Cybersecurity the basics. Ethnus Codemithra article cover.

What is cybersecurity? Types, threats and the CIA triad

Codemithra Team

Codemithra Team

Cybersecurity protects networks, devices and data from unauthorised access or criminal use. It aims to keep information confidential, accurate and available when it is needed, a goal security teams call the CIA triad. That is the working definition used by the US Cybersecurity and Infrastructure Security Agency (CISA). Common threats include phishing, ransomware, malware, insider threats and man-in-the-middle attacks. This article expands on each of these, and also covers the main types of cybersecurity work.

Why cybersecurity matters more each year

The cost of getting this wrong keeps rising. The IBM 2026 Cost of a Data Breach Report puts the global average cost of a breach at $4.99 million. That is a 12% increase over the previous year and a record high, per the official IBM report. In the United States the average cost reaches $11.5 million, according to coverage of the same IBM report. Those figures cover investigation, lost business, downtime and reputational recovery.

Demand for defence grows at a similar pace. MarketsandMarkets projects the global cybersecurity market to grow from $227.59 billion in 2025 to $351.92 billion by 2030. That is a 9.1% annual growth rate, per its market forecast. On the crime side, the FBI Internet Crime Complaint Center recorded 1,008,597 complaints in 2025. Reported losses reached $20.877 billion, a 26% rise over 2024, per the 2025 IC3 Annual Report.

The CIA triad: how security professionals frame the problem

Security teams do not defend against everything equally. They organise the work around three properties, known together as the CIA triad. These are formally defined in the US FIPS 199 standard. Confidentiality means keeping authorised restrictions on who can access or see information. Integrity means guarding against improper change or destruction of information, including proof of where it came from. Availability means making sure the right people can reach information reliably when they need it.

Each pillar has a matching failure mode, and FIPS 199 defines those too. A loss of confidentiality shows up as unauthorised disclosure. A loss of integrity shows up as unauthorised modification or destruction. A loss of availability shows up as disrupted access. Every control an organisation puts in place maps back to one of these three properties. A password policy and a backup schedule are two everyday examples.

The CIA triad. Confidentiality: Preserving authorised restrictions on information access and disclosure. Failure looks like unauthorised disclosure.. Integrity: Guarding against improper modification or destruction of information. Failure looks like unauthorised modification or destruction.. Availability: Ensuring timely and reliable access to and use of information. Failure looks like disrupted access.
The CIA triad, with the failure that follows when each property is lost. Source: FIPS 199, quoting 44 U.S.C. Sec. 3542.

Five cyber threats you are likely to meet

Most incidents trace back to a small set of well-understood threats. Here is how each one actually works, not just its name.

  • Phishing. A form of social engineering that uses email or a fake website to pose as a trustworthy organisation, per CISA. The goal is to collect personal information. The victim enters credentials on the fake page, and the attacker uses them to take over the account.
  • Ransomware. An evolving form of malware that encrypts files on a device, making them unusable, per the CISA Ransomware 101 guide. Attackers demand a ransom for decryption. Many now also threaten to leak the stolen data if the ransom goes unpaid.
  • Malware. CISA's term for unwanted files or programs that can damage a computer or expose the data on it. The category includes viruses, worms and Trojan horses, per CISA. Running the file is usually enough to grant the attacker access or cause damage.
  • Insider threat. The risk that someone with authorised access uses it to cause harm, knowingly or unknowingly, per CISA. An insider is anyone who currently has, or previously had, that access. The threat does not need malicious intent to cause real damage.
  • Man-in-the-middle attack. An attack where the adversary positions itself between a user and a system, per the NIST glossary. From there it can intercept and alter the data travelling between them. Neither side may notice a third party reading or changing the traffic.

These threats are not equally common. In 2025, phishing and spoofing was the largest crime type IC3 tracked by complaint count, at 191,561 complaints. Ransomware complaints numbered only 3,611. Even so, they caused $32,320,105 in reported losses, per the 2025 IC3 Annual Report. Investment fraud was the costliest category overall, at $8.65 billion.

How five common threats play out. Phishing: A deceptive message asks the reader to enter credentials, which the attacker then uses to take over the account. Then Ransomware: Initial access lets an attacker encrypt files, then demand a ransom and sometimes threaten to leak the stolen data. Then Malware: A malicious file or program runs on a device, granting unauthorised access or causing direct damage. Then Insider threat: Someone with authorised access misuses it, wittingly or unwittingly, causing harm to data or systems. Then Man-in-the-middle: An attacker positions itself between two parties to intercept and alter the traffic passing between them.
How each threat actually plays out, step by step. Sources: CISA and NIST definitions cited above.

Types of cybersecurity: what each domain protects

Cybersecurity covers several distinct areas of work. Each protects a different part of an organisation. The IBM cybersecurity overview groups this work into domains such as the six below. Treat this as one widely used way to divide the field, not a single official standard. Neither CISA nor NIST publishes one universal numbered list.

Domain What it protects Typical control example Source
Network security Servers, connections and devices that make up a network Firewalls and network segmentation CISA
Application security Software, from design through to everyday use Secure code review and application testing IBM
Cloud security Data and infrastructure hosted with a cloud provider Identity-based access policies and encryption IBM
Endpoint security Laptops, phones and other devices that connect to a network Endpoint detection and response software IBM
Identity security Accounts and credentials used to reach systems and data Multi-factor authentication IBM
Critical infrastructure security Physical and digital systems that power and water utilities depend on Strict access control on operational technology CISA

Network security itself already spans servers, cloud systems and connected devices, per CISA's guidance on securing networks. That overlap is normal, not a contradiction. One incident can touch several domains at once. A phishing email that leads to ransomware on a cloud server is a common example.

A five-minute self-check using the CIA triad

Before you read further, run this exercise on one account or device you use daily. Your email or your laptop both work well for this.

  1. Confidentiality. Who else could see your password if it leaked today. Do you reuse that password anywhere else.
  2. Integrity. If a file changed without your knowledge, would you notice. Do you have a way to check that a download has not changed.
  3. Availability. If this device failed right now, could you recover your data within an hour. When did you last test a backup, not just create one.

A weak answer to any question points to a real gap, not a hypothetical one. This is the same reasoning a security team applies at organisation scale. It simply starts from one account instead of thousands.

Who works in cybersecurity, and how the Codemithra CSA course teaches it

One common entry-level and intermediate role is the Security Operations Center (SOC) analyst. This person monitors an organisation's systems, investigates alerts and responds to incidents. Codemithra runs a live Certified Security Operations Center Analyst (CSA) course built for this role. It targets current and aspiring Tier I and Tier II SOC analysts.

The course runs 150 hours across six sections and 39 lessons. It prepares students for the EC-Council Certified SOC Analyst exam. The six syllabus modules cover security operations and management, cyber threats and attack methodology, and incidents, events and logging. The remaining three cover SIEM incident detection, threat intelligence, and incident response. The course includes trainer-led sessions, industry-relevant projects, quizzes and assignments, and placement assistance. It currently lists 635 students enrolled with a 4.6 out of 5 rating on the Codemithra courses page.

This article covers the fundamentals under that syllabus, such as the CIA triad and the five threats above. It does not cover exam preparation itself. Ethnus, the group behind Codemithra, reached the milestone of training over 5 lakh students across all its courses. It names cybersecurity among its focus areas, alongside cloud computing, IoT, AI and machine learning, per the Ethnus about page.

Frequently asked questions

What is cybersecurity?

Cybersecurity is the practice of protecting networks, devices and data from unauthorised access or criminal use. It keeps information confidential, accurate and available, per the CISA definition.

What are the main types of cyber threats?

This article covers five threats. They are phishing, ransomware, malware, insider threats and man-in-the-middle attacks. Each has its own mechanism, described above with a CISA or NIST source.

What are the types of cybersecurity, and is there one official list?

No single CISA or NIST document publishes one numbered list. A current industry grouping from IBM covers network, application, cloud, endpoint, identity and critical infrastructure security. See the table above for what each one protects.

What does a SOC analyst do?

A SOC analyst monitors an organisation's systems, investigates security alerts and helps respond to incidents. The Codemithra CSA course trains for this role across six modules. These cover operations, threat methodology, logging, SIEM detection, threat intelligence and incident response.

To move from these fundamentals toward SOC analyst skills, start with the Certified Security Operations Center Analyst (CSA) course on Codemithra.

About the Author

Read More

Ethnus User Agreement

I agree to submit my personally identifiable information to Ethnus, who may use it to communicate regarding their events, courses, and other services through various media including phone calls, text messages, email, and social media. I also agree with Ethnus' Privacy Policy and Terms of Service.

I agree with Ethnus sharing my personal data, including email address, with Salesforce family of companies, who may contact me for sales and marketing purposes and as described in Salesforce's Privacy Statement.

Privacy Policy

This Privacy Notice describes how we collect and use your personal information in relation to Ethnus websites, applications, products, services, events, and experiences that reference this Privacy Notice (together, "Ethnus Offerings").

This Privacy Notice does not apply to the "content" processed, stored, or hosted by our customers using Ethnus Offerings in connection with an Ethnus account. This Privacy Notice also does not apply to any products, services, websites, or content that are offered by third parties or have their own privacy notice.

Personal Information We Collect

We collect your personal information in the course of providing Ethnus Offerings to you.

Here are the types of information we gather:

        a) Information You Give Us: We collect any information you provide in relation to Ethnus Offerings. Click here to see examples of information you give us. Example: Name, email, phone, etc.

        b) Automatic Information: We automatically collect certain types of information when you interact with Ethnus Offerings. Example: IP address, location, browser identity, etc.

        c) Information from Other Sources: We might collect information about you from other sources, including service providers, partners, and publicly available sources. Example: marketing analytics, keywords, etc.

How We Use Personal Information

We use your personal information to operate, provide, and improve Ethnus Offerings. Our purposes for using personal information include:

        a) Provide Ethnus Offerings: We may use your personal information to provide and deliver Ethnus Offerings and process transactions related to Ethnus Offerings, including registrations, subscriptions, purchases, and payments.

        b) Measure, Support, and Improve Ethnus Offerings: We use your personal information to measure use of, analyze the performance of, fix errors in, provide support for, improve, and develop Ethnus Offerings.

        c) Recommendations and Personalization: We use your personal information to recommend Ethnus Offerings that might be of interest to you, identify your preferences, and personalize your experience with Ethnus Offerings.

        d) Comply with Legal Obligations: In certain cases, we have a legal obligation to collect, use, or retain your personal information.

        e) Communicate with You: We use your personal information to communicate with you in relation to Ethnus Offerings via different channels (e.g., by phone, email, chat) and to respond to your requests.

        f) Marketing: We use your personal information to market and promote Ethnus Offerings. We might display interest-based ads for Ethnus Offerings.

        g) Purposes for Which We Seek Your Consent: We may also ask for your consent to use your personal information for a specific purpose that we communicate to you.

Cookies

To enable our systems to recognize your browser or device and to provide Ethnus Offerings, we use cookies.

How We Share Personal Information

Information about our customers is an important part of our business and we are not in the business of selling our customers' personal information to others. We share personal information only as described below and with Ethnus Consultancy Services Private Limited, . and its affiliates that are either subject to this Privacy Notice or follow practices at least as protective as those described in this Privacy Notice.

Transactions Involving Third Parties: We make available to you services, software, training, and content provided by third parties for use on or through Ethnus Offerings. You can tell when a third party is involved in your transactions, and we share information related to those transactions with that third party. For example, you can order services, software, and content from sellers using the Authorized Training Partner's marketplace and we provide those sellers information to facilitate your subscription, purchases, or support.

Other than as set out above, you will receive notice when personal information about you might be shared with third parties, and you will have an opportunity to choose not to share the information.

How We Secure Information

        a) We protect the security of your information during transmission to or from websites, applications, products, or services by using encryption protocols and software.

        b) We maintain physical, electronic, and procedural safeguards in connection with the collection, storage, and disclosure of personal information.

Internet Advertising and Third Parties

Ethnus Offerings may include third-party advertising and links to other websites and applications. Third party advertising partners may collect information about you when you interact with their content, advertising, or services. For more information about third-party advertising, including interest-based ads, please read our Interest-Based Ads notice.

Access and Choice

You have choices about the collection and use of your personal information. Many Ethnus Offerings include settings that provide you with options as to how your information is being used. You can choose not to provide certain information, but then you might not be able to take advantage of certain Ethnus Offerings.

        a) Communications: If you do not want to receive promotional messages from us, please unsubscribe or adjust your communication preferences in the emails.

        b) Advertising: If you don't want to see interest-based ads, please adjust your Advertising Preferences.

        c) Browser and Devices: The Help feature on most browsers and devices will tell you how to prevent your browser or device from accepting new cookies, how to have the browser notify you when you receive a new cookie, or how to disable cookies altogether.

Children's Personal Information

We don't provide Ethnus Offerings for purchase by children. If you're under 18, you may use Ethnus Offerings only with the involvement of a parent or guardian.

Retention of Personal Information

We keep your personal information to enable your continued use of Ethnus Offerings, for as long as it is required in order to fulfill the relevant purposes described in this Privacy Notice, as may be required by law (including for tax and accounting purposes), or as otherwise communicated to you. How long we retain specific personal information varies depending on the purpose for its use, and we may delete your personal information in accordance with applicable law.

Contacts, Notices, and Revisions

If you have any concern about privacy at Ethnus, you may also contact us at the addresses below:

Ethnus Consultancy Services Pvt Ltd,

SST Chambers, No.151/17/1 Second Floor, 36th Cross Rd, 5th Block, Jayanagar, Bengaluru, Karnataka 560041

Or, email us at [email protected]

Or call us at: +91 - 8929 334 324

You will find the updated contact information on our website: www.ethnus.com/contact/

If you interact with Ethnus Offerings on behalf of or through your organization, then your personal information may also be subject to your organization's privacy practices, and you should direct privacy inquiries to your organization.

Our business changes constantly, and our Privacy Notice may also change. You should check our website frequently to see recent changes. You can see the date on which the latest version of this Privacy Notice was posted. Unless stated otherwise, our current Privacy Notice applies to all personal information we have about you and your account. We stand behind the promises we make, however, and will never materially change our policies and practices to make them less protective of personal information collected in the past without informing affected customers and giving them a choice.

Terms & Conditions

This Privacy and Security Policy is provided for the benefit of customers and clients of Ethnus Consultancy Services Private Limited. ("Ethnus") as well as other consumers and parties who use Ethnus and/or its website(s), particularly codemithra.com ("Website", "www.codemithra.com", "Codemithra" or "Ethnus Codemithra"), and/or applications ("Apps") (collectively, "Ethnus Services" or "Ethnus Platform").

Since Ethnus serves several different audiences, customers find it helpful to read the Terms of Use that apply specifically to them based upon the purpose for which they use Ethnus. For this reason, we link to three separate agreements below for employer customers, job seeker customers, and staffing customers, respectively.

For your convenience, we define each of these audiences that Ethnus serves as follows:

"Employer Customer" means an entity using Ethnus Services that is seeking to hire an individual as an employee and/or independent contractor to be employed by it directly.

"Job Seeker Customer" means an individual using Ethnus Services who is seeking to be employed as an employee or independent contractor by an employer.

"Staffing Customer" means a staffing company using Ethnus Services that provides staffing services to their own Staffing Clients.

So long as your use of the Ethnus website and services remains within the scope of the particular audience or customer for which you began using Ethnus (e.g. a job seeker does not use Ethnus as an employer, or an employer does not use Ethnus as a job seeker), the complete Terms of Use applicable to your use of the Ethnus website and services is contained within the applicable Terms of Use linked below.

Employer Terms of Use

The following Terms of Use apply to any Ethnus Employer Customer seeking to hire employees or independent contractors for its own business. If you seek to find employees or independent contractors for the benefit of your clients (and not yourself), you need to review the Terms of Use specifically for our Ethnus Staffing Customers accessible at www.Codemithra.com/terms/staffing.

Ethnus, Inc. ("Ethnus") provides online services through which employers and staffing companies seeking employees and independent contractors can efficiently and effectively review and interview candidates. Ethnus provides these services and its suite of features and products through its Apps and Website (collectively, "Ethnus Services") subject to these terms of use ("Terms of Use") and the agreements incorporated herein.

Your privacy is very important to us. We designed our accompanying Privacy and Security Policy to provide important disclosures about how your information will be used by Ethnus in providing you Ethnus Services. These Terms of Use expressly incorporate our Privacy and Security Policy.

Please read these Terms of Use and our Privacy and Security Policy carefully before using any of the diverse Ethnus Services. By visiting the Website, installing any of the Apps, and/or using any of the Ethnus Services, you shall have affirmed your agreement to these Terms of Use.

1. Definitions

2. Modifications - Will Ethnus ever modify these Terms of Use?

3. Ethnus Services - What are the Ethnus Services?

4. Video Content and Services - How and when do you record videos?

5. Pricing, Payments, and Billing - How and when will I be billed for Ethnus Services?

6. Objectionable Content - What if I find content to be objectionable?

7. Customer Conduct

8. Intellectual Property

9. DMCA Policy

10. Reserved for Future Use

11. Resale of Services

12. Indemnification

13. Disclaimer of Warranties

14. Third Party Links and Products

15. Limitations of Liability

16. Exclusions and Limitations

17. General Terms

1. Definitions

"Consumer" means any individual or entity that uses any of the Ethnus Services. Where applicable, the term "Consumer" shall encompass all Ethnus Customers.

"Content" means all material, whether publicly posted or privately transmitted, available on or through any of the Ethnus Services.

"Customer" means, for purposes of this Terms of Use, You, a Job Seeker Customer.

"Customer Content" means any Content uploaded to and/or created through the Ethnus Services by a Ethnus Customer.

"Employer Customer" means an entity using Ethnus Services that is seeking to hire an individual as an employee and/or independent contractor to be employed by it directly.

"GDPR" means the European Union's General Data Protection Regulation.

"Job Seeker Customer" means an individual using Ethnus Services who is seeking to be employed as an employee or independent contractor by an employer.

"Profile Video" means a promotional video created by a Job Seeker Customer to promote themselves as a candidate employee and/or independent contractor. It is not an interview. The Job Seeker Customer completes this independently and on their own.

"Software" means any necessary software used in connection with the Ethnus Services.

"Ethnus Account" means an account associated with a Ethnus Customer who uses or has used Ethnus Services.

"Ethnus Content" means any Content excluding Customer Content and Video Content in which Ethnus does not participate.

"Ethnus Customer" means any person who uses or has used Ethnus Services including, but not limited to, Employer Customers, Job Seeker Customers, and Staffing Customers.

"Ethnus Services" means the suite of features, products and services offered through Ethnus, its Apps, its App Services, the Website, and the Website Services.

"Ethnus Trademarks" means any trademarks, tradenames, logos, and other commercial designs of Ethnus or licensed to Ethnus, whether or not formal registration exists including, but not limited to, "Ethnus."

"Staffing Clients" means third-party employer clients of Staffing Customers.

"Staffing Customer" means a staffing company using Ethnus Services that provides staffing services to their own Staffing Clients.

"Strategic Partners" means those trusted partners that Ethnus employs, engages, or retains to perform functions and/or provide services on its behalf.

"Sub Accounts" means subsidiary accounts created for or by an Employer Customer or Staffing Customer ("such as a consultant group or employer") under its primary account.

"Username" means the valid email address provided by each Ethnus Customer to be used as their username or login identification.

"Video Content" means any video content created by or associated with any Ethnus Customer accessible on and through Ethnus Services including, but not limited to, Profile Videos, Video Questions, Video Interviews, and Welcome Videos.

"Video Interview" means an interview completed through Ethnus Services using a video or "web" camera that an Employer Customer or Staffing Customer requests a Job Seeker Customer complete. A Video Interview may involve a Job Seeker Customer alone or with other participants from an Employer Customer or Staffing Customer. A Video Interview may be pre-recorded by a Job Seeker in response to questions or occur live at which time it would be recorded.

"Video Question" means a question recorded in video and audio that can be sent to potential employee and independent contractor candidates by an Employer Customer or Staffing Customer.

"Website" means all of the content, information and services (in any format whatsoever) accessible through the World Wide Web at the domain name Codemithra.com.

"Website Services" means the services provided by Ethnus through the website at the domain name Codemithra.com, hire.li, and any of our other websites that may be used from time to time