The 7 types of cybersecurity, explained for UK beginners
Updated on August 03, 20265 minutes read
Picture a hospital in Leeds at 3am. A junior member of staff clicks a fake invoice email, and within minutes an attacker is quietly moving through the network towards patient records. Whether that ends in a headline breach or a shrugged-off near-miss comes down to layers of defence that most people never see. That is what cybersecurity actually does, and it is why the field is split into distinct types rather than treated as one giant job.
If you've searched for the 7 types of cybersecurity, you've probably found lists that read like glossaries and tell you nothing about what the work feels like. This guide fixes that. I'll walk through each type with a concrete example, show you where UK salaries sit, and point out where a total beginner can realistically start.
What cybersecurity actually does
At its simplest, cybersecurity keeps data and systems available to the right people and shut off from the wrong ones. That covers stopping attacks before they land, spotting them when they slip through, and cleaning up afterwards so the same gap can't be used twice.
Here's the beginner-friendly version. Think of an organisation as a building. Some people guard the front door, some check who's already inside, some lock the filing cabinets, and some review the CCTV every morning. No single guard does all of it. Cybersecurity works the same way, which is exactly why it breaks down into specialisms.
The 7 types of cybersecurity
1. Network security
This protects the connections between machines: firewalls, VPNs, and the rules deciding what traffic is allowed in and out. A practical example is blocking an unfamiliar server from reaching your internal systems, so even if malware lands on one laptop it can't phone home. In the UK this is often the entry point for people moving over from IT support and networking roles.
2. Application security
Software has bugs, and some bugs are doorways. Application security is about finding and fixing those weaknesses before attackers do — a login form that doesn't check its inputs, say, letting someone inject a command that dumps the customer database. Developers and security specialists work together here, which is why coding knowledge pays off.
3. Information security
This is the discipline of protecting data itself, wherever it lives, through encryption and access controls. If a laptop is nicked from a train at King's Cross and the drive is encrypted, the thief gets an expensive paperweight rather than 40,000 customer records. Under UK GDPR, getting this wrong carries real legal weight.
4. Cloud security
Most UK businesses now run on AWS, Microsoft Azure or Google Cloud, and those platforms need securing differently from a server in a cupboard. A classic mistake is a storage bucket left open to the public internet, quietly leaking files for months. Cloud security roles are among the fastest-growing in the country.
5. Operational security
Often shortened to OpSec, this covers the day-to-day processes: who gets access to what, how permissions are removed when someone leaves, and how sensitive tasks are handled. A leaver keeping active admin access three months after quitting is a classic OpSec failure — dull to fix, dangerous to ignore.
6. Endpoint and mobile security
Endpoints are the devices people actually touch: laptops, phones, tablets. This type keeps them patched and monitored, and it's grown as hybrid work spread across the UK. If a marketer in Manchester installs a dodgy browser extension, endpoint tooling should flag it before it spreads.
7. Disaster recovery and business continuity
When something does go wrong, this is the plan to get running again. Backups, tested restore procedures, and a clear order for bringing systems back. The organisations that recover from ransomware in hours rather than weeks are almost always the ones that rehearsed their recovery beforehand.
If you want to see how these map onto a single job, our breakdown of what a cybersecurity analyst does day to day shows how one role touches several of these types at once.
UK cybersecurity salaries: what to expect
Cyber security salaries in the UK are genuinely strong, which is a big part of the field's appeal. Figures vary by city, sector and clearance level, so treat these as broad ranges rather than promises. London and the South East tend to pay more; Manchester, Bristol, Edinburgh and Leeds have busy markets too.
| Career stage | Typical UK salary range | What the role looks like |
|---|---|---|
| Entry-level (SOC analyst, junior security) | £28,000–£40,000 | Monitoring alerts, triaging incidents, learning the tooling |
| Mid-level (security engineer, analyst) | £45,000–£65,000 | Owning defences, investigating breaches, hardening systems |
| Senior / specialist (architect, lead) | £70,000–£95,000+ | Designing security strategy, leading response, mentoring |
Is cyber security a high salary field? Compared with most graduate and career-change routes, yes. The demand for skilled people in the UK still outstrips supply, which keeps pay competitive and gives newcomers room to move up quickly once they've proven themselves.
Do you need to be a coder or a genius?
No. Plenty of strong analysts come from IT support, help desk, or even non-technical backgrounds. What you do need is genuine curiosity about how things break, patience for detail, and comfort with picking up new tools. Some coding helps, especially for application and cloud security, but you don't need a computer science degree to start.
The honest bit: the first few months are a steep learning curve. There's a lot of vocabulary and a lot of tooling. Structured learning shortens that curve considerably, which is why so many career-changers choose a bootcamp over teaching themselves from scattered YouTube videos.
How to get started in the UK
Start by getting hands-on rather than only reading. Set up a home lab, break things safely, and learn how attacks and defences actually behave. From there, a focused programme can take you from curious beginner to job-ready with a portfolio and support.
If you'd rather learn at your own speed alongside a job, our self-paced cybersecurity course covers the fundamentals with structure built in. If you want to compare the full range of options and see what fits your budget, the course and pricing overview lays it out plainly.
Cybersecurity isn't one job — it's seven overlapping specialisms, and you only need to be genuinely good at one to build a well-paid UK career. Pick the type that interests you most, get hands-on, and let the rest follow. Ready to make the switch? Explore the Code Labs Academy cybersecurity bootcamp and start building the skills employers are hiring for now.
