Technology security disciplines
Network security controls communication paths and boundaries; endpoint security protects laptops, servers and mobile devices; application and API security protects software behaviour; cloud security covers provider and customer responsibilities; and identity security controls human and machine access.
Data security follows information across storage, processing and sharing. Mobile, IoT and operational technology security address devices and environments with different operating and safety constraints.
- Network security: traffic, segmentation and remote access
- Endpoint security: device posture, prevention and response
- Application and API security: design, code and runtime behaviour
- Cloud security: identity, configuration, workloads and shared responsibility
- Identity security: authentication, authorization and privileged access
- Data security: classification, access, encryption, retention and loss prevention
Operational security disciplines
Security operations brings telemetry, detection, investigation and response together. Threat intelligence provides relevant context; vulnerability management reduces exploitable exposure; incident response coordinates containment and recovery; and digital forensics preserves and analyses evidence.
These capabilities should work as a loop. Intelligence changes detection, incidents change hardening, and vulnerability evidence changes priorities.
- Security monitoring and SOC
- Threat intelligence and detection engineering
- Vulnerability and exposure management
- Incident response and digital forensics
- Business continuity and cyber recovery
Governance and human disciplines
Governance, risk and compliance sets objectives, accountability and evidence. Security architecture turns those objectives into designs. Awareness and workforce development help people make better decisions. Third-party and supply-chain security manages dependencies outside direct control.
Privacy and safety have their own goals but share data, identity and assurance mechanisms with security. Treat them as partners, not aliases.
- Security governance and enterprise risk
- Security architecture and assurance
- Privacy engineering
- Third-party and supply-chain security
- Security awareness and culture
- Workforce and role development
How the types work together
A customer application illustrates the overlap: identity authenticates the user; application security validates behaviour; cloud and network controls isolate services; data security protects records; endpoints secure administrators; operations detects abuse; and governance decides acceptable risk.
Use a service map to assign outcomes to owners. Review handoffs during design and incidents, because unowned boundaries create more risk than an imperfect org chart.
- One accountable service owner
- Named control operators
- Shared telemetry and incident process
- Architecture review across disciplines
A practical 30-day field plan
Week one — Govern. Risk, policy, architecture and compliance. Put one accountable owner in the room, agree which business service or decision is in scope, and record the assumptions the team is making. Resist the urge to begin with a technology purchase; the first deliverable is a shared view of the problem and the authority to change it.
Week two — Prevent. Identity, data, application, cloud, endpoint and network controls. Walk through the current process with the people who operate it. Compare the written design with real access paths, data flows, exceptions and on-call practice. Mark every point where an owner is missing or where the team cannot produce evidence that a control works.
Week three — Detect. Telemetry, intelligence and security operations. Choose a narrow pilot that can be observed safely. Define the expected result, the rollback path and the person who may accept a trade-off. Capture operational friction as product feedback; controls that are difficult to use will eventually be bypassed.
Week four — Respond. Containment, recovery, learning and improvement. Review the pilot with engineering, operations, security and the service owner. Close urgent gaps, assign longer work to a funded backlog and set the next evidence review. The month should end with a repeatable operating rhythm, not a one-time presentation.
Evidence worth keeping
Good evidence is understandable outside the team that created it. Keep a concise record that connects the decision, owner, technical implementation and observed result. Screenshots can support evidence, but configuration, logs, test output and approved records are stronger because another person can reproduce or challenge them.
- Network security: traffic, segmentation and remote access — owner, current state, last validation and any open exception
- Security monitoring and SOC — owner, current state, last validation and any open exception
- Security governance and enterprise risk — owner, current state, last validation and any open exception
- One accountable service owner — owner, current state, last validation and any open exception
- Decision log showing who approved residual risk and when it will be reviewed
- Test or exercise result with the actual outcome, not only a pass label
Questions for the leadership review
Use these questions to keep the discussion connected to operating risk rather than tool activity. A useful answer names a person, a service and evidence.
- Who is accountable for the cybersecurity fundamentals outcome when teams disagree about delivery and risk?
- Which critical service or customer promise would be affected by a failure in this area?
- What evidence would tell us the design is working in production today?
- Which exception creates the largest concentration of access, dependency or recovery risk?
- What would the team contain first, and how would it restore a trustworthy service?
- Which improvement can be completed in the next 30 days without waiting for a large programme?
Common questions
How many types of cybersecurity are there?
There is no single official count. This guide groups the field into technology, operations, governance and human disciplines so responsibilities are easier to assign.
Does a small company need every specialty?
It needs the outcomes, not a separate employee for each. Combine roles internally and use qualified providers where scale or independence requires it.
