Whether you work in finance, HR, operations, or law, you need to understand the vocabulary, mental models, and practical judgments of cybersecurity. Fundamentals of Cybersecurity introduces cybersecurity fundamentals in plain English, with practical examples, clear illustrations, and real-world scenarios. Based on their experience teaching over 25,000 students, authors Paulo Carreira and Andreé Miranda Louraço align cybersecurity concepts with practical skills like recognizing a phishing attempt, knowing what to do when a staff member leaves, and understanding why a firewall rule matters.
You’ll start with the fundamentals: assets, threats, vulnerabilities, and how risk is identified, assessed, and treated. From there, you’ll work through security controls and defense in-depth, discover governance frameworks, and learn the full incident response lifecycle, business impact analysis, and disaster recovery. You’ll also dive into access control and understand networking from the ground up, and even understand the attacker’s playbook: malware, phishing, social engineering, on-path attacks, DoS, insider threats, and more.
The final chapters cover the security operations that hold everything together, from cryptography, to system hardening, to the awareness programs that turn employees into a first line of defense. Each chapter builds on the last, moving from core security principles, through risk and governance, into the operational disciplines that keep real organizations safe.
Best of all, the book follows the six knowledge domains of the ISC2 Certified in Cybersecurity (CC) exam, making it an ideal starting point for anyone pursuing their first credential. As an added bonus, full practice exams ensure that you’re ready to tackle the ISC2 and get fully certified in cybersecurity!