Threats And Attacks — The Real Difference
Threat and attack are two sides of Schrödinger’s cat — one potential, the other realized until the box is opened.
Today, in the morning I had a class on Web and Mobile Security, and the professor asked us a question, As a cybersecurity student, I felt ashamed for thinking that both were the same until this morning, when our professor, Vishvendu Bhatt sir told that they both are actually different and in this 3-minute read I will try my level best to explain both the concepts easily.
Context Building
Imagine you are on the way to a café and you hear various dangerous rumors about 125th Street, Manhattan at 7 PM, If you walk through it, the potential threat is clear. The street is known for risks like theft or violence.
In this attack, if you deny them to give the purse or other demanding belongings of yours then you must end in severe injuries unless and until you are Khabib Nurmagomedov.
So the thing I want to say is that we must be aware of the various things or the various aspects of the street so that we can incur fewer losses.
Here is the takeaway — As there is only one road to our café, practically we need to pass from there — To minimize the losses you must need to distinguish or asses which ones can be recoverable(here in this case money or belongings) and the one which can’t be recovered like (your life).
So Similarly in cybersecurity, protecting critical assets over less important ones helps mitigate the impact of an attack.
What Is a Threat?
A threat is any potential risk or vulnerability that could lead to an attack or harm in the upcoming future. In our context-building paragraph, the dangerous rumors and the inherited risks of 125th Street represent the threat. Similarly, cybersecurity, threats could be of various types:
- A software vulnerability.
- Phishing attempts.
- Malware waiting to be executed — Atrojan Horsee
- Ransomware.
Threats exist as possibilities and may or may not materialize. It’s just a possibility of a dying or living cat in Schodinger’s thought experiment.
What Is an Attack?
An attack is when a threat is actively exploited.
In the example we discussed before the moment when the thief confronts you and demands your belongings is an attack, from which you can’t be able to escape — your ultimate goal is to reduce the losses by giving him the belongings you have. In a cybersecurity context, this might include:
- A hacker exploits a vulnerability in the form of a backdoor to steal data.
- A ransomware infection that potentially locks your whole system until or unless you fulfill the attacker’s demand.
An attack is the realization of a threat, turning potential danger into actual harm.
The Importance of Risk Management
In our example, you face a decision: should you hand over your purse or belongings? If you prioritize your life(An non — recoverable asset) over money(A recoverable asset), you minimize the overall impact of the attack. This mirrors the ability being sustained after the attack itself. Always note that
Fall seven times, stand up eight.
The attack is unpredictable, but by assessing the threats correctly, we can minimize the losses and can able to stand up even after an attack. Similarly, in cybersecurity:
- Critical assets(eg., sensitive data, critical system log files) must be protected at any cost.
- Less critical assets (e.g., temporary files) can be sacrificed if necessary.
If you liked this content drop a clap or two, and let’s connect on X.