Previously, after writing multiple articles on cloud computing, virtualization, and containerization, we are going to pivot to a different domain in today's article. We are going to shed some light on the security of the internet and the things that are on the internet, including you, the user, your application, be it a website, SaaS, or any other operations that you conduct online.
There is always a lingering threat of you or your operations getting compromised by people, organizations, and even bots. See, we have this concept that if we do not click on obviously malicious links or files, or do not download content from an unknown provider, we will not get hacked. But this is an absolute dilemma.
Some threats are way less obvious, and literally anyone can fall for them.
The Delusion of an Average User
An average user on the internet might think that they are safe after following a few protocols of engagement online, but the reality is that real hacking is done beyond these protocols.
Safety on the internet is a myth, and it always has been a myth. Now those who believe in this myth are the ones to get hacked the most. Compromising such individuals is the easiest task for anyone with malicious intent.
Your Business Is Not Safe Either
Your software, your networks, and your websites- nothing is safe. One mistake and your whole network can be compromised. One mistake and you will lose access to your own website.
Now, on a broader note, getting hacked is also a part of the internet we use. But the reality is not this simple. When your business gets hacked, you lose credibility in front of official and potential clients. It ruins your reputation.
Their perspective is also very straightforward. How good is our business with the people who can not save their own business?
Role of Cybersecurity
As on the internet there are people with malicious intent, there are also people who work just to protect individuals and businesses online.
And the profession as a whole in which such security operations are conducted is called Cybersecurity.
But this is a very vast field with many, many areas of speciality. From defending to attacking to creating systems that can not be attacked and require way less defence. This is the purest aspect of cybersecurity.
Fields of Cybersecurity
Cybersecurity has multiple fields. There is red teaming, blue teaming, purple teaming, security engineering, Governance Risk Compliance (GRC), and AI red teaming. There are many more micro niches in it, but these are overall the most general and detailed ones.
Red Teaming
In red teaming, a person works by attacking existing systems and making them go through simulated and controlled attacks.
These are done to check the security of applications, websites, and many other things. These are controlled attacks done specifically and personally I would say that this is the best way we can expect to test the defences of an application.
This is also regarded as offensive security.
And the individuals that perform these tasks are called red teamers and penetration testers.
Blue Teaming
In blue teaming, a person works by defending the existing systems; they constantly monitor the security of applications and networks or whatever they are assigned to.
They check logs, files, folders, and terminals for any attacks or malicious activity.
These gentlemen are also the first to react in case of attacks and are a company's first layer of defence.
The job role these gentlemen are assigned could vary, but it is commonly a SOC analyst.
SOC analyst stands for Security Operations Centre.
Governance Risk Compliance (GRC)
In GRC, we mix cybersecurity with business.
The main job of a GRC individual is to translate and explain security operations, complications and compliance issues to non-tech-savvy businessmen.
In a security company, this is a very important position as it fills the business gap in cybersecurity.
They also help ensure that the business they work for is up to date with current security metrics.
AI Red Teaming
In AI red teaming, the main purpose is to check the security and also ensure that the AI bots are not confused into performing tasks that are not allowed.
Because, in a way, this compromises the security of the AI company the bots are from.
Imagine someone getting access to the data by confusing an AI agent into giving that person access.
This field, however, is very new and is constantly evolving. This will keep on evolving along with the evolution of AI.
Careers in Cybersecurity
In cybersecurity, currently there is a major lack of skilled individuals and the need increases day by day as more and more companies convert their businesses online.
Currently, almost 3.6 million cybersecurity positions are open.
But this field changes fast; if you stop learning, you become the past, and when you become the past, you become irrelevant.
Cloud Security
In cloud security as businesses bring their data to save it on cloud storages, websites shift their hosting to cloud vendors like AWS and Microsoft Azure, we are also shifting and expanding cybersecurity into the cloud.
I mean, isn't it obvious?
If businesses shift their data to the cloud, hackers, agencies, and groups with malicious intent will also set their eyes on them.
So Cloud Security is also starting to trend; individuals who understand cloud infrastructure the best are the best for this job.
Conclusion
Let this be an introduction to cybersecurity.
We discussed security threats, security operations, and fields.
Cybersecurity is a profession that changes almost every day.
I, along with my cloud computing articles, will keep on posting more and more articles from beginner to advanced.
Those who are reading my articles, I assure you that I will explain the most complex cybersecurity operations in the simplest yet elegant manner.
I am Abdullah Zahid, and this was my take on cybersecurity. Let this article be the start of your cybersecurity journey.
Thanks for reading!

