Discover our full range online
Degrees
Masters
VET
Any questions? Don’t keep them to yourself – just ask us.

All fields are required

What is IT security and what exactly does it cover?

IT security is the discipline responsible for protecting information systems: physical equipment, installed software, communication networks and the data stored on them. Its aim is to ensure that these assets function correctly and that only authorised individuals can access them.

This field emerged long before the internet as we know it today. Even in the earliest data centres, engineers were concerned with protecting physical servers from unauthorised access, power cuts or hardware failures. For this reason, IT security has a very broad scope, which includes:

  • Physical security: protecting equipment against theft, fire or natural disasters.
  • Logical security: access control, passwords, user permissions and system audits.
  • Network security: configuration of firewalls, routers and secure communication protocols.
  • Vulnerability management: identifying and fixing faults in software and operating systems before they can be exploited.

In simple terms, if you think of a business as a building, IT security is the entire system of locks, cameras and security guards that protect both the physical building and its internal facilities.

What is cybersecurity and how does it differ from IT security?

Cybersecurity cybersecurity is a specialisation that has emerged with the widespread adoption of the internet and digital networks. It focuses specifically on protecting the systems, networks and data connected to cyberspace against malicious attacks and unauthorised access with harmful intent.

Unlike IT security, which has a broader scope and also encompasses physical and internal management aspects, cybersecurity is directly targeted at external threats: hackers, cybercriminals, industrial espionage groups and automated attacks. Its areas of focus include:

  • Incident detection and response: identifying attacks in real time and neutralising them before they cause damage.
  • Ethical hacking and penetration testing: simulating attacks to find vulnerabilities before attackers do.
  • Digital forensics: investigating the digital traces left by an attack to understand how it occurred and who carried it out.
  • Web and mobile application security: protecting the digital services used by millions of people every day.
  • Threat intelligence: gathering and analysing information on global threats to anticipate future attacks.

To continue with the building analogy, cybersecurity would be the specialist team that detects anyone attempting to gain unauthorised entry from outside, analyses their techniques and installs systems to prevent them from trying again.

What are the key differences between cybersecurity and IT security?

To help you see the differences at a glance, here is a comparison table highlighting the most relevant aspects:

Feature

IT security

Cybersecurity

What it isA discipline aimed at protecting systems, devices, networks and dataA field focused on protecting digital assets and environments from cyber threats
ObjectiveTo maintain the confidentiality, integrity and availability of systems and informationTo prevent, detect, respond to and recover from cyber-attacks
ScopeIT systems, devices, networks and dataDigital systems and environments, particularly those that are connected
ThreatsUnauthorised access, vulnerabilities, data loss or system failuresMalware, ransomware, phishing, DDoS, intrusions and other cyber threats
Examples of activitiesAccess control, vulnerability management, device and network protectionThreat detection, incident response, penetration testing and forensic analysis
RelationshipA concept closely related to the protection of systems and dataIt shares objectives and techniques with IT security, with a particular focus on threats in the digital environment

As you can see, IT security is the broader field and cybersecurity is, to a certain extent, a specialisation within it. However, in practice, the two disciplines are so closely intertwined that professionals in the sector often work in both simultaneously.

What threats does each discipline tackle in the real world?

In the field of IT security, professionals deal with an employee accessing files without permission, a server with unpatched vulnerabilities, a power cut rendering critical data inaccessible, or an unencrypted device vulnerable to physical theft.

In the field of cyber security, the challenges are quite different:

  • A ransomware attack that encrypts all a company’s data and demands a financial ransom.
  • A phishing campaign that tricks employees into revealing their passwords.
  • A DDoS attack that overwhelms a company’s servers and takes its website offline.
  • An advanced persistent threat (APT) in which a cyber-espionage group silently infiltrates systems for months.

In 2023, Spain was the third most targeted European country by cybercriminals, according to the report by the National Cryptology Centre (CCN-CERT), with over 110,000 incidents handled. This figure alone justifies the growing demand for cybersecurity experts in our country.

What training do you need to work in cybersecurity?

Cybersecurity requires knowledge of computing, networks, systems and data protection, although there is no single training pathway to enter this field. Prior training in technological areas can provide a useful foundation, which can subsequently be complemented by a specific specialisation in cybersecurity.

For those wishing to specialise in this field, there are specialised training programmes that enable you to gain knowledge of vulnerability analysis, threat detection, incident response and the protection of systems and networks.

At UAX, the Online Master’s in Cybersecurity and the Málaga enables students to specialise in this field and gain in-depth knowledge of the techniques and tools used to protect systems and digital environments against current threats.

Online Master’s Degree in Cybersecurity

Further information

Which professional roles correspond to each specialism?

Roles most closely linked to IT security:

  • Systems administrator: manages the technological infrastructure and ensures its proper functioning and security.
  • Network technician: designs and maintains communication networks in accordance with security criteria.
  • Security auditor: assesses a company’s systems to verify regulatory compliance.

Roles more focused on cybersecurity:

  • Cybersecurity analyst (SOC analyst): monitors and responds to incidents in real time from a Security Operations Centre.
  • Pentester or ethical hacker: tests systems from an attacker’s perspective to find vulnerabilities before others do.
  • Digital forensic analyst: investigates attacks to identify those responsible and prevent them from happening again.
  • Chief Information Security Officer (CISO): leads the security strategy across the entire organisation.

Is there a third concept? Information security explained

When discussing cybersecurity versus computer security, there is one term you cannot ignore: information security. It is the broadest of the three concepts and acts as the umbrella under which the other two fall.

Information security protects data regardless of its format: it may be on a computer system, but also in a physical paper document, in a conversation or even in an employee’s memory. Its aim is to guarantee three fundamental principles known as the CID triad:

  • Confidentiality: ensuring that information reaches only those it is intended for.
  • Integrity: ensuring that data is not altered without authorisation.
  • Availability: ensuring that information is accessible when needed.

This discipline is underpinned by international standards such as ISO 27001, which sets out the requirements for implementing an Information Security Management System (ISMS) in any organisation, and in Spain by the National Security Scheme (ENS), regulated by Royal Decree 311/2022, which requires public administrations to comply with minimum standards for information protection.

Conclusion

The question is not which is more important – cybersecurity or IT security – but rather that both are complementary and essential. IT security forms the foundation, whilst cybersecurity is the specialisation that adapts it to today’s digital environment. If you’re interested in this field, combining a solid background in computer engineering with a specialist master’s degree in cybersecurity is the best way to stand out in a job market where demand is constantly growing.

Sources

  • National Cryptology Centre (CCN-CERT). Report on cyber threats and trends 2023. ccn-cert.cni.es
  • National Cybersecurity Institute (INCIBE). Glossary of Cybersecurity Terms. incibe.es
  • Royal Decree 311/2022 of 3 May, regulating the National Security Framework. Official State Gazette (BOE).
  • ISO/IEC 27001:2022. Information security, cybersecurity and privacy protection. ISO.