1 of 70

Cybersecurity �Fundamentals

2 of 70

Welcome to the Workshop!

1-day Workshop from 12pm-8pm.

Course notes and materials provided.

Answers to exercises should be placed in the PPT template provided.

3 of 70

Executive Diploma Program in Cybersecurity - SPACE

Cybersecurity Defense

Page #

  1. Cybersecurity Fundamentals
  2. Offensive Security
  3. Intro to Cybersecurity Defense
  4. Security Education, Awareness and Training
  5. Governance, Risk Management and Cybersecurity Planning
  6. Security Architecture
  7. Data Privacy and Protection
  8. Security Operations

Page 3

4 of 70

Agenda

Session 1 (12pm-4pm)

  • General Security Concepts
  • Caselet 1: Waymo v Uber

Session 2 (4pm-8pm)

  • Threats and Risks
  • Caselet 2: Equifax

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

5 of 70

Getting to Know

  • Name:
  • Position/Role:
  • Company:
  • Why are you taking this course?
  • Cybersecurity knowledge (1-5), 1=lowest 5=highest

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

6 of 70

About the Facilitator: Justin Pineda

Industry

Certs

Academe

Pineda Cybersecurity

Alorica

Ingram Micro

Bnext Inc.

JG Summit Holdings Inc.

The Coca-Cola Company

Silversky/Perimeter Security

DPO ACE, CISSP, ISO/IEC 27032, ISO/IEC 27035, ISO 27034, ISO 42001, ISO 27001, CISM, CEH, GWAPT, GMOB, CEH, Security+, CCNA, IBM DB2, ISO 27002, Cato SASE, Parallels RAS, ITILv3, APMG CISM, ISC2 Trainer

Asian Institute of Management (AIM)

DLS-CSB

Asia Pacific College

LPU

NU

San Beda

Mapua

TIP

Page 6

7 of 70

Learning Process

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

Read Materials

Join the Lecture

Share Insights

Answer the Assessment

* A PDF Glossary of Cybersecurity terms is also uploaded for reference.

8 of 70

Cybersecurity Talent Shortage

Microsoft is launching a national campaign with U.S. community colleges to help skill and recruit into the cybersecurity workforce 250,000 people by 2025, representing half of the country’s workforce shortage

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

9 of 70

Global Cybersecurity Skills Needed

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

10 of 70

11 of 70

Common Security Misconception

That there are only 2 teams:

Attackers (Red) and Defenders (Blue)

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

12 of 70

But in the actual practice…

There are seven (7) teams.

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

13 of 70

Survey – Which cybersec color are you interested to explore?

    • Blue Team (Defend)
    • Red Team (Breakers)
    • Purple Team (Integrate)
    • Green Team (Automate)
    • Yellow Team (Build)
    • Orange (Educate)
    • White (Manage)
  • Why did you choose that cybersecurity color?

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

14 of 70

15 of 70

Security Certifications

  • CompTIA – Security+
  • EC-Council – Certified Ethical Hacker, Certified Security Analyst, Certified Hacking & Forensics Investigator etc.
  • SANS – GIAC Certified Reverse Engineering Malware, Incident Handler, Intrusion Analyst etc.
  • ISACA – Certified Information Systems Auditor etc.
  • ISC2 – Certified Information Systems Security Professional (CISSP), etc.

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

16 of 70

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

https://certification.comptia.org/docs/default-source/downloadablefiles/it-certification-roadmap.pdf

17 of 70

General Security Concepts

1 of 2

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

18 of 70

"Information security involves the definition, implementation, maintenance, and evaluation of a coherent system of measures..."

Ensuring the availability, integrity and confidentiality of information provision.

19 of 70

Information Security

  • Protection of information from a wide range of threats in order to ensure business continuity, minimize business risk, and maximize return on investments and business opportunities

Code of practice for information security management��

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

20 of 70

Information Security vs. IT Security

  • Information Security has many domains.
    • Access control, telecommunications and network security, Information security governance and risk management, Software development security, Cryptography, Security architecture and design, Operations security, Business continuity and disaster recovery planning, Legal, regulations, investigations and compliance, Physical (environmental) security – from CISSP’s domains on ISC2
  • IT Security only focuses on software and hardware technologies.

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

21 of 70

How to Implement Information Security?

  • The quality requirements an organization may have for the information;
  • The risks for these quality requirements;
  • The measures that are necessary to minimize these risks;
  • Ensuring the continuity of the organization in the event of a disaster.

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

22 of 70

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

Availability

Ensuring that information and critical services are accessible and usable upon demand by authorized users.

Integrity

Maintaining and assuring the accuracy and completeness of data over its entire lifecycle without unauthorized changes.

Confidentiality

Protecting information from being accessed by unauthorized individuals, ensuring privacy and restricted access.

THE THREE PILLARS OF INFOSEC

23 of 70

Confidentiality

  • Degree to which access to information is restricted to a defined group authorized to have this access.
  • Includes measures to protect privacy

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

DFA probes data breach into PHL passport tracking system

(Businessworld, Nov 2021)

24 of 70

Integrity

  • Degree to which the information is up to date and without errors.
    • Correctness
    • Completeness

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

25 of 70

Availability

  • Degree to which information is available for the user and for the information system that is in operation the moment the organization requires it.
    • Timeliness
      • The information systems are available when needed;
    • Continuity
      • The staff can carry on working in the event of a failure;
    • Robustness
      • There is sufficient capacity to allow all staff in the system to work.

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

26 of 70

Defense in Depth (DiD)

  • There should be multiple layers of security before gaining access to the data.

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

27 of 70

Security Service and Mechanisms

  • Security Service – how objectives are manifested.
  • Security Mechanisms – solutions we can implement in the enterprise.
    • Inconvenient Truth:
      • 1.You cannot protect everything from everyone.
      • 2.There are not enough resources and money in the world to totally mitigate all risks.
      • 3.Focus on protecting the most important information first, that which must be protected, and that with the highest risk.

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

28 of 70

Service & Mechanism Example

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

Goal: I want to focus on physical security

Security Services: (1)Personnel security; (2) Access control

Security Mechanisms: (1) Security clearance, training, rules of behavior; (2) Biometrics, proximity card, mantraps;

29 of 70

Operational Model of Security

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

For many years, the focus was on prevention.

Protection = Prevention

For example: Use of Firewall

(Conklin et al, 2011)

30 of 70

Operational Model

  • But what are the realities of a network environment?
  • How about Zero-day attacks?
  • How about DDoS on port 80?

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

31 of 70

Operational Model (cont’d)

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

32 of 70

Security Principles (cont’d)

  • Least Privilege – an object should only have the rights and privileges necessary to perform its task with no additional permissions.

Case of User Privilege:

Linux – sudo su (super user)

Microsoft – default admin

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

33 of 70

Diversity of Defense

    • Do not rely on a single brand of security device.
    • Why should companies NOT rely on a single brand of security device?

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

34 of 70

Diversity of Defense

    • Why should companies NOT rely on a single brand of security device?

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

Because if a VULNERABILITY is FOUND in a particular brand, NO MATTER how many devices you have, ALL OF THEM ARE VULNERABLE.

35 of 70

Security through Obscurity (STO)

    • From Daniel Messler: “An example of security by obscurity is when someone has an expensive house outfitted with the latest lock system, but the way you open the lock is simply by jiggling the handle.”

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

36 of 70

Cost Benefit Analysis (CBA)�

  • The cost of safeguard or protection should not be greater than the value of the asset.

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

37 of 70

Cost Benefit Analysis (CBA)�

  • The cost of safeguard or protection should not be greater than the value of the asset.

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

38 of 70

NIST Cybersecurity Framework

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

39 of 70

NIST Cybersecurity Framework

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

40 of 70

NIST Cybersecurity Framework Application

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

Identify

Protect

Detect

Respond

Recover

House

Gate

CCTV

Call the police

Evacuate

41 of 70

Exercise 1�General Security Concepts�(Waymo vs. Uber) �45 minutes to answer�15 minutes to discuss

Refer to your Exercise Document.

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

42 of 70

CYBERSECURITY FUNDAMENTALS

TAKE A BREAK

60

MINUTES

local_cafe

Grab a Refreshment

Step away from your screen, stretch, and hydrate.

schedule

Session Resumes Promptly

We will begin the next module immediately after the hour.

43 of 70

Threats and risks

2 of 2

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

44 of 70

Security Relationships

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

Threat Agent

Threat

Vulnerability

Risk

Asset

Exposure

Safeguard

Gives rise to

Exploits

Leads to

Can damage

And causes

Can be counter-measured by a

Directly affects

45 of 70

Example: Broken door knob

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

Thief

Threat agent/actor

Robbery

Threat

Broken Door Knob

Vulnerability

46 of 70

Cyber Threat Environment

Cyber Threat

  • Activity intended to compromise the security of an information system by altering the availability, integrity, or confidentiality of a system or the information it contains.

Cyber Threat Environment

  • Online space where cyber threat actors conduct malicious cyber threat activity.

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

47 of 70

Cyber Threat Actors

  • States, groups, or individuals who, with malicious intent, aim to take advantage of vulnerabilities, low cyber security awareness, and technological developments to gain unauthorized access to information systems in order to access or otherwise affect victims’ data, devices, systems, and networks

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

48 of 70

Cyber Threat Actor and Motivation

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

Cyber Threat Actor

Motivation

Nation-states

Geopolitical

Cybercriminals

Profit

Hacktivists

Ideological

Terrorist Groups

Ideological Violence

Thrill-Seekers

Satisfaction

Insider Threats

Discontent

Anonymous

Hacktivists

Employee Negligence

Insider Threats

49 of 70

Cyber Threat Surface

  • Refers to all the available endpoints that a threat actor may attempt to exploit in Internet-connected devices within the cyber threat environment.

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

50 of 70

Risk Analysis

  • Used to outline the risks that an organization faces
  • Purpose to clarify which threats are relevant to the operational processes and to identify the associated risks.
  • Used to ensure that the security measures are deployed in a cost-effective and timely manner, and consequently provide an effective answer to the threats.

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

(Conrad, Misenar & Feldman, 2010)

51 of 70

Risk Formula

Risk = Threat x Vulnerability

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

52 of 70

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

53 of 70

Calculating Risk

  • Using a scale of 1-5, here’s San Francisco’s risk, using the risk = threat X vulnerability calculation:
    • San Francisco threat: 4
    • San Francisco vulnerability: 2
    • San Francisco risk: 4 X 2 = 8
  • Here is Boston’s risk:
    • Boston threat: 2
    • Boston vulnerability: 4
    • Boston risk: 2 X 4 = 8

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

54 of 70

Impact

Risk = Threat x Vulnerability x Impact

*Impact – severity of the damage

*Impact – consequences

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

55 of 70

With Impact

  • Empty Building Risk: 2 (threat) X 4 (vulnerability) X 2 (impact) = 16
  • Full Building Risk: 2 (threat) X 4 (vulnerability) X 5 (impact) = 40

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

56 of 70

Risk Management Process

(NIST 800-30)

1. System Characterization

2. Threat Identification

3. Vulnerability Identification

4. Control Analysis

5. Likelihood Determination

6. Impact Analysis

7. Risk Determination

8. Control Recommendations

9. Results Documentation

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

57 of 70

Calculating Annualized Loss Expectancy

  • Annualized Loss Expectancy (ALE) – used to determine the annual cost of a loss due to a risk.
    • Calculated by multiplying the Single Loss Expectancy (SLE) times the Annual Rate of Occurrence (ARO).
  • Asset Value (AV) – value of asset you protect
  • The Exposure Factor (EF) - percentage of value an asset lost due to an incident
  • The Single Loss Expectancy (SLE) - cost of a single loss.
    • SLE is the Asset Value (AV) times the Exposure Factor (EF)
  • Annual Rate of Occurrence (ARO) - number of losses you suffer per year.

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

(Conrad, Misenar & Feldman, 2010)

58 of 70

Example Scenario:

Assume your company has 1,000 laptops that contain Personally Identifiable Information (PII). You are the Security Officer, and you are concerned about the risk of exposure of PII due to lost or stolen laptops. You would like to purchase and deploy a laptop encryption solution. The solution is expensive, so you need to convince management that the solution is worthwhile.

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

59 of 70

Asset Value

  • Each laptop costs $2500, but the real value is the PII. Theft of unencrypted PII has occurred previously, and has cost the company many times the value of the laptop in regulatory fines, bad publicity, legal fees, staff hours spent investigating, etc. The true average Asset Value of a laptop with PII for this example is $25,000 ($2500 for the hardware, and $22,500 for the exposed PII)
  • In the case of a stolen laptop with unencrypted PII, the Exposure Factor is 100%: the laptop and all the data are gone.

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

60 of 70

SLE, ARO and ALE

  • SLE is $25,000 (Asset Value) times 100% (Exposure Factor), or $25,000.
  • Looking through past events, you discover that you have suffered 11 lost or stolen laptops per year on average. Your ARO is 11.
  • In our case, it is $25,000 (SLE) times 11 (ARO), or $275,000.

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

61 of 70

TCO

  • Software cost : $100,000
  • Three year’s vendor support: $10,000 X 3 = $30,000
  • Hourly staff cost : $280,000
  • Total Cost of Ownership over 3 years: $410,000
  • Total Cost of Ownership per year : $410,00 0/3 = $136,667 /year
  • Your Annual Total Cost of Ownership for the laptop encryption project is $136,667 per year

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

62 of 70

ROI

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

You will save $247,500/year (the old ALE, $275,000, minus the new ALE, $27,500)

by making an investment of $136,667. Your ROI is $110,833 per year ($247,500 minus

$136,667). The laptop encryption project has a positive ROI, and is a wise investment.

Annualized Loss Expectancy of Unencrypted Laptops

Annualized Loss Expectancy of Encrypted Laptops

(Conrad, Misenar & Feldman, 2010)

63 of 70

Measures that reduce risk

  • Security tries to prevent the threat
  • Ex: Firewall prevents unwanted traffic.
    • permit web traffic (port 80)

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

64 of 70

Types of Risk Strategies

  • Risk Acceptance
    • When the management acknowledges the risk and decides to accept it.
  • Risk Mitigation
    • Security measures are taken such that the threats either no longer manifest themselves or if they do, the resulting damage is minimized.
  • Risk Avoidance
    • Measures are taken such that the threat is neutralized to such an extent that the threat no longer leads to an incident.
  • Risk Transference
    • Shifting risks from one area (or organization) to another.

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

65 of 70

Example Scenario

Your company sells Apple iPods online and has suffered many denial-of-service (DoS) attacks. Your company makes an average $20,000 profit, and a typical DoS attack lowers sales by 40%. You suffer seven DoS attacks on average per year. A DoS-mitigation service is available for a subscription fee of $10,000/month. You have tested this service, and believe it will mitigate the attacks.��

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

(Conrad, Misenar & Feldman, 2010)

66 of 70

Question 1

What is the Annual Rate of Occurrence in the above scenario?

A. $20,000

B. 40%

C. 7

D. $10,000

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

67 of 70

Question 2

What is the annualized loss expectancy (ALE) of lost iPod sales due to the DoS attacks?

A. $20,000

B. $8000

C. $84,000

D. $56,000

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

68 of 70

Question 3

Is the DoS mitigation service a good investment?

A. Yes, it will pay for itself

B. Yes, $10,00 is less than the $56,000 Annualized Loss Expectancy

C. No, the annual Total Cost of Ownership is higher than the Annualized Loss Expectancy

D. No, the annual Total Cost of Ownership is lower than the Annualized Loss Expectancy

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

69 of 70

Exercise 2Risk Analysis�(Equifax)�45 minutes to answer�15 minutes to discuss

Refer to your Exercise Document.

Cybersecurity Fundamentals rev9 | J. Pineda 06-2026

70 of 70

Cybersecurity �Fundamentals