Skip to content

What is Cybersecurity? Definition and explanations

Cybersecurity is the set of practices, controls and technologies that protect systems, data and users against unauthorized access, service disruption and tampering. It covers three inseparable phases: preventing what can be prevented, detecting what gets through anyway, and responding to limit the impact. It is not a product to install but a capability to maintain, organisational as much as technical.

In one sentence

Cybersecurity protects systems, data and users, across prevention, detection and response.

Key points

  • Not just a firewall: governance, training, and vendors matter equally.
  • OWASP and CIS Controls offer actionable priorities for SMBs and enterprises.
  • Attack surface spans email, cloud identities, APIs, and software supply chain.
  • Measure: MTTD, MTTR, MFA coverage, critical patches applied.
  • Security is continuous; a one-off audit without follow-through falls short.

Term at a glance

Cybersecurity
Information security · Cyber security
French term
Cybersécurité
Domain
Cybersecurity
Category
Fundamentals
Level
Beginner to intermediate

Beyond antivirus: what cybersecurity includes

It is not a single product: policies, authentication, patching, backups, training and monitoring work together.

For SMEs, the most common risks remain phishing and poorly protected accounts.

Compliance (Law 25, industry norms) sits alongside technical protection.

Structuring a cybersecurity programme

  1. 01

    Inventory

    Critical assets, sensitive data, privileged access, SaaS dependencies.

  2. 02

    Prioritise controls

    MFA, tested backups, patch management, segmentation, phishing awareness.

  3. 03

    Monitor

    Centralised logs, alerts on abnormal sign-ins, periodic access reviews.

  4. 04

    Respond and learn

    Incident playbook, internal comms, blameless post-mortems.

A concrete cybersecurity example

Mandatory MFA, tested backups and critical patches within 72 hours drastically cut the impact of an account compromise.

Areas covered by cybersecurity

Identity protection

MFA, SSO, privileged access management.

Application security

OWASP testing, code review, WAF on web exposures.

Infrastructure and cloud

Hardening, CSPM, encryption at rest and in transit.

Continuity

Immutable backups, DR plans, quarterly restore tests.

Investing in cybersecurity

  • Lowers financial, reputational, and regulatory risk
  • Reassures clients, insurers, partners
  • Clarifies IT / business / vendor duties
  • Recurring cost
  • User friction if poorly tuned
  • False confidence without process

Cybersecurity for Quebec organisations

Ransomware and CEO fraud hit SMBs without dedicated SOCs. CIS IG1 basics (inventory, MFA, backups, patches) deliver quick wins before heavy projects. Align security with Law 25 so you do not harden the network while leaving unencrypted CSV exports with an unevaluated vendor.

Frequently asked questions

Cybersecurity vs information security?

Closely related. ISO 27001 information security also covers paper classification; cybersecurity focuses on digital systems.

Does an SMB need 24/7 SOC?

Not always initially. MDR or native cloud alerts may suffice before building in-house.

How to prove maturity to clients?

Questionnaires, audit reports, ISO 27001 certification or a SOC 2 attestation report where relevant — document controls.

Related notions

Sources and references

Want a realistic cybersecurity plan for your organisation size — not a generic checklist?

Assess your posture
Glossary