Fundamentals of Business Laws and Business Communication · Internet-based Business Communication
Cyber Security and Safe Online Communication for CMA Foundation
Updated 10 October 2026 · Fact-checked
Cyber security means protecting devices, networks, accounts and data from misuse while communicating online. Key risks are phishing, malware, data theft, hacking and identity theft. To answer exam questions, identify the threat from its description, then match it to the right precaution: strong passwords, updates, antivirus, verification and encryption.
Understand Cyber Security and Safe Online Communication
Businesses now send emails, share files and hold meetings online. Each of these can be attacked. Cyber security is the set of steps that keep online communication and data safe from unauthorised access, misuse or damage.
The main risks are easy to recognise. Phishing is a fake email, message or website that pretends to come from a trusted source, such as a bank, to trick you into giving passwords, OTPs or card details. Malware is harmful software, such as viruses, worms, trojans and ransomware, that damages systems or steals data. Hacking is unauthorised access to a system or account. Data theft is copying confidential information without permission. Identity theft is using someone else's personal details to cheat. Spam is unwanted bulk email, which often carries links or attachments that spread malware.
Other email risks include spoofing (a forged sender address), interception of unencrypted messages, and sending confidential mail to the wrong person. Sharing files on public Wi-Fi is also risky.
Precautions fall into three groups. Technical: antivirus and firewall, software updates, encryption, regular backups and two-factor authentication. Behavioural: strong and unique passwords, not opening unknown attachments or links, verifying unusual requests by another channel, and logging out of shared devices. Organisational: a clear security policy, staff training, limited access to sensitive data and a reporting process for incidents.
In the exam, questions are mostly direct. They give a situation and ask you to name the threat, or ask which action is the correct precaution.
Key formulas to remember
- Phishing
- Phishing = fake message + trusted-looking sender + request for sensitive details
- Think of it as fishing for passwords, OTPs and card details.
- Malware types
- Virus, worm, trojan, ransomware, spyware
- Ransomware locks data and demands payment. Spyware secretly collects information. A trojan looks useful but is harmful.
- Two-factor authentication
- Password (what you know) + OTP or device (what you have)
- It protects an account even if the password is stolen.
- Encryption
- Readable data → coded data → readable again only with the key
- It protects data from being read if intercepted.
- Core precautions
- Strong passwords, updates, antivirus, firewall, backups, verification, training
- Learn these as the standard checklist for any 'precautions' question.
How to solve Cyber Security and Safe Online Communication questions
Use this method for any question on cyber security or safe online communication.
- 1Read the scenario and find the key clue: fake sender, harmful software, locked files, stolen identity, wrong recipient.
- 2Match the clue to a threat: fake request means phishing, locked files means ransomware, forged sender means spoofing, unauthorised access means hacking.
- 3If the question asks for a precaution, match it to the threat: phishing needs verification and not clicking links, malware needs antivirus and updates, weak access needs strong passwords and two-factor authentication.
- 4Eliminate options that are unsafe, such as sharing passwords, opening unknown attachments or using public Wi-Fi for sensitive work.
- 5Eliminate options that are too absolute, such as 'no risk' or 'completely secure'.
- 6Pick the option that best fits the exact threat and check it once more.
Quickest way: Clue-to-threat matching
When to use it: Use this for one-line MCQs that ask you to name a threat or the correct precaution.
- Spot the clue word: fake, locked, copied, forged, unwanted, unauthorised.
- Link it: fake means phishing, locked means ransomware, copied means data theft, forged means spoofing, unwanted means spam, unauthorised means hacking.
- For precaution questions, choose the safe, verifying and cautious action.
- Reject any option that shares credentials or clicks unknown links.
Common mistakes in Cyber Security and Safe Online Communication
Confusing phishing with spam.
Both arrive as unwanted emails.
Fix: Spam is just unwanted bulk mail. Phishing is deceptive and tries to get your sensitive details.
Treating a virus and ransomware as the same thing.
Both come under malware.
Fix: Ransomware specifically locks or encrypts data and demands payment. Look for the demand for money.
Thinking antivirus alone makes you safe.
Students rely on one tool.
Fix: Security needs layers: updates, passwords, two-factor authentication, backups and careful behaviour.
Trusting an email because it uses a bank's name or logo.
Logos and names are easy to copy.
Fix: Check the sender address and verify through the official website or helpline, not through the email's links.
Mixing up hacking with data theft.
They often happen together.
Fix: Hacking is the unauthorised access. Data theft is the copying of information. Answer according to what the question stresses.
Worked examples
Example 1
Meera receives an email that looks like it is from her bank. It says her account will be blocked unless she clicks a link and enters her card number and OTP. What is this threat, and what should she do?
A. Spam; delete it after reading
B. Phishing; do not click, and verify with the bank through official channels
C. Ransomware; pay the fee
D. Spoofing only; reply to the sender
Show the solution
- The email pretends to be from a trusted bank and asks for card details and OTP. This is the pattern of phishing.
- Option A calls it spam and only suggests deleting. It misses the deception.
- Option C is wrong because nothing is locked and no payment is demanded.
- Option D suggests replying, which is unsafe.
- Option B names the threat correctly and gives the safe action.
Answer: B
Example 2
A company's files are suddenly locked and a message demands payment to unlock them. Which threat is this, and which precaution best reduces the damage?
A. Phishing; use a longer subject line
B. Spyware; switch off the firewall
C. Ransomware; keep regular offline backups and updated security software
D. Spam; unsubscribe from mailing lists
Show the solution
- Locked files plus a payment demand point to ransomware.
- Options A, B and D name the wrong threat or suggest a useless or harmful action.
- Regular backups let the company restore its data without paying. Updated security software lowers the chance of infection.
- Option C matches both the threat and the precaution.
Answer: C
Exam tips
- Most questions ask you to name a threat from a short scenario. Learn the clue words for each threat.
- For precaution questions, pick the cautious and verifying option, and avoid anything that shares passwords or clicks unknown links.
- Be careful with options that say 'completely safe' or 'no risk'. Cyber security reduces risk but cannot remove it.
- Know the difference between phishing, spam, spoofing and ransomware, since options often place them side by side.
- Attempt every question. There is no negative marking, so never leave an answer blank.
Practice questions from Internet-based Business Communication
- A well-written subject line in a business email should be:
- Meera, an executive at a Pune firm, receives an email that appears to come from her bank. It asks her to click a link and enter her net-bank…
- Ravi receives an email sent by his manager to him and 20 colleagues. He wants to reply only to the manager with a clarification. Which actio…
- A manufacturing firm wants to hold a quarterly review with its dealers in Pune, Delhi and Chennai without travel, where all can see slides a…
- In a professional email, the 'Subject' line is best used to:
Cyber Security and Safe Online Communication in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Cyber Security and Safe Online Communication: frequently asked questions
What is phishing and how can it be prevented?
Phishing is a fake message or website that pretends to be a trusted source to steal passwords, OTPs or card details. Prevent it by not clicking unknown links or attachments, checking the sender address and verifying requests through official channels. Never share OTPs or passwords.
What are the main security issues in email communication?
The main issues are phishing, spam, malware in attachments, spoofed sender addresses, interception of unencrypted messages and sending confidential mail to the wrong person. Encryption, careful checking and security software reduce these risks.
What precautions are needed for safe internet communication?
Use strong and unique passwords, turn on two-factor authentication, keep software updated and use antivirus and a firewall. Avoid public Wi-Fi for sensitive work, back up data regularly and train staff on security.
Do I need to memorise laws for this topic?
For this topic, focus on understanding threats and precautions. Questions are usually about identifying the risk and the right safeguard. Legal aspects of cyber misuse are covered under related topics.