# What is Cybersecurity?

> Cybersecurity is the practice of managing risks to information, technology, and digitally enabled operations.

- Canonical URL: https://yellowcube.eu/glossary/cybersecurity/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

It combines governance, people, processes, architecture, and technical safeguards to reduce the likelihood and impact of unauthorized access, disruption, manipulation, destruction, or disclosure.

Cybersecurity is not a state in which attacks never occur. Organizations use it to understand what matters, protect important assets and services, detect adverse activity, respond effectively, and restore operations. The appropriate measures depend on business objectives, threat exposure, legal duties, safety needs, and risk tolerance.

In practice, a cybersecurity program runs as a loop rather than a project: inventory and risk assessment set priorities, controls are implemented and tested, incidents feed lessons back into governance, and leadership reviews risk acceptance explicitly. Maturity is usually judged by how repeatable and measured this loop is — not by the number of tools deployed.

### Key points

- **Primary purpose:** Support the organization’s mission while managing harmful digital events and conditions.
- **NIST CSF 2.0 functions:** Govern, identify, protect, detect, respond, and recover.
- **Scope:** People, data, applications, identities, devices, networks, cloud services, operational technology, suppliers, and business processes.
- **Important limitation:** More security products do not automatically create better cybersecurity; disconnected controls can add cost and complexity without reducing material risk.

### Related terms

[Cyber risk](<https://yellowcube.eu/glossary/cyber-risk/>) · [Defense in depth](<https://yellowcube.eu/glossary/defense-in-depth/>) · [Incident response (IR)](<https://yellowcube.eu/glossary/incident-response/>) · [Cyber resilience](<https://yellowcube.eu/glossary/cyber-resilience/>) · [Information security](<https://yellowcube.eu/glossary/information-security/>) · [Confidentiality, integrity, and availability (CIA triad)](<https://yellowcube.eu/glossary/confidentiality-integrity-and-availability/>) · [Hacking and ethical hacking](<https://yellowcube.eu/glossary/hacking-and-ethical-hacking/>) · [NIST Cybersecurity Framework (CSF)](<https://yellowcube.eu/glossary/nist-cybersecurity-framework/>)

### Sources

[NIST Cybersecurity Framework 2.0](https://www.nist.gov/cyberframework) · [NIST glossary: Cybersecurity](https://csrc.nist.gov/glossary/term/cybersecurity)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

