Glossary · Term

Cybersecurity explained

Cybersecurity is the protection of IT systems, data and services against attack, failure and misuse.

At a glance
Meaning
Protection of IT systems, data and services
Security objectives
Availability, integrity, confidentiality, authenticity
Building blocks
Technology, processes, people
Link to NIS2
The core subject of the directive
Updated
June 2026
Editorial team
Compliance Compass

What is cybersecurity?

Cybersecurity covers every measure that protects digital systems, data and services against attack, failure and misuse. It is not a single product but a lasting interplay of technology, processes and people. While the NIS2 Directive and its National transposition set the legal framework, cybersecurity is the professional discipline behind them: the actual protecting of information and services.

The security objectives

At its core, cybersecurity protects four values, known together as the Security objectives: availability, integrity, confidentiality and authenticity. Availability means that systems are reachable; integrity that data stay unaltered; confidentiality that only authorised people have access; authenticity that origin and genuineness are assured. A security incident usually affects one or more of these values – for example when ransomware paralyses the availability of production.

How cybersecurity is achieved

Effective cybersecurity rests on three pillars that have to interlock. Technology on its own, without processes that are actually lived and people who are trained, stays full of gaps:

Cybersecurity and NIS2

NIS2 is at heart a cybersecurity directive. It requires cybersecurity to be run systematically, appropriately and demonstrably – best of all bundled into an ISMS built on standards such as ISO 27001. Being able to demonstrate it is what counts: in a dispute or an inspection, an entity has to show which measures it has taken.

An example: A member of staff receives a phishing email that looks entirely genuine. Where cybersecurity works, awareness training lets them recognise it, a spam filter (technology) catches comparable messages, and a defined reporting process (processes) makes sure the incident reaches the IT team at once – so a potential data leak stays nothing more than a reported and repelled threat.

Further reading: ENISA – the European Union Agency for Cybersecurity

Frequently asked questions

What is cybersecurity in simple terms?

Cybersecurity is the protection of IT systems, data and services against attack, failure and misuse. It is not a single product but a lasting interplay of three pillars: technology such as encryption and backups, clearly defined processes, and people who are trained. Reliable protection against threats such as phishing, ransomware or data theft only emerges when all three building blocks work together.

What are the security objectives of cybersecurity?

Cybersecurity pursues four central security objectives: availability (systems are reachable), integrity (data stay unaltered), confidentiality (only authorised people have access) and authenticity (origin and genuineness are assured). Article 6 of the NIS2 Directive names the same four values when it defines the security of network and information systems. A security incident typically affects one or more of them, for example when a ransomware attack paralyses the availability of production or encrypts data.

How does cybersecurity relate to NIS2?

NIS2 is at heart a cybersecurity directive and has applied since 18 October 2024. It obliges the entities it covers to run cybersecurity systematically, appropriately and demonstrably – best of all bundled into an ISMS built on standards such as ISO 27001. Being able to demonstrate this is decisive, because in an inspection an entity has to show which measures it has taken. Article 34 sets a minimum ceiling for fines of EUR 10 million or 2 % of total worldwide annual turnover for essential entities, and Member States may set higher amounts.

Cybersecurity

Cybersecurity you can prove on paper

Compliance Compass joins technology, processes and evidence into cybersecurity that is actually lived under NIS2.