<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Cybersecurity on Explain It</title><link>https://explainit.metacog.co.kr/tags/cybersecurity/</link><description>Recent content in Cybersecurity on Explain It</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 26 Aug 2026 11:30:45 +0900</lastBuildDate><atom:link href="https://explainit.metacog.co.kr/tags/cybersecurity/index.xml" rel="self" type="application/rss+xml"/><item><title>Why good security always has a backup plan for its backup plan</title><link>https://explainit.metacog.co.kr/posts/2026-08-26-why-good-security-always-has-a-backup-plan-for-its-backup-pl/</link><pubDate>Wed, 26 Aug 2026 11:30:45 +0900</pubDate><guid>https://explainit.metacog.co.kr/posts/2026-08-26-why-good-security-always-has-a-backup-plan-for-its-backup-pl/</guid><description>&lt;h2 id="-what-is-it"&gt;🤔 What Is It?&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;defense in depth&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Defense in depth means protecting your stuff with many layers of security, so even if a hacker breaks through one layer, several more layers are waiting to stop them.&lt;/p&gt;
&lt;h2 id="-like-defending-a-castle"&gt;🧩 Like defending a castle&lt;/h2&gt;
&lt;p&gt;Imagine a medieval castle. To reach the king&amp;rsquo;s treasure room, an attacker would first have to swim across the moat, then scale the high outer wall, then get past armed guards at every inner gate, then pick the lock on the treasury door, and finally crack open a heavy iron chest — all without being spotted by lookouts on the towers. No single wall keeps the castle safe; it is the combination of every obstacle working together. If the moat gets bridged, the outer wall is still standing. If someone sneaks over the wall, the guards are still there. Defense in depth works exactly the same way for computer systems.&lt;/p&gt;</description></item><item><title>IoC: The Digital Clues That Show a Computer Was Hacked</title><link>https://explainit.metacog.co.kr/posts/2026-07-26-ioc-the-digital-clues-that-show-a-computer-was-hacked/</link><pubDate>Sun, 26 Jul 2026 04:21:42 +0900</pubDate><guid>https://explainit.metacog.co.kr/posts/2026-07-26-ioc-the-digital-clues-that-show-a-computer-was-hacked/</guid><description>&lt;h2 id="-what-is-it"&gt;🤔 What Is It?&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;IoC(Indicator of Compromise)&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;An Indicator of Compromise (IoC) is a digital clue — like a suspicious file or an unusual connection — that tells security experts a computer may have been attacked. By collecting and sharing these clues, security teams can spot the same hackers targeting other systems too.&lt;/p&gt;
&lt;h2 id="-like-a-detectives-crime-scene-clue-book"&gt;🧩 Like a detective&amp;rsquo;s crime-scene clue book&lt;/h2&gt;
&lt;p&gt;Imagine a burglar breaks into a house and gets away, but they leave clues behind — a muddy boot print near the back door, a greasy fingerprint on the window, and scratch marks on the lock. A detective arrives, photographs every clue, and records them all in an evidence book. Then that detective shares the book with every police station in the country, so if those same boot prints or fingerprints turn up at another crime scene, officers instantly know: it&amp;rsquo;s the same burglar. IoCs work exactly the same way — except the crime scene is a hacked computer, the clues are things like suspicious files or unusual connections, and the detectives are security analysts sharing their evidence book with the whole world.&lt;/p&gt;</description></item><item><title>How the Internet's Neighborhood Watch Catches Hackers Early</title><link>https://explainit.metacog.co.kr/posts/2026-07-26-how-the-internet-s-neighborhood-watch-catches-hackers-early/</link><pubDate>Sun, 26 Jul 2026 03:54:34 +0900</pubDate><guid>https://explainit.metacog.co.kr/posts/2026-07-26-how-the-internet-s-neighborhood-watch-catches-hackers-early/</guid><description>&lt;h2 id="-what-is-it"&gt;🤔 What Is It?&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Cyber Threat Intelligence)&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Cyber Threat Intelligence is when security experts collect and share clues about hackers — who they are, how they attack, and what they want — so everyone can defend themselves before an attack even happens.&lt;/p&gt;
&lt;h2 id="-like-a-neighborhood-watch-sharing-burglary-clues"&gt;🧩 Like a neighborhood watch sharing burglary clues&lt;/h2&gt;
&lt;p&gt;Imagine your street has been having break-ins. One neighbor notices muddy boot prints near their window, another spots a suspicious van parked outside, and a third sees their doorknob had been jiggled. They all share these clues at a neighborhood meeting and figure out it&amp;rsquo;s a crew that targets houses with broken porch lights on Tuesday nights. Now every neighbor knows to fix their porch light and double-lock the back door before Tuesday — and when the crew shows up, they find nothing easy to break into. Cyber Threat Intelligence works exactly like this: the neighborhood is the internet, the break-in crew is hackers, and the clues are digital footprints left behind in computer systems.&lt;/p&gt;</description></item></channel></rss>