Information security vs cyber security: are they actually the same thing?

Short answer: no. Slightly longer answer: no, and the difference is worth five minutes of your time, because getting it wrong in a tender response or a job description is one of those small mistakes that quietly tells a reader you haven’t quite done your homework.

We hear the two terms swapped constantly — in policies, in LinkedIn job titles, in “cyber security officer” roles that are really information security roles wearing a trendier badge. It’s an easy mix-up, because the two overlap so much that most people never have a reason to pull them apart. So let’s pull them apart.

The short version

Information security is the big one. It covers protecting information full stop — however it exists, wherever it lives. A client contract in a locked filing cabinet, a password muttered a bit too loudly on a train, a spreadsheet on a laptop, a conversation in a lift. All of it falls under information security, because all of it is information that could be lost, leaked, or misused.

Cyber security is the part of that which happens to live online. Networks, devices, software, the digital estate. It’s a real and increasingly enormous discipline in its own right — but it’s a subset of information security, not a replacement for it.

Put another way: every cyber security control is also an information security control. A firewall protects information, so it counts. But not every information security control is a cyber security control. A locked cupboard protects information too, and it’s never going to show up on a penetration test.

This isn’t just pedantry. A few places it genuinely bites:

If you’re working towards ISO 27001, you’re working towards an information security standard, not a cyber security one — the clue is in the name, but it still trips people up. It covers your physical access controls and your staff vetting right alongside your firewalls.

If you’re writing a job description or a tender response, the two words signal different scope to anyone who knows the field. Asking for a “cyber security manager” when what you actually need is someone who also owns document handling, physical access and staff training is going to attract the wrong applicants, or the right applicant with the wrong expectations.

And if you’re building out a security programme for a small or growing organisation, starting from “information security” rather than “cyber security” tends to produce a more complete picture — because it forces you to think about the filing cabinet as well as the firewall, rather than assuming that anything not on a screen doesn’t count.

Where most organisations actually fall short

In our experience, it’s rarely the cyber side that gets neglected — everyone’s had the phishing training, everyone’s heard of ransomware. It’s the quieter information security half: what happens to a printed document once it’s been read, whether the office door genuinely locks itself, whether “we trust everyone here” is doing a lot of heavy lifting in place of an actual access policy. None of that shows up in a vulnerability scan, so it’s easy for it to go unnoticed until something goes wrong.

Grab the cheat sheet

We’ve put together a one-page infographic that lays out the distinction visually, with the same examples above — handy if you want something to pin up, drop into an induction pack, or forward to whoever wrote that job advert. It’s a free download, no email required.

 

Infographic explaining the difference between information security and cyber security. Information security covers protecting information in any form — digital, paper, even spoken — while cyber security is the narrower part of that covering only digital systems and networks. Includes examples: a locked filing cabinet (information security) versus a firewall (cyber security).

And if you’d rather your whole team understood this properly rather than just eyeballing a diagram, our Information Security Awareness Training for Staff course covers confidentiality, integrity and availability in plain English, mapped to ISO 27001:2022, in about 20 minutes. It’s built for people who’ve never had security training before, not for people who already know what “CIA triad” means. Take a look here.

Share The Post

Helen Molyneux Director RiskReady

Helen Molyneux is the founder of Cambridge Risk Solutions, a specialist resilience consultancy with nearly two decades of experience in business continuity, crisis management and information security. She holds Lead Auditor certifications for ISO 22301 and ISO 27001, and has worked across both public and private sectors helping organisations prepare for, respond to, and recover from disruption. RiskReady is her e-learning platform, built to make that same practical expertise accessible to individuals and teams at every level.

Find out more about Cambridge Risk Solutions →

Leave a Comment

Your email address will not be published. Required fields are marked *