Security

8.2 Types of threats and vulnerabilities

8.2.1 Technical threats

Botnets and DoS/DDoS Attacks
Botnets are networks of compromised devices used to carry out attacks.

DoS / DDoS attacks aim to overwhelm systems and make services unavailable.

Mitigation: Traffic filtering, firewalls, intrusion detection systems, rate limiting.
Malicious Hacking
Hackers may include hacktivists, nation states, organised crime, or individuals.

Common techniques include:
  • Password cracking and brute‑force attacks
  • Cross‑site scripting (XSS)
  • SQL injection
  • Buffer overflow
Mitigation: Secure coding, input validation, authentication controls, patching.
Malware
Malware is software designed to cause harm. Types include:
  • Viruses
  • Worms
  • Key loggers
  • Ransomware
  • Spyware
  • Remote access trojans
Mitigation: Anti‑malware tools, updates, user awareness, backups.
Social Engineering
Social engineering exploits human behaviour.

Techniques include:
  • Phishing and spear phishing
  • Smishing and vishing
  • Pharming
  • Watering hole attacks
  • USB baiting
Mitigation: Staff training, awareness campaigns, verification procedures.
DNS Attacks and Unsecured Wi‑Fi
DNS attacks redirect users to malicious sites.

Unsecured Wi‑Fi networks allow eavesdropping and data interception.

Mitigation: Secure DNS, encryption, trusted wireless access points.

8.2.2 Technical vulnerabilities

Inadequate Security Processes
Vulnerabilities can arise from:
  • Weak or absent encryption
  • Poor password policies
  • Failure to use multi‑factor authentication
Out‑of‑Date Components
Systems become vulnerable when using:
  • Unsupported hardware
  • Out‑of‑date software
  • Legacy systems with zero‑day vulnerabilities
  • Outdated firmware

8.2.3 Human threats

Human‑Related Threats
Human error:
  • Incorrect file permissions
  • Ignoring confirmation warnings
  • Lack of training
Malicious employees:
  • Immediate removal from premises
  • Immediate account suspension
Disguised criminals:
  • Escort all visitors
  • Check identification
Poor cyber hygiene:
  • Leaving devices unlocked
  • Writing passwords down
  • Poor password management

8.2.4 Physical vulnerabilities

Physical Threats and Weaknesses
Physical vulnerabilities include:
  • Lack of entry control systems
  • Poor access control and tailgating
  • Weak or reused access codes
  • Failure to monitor access areas
  • Lack of access audits
  • Exposure to shoulder surfing
  • Environmental risks
  • Vandalism
  • Non‑rugged equipment
  • Natural disasters
Mitigation: Physical security controls, monitoring, robust equipment, disaster planning.

8.2.5 Impact of threats and vulnerabilities

Organisational Impact
If threats and vulnerabilities are not addressed, organisations may face:
  • Loss or leakage of sensitive data
  • Unauthorised access to digital systems
  • Data corruption
  • Service disruption
  • Unauthorised access to restricted physical areas