What Is Cybersecurity?
Cybersecurity is the practice of protecting computers, networks, applications, and data from unauthorized access, disruption, or theft. It combines technology firewalls, encryption, monitoring tools with processes and people: policies, training, and a plan for what happens when something goes wrong.
The goal isn’t to make a system un-hackable. That’s not a realistic standard for any organization or individual. The goal is to make attacks harder to pull off, catch them faster when they happen, and recover with as little damage as possible. A lot of the field is built around that last assumption: prevention will eventually fail somewhere, so detection and recovery carry as much weight as the locks on the front door.
Why Cybersecurity Matters
For individuals, weak cybersecurity shows up as identity theft, drained bank accounts, or a ransomware note locking up years of family photos. For organizations, it shows up as halted operations, exposed customer data, regulatory penalties under laws like Canada’s PIPEDA and BC’s Personal Information Protection Act, and a reputation hit that can outlast the technical fix.
Neither of those outcomes requires a sophisticated attacker. Most breaches still start with something ordinary, a reused password, an unpatched system, or an employee clicking a convincing link. That’s part of why cybersecurity is treated as a discipline rather than a single tool: no one product closes every one of those gaps.
The Main Areas of Cybersecurity

“Cybersecurity” covers several distinct specializations. Most working professionals focus on one or two of the following, even though the field is often talked about as one thing
|
Area |
What it protects |
|
Network security |
Traffic and infrastructure moving between systems — firewalls, segmentation, VPNs. |
|
Application security |
Software itself, by finding and fixing flaws before and after release. |
|
Cloud security |
Data and workloads hosted on platforms like AWS, Azure, or Google Cloud. |
|
Identity and access management |
Who is allowed to see or change what — authentication and permissions. |
|
Endpoint security |
Individual devices: laptops, phones, servers. |
|
Data security |
Information itself, through encryption, backups, and data-loss prevention. |
|
Incident response |
What happens during and after an attack — containment, recovery, and the after-action review. |
The NIST Cybersecurity Framework: A Shared Language for Managing Risk
The NIST Cybersecurity Framework (CSF) is voluntary guidance published by the U.S. National Institute of Standards and Technology. It doesn’t tell an organization which specific tools to buy; it gives them a common vocabulary for describing and managing cybersecurity risk, which is why it’s referenced well beyond the United States, including by Canadian organizations that use it alongside guidance from the Canadian Centre for Cyber Security.
The current version, CSF 2.0, has been in effect since February 2024 and organizes the work into six functions:
|
Function |
In plain terms |
|
Govern |
Set the risk strategy, roles, and accountability that everything else depends on. |
|
Identify |
Know what systems, data, and risks actually exist. |
|
Protect |
Put safeguards in place — access controls, training, protective technology. |
|
Detect |
Notice when something is going wrong. |
|
Respond |
Contain and manage an incident once it’s detected. |
|
Recover |
Restore normal operations and apply what was learned. |
“Govern” is the newest addition in CSF 2.0 — earlier versions treated risk governance as implied rather than naming it as its own function. For anyone studying cybersecurity, the NIST CSF is worth learning early: it shows up in job postings, in how security teams structure their work, and as a reference point in more advanced frameworks and certifications.
Source: nist.gov/cyberframework, retrieved 2026-09-01.
How AI Is Changing Cybersecurity
AI shows up on both sides of this field right now, and that’s the honest starting point for anyone researching it.
On the defensive side, AI and machine-learning tools help security teams process a volume of alerts and log data that no human team could review manually — flagging unusual behavior, speeding up triage, and automating some of the repetitive analysis work that used to consume an analyst’s day.
On the offensive side, the same underlying technology lowers the effort required to run a convincing attack. AI-generated phishing emails read more naturally than the broken-English messages of a decade ago, and voice- or video-based deepfakes have made certain social-engineering scams harder to spot on sight.
What this means practically is that AI is changing the tools on both sides faster than it’s changing the underlying skills. Understanding how networks behave, how to read logs, and how to assess risk stays relevant no matter which tool sits on top of that judgment — which is part of why cybersecurity training still centers on fundamentals rather than any single AI product.
Practical Cybersecurity Tips: Where to Start
None of these guarantee protection — nothing does — but each one closes a gap that a large share of real incidents start from:
- Turn on multi-factor authentication (MFA) everywhere it’s offered, especially email and banking.
- Use a password manager and a unique password for every account.
- Install software and security updates promptly rather than postponing them.
- Slow down on links and attachments in unexpected messages, even from familiar-looking senders.
- Keep a working backup of anything you can’t afford to lose, stored somewhere separate from your main device.
- For organizations: apply least-privilege access, so people and systems only have the permissions they actually need.
Cybersecurity Careers and Jobs
“Cybersecurity” as a career covers a range of roles, not one job. Common entry points and specializations include:
|
Role |
Typical focus |
|
SOC analyst |
Monitors alerts and investigates suspicious activity in real time. |
|
Penetration tester |
Simulates attacks to find weaknesses before real attackers do. |
|
Security engineer |
Builds and maintains the tools and infrastructure that protect systems. |
|
Incident responder |
Leads containment and recovery once an incident is confirmed. |
|
GRC analyst |
Works on governance, risk, and compliance — policy, audits, and regulatory requirements. |
|
Security architect |
Designs how security fits into a system before it’s built. |
Demand for these roles is generally shaped by how much an organization depends on digital systems, cloud adoption, and the regulatory requirements it has to meet — which a large part is of why the field has grown across almost every industry rather than staying confined to tech companies.
For current, occupation-specific demand data in British Columbia, the Government of Canada’s Job Bank and WorkBC both publish outlook ratings by occupation code — Information Systems Security Analysts is filed under NOC 21220. Those are the sources to check directly rather than relying on a general “cybersecurity jobs” headline, since demand varies by role, region, and how recently the data was updated.
Cybersecurity Salary: What Actually Determines It

A general search for “cybersecurity salary” tends to surface U.S. figures or blended global averages that don’t reflect pay in British Columbia or Canada more broadly. What actually moves the number for a given person is the specific role, years of experience, certifications held, employer size and sector, and location — a penetration tester and a GRC analyst with the same years of experience are not paid on the same scale.
Rather than repeat a figure here that can’t be dated and sourced with confidence, the reliable path is to check current wage data directly: the Government of Canada’s Job Bank wage report for Information Systems Security Analysts (NOC 21220), filtered to British Columbia, and WorkBC’s occupation profile for the same code. Both are updated on a regular cycle and will always be more current than a number printed in an article.
How to Stay Current on Cybersecurity News
Cybersecurity changes fast enough that a general news search is a weak way to stay current — headlines chase the newest breach without much follow-up. A more durable habit is a short, recurring check-in against a small number of primary sources: the Canadian Centre for Cyber Security’s alerts and advisories, CISA’s advisories, NIST’s publication updates, and a vendor-neutral feed like the SANS Internet Storm Center. Fifteen minutes a week against sources like these tends to hold up better over time than following a stream of headlines.
Is a Career in Cybersecurity Right for You?
If the sections above interested you rather than overwhelmed you — the mix of technical detail, the puzzle-solving involved in incident response, the constant need to keep learning as tools and attackers change — that’s a reasonable signal to look further. If they read as exhausting rather than interesting, that’s worth taking seriously too; the field rewards people who stay curious about how things break.
Edison College Canada’s Cybersecurity Diploma is a 71-week, 1,420-hour program designed to prepare students for roles such as those described above, delivered in-class or by distance. Tuition is published at $24,842, with a total of $25,792 including related fees (Edison program page, retrieved 2026-08-05 — confirm current figures before publishing). Edison College Canada is listed as a StudentAid BC designated institution; eligible students may be able to apply for StudentAid BC funding, though eligibility depends on the student and the program.
Employment after graduation depends on the employer, the labour market, and the graduate’s own experience and qualifications — no program can guarantee a placement or a starting salary.
If you want the details — admission requirements, the full course list, and delivery format — the Cybersecurity Diploma program page is the place to start.
FAQ
What is cybersecurity in simple terms?
Cybersecurity is the practice of protecting computers, networks, and data from unauthorized access, disruption, or theft, using a combination of technology, processes, and trained people.
What is the NIST Cybersecurity Framework?
It’s voluntary guidance from the U.S. National Institute of Standards and Technology that organizes cybersecurity risk management into six functions: Govern, Identify, Protect, Detect, Respond, and Recover. The current version is CSF 2.0, in effect since February 2024.
Is AI making cybersecurity jobs less necessary?
No — AI is changing the tools used on both the defensive and offensive sides, but it has not removed the need for people who understand networks, risk, and how to interpret what a tool is telling them. Most current use treats AI as an assistant to analysts, not a replacement for them.
Do you need a university degree to work in cybersecurity?
Not necessarily. Many entry-level and mid-level roles are filled by people with a diploma or certificate plus relevant certifications and hands-on skills, alongside others who hold a degree. Requirements vary by employer and role.
How much do cybersecurity jobs pay in British Columbia?
It depends heavily on the specific role, experience, and employer. For current, sourced figures, check the Government of Canada’s Job Bank wage report and WorkBC’s occupation profile for Information Systems Security Analysts (NOC 21220), filtered to BC.
How do I get started learning cybersecurity?
Start with the fundamentals — how networks and operating systems work — then build toward a specific area like network security, application security, or incident response. A structured program, like Edison’s Cybersecurity Diploma, is one route; self-directed study and entry-level certifications are another.
Contact us today for more information on this program.
Read more industry-related blogs here.











