Cyber security terms
Back to Blog

CYBER SECURITY TERMINOLOGY
Information security, IT security, cyber security, or digital security? These terms are often used interchangeably and are synonyms for most people in everyday language. Do you find it difficult to distinguish all the concepts within digital security from each other? You are not alone!
Of all these terms, cyber security has gained the strongest foothold in recent years. This is probably because it is the most marketable, as ‘cyber’ sounds exciting. But what does the concept actually involve?
Clarifying the Concepts
Attempts have been made to establish a clearer description of these terms: In 2013, Von Solms and van Niekerk published the article “From information to cyber security.” This article forms the basis for clarifying these concepts and usually serves as the foundation when this topic is addressed in various professional forums, even though the quote itself is often omitted. According to the authors, the choice of term depends on the assets and vulnerabilities that could be exploited. These can be physical or digital assets in the form of hardware, information, or resources within an organisation. Information and data have different values depending on factors such as confidentiality, integrity, and availability. For example, financial information, personal data, or trade secrets can be of high value to organisations.
A vulnerability refers to a weakness or flaw in, for example, an IT system, an application, or an organisation that could be exploited by a threat to gain access to an asset and cause harm. Vulnerabilities can exist in software, hardware, physical infrastructure, and human factors. They can arise for various reasons, such as poor design, incorrect configuration, lack of updates, or inadequate user training.

Figure 1: Relationship between information security, IT security, and cyber security. Source: Von Solms and Van Niekerk (2013)
When we work on security measures, we can break them down into the following areas:
Information Security: Protecting information, regardless of whether it is stored digitally or on paper.
IT/ICT Security: Securing information and communication technology (ICT), including hardware and software. Hardware can range from PCs, servers, network equipment, mobile phones, and sensors to drones and satellites. Software includes programs used for signal processing, analysis, data processing, algorithms, models, and control systems.
Cyber Security: Protecting everything vulnerable through the use of ICT. This can include drones, cars, telecommunications, or power supplies. Since almost everything in our daily lives is controlled by ICT, cyber security forms the basis for societal security and safety in a broad sense.
In more recent versions of the model above, the concept of Digital Security has been introduced as the overarching term that encompasses parts or the entirety of the other areas.
In Summary
The terms information security, IT security, cyber security, and digital security are often intertwined in a complex digital world. Cyber security has gained increased prominence due to its exciting appeal. Von Solms and van Niekerk clarified the concepts in 2013 with a structured categorisation: Information security protects all information regardless of form, IT security protects technology and software, and cyber security safeguards everything vulnerable through ICT. Modern frameworks now include “Digital Security” as an all-encompassing term for everything digital.

Back to Blog