.

Computer Security Uses Multiple Layers

No single security tool provides complete protection.

flowchart TD
    A["User awareness"]
    A --> B["Passwords and MFA"]
    B --> C["Updates and secure settings"]
    C --> D["Antivirus and firewall"]
    D --> E["Encryption and access control"]
    E --> F["Backups and recovery"]

This approach is called defence in depth. If one layer fails, another layer may still stop or limit the attack.

Cybersecurity Risk Management

Computer security is not only about stopping attacks. It also includes preparation, detection, response and recovery.

The current NIST Cybersecurity Framework 2.0 organizes cybersecurity outcomes into six functions:

flowchart TD
    A["Govern"]
    A --> B["Identify"]
    B --> C["Protect"]
    C --> D["Detect"]
    D --> E["Respond"]
    E --> F["Recover"]
  • Govern: Set security responsibilities, policies and priorities.
  • Identify: Understand devices, data, systems and risks.
  • Protect: Apply safeguards to reduce risk.
  • Detect: Find suspicious activity and incidents.
  • Respond: Control and manage an incident.
  • Recover: Restore systems and improve protection.

These functions provide a complete view of managing cybersecurity risk. (NIST Cybersecurity Framework 2.0)

Signs That a Computer May Be Compromised

Possible warning signs include:

  • Computer suddenly becomes very slow
  • Unknown programs appear
  • Frequent pop-ups
  • Antivirus is disabled
  • Files become encrypted or renamed
  • Browser opens unknown websites
  • Passwords stop working
  • Unknown login alerts appear
  • Messages are sent without permission
  • Unusual network activity
  • Camera or microphone activates unexpectedly

One symptom alone does not always prove an infection, but unexpected behaviour should be investigated.

What to Do If Your Computer or Account Is Hacked

flowchart LR
    A["Notice the problem"] --> B["Contain it"]
    B --> C["Remove the threat"]
    C --> D["Recover safely"]
    D --> E["Improve security"]

Take these basic steps:

  1. Disconnect an infected device from the network if malware may be spreading.
  2. Inform your workplace or school IT team if it is their device or account.
  3. Use a clean device to change affected passwords.
  4. Secure the email account first because it may reset other accounts.
  5. Enable MFA.
  6. Sign out of unknown sessions and devices.
  7. Update the system and security software.
  8. Run a trusted antivirus scan.
  9. Contact the account provider, bank or relevant organization.
  10. Restore files only from a known clean backup.
  11. Preserve important messages, alerts and other evidence.
  12. Seek professional help if the infection cannot be removed safely.

The UK NCSC recommends changing compromised passwords, signing out of devices and enabling two-step verification. (NCSC Hacked Accounts Guidance)

Computer Security vs Cybersecurity

Computer SecurityCybersecurity
Focuses mainly on computers, software and stored dataCovers digital systems, networks, cloud services, devices and online activity
May protect an individual computerCan protect complete organizations and infrastructure
Includes physical and logical protectionIncludes technical, human and organizational risks

The terms overlap, and they are often used interchangeably in beginner-level discussions.

Security vs Privacy

Security and privacy are connected but different.

Security

Security protects information from unauthorized access, damage and theft.

Privacy

Privacy concerns how personal information is collected, used, shared and controlled.

Real-Life Example

A company may secure its customer database against hackers but still collect more personal information than customers expect. The database may be secure, but there may still be a privacy concern.

Daily Computer Security Checklist

  • Use a screen lock.
  • Use unique passwords.
  • Store passwords in a trusted password manager.
  • Enable MFA.
  • Keep automatic updates enabled.
  • Use antivirus and firewall protection.
  • Back up important data.
  • Download software from trusted sources.
  • Check links before clicking.
  • Never share verification codes.
  • Remove applications you no longer use.
  • Review account login activity.
  • Protect administrator accounts.
  • Keep sensitive information encrypted.
  • Report suspicious activity quickly.

CISA’s main public safety actions include recognizing phishing, using strong passwords, enabling MFA and updating software. (CISA Secure Our World)

Topics Covered Under Computer Security

This pillar page connects to the following detailed topics:

  • Malware
  • Viruses, worms and Trojans
  • Ransomware
  • Spyware and keyloggers
  • Phishing
  • Social engineering
  • Password attacks
  • Strong passwords and password managers
  • Multi-Factor Authentication
  • Antivirus software
  • Firewalls
  • Software updates and patching
  • Data backups
  • Encryption
  • Access control
  • Network security
  • Wi-Fi security
  • Safe internet browsing
  • Email security
  • Mobile-device security
  • Physical security
  • Data privacy
  • Incident response and recovery
  • Cyber hygiene

Frequently Asked Questions

What is computer security in simple words?

Computer security means protecting computers, accounts, software and data from theft, damage and unauthorized access.

What are the three goals of computer security?

The three main goals are confidentiality, integrity and availability.

What is the CIA Triad?

The CIA Triad is a security model consisting of confidentiality, integrity and availability.

What is a computer-security threat?

A threat is something that could cause harm to a computer, system or information.

What is a vulnerability?

A vulnerability is a weakness that could be exploited by a threat.

What is malware?

Malware is malicious software created to steal information, damage devices, spy on users or disrupt systems.

Is antivirus enough for complete security?

No. Antivirus is one layer. Strong passwords, MFA, updates, backups, safe behaviour and other security controls are also required.

Why are software updates important?

Updates often fix known weaknesses that attackers could exploit.

What is the difference between authentication and authorization?

Authentication verifies identity. Authorization decides what the verified user is allowed to access.

What is the best way to protect an account?

Use a strong and unique password, enable MFA, keep recovery information updated and avoid suspicious links.

Why are backups important?

Backups help recover information after deletion, hardware failure, theft, ransomware or another incident.

Can computer security remove every risk?

No security system can remove all risk. Good security controls reduce the likelihood and impact of incidents.

Conclusion

Computer security protects devices, accounts, software and information from unauthorized access, theft, modification, damage and disruption.

The main security goals are:

Confidentiality + Integrity + Availability

Effective security requires multiple layers:

Strong authentication + Updates + Safe behaviour + Security tools + Backups

The simplest rule to remember is:

Protect, detect, respond and recover.

Security is not a one-time task. Devices, software, passwords, backups and user habits must be reviewed and improved regularly.

Continue Learning