01
Cyber attacks at a glance
A cyber attack is malicious activity or an attempt that can affect confidentiality, integrity, availability, access, or service operation. It differs from an ordinary failure because the cause or intent involves unauthorized or harmful action.
The broad label is a starting point, not a diagnosis. Understanding the affected asset, observed evidence, and current impact is more useful than assuming that every alert represents the same kind of attack.
02
Cyber attack, threat, vulnerability, incident, and breach: what is the difference?
A threat is potential danger; a vulnerability is a weakness; an attack is malicious action or an attempt; an incident is a security event requiring attention; and a breach is unauthorized access or disclosure when that determination is supported by evidence and applicable definitions.
These terms should not be treated as interchangeable. A vulnerability can exist without an attack, an attack can fail, and an incident can require response before the final impact or breach status is known.
03
Common types of cyber attacks
Phishing and social engineering manipulate trust; malware and ransomware introduce harmful software or extortion; credential abuse misuses accounts; exploitation targets weaknesses; denial of service affects availability; supply-chain compromise abuses dependencies; insider misuse and data theft affect trust and information.
Each type has distinct signals and defensive owners, but the hub does not teach attack execution. Use focused CYBERoinfo pages for recognition, vulnerability context, malware, cloud, network, and incident-response depth.
04
How an attack can move from access to impact
A safe high-level chain is exposure or deception, initial access, identity or privilege misuse, movement or persistence, service or data impact, detection, containment, and recovery. The chain is a defensive model for asking where controls and evidence can interrupt harm.
The exact sequence varies, and not every attack reaches every stage. Avoid filling uncertainty with speculation; record what is known, what is suspected, and which owner can verify it.
05
Warning signs and evidence to preserve
Unexpected sign-ins, unusual prompts, disabled controls, unexplained file or service changes, suspicious messages, unavailable systems, and abnormal data movement can justify careful review. A symptom alone is not proof, and false positives are possible.
Record times, affected assets, messages, alerts, and decisions using the organization’s process. Avoid opening suspicious files, altering evidence unnecessarily, improvising retaliation, or making public claims before the responsible owner has assessed the situation.
06
Reduce cyber-attack risk before an incident
Before an incident, clarify asset and identity ownership, reduce unnecessary exposure, use strong authentication, limit privileges, segment important systems, apply updates, collect useful logs, protect backups, and rehearse communications. These measures support prevention and make response more reliable.
A control is only useful when someone operates it and knows what to do with its output. Review whether alerts have owners, whether backups can be restored, and whether recovery channels remain protected if normal systems are unavailable.
- Know what matters
- Limit common paths
- Practice recovery
07
What to do when a cyber attack is suspected
Slow down and use a trusted communication path. Notify the system owner or response lead, isolate an affected device or account when appropriate to the local plan, preserve useful evidence, protect recovery channels, and follow approved escalation steps.
Do not retaliate, guess at attribution, spread unverified details, or destroy evidence. If personal accounts or devices are involved, seek trusted support and prioritize account protection from a separate clean device when feasible.
08
Examples and incident patterns
Case studies and threat records can help readers compare ransomware, cloud exposure, supplier access, email fraud, availability attacks, and session theft by access pattern, impact, containment, and recovery lesson. They should be read with their dates, evidence limits, and uncertainty labels.
Current intelligence is not a universal inventory of all attacks. Use dated records to understand decisions and patterns, then return to evergreen controls and response ownership for action.
09
Choose the next CYBERoinfo path
Use the Learning Hub for foundations, focused topics for recurring risk areas, resources for practical decision aids, and articles for deeper explanations. Threat intelligence and daily intelligence are for changing developments; case studies are for structured incident lessons.
The best next page depends on the reader’s need: recognize a message, understand malware, assess a vulnerability, prepare for ransomware, or respond to a suspected incident. The hub routes without duplicating those owners.
10
Cyber attacks FAQ
Cyber attacks can affect individuals, small organizations, and large services, although the pathways and impacts differ. Malware and ransomware are related but not identical: ransomware is a harmful outcome or capability centered on extortion or disruption, while malware is the broader category.
Start with trusted communication, evidence preservation, and the documented response path. Not every vulnerability is an attack, and prevention and response are complementary rather than interchangeable.