October 2, 2026
CEH Part 1: Introduction to Cybersecurity (in simple words)
My notes on the CIA triad, the cyber kill chain, IDS vs IPS and more, from my CEH โ eJPT โ OSCP journey

By ThePentestLab
3 min read
I'm learning ethical hacking step by step, and I'm sharing everything I learn here on ThePentestLab.
My plan is simple: CEH first, then eJPT, then OSCP. CEH builds the theory, eJPT gives me my first hands-on practice, and OSCP is the advanced, practical goal.
This is Part 1: the basics. I'll explain everything in simple words, and I practice only on my own lab and legal platforms.
## What is cybersecurity?
Cybersecurity means protecting computers, networks, apps and data from attackers.
Attackers usually want money, data, or to cause damage. Defenders protect three things: people, process and technology. Ethical hackers think like attackers, but with permission, to find weak points before real attackers do.
## Why are cyber attacks increasing?
-
More people and devices online: phones, cloud, IoT and remote work
-
More money in it: ransomware and stolen data sold online
-
Easy tools: ready-made attack kits mean even beginners can attack
-
Weak security: weak passwords, missing updates and untrained users
-
Hard to catch: attackers hide behind other countries and anonymous payments
## What is a data breach?
A data breach is when private data (passwords, ID numbers, card details, medical records) is accessed, stolen or leaked without permission.
Common causes are phishing, weak passwords, unpatched software, misconfigured cloud storage and insider mistakes. The impact can be money loss, legal trouble, lost trust and identity theft.
## Information security and its five elements
Information security means keeping information safe from unauthorized access, change or loss. It has five elements:
| Element | Simple meaning |
| โ -| โ -|
| Confidentiality | Only the right people can see it |
| Integrity | It isn't changed by the wrong people |
| Availability | It's there when needed |
| Authenticity | It's genuine and from a real source |
| Non-repudiation | Nobody can deny what they did |
## The CIA triad
The first three elements are the core goals of security:
Confidentiality: data theft is an attack on this
-
Integrity: someone secretly editing a bank record is an attack on this
-
Availability: DDoS or ransomware is an attack on this
Easy memory trick: Secret, Correct, Accessible.
## Information security threats
A threat is anything that can harm your data or systems:
-
Network threats: DDoS, sniffing, man-in-the-middle
-
Host threats: malware, ransomware, password attacks
-
Application threats: SQL injection, XSS, broken login
-
Human threats: phishing, social engineering, insider threats
## The Cyber Kill Chain
An attack happens as a series of steps. If a defender breaks one step, the attack can fail.
-
Reconnaissance: the attacker gathers information about the target
-
Weaponization: the attacker builds the attack (for example malware inside a PDF)
-
Delivery: the attack is sent to the victim (phishing email, infected USB, malicious link)
-
Exploitation: a weakness is triggered, for example when the victim opens the file
-
Installation: malware is planted, such as a backdoor
-
Command and Control: the attacker controls the system remotely
-
Actions on Objectives: the attacker reaches the goal, such as stealing or encrypting data
Delivery is a good place to defend: email filtering, user training and updates stop many attacks here.
## IoC: Indicators of Compromise
IoCs are clues that a system may already be hacked, such as unknown IP addresses in logs, strange files, unusual login times, sudden traffic spikes or new accounts nobody created. Security teams use them to find and confirm attacks.
## Risk management
Risk is how likely something bad is, multiplied by how much damage it would do. The process is a cycle: identify risks, assess how bad they are, treat them, then monitor and review. You can treat a risk by reducing it, avoiding it, transferring it (like insurance), or accepting it when the impact is low.
## Responding to threats
When an attack happens, incident response follows these steps: preparation, detection, containment, eradication, recovery and lessons learned.
## IDS vs IPS
-
An IDS (Intrusion Detection System) watches traffic and alerts. Think of a CCTV camera.
-
An IPS (Intrusion Prevention System) watches traffic and blocks. Think of a security guard.
## SOAR
SOAR stands for Security Orchestration, Automation and Response. It connects security tools, automates routine steps (like blocking an IP) and uses playbooks, so analysts spend their time on real threats instead of thousands of repeated alerts.
## Quick revision
-
Cybersecurity protects systems and data.
-
Attacks rise because of more devices, more money, easy tools and weak security.
-
A data breach exposes private data without permission.
-
The five elements: Confidentiality, Integrity, Availability, Authenticity, Non-repudiation.
-
CIA is the three core goals.
-
Threats come as network, host, application and human threats.
-
The kill chain has 7 steps, and Delivery is step 3.
-
IoCs are clues of compromise.
-
Risk management: identify, assess, treat, monitor.
-
Incident response: prepare, detect, contain, eradicate, recover, learn.
-
IDS alerts, IPS blocks.
-
SOAR automates security response.
Next: Part 2 covers footprinting and reconnaissance.
If you're learning CEH, eJPT or OSCP too, follow along. You can find me on X as @thepentestlab.