Security
8.2 Types of threats and vulnerabilities
8.2.1 Technical threats
Botnets and DoS/DDoS Attacks
Botnets are networks of compromised devices used
to carry out attacks.
DoS / DDoS attacks aim to overwhelm systems and make services unavailable.
Mitigation: Traffic filtering, firewalls, intrusion detection systems, rate limiting.
DoS / DDoS attacks aim to overwhelm systems and make services unavailable.
Mitigation: Traffic filtering, firewalls, intrusion detection systems, rate limiting.
Malicious Hacking
Hackers may include hacktivists, nation states, organised crime,
or individuals.
Common techniques include:
Common techniques include:
- Password cracking and brute‑force attacks
- Cross‑site scripting (XSS)
- SQL injection
- Buffer overflow
Malware
Malware is software designed to cause harm.
Types include:
- Viruses
- Worms
- Key loggers
- Ransomware
- Spyware
- Remote access trojans
Social Engineering
DNS Attacks and Unsecured Wi‑Fi
DNS attacks redirect users to malicious sites.
Unsecured Wi‑Fi networks allow eavesdropping and data interception.
Mitigation: Secure DNS, encryption, trusted wireless access points.
Unsecured Wi‑Fi networks allow eavesdropping and data interception.
Mitigation: Secure DNS, encryption, trusted wireless access points.
8.2.2 Technical vulnerabilities
Inadequate Security Processes
Vulnerabilities can arise from:
- Weak or absent encryption
- Poor password policies
- Failure to use multi‑factor authentication
Out‑of‑Date Components
Systems become vulnerable when using:
- Unsupported hardware
- Out‑of‑date software
- Legacy systems with zero‑day vulnerabilities
- Outdated firmware
8.2.3 Human threats
Human‑Related Threats
Human error:
- Incorrect file permissions
- Ignoring confirmation warnings
- Lack of training
- Immediate removal from premises
- Immediate account suspension
- Escort all visitors
- Check identification
- Leaving devices unlocked
- Writing passwords down
- Poor password management
8.2.4 Physical vulnerabilities
Physical Threats and Weaknesses
Physical vulnerabilities include:
- Lack of entry control systems
- Poor access control and tailgating
- Weak or reused access codes
- Failure to monitor access areas
- Lack of access audits
- Exposure to shoulder surfing
- Environmental risks
- Vandalism
- Non‑rugged equipment
- Natural disasters
8.2.5 Impact of threats and vulnerabilities
Organisational Impact
If threats and vulnerabilities are not addressed, organisations may face:
- Loss or leakage of sensitive data
- Unauthorised access to digital systems
- Data corruption
- Service disruption
- Unauthorised access to restricted physical areas
Techniques include:
- Phishing and spear phishing
- Smishing and vishing
- Pharming
- Watering hole attacks
- USB baiting
Mitigation: Staff training, awareness campaigns, verification procedures.