🔒
Year 9 • Lesson 12

Cybersecurity Pro

Real threats, realistic protection

Cyber attacks cost the UK billions per year. The most common entry point is human error.

🎯 Learning Objectives

  • Conduct a cybersecurity risk assessment for a realistic digital setup
  • Explain the most common attack vectors and how they are mitigated
  • Prioritise security improvements by risk level and feasibility

📚 Key Vocabulary

Attack vector
The method used to gain unauthorised access to a system
Social engineering
Manipulating people rather than systems to get access
Malware
Malicious software: viruses, ransomware, spyware, trojans
Ransomware
Malware that encrypts your files and demands payment to restore them
Zero-day vulnerability
A security flaw unknown to the developer — no patch exists yet
Penetration testing
Authorised hacking to find vulnerabilities before criminals do

⏱️ Lesson Timing (50 mins)

🪝
Hook
5 mins

Show a real UK cyber attack case study (e.g. WannaCry NHS attack 2017 — public info). What failed? What was the human element? What did it cost?

👨‍🏫
Teach
12 mins
  • Attack types: phishing, malware, ransomware, man-in-the-middle, credential stuffing
  • Most attacks exploit people, not just technology — social engineering
  • The cyber kill chain: reconnaissance → delivery → exploitation → persistence
  • Defences: MFA, updates, backups, least privilege, VPN on public Wi-Fi
  • Incident response: what to do if you think you've been hacked
  • Cyber careers: ethical hacker, security analyst, pen tester — all in demand
🛠️
Create
38 mins

Students receive a fictional profile of a teenager's digital life (named accounts, devices, habits, passwords). Task: produce a full "Cybersecurity Risk Assessment" — for each risk area (accounts, devices, networks, social media, physical), rate likelihood (1-5) and impact (1-5), giving a risk score. Then produce a "Top 5 Recommendations" report with justification. Finally, write a 100-word cover note for the fictional "client" explaining the most urgent action.

Tools:
Word OnlineExcel Online
📢
Share
5 mins

What was the #1 risk? Was it the same for everyone? Which recommendation would be hardest to follow — and why?

🔧 Tools & Resources

🤖 AI Angle

AI is increasingly used in both cyberattacks (more convincing phishing) and defences (anomaly detection, threat analysis). The arms race is accelerating.

📝 Evidence of Learning

Cybersecurity risk assessment + top 5 recommendations + client cover note

📚 Homework

Check your own top 5 used apps/accounts. For each: is MFA on? Is the password strong? Are there any security alerts? Write up your personal audit.

⏱️ 20 mins

♿ Differentiation

Support (for students who need help)

Risk matrix template with descriptions of each risk level

Extension (for advanced learners)

Research how a penetration tester gets into a network legally. What qualifications are needed? What does a day in the job look like?