Identity protection
MFA, SSO, privileged access management.
Cybersecurity is the set of practices, controls and technologies that protect systems, data and users against unauthorized access, service disruption and tampering. It covers three inseparable phases: preventing what can be prevented, detecting what gets through anyway, and responding to limit the impact. It is not a product to install but a capability to maintain, organisational as much as technical.
In one sentence
Cybersecurity protects systems, data and users, across prevention, detection and response.
Key points
Term at a glance
It is not a single product: policies, authentication, patching, backups, training and monitoring work together.
For SMEs, the most common risks remain phishing and poorly protected accounts.
Compliance (Law 25, industry norms) sits alongside technical protection.
Critical assets, sensitive data, privileged access, SaaS dependencies.
MFA, tested backups, patch management, segmentation, phishing awareness.
Centralised logs, alerts on abnormal sign-ins, periodic access reviews.
Incident playbook, internal comms, blameless post-mortems.
Mandatory MFA, tested backups and critical patches within 72 hours drastically cut the impact of an account compromise.
MFA, SSO, privileged access management.
OWASP testing, code review, WAF on web exposures.
Hardening, CSPM, encryption at rest and in transit.
Immutable backups, DR plans, quarterly restore tests.
Ransomware and CEO fraud hit SMBs without dedicated SOCs. CIS IG1 basics (inventory, MFA, backups, patches) deliver quick wins before heavy projects. Align security with Law 25 so you do not harden the network while leaving unencrypted CSV exports with an unevaluated vendor.
Closely related. ISO 27001 information security also covers paper classification; cybersecurity focuses on digital systems.
Not always initially. MDR or native cloud alerts may suffice before building in-house.
Questionnaires, audit reports, ISO 27001 certification or a SOC 2 attestation report where relevant — document controls.
Want a realistic cybersecurity plan for your organisation size — not a generic checklist?
Assess your posture