Stage 1 summary. Foundations

8 min 6 concepts 6 figures

Stage 1 builds the shared language and the way of thinking that the rest of the course depends on. It sets out what cybersecurity actually protects, who is on the other side and why they bother, how to weigh a risk instead of reciting a control, why identity is the ground most attacks fight over, how modern deception has outgrown the spot-the-typo advice, and what the law now asks of anyone who holds other people's data. The frame throughout is the NIST Cyber Security Framework 2.0, with its Govern function at the hub, so that every later topic hangs off a decision someone is accountable for.

One argument runs through the stage. Security is a judgement made under uncertainty, not a checklist that is either ticked or not. The attacker is running a business and reaches for the cheapest route in, which is almost always a stolen credential, a convincing message or an unpatched device that faces the internet. So the reader who finishes Stage 1 should stop asking whether a control exists and start asking whether it survives contact with a motivated, well-resourced and thoroughly commercial adversary.

The sections follow the stage's teaching order, so you can read straight through to rebuild the stage in your head, or jump to the concept you need. Each section links back to its module for the full treatment, and the course map figure shows where this stage sits in the whole.

What you carry out of this stage

  • Define cybersecurity in the NCSC's terms and separate it cleanly from information security and IT security
  • Explain the ransomware-as-a-service economy and name who profits at each link, so that likelihood is grounded in economics rather than guesswork
  • Reason about a risk using threat, vulnerability and exploit, and place a baseline such as Cyber Essentials correctly as a floor rather than an assurance
  • Rank second factors by the adversary-in-the-middle test and say which credential a proxy phishing kit cannot replay and why
  • Design an out-of-band verification procedure that would stop a deepfake payment request, and choose metrics that measure behaviour change rather than click rates
  • State the current UK lawful bases for processing personal data and what the Data (Use and Access) Act 2025 changed

The cybersecurity course: four stages around one governing habit

Each stage hands the next one thing: a shared vocabulary, then design judgement, then an operating capability, with the Govern hub tied to all four, making governance something exercised at every stage rather than added once the technical work is done.

The course runs Foundations to Applied practice to Practice and strategy to Exam, each handing the next a capability, with Govern tied to every stage because risk-led decisions are made throughout, not at the end. Source: NIST CSF 2.0.

The cybersecurity course: four stages around one governing habit A central Govern hub (the governing habit; Govern: risk-led decisions at every stage) sits above four stage cards, tied to each by thin dashed lines. Stages, left to right: Stage 1 Foundations (threats and risk, identity, people and privacy); Stage 2 Applied practice (threat modelling, web and API security, release gates); Stage 3 Practice and strategy (operations and resilience, regulation, OT and AI); Stage 4 Exam and certification (revision, mocks, certificate). A progression line beneath carries what each hands on: a shared vocabulary and risk model, design judgement under attack, an operating and governing capability, and a final outward arrow from Exam to evidence of expertise. THE CYBERSECURITY COURSE · FOUR STAGES AROUND ONE GOVERNING HABIT THE GOVERNING HABIT · NIST CSF 2.0 Govern: risk-led decisions Exercised at every stage, not bolted on at the end STAGE 1 Foundations Threats and riskIdentityPeople and privacy STAGE 2 Applied practice Threat modellingWeb and API securityRelease gates STAGE 3 Practice andstrategy Operations, resilienceRegulationOT and AI STAGE 4 Exam andcertification RevisionMocksCertificate a shared vocabularyand a risk modeldesign judgement underattackan operating andgoverning capabilityevidence ofexpertise

Cybersecurity protects a system, and it is not the same as IT security

Cybersecurity is the practice of protecting systems, networks and data from digital attack, and its purpose is to keep three properties intact: confidentiality, integrity and availability, the CIA triad. It is broader than IT security, which guards the technology itself, and narrower than information security, which covers information in every form including paper and conversation. Naming the boundary matters, because a control that protects a database says nothing about the printed report left on a desk, and a policy about documents does nothing for a misconfigured cloud bucket.

The triad is the working test, but it no longer captures everything a modern defender owns. Three extensions matter in 2026. Safety, because in operational technology the worst outcome is physical harm, not lost data. Resilience, because surviving and recovering is now a designed capability in its own right, set out in the Cyber Assessment Framework's objective D. And authenticity, because deepfakes attack the simple trust that a person is who they appear to be. Each of these is taken up properly in Stage 3, but the reader should already hold them alongside the triad.

The organising map for the whole course is the NIST Cyber Security Framework 2.0. Its six functions are Govern, Identify, Protect, Detect, Respond and Recover, and Govern was added at the centre in the 2024 revision to make plain that risk decisions sit above the technical work, not beside it. WannaCry at the NHS in 2017 is the anchoring case: a preventable outbreak that cost the health service around 92 million pounds and led to 19,494 cancelled appointments, and every one of those figures traces to a governance failure as much as a technical one.

The attacker is running a business, which is why defence must assume volume

Most incidents are not the work of a lone genius. They are the output of an industry. In the ransomware-as-a-service economy the roles are specialised: developers license the malware, initial access brokers sell footholds into companies they have already breached, affiliates run the intrusions, and launderers move the proceeds, each taking a margin. Once attack has specialisation and margins like any other business, defence has to assume commodity tooling and high volume rather than artisanal brilliance, which changes where you spend your effort.

Motivation predicts behaviour, and four classes cover most of it. Financially motivated crime drives the largest share of incidents. State actors pursue espionage and quiet prepositioning inside networks they may want later. Hacktivists lean on disruption and denial of service. Insiders already hold access and need no intrusion at all. Reading the headline evidence critically matters just as much: ENISA's Threat Landscape 2025 counted 4,875 incidents with phishing behind roughly 60 percent of initial access, while Verizon's 2025 Data Breach Investigations Report found ransomware present in 44 percent of breaches and third-party involvement doubled to 30 percent. Incident populations and breach populations are different denominators, so check which one a number came from before quoting it in a board paper.

Enforcement disrupts brands, not the economics. Operation Cronos took down LockBit in February 2024, and the ecosystem fragmented rather than shrank, reaching around 85 active groups by the third quarter of 2025 while the share of victims who paid fell to about 23 percent. The lesson for the rest of the course is unglamorous: because most breaches still start with phishing, stolen credentials or an unpatched edge device, the depth goes into identity, exposure and detection rather than exotica.

Risk is threat times vulnerability times consequence, judged against an appetite

A risk is not a threat and not a vulnerability. It is the chance that a threat exploits a vulnerability to cause a consequence you care about. A threat is who or what might act against you, a vulnerability is the weakness they could use, and an exploit is the act that turns the weakness into harm. The Target breach of 2013 walks the whole chain: a phishing email to a heating and ventilation contractor gave stolen credentials, weak network segmentation was the vulnerability, and the exploit was lateral movement into the payment systems that exposed around 40 million cards.

Two ideas keep a risk conversation honest. Risk appetite is how much risk an organisation is willing to seek in pursuit of its goals, set at board level. Risk tolerance is how far it will let a specific risk drift before acting. Confusing the two produces either paralysis or recklessness. Once a risk is understood, the treatment options are the familiar four: avoid the activity, reduce the likelihood or impact, transfer some of it through insurance or contract, or knowingly accept it. Transfer is the one most often misread, because a cyber insurance policy moves some financial loss but none of the operational or reputational harm.

A baseline scheme such as the UK's Cyber Essentials is a floor, not a certificate of safety. It removes the commodity attacks that make up most of the volume, which is genuinely valuable, but it evidences nothing about resistance to a targeted adversary. This is the first appearance of a theme the course returns to repeatedly: compliance is a snapshot of a management system, and the honest follow-up question is always what an attacker would do anyway.

Multi-factor authentication has tiers, and phishing kits know which ones fail

Identity is the ground most attacks fight over, because a valid credential walks through the front door. The password advice that most organisations still enforce is the advice the standard now prohibits. NIST Special Publication 800-63B-4, finalised in 2025, says verifiers shall not impose composition rules and shall not force periodic rotation, and instead calls for length over complexity, screening against blocklists of known-breached passwords, and a minimum of 15 characters where a password is the sole factor. Longer and unrotated beats short and churned.

The wrong question is whether an account has multi-factor authentication. The right question is which tier. SMS codes sit at the bottom, one-time codes and push approvals in the middle, and phishing-resistant credentials such as passkeys and FIDO2 security keys at the top. The reason is the adversary-in-the-middle attack. Kits such as Evilginx, Tycoon 2FA and EvilProxy proxy the real login page, capture whatever the victim types, and replay the resulting session token, so a one-time code or a push approval falls just like a password. A passkey refuses at that step because the credential is cryptographically bound to the genuine domain and the proxy is not it.

What the attacker steals in that attack is the session token, which is why session lifetime and binding matter as much as the strength of the login. Access control models decide what a valid identity may then do. Role-based access grants permissions by job role, attribute-based access decides by context, and least privilege insists that people and services hold only the access they actually need, so that a single stolen identity opens the smallest possible door.

The old phishing tells are gone, so verification must beat vigilance

Social engineering manipulates people rather than machines, and the advice to watch for bad spelling has expired. Large language models write fluent, error-free lures at scale, and deepfake voice and video defeat the instinct that something merely looks wrong. The defining case is Arup in January 2024: a finance employee in Hong Kong joined a video call on which the chief financial officer and several colleagues were all deepfakes, and authorised 15 transfers totalling about 25.6 million US dollars. Any control that depends on a human detecting the fake is now a broken control.

The reliable answer is a procedure, not vigilance. Out-of-band callback on a known and previously held number, dual authorisation for payments and for changes to standing data, cooling-off periods on unusual requests, and pre-agreed code phrases for executives all move the decision off the channel the attacker controls. The design goal is to make following the procedure easier than breaking it, so that the safe path is also the path of least resistance.

Measuring the human layer well means dropping the click rate. The NCSC's human-centred security position is that badly designed systems set people up to fail and that a blame culture suppresses the reporting you most need. So the metrics that matter are reporting rates and demonstrable behaviour change, not how many people clicked a simulated lure. Calling users the weakest link gets the causation backwards: more often the system asked something unreasonable of them.

UK data protection now runs on seven lawful bases, since the Data (Use and Access) Act 2025

Holding personal data carries legal duties, and the starting point is knowing what kind of data you have. Personal data identifies a living individual. Special category data covers the sensitive classes such as health, ethnicity and biometrics, which carry extra conditions. Anonymised data, genuinely and irreversibly, falls outside the regime altogether, which is why the line between anonymisation and mere pseudonymisation is worth defending carefully.

Every act of processing needs a lawful basis. UK GDPR has long recognised six: consent, contract, legal obligation, vital interests, public task, and legitimate interests. The Data (Use and Access) Act 2025, which received Royal Assent in June 2025, added a seventh, recognised legitimate interests, for a defined set of public-interest purposes, and unlike ordinary legitimate interests it requires no balancing test. That single change is why the course now teaches seven bases rather than six, and it dates precisely to 2025 rather than sitting in the older framework.

The rest of the everyday duties still hold. Data subjects retain their rights of access, rectification, erasure and objection, and the principles of data minimisation and purpose limitation require that you collect only what you need and use it only for the reason you gave. The 2025 Act also changed subject access, automated decision-making and cookies. All of its data protection provisions are now in force, the last of them on 19 June 2026, and the full treatment of those threads waits for Stage 3.

The traps this stage warns against

  • Reading the padlock in the address bar as proof that a site is safe.

    Instead: The padlock proves transport encryption to that domain and nothing about who runs it. Most phishing sites use valid HTTPS, so treat the padlock as a statement about the channel, never about trust.

  • Asking whether an account has multi-factor authentication, as a yes or no.

    Instead: Ask which tier. SMS and one-time codes and push approvals are replayed by adversary-in-the-middle kits; only phishing-resistant, domain-bound credentials such as passkeys and FIDO2 keys survive.

  • Calling users the weakest link and drilling them on spotting fakes.

    Instead: Badly designed systems set people up to fail and AI-generated lures carry no tells. Build out-of-band verification procedures and measure reporting rates and behaviour change, not click rates.

  • Treating a certification such as Cyber Essentials or ISO 27001 as evidence of security.

    Instead: Certification is a snapshot of a management system, not proof of resistance to attack. Pair every framework with the question of what a motivated attacker would do anyway.

  • Forcing complex passwords and periodic rotation because it feels rigorous.

    Instead: NIST SP 800-63B-4 makes composition rules and forced rotation a shall-not. Favour length, blocklist screening and a 15-character minimum where a password is the sole factor.

Core distinctions

  • Cybersecurity protects systems and data from digital attack, IT security guards the technology, and information security covers information in every form including paper and speech
  • A threat is who might act, a vulnerability is the weakness they could use, and an exploit is the act that turns the weakness into harm; risk is the chance of all three combining
  • Risk appetite is how much risk an organisation seeks in pursuit of its goals; risk tolerance is how far it lets a specific risk drift before it must act
  • A one-time code proves possession of a device and is replayed by a proxy phishing kit; a passkey is bound to the genuine domain and refuses to sign in to the fake
  • Personal data identifies a living individual; special category data covers sensitive classes such as health and biometrics and carries extra conditions on processing
  • An incident is any event that may harm security; a breach is a confirmed compromise of data or systems, so most incidents never become breaches and the denominators differ
  • Cyber Essentials is a floor that removes commodity attacks; it is not an assurance of resistance to a targeted adversary

That is Stage 1 in one place. What cybersecurity protects and how it differs from IT and information security, the commercial attacker behind most incidents, risk as a judgement rather than a checklist, the tiers of identity that decide whether a stolen credential works, the verification procedures that outlast human vigilance, and the seven lawful bases that now govern personal data in the UK. The foundations scenario practice puts those ideas under pressure with realistic situations, so the common mistakes get caught before you carry a shared vocabulary and a risk model into Stage 2.

Sources and further reading