Business and Technology · Financial systems and technology
Cyber Security and Data Protection for ACCA BT
Updated 11 October 2026 · Fact-checked
Cyber security is protecting systems and data from attack, damage or unauthorised access. Data protection is the legal and ethical handling of personal data. To answer BT questions, identify the threat, then match it to a control: preventive, detective or corrective, general or application, and a data protection principle.
Understand Cyber Security and Data Protection
Every modern business depends on IT systems and data. Cyber security is the set of measures that protect those systems, networks and data from attack, damage or unauthorised access. The risk is not only hackers. Staff errors, lost laptops, weak passwords and unpatched software cause many breaches.
Common threats you should know: malware (viruses, worms, trojans, ransomware, spyware), phishing (fake emails that trick people into giving details or clicking links), hacking (unauthorised access), denial of service attacks (flooding a system so legitimate users cannot use it), social engineering (manipulating people rather than systems), and insider threats (staff misusing access). A breach can cause financial loss, fines, lost customers, legal action and damaged reputation.
Controls are the answer to threats. General controls apply across the whole IT environment: access controls and passwords, firewalls, anti-malware, encryption, backups and disaster recovery, software patching, physical security of servers, and controls over system development and changes. Application controls work inside a specific program or process: input checks (validation, such as format, range and check digits), processing controls (control totals, reconciliations), and output controls (review and distribution of reports).
Data protection is about personal data, which is information that identifies a living individual. Laws differ by country, but most follow similar principles. Data should be processed lawfully, fairly and transparently, collected for a specific purpose, limited to what is needed, accurate, kept no longer than necessary, and held securely. The organisation is accountable for complying. Individuals usually have rights, such as to see their data and have errors corrected.
In the exam, think of layers. Prevent the attack (firewalls, training, access rights), detect it (monitoring, intrusion detection, logs), and recover from it (backups, incident response plans). Do not rely on technology alone. People and procedures matter just as much.
Key formulas to remember
- General controls vs application controls
- General = whole IT environment; Application = one specific program or process
- Passwords, firewalls and backups are general. Input validation and control totals are application controls.
- Control types
- Preventive (stop it) | Detective (spot it) | Corrective (fix it)
- Firewall = preventive. Intrusion detection or log review = detective. Restoring from backup = corrective.
- Data protection principles (typical)
- Lawful, fair and transparent | Purpose limitation | Data minimisation | Accuracy | Storage limitation | Integrity and confidentiality | Accountability
- Exact wording varies by country. Learn the ideas, not a fixed legal text.
- Information security aims (CIA)
- Confidentiality | Integrity | Availability
- Confidentiality: only authorised people see data. Integrity: data is accurate and complete. Availability: data is accessible when needed.
- Input control examples
- Validation checks: range, format, presence, check digit, reasonableness
- These are application controls over input.
How to solve Cyber Security and Data Protection questions
Use this method for scenario and definition questions on cyber security and data protection.
- 1Read the question and decide what it asks: a threat, a control, a control type or a data protection principle.
- 2Underline the key facts in the scenario: what happened, what data or system is involved, and who is affected.
- 3Identify the threat or weakness. For example, a phishing email, weak passwords or data kept too long.
- 4Match it to the right control or principle. Ask: is this general or application, and preventive, detective or corrective?
- 5Check the aim affected: confidentiality, integrity or availability.
- 6For multiple response, pick exactly the stated number and reject options that do not fit the scenario.
- 7For number entry, read units and rounding rules carefully, though this topic rarely needs calculation.
- 8Review your answer against the scenario once. Make sure it solves the stated problem, not a different one.
Quickest way: Threat, control, type
When to use it: Use for most multiple choice questions in Section A where time is short.
- Name the threat in two words, such as phishing or ransomware.
- Ask what stops it, spots it or fixes it. This tells you preventive, detective or corrective.
- Ask where the control sits: whole IT environment (general) or one program (application).
- Eliminate options that are controls of the wrong type or that do not address the scenario.
- Pick the best remaining answer and move on.
Common mistakes in Cyber Security and Data Protection
Calling input validation or control totals general controls.
Students see 'control' and assume it covers all IT.
Fix: Ask whether the control works inside one program or process. If yes, it is an application control.
Mixing up detective and preventive controls.
Some tools do both, such as a firewall that also logs traffic.
Fix: Choose based on the main purpose. Stopping access is preventive. Reviewing logs after the event is detective.
Thinking data protection covers all business data.
The word 'data' is used loosely.
Fix: Data protection law is mainly about personal data of living individuals, not all company information.
Treating cyber security as only a technology problem.
Students focus on firewalls and software.
Fix: Include people and procedures: staff training, clear policies, access rights and incident response plans.
Confusing a backup with a preventive control.
Backups feel like protection.
Fix: A backup does not stop an attack. It helps you recover afterwards, so it is corrective.
Learning data protection principles as one country's exact law.
Notes often copy a specific statute.
Fix: Learn the common principles and apply them to the scenario in plain words.
Worked examples
Example 1
A company's finance team receives an email that looks like it is from the bank. It asks them to click a link and enter login details. One employee does so and the account is compromised. Which TWO controls would best reduce the risk of this happening again? (A) Staff awareness training on phishing (B) Daily offsite backups (C) Multi-factor authentication on bank logins (D) Control totals on payroll input
Show the solution
- Identify the threat: phishing, a social engineering attack that steals login details.
- Ask what stops it from working. Training makes staff less likely to click. Multi-factor authentication means stolen passwords alone are not enough. Both are preventive.
- Check option B: backups help recovery of data but do not stop stolen credentials being used.
- Check option D: control totals are an application control over payroll input, unrelated to the bank login.
Answer: A and C
Example 2
Classify each control as general or application: (1) a firewall, (2) a check digit on customer account numbers entered into the sales system, (3) daily backups of all servers, (4) a control total of invoices batched before processing.
Show the solution
- Firewall: protects the whole network, so general.
- Check digit: tests input into one system, so application.
- Daily backups: cover all servers and support recovery across the environment, so general.
- Batch control total: checks completeness of processing of a specific batch, so application.
Answer: (1) General, (2) Application, (3) General, (4) Application
Exam tips
- Learn the general versus application split with two examples each. This is a frequent test point.
- In scenario questions, link your answer to the facts given. Generic lists of controls earn little.
- For multiple response, select exactly the stated number. Do not add an extra 'safe' option.
- Remember that data protection concerns personal data. Check whether the data in the question identifies a person.
- Pair each control with its type: preventive, detective or corrective. Examiners often ask for this.
Practice questions from Financial systems and technology
- Which of the following is an example of a preventive, rather than detective, cyber security control?
- A bank uses software that applies a built-in set of rules captured from experienced loan officers to recommend whether to approve routine lo…
- Which of the following best describes the difference between data and information?
- A manager at Corvo Ltd receives a monthly report comparing actual costs with budget for her department, with explanations of the main differ…
- Which of the following is a characteristic of an unstructured decision, for which a decision support system is typically most useful?
Cyber Security and Data Protection in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Cyber Security and Data Protection: frequently asked questions
What is the difference between general controls and application controls?
General controls apply across the whole IT environment, such as passwords, firewalls and backups. Application controls work inside a specific program or process, such as input validation and control totals. General controls support the environment in which application controls operate.
What are the main data protection principles?
Most laws require personal data to be processed lawfully, fairly and transparently, collected for a clear purpose, limited to what is needed, kept accurate, retained no longer than necessary, and held securely. The organisation must also be able to show it complies. Exact wording varies by country.
How can a business protect data from cyber attacks?
Use layers of protection. Prevent attacks with firewalls, anti-malware, access controls, encryption and staff training. Detect them with monitoring and log review. Prepare to recover with backups and an incident response plan.
Is this topic calculation-heavy in ACCA BT?
No. It is tested mainly through multiple choice, multiple response and scenario questions. You need to identify threats, match controls and apply principles to a short scenario.