Network Security
intermediate30 minLearning objectives
- Identify common cyber threats
- Explain methods used to secure networks
- Evaluate security measures for different organisations
Learn
AQA 4.8.1 — Network security
Retrieval: the previous lesson traced how a web page normally loads. This lesson asks what happens when someone deliberately tries to interfere with that process, or with a network more generally — and how organisations defend against it.
Key vocabulary
- Malware — malicious software (viruses, ransomware, spyware) designed to damage, disrupt or gain unauthorised access to a system.
- Phishing — tricking a person into revealing sensitive information (like a password) by pretending to be a trustworthy source.
- Firewall — a system that filters network traffic, blocking anything that doesn't match a set of allowed rules.
- Encryption — scrambling data so it's unreadable to anyone without the correct key, even if intercepted.
- Authentication — verifying that a user genuinely is who they claim to be (e.g. a password, or two-factor authentication).
Understand — different threats exploit different weaknesses
Malware exploits weaknesses in software — a flaw or a lack of protection that lets malicious code run or spread. Phishing exploits weaknesses in human judgement instead — no software flaw is needed at all if a person can simply be persuaded to hand over their own credentials voluntarily. Because the two threats target completely different weaknesses, no single defence can address both — this is exactly why real security uses multiple, different layers together.
Visualise — matching threats to controls
| Threat | What it exploits | Control that specifically addresses it |
|---|---|---|
| Malware | Software vulnerabilities, unsafe downloads | Antivirus software, keeping software updated |
| Phishing | Human trust and urgency | Staff training, verifying sender/link authenticity |
| Data interception on a network | Unencrypted data in transit | Encryption (e.g. HTTPS) |
| Unauthorised network access | Weak or absent traffic filtering | A firewall |
| Stolen/guessed passwords | Weak authentication | Strong passwords, two-factor authentication |
Apply to scenario — cybersecurity incident analysis
An employee receives an email that appears to be from their company's IT department, asking them to "verify their account" by clicking a link and entering their username and password. They do so. Shortly afterwards, unusual activity appears on their account.
Analyse this incident: what type of attack is this, what specific detail should have raised suspicion, and which control (from the table above) would most directly have reduced the risk here?
(This is phishing — it exploits trust in a familiar-looking sender rather than any software flaw. A genuine IT department would rarely ask for a password to be re-entered via an emailed link at all. Staff training to recognise and verify suspicious requests before acting on them is the control that most directly addresses this specific weakness — technical controls like a firewall or antivirus software wouldn't have stopped a legitimate-looking email being acted on voluntarily.)
Cumulative retrieval — from Sequence 6
Sequence 6 introduced decomposition: breaking a problem into smaller, more manageable sub-problems before trying to solve the whole thing at once. Apply that same skill here, to the phishing incident above, rather than treating it as one single event: decompose it into at least three distinct stages (for example: the email being crafted and sent; the employee deciding to trust and click it; the credentials being entered and captured). For each stage you identify, state one control from the table above that could have interrupted the incident at that specific stage — showing that "layered security" is really decomposition applied to defence, not a new idea from scratch.
Analyse — identify the vulnerabilities
A small business's current setup: no firewall configured on their router, staff share one login for a shared computer, and no one has received any security training. Identify at least three distinct vulnerabilities in this setup, and match each to the specific type of threat it leaves the business most exposed to.
Evaluate — proportionate security
A one-person hobby blog and a national bank both hold some form of user data, but evaluate whether they genuinely need the same level of security investment. What specifically differs between them that should change how much is spent on security, and on which controls?
Common mistake
Assuming antivirus software alone is "enough" security. Antivirus specifically addresses malware — it does nothing to stop a phishing email being acted on, unencrypted data being intercepted, or a weak password being guessed. Real security requires multiple, different layers working together, precisely because each threat exploits a different weakness.
Justify
A school is deciding how to allocate a limited security budget between three options: staff cybersecurity training, a more advanced firewall, or mandatory two-factor authentication for all staff accounts. Recommend a priority order and justify it using the threat-to-control matching above.
Looking ahead: the final lesson of this sequence (Ethical, Legal, Cultural and Environmental Issues) widens the lens beyond technical security specifically, to the broader responsibilities computing professionals and organisations have towards the people and world their systems affect.