Skip to content
ICT 04178.1

Security threats and protection

Malware, phishing, hacking, and how data is kept safe.

Learning objectives

What you need to be able to do

Teacher-mapped phrasing — check against the official Cambridge syllabus for exact wording.

  • 8.1.1Describe security threats including malware, phishing, pharming and hacking.
  • 8.1.2Describe methods of protecting data, including encryption, firewalls and authentication.

6 minute read

Security threats and protection

The threats

  • Virus — a program that replicates itself and can corrupt or delete files. It needs a host file and usually a user action to spread.
  • Spyware / key-logging software — secretly records keystrokes to capture passwords and card numbers.
  • Phishing — a fake email or message pretending to be from a legitimate organisation, tricking the user into clicking a link and entering personal details.
  • Pharming — malicious code redirects the user to a fake website even when they type the correct address. It is more dangerous than phishing because the user does nothing wrong.
  • Hacking — gaining unauthorised access to a computer system.
  • Spam — unsolicited bulk email; mostly a nuisance, but a common carrier for the above.

The phishing/pharming distinction is examined constantly: phishing needs you to take the bait; pharming redirects you without your involvement.

Protection methods

  • Firewall — monitors incoming and outgoing traffic and blocks anything not meeting the security rules; sits between the network and the outside world.
  • Anti-virus / anti-spyware software — scans for known malware and quarantines or removes it. Must be kept up to date to recognise new threats.
  • Encryption — scrambles data so that if it is intercepted it cannot be understood without the key. Note carefully: encryption does not stop interception, it makes intercepted data useless.
  • Authentication — proving who you are: strong passwords, biometrics (fingerprint, retina, face), two-factor authentication, and physical tokens.
  • Access rights — limiting each user to only the data their role requires, so a breach of one account exposes less.

Strong passwords

Long, mixing upper and lower case, digits and symbols, avoiding dictionary words and personal information, changed regularly and never reused across sites.

Think of it like this

Encryption is writing your diary in a private code. It does not stop someone taking the diary — it stops the theft mattering, which is precisely the point when data travels across networks you do not control.

Worked examples

Method, step by step

A bank encrypts customer data sent over the internet. Explain how this protects the customer if the data is intercepted.

  1. 1Encryption scrambles the data into a form that cannot be understood without the decryption key.
  2. 2If a hacker intercepts the transmission, they receive only the scrambled version.
  3. 3Without the key they cannot convert it back into meaningful information, so the customer's details remain private.

The data is scrambled before transmission, so an interceptor obtains only meaningless ciphertext. Without the decryption key it cannot be read, so the customer's details stay secure even though the data was intercepted.

Common misconceptions

  • Saying encryption "stops hackers accessing data". It does not prevent access or interception; it makes the intercepted data unreadable.
  • Confusing phishing and pharming. Phishing requires the victim to respond to a fake message; pharming redirects them automatically via malicious code.
  • Believing a firewall removes viruses. A firewall filters network traffic; anti-virus software detects and removes malware already present.

In the exam

  • Define phishing and pharming by their *mechanism*, not just "a scam". The marks are for the fake email versus the automatic redirection.
  • When asked how to keep data safe, give a mix of technical measures (firewall, encryption, anti-virus) and human ones (strong passwords, staff training, access rights).