Business and Technology · The impact of advances in technology
Cyber Security, Data Protection and Technology Risks
Updated 11 October 2026 · Fact-checked
Cyber security is the set of controls that protect systems and data from threats such as hacking, malware and phishing. Data protection is the legal and ethical duty to handle personal data properly. To answer a question, identify the threat, name the matching control, then link it to the business impact.
Understand Cyber Security, Data Protection and Technology Risks
Every organisation now depends on technology. That brings benefits, but it also creates risk. A cyber security risk is the chance that someone attacks, damages or misuses your systems or data. The harm can be financial loss, fines, lost customers and damaged reputation.
Learn the main threats first:
- Hacking: gaining unauthorised access to a system.
- Malware: harmful software such as viruses, worms, trojans, spyware and ransomware. Ransomware locks data until a payment is made.
- Phishing: fake emails or messages that trick people into giving up passwords or details.
- Denial of service: flooding a system so genuine users cannot use it.
- Data breach: personal or confidential data is lost, stolen or exposed. Causes include attacks, errors and lost devices.
- Insider threat: staff misuse their access, deliberately or by mistake.
Now learn the controls. They fall into groups. Preventive controls stop incidents: passwords, multi-factor authentication, firewalls, antivirus, encryption, access rights and staff training. Detective controls spot incidents: intrusion detection, activity logs and exception reports. Corrective controls limit damage: backups, a disaster recovery plan and an incident response plan.
Students often mix up two terms. Data security is about protecting data from loss, theft or unauthorised access. It is a technical and organisational matter. Data protection is about the rights of individuals and how personal data is collected, used, stored and shared. It is driven by law. You need good data security to meet data protection duties, but they are not the same thing.
Data protection laws differ by country. A well-known example is the EU General Data Protection Regulation (GDPR). Typical principles in such laws are that data is used lawfully and fairly, for a stated purpose, kept accurate, kept only as long as needed, and held securely. Individuals usually have rights to see and correct their data. Do not assume every country has identical rules. Technology also changes the accountancy profession by automating routine work, so risks of error shift to system design and data quality.
Key formulas to remember
- Risk-control matching rule
- Threat → Preventive control + Detective control + Corrective control
- For any threat, give at least one control of each type if the question allows.
- Data protection principles (typical)
- Lawful and fair → Specific purpose → Adequate and accurate → Kept no longer than needed → Secure
- Based on common laws such as GDPR. Wording varies by country.
- Information security aims (CIA)
- Confidentiality + Integrity + Availability
- Confidentiality: only authorised people see data. Integrity: data is accurate and unaltered. Availability: data is accessible when needed.
- Data security vs data protection
- Data security = protecting data; Data protection = lawful handling of personal data
- Security is a means. Protection is a legal and rights-based duty.
How to solve Cyber Security, Data Protection and Technology Risks questions
Use this order for any objective test or scenario question on cyber risk and data.
- 1Read the scenario and underline the asset at risk: personal data, financial records, or system access.
- 2Identify the threat: hacking, malware, phishing, denial of service, insider misuse or accidental loss.
- 3Decide whether the question asks about security (technical protection) or data protection (legal duty over personal data).
- 4Match the control to the threat, such as encryption for stolen data, backups for ransomware, training for phishing.
- 5Classify the control as preventive, detective or corrective if asked.
- 6Check the answer against the CIA aims: which of confidentiality, integrity or availability is affected?
- 7Eliminate options that are too weak or do not address the stated threat, then choose the best fit.
Quickest way: Threat, aim, control in 20 seconds
When to use it: Use for two-mark multiple choice and multiple response questions where time is short.
- Name the threat in one word from the scenario.
- Ask which CIA aim it damages.
- Pick the option that directly stops, spots or repairs that damage.
- If two options look right, choose the one that is preventive and specific over the one that is general.
- For multiple response, select exactly the number stated and check each against the threat.
Common mistakes in Cyber Security, Data Protection and Technology Risks
Treating data protection and data security as the same thing.
Both involve safeguarding data, so the terms feel interchangeable.
Fix: Link data protection to law and personal data rights. Link data security to technical and organisational safeguards.
Choosing antivirus software for every threat.
Antivirus is the most familiar control.
Fix: Match the control to the threat. Phishing needs training and filtering. Ransomware recovery needs backups. Insider misuse needs access rights and logs.
Confusing preventive, detective and corrective controls.
One control, such as a log, can seem to do several jobs.
Fix: Ask when it acts. Before the event is preventive, during or after discovery is detective, and restoring is corrective.
Ignoring human and insider risk.
Students picture hackers as outsiders only.
Fix: Remember that error, weak passwords and misuse by staff cause many breaches. Training and access limits are key controls.
Assuming one country's data law applies everywhere.
GDPR is taught as the standard example.
Fix: Say that laws vary by country and use GDPR only as an example of typical principles.
Worked examples
Example 1
A company's staff receive an email that looks like it is from the bank and asks them to enter their login details on a website. Which threat is this, and which control is most effective to reduce the risk? Options: A) Denial of service, firewall; B) Phishing, staff training and awareness; C) Ransomware, daily backups; D) Hacking by an insider, encryption.
Show the solution
- Identify the threat: a fake email that tricks staff into giving up login details is phishing.
- Eliminate A: no flooding of a system occurs, so it is not denial of service.
- Eliminate C: nothing is being locked for payment.
- Eliminate D: the sender is external and the attack relies on deception, not insider access.
- Choose the control that tackles the cause, which is human behaviour: training and awareness, supported by email filtering.
Answer: B) Phishing, staff training and awareness.
Example 2
Explain the difference between data security and data protection, and give one control for each, for a retailer holding customer details.
Show the solution
- Define data security: protecting data from loss, theft or unauthorised access.
- Give a security control: encrypt the customer database and restrict access by user role.
- Define data protection: the legal duty to handle personal data lawfully, fairly and for a stated purpose.
- Give a protection control: collect only the details needed, keep them no longer than required and let customers see and correct their data.
- Link them: good security helps meet the duty, but legal compliance also covers how data is collected and used.
Answer: Data security is the technical and organisational protection of data, for example encryption and access rights. Data protection is the lawful handling of personal data, for example collecting only necessary details and allowing customers to correct them.
Exam tips
- Read whether the question says security or protection. The answer changes.
- Match each control to a specific threat. Generic answers like 'use passwords' score poorly in scenarios.
- Know the three control types and give a real example of each.
- In multiple response questions, select exactly the number stated and avoid options that do not address the threat.
- For technology and the accountancy profession, link automation to fewer routine errors but greater reliance on system security and data quality.
Practice questions from The impact of advances in technology
- A retailer has automated its reordering: the system raises purchase orders when inventory falls below preset levels. An accountant notes tha…
- A company installs software that automatically matches supplier invoices to purchase orders and goods received notes, with no human keying o…
- A company wants to use a cloud provider's virtual servers and storage but install and manage its own operating systems and applications on t…
- A bank's internal audit team uses software to test 100% of transactions for unusual patterns instead of sampling. Which statement best ident…
- A firm is hit by ransomware that encrypts its files. Management wants a control that would MOST effectively allow it to restore operations w…
Cyber Security, Data Protection and Technology Risks in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Cyber Security, Data Protection and Technology Risks: frequently asked questions
What is the difference between data protection and data security?
Data security is about protecting data from loss, theft or unauthorised access using technical and organisational controls. Data protection is about the lawful handling of personal data and the rights of individuals. You need security to achieve protection.
How can organisations prevent data breaches?
Use layered controls: strong passwords with multi-factor authentication, encryption, firewalls, access limited to those who need it, and regular staff training. Add detective controls such as logs, and corrective controls such as backups and an incident response plan.
What are the main cyber security threats in ACCA BT?
Expect hacking, malware including ransomware, phishing, denial of service, data breaches and insider threats. You should be able to match each to a suitable control.
How does technology affect the accountancy profession?
Technology automates routine tasks such as data entry and reconciliation, and gives faster access to data. Accountants then spend more time on analysis and advice, and must also manage risks such as cyber attacks and poor data quality.