Communication Technologies Grade 12
This page focuses on how data is kept safe as it travels across a network — VPNs, encryption, digital certificates and authentication. For network hardware, internet access technologies and general remote access, see Networks & Remote Access.
T3Term 3 · VPNs, Encryption & Secure Communication
VPN — Virtual Private Network
A VPN creates an encrypted tunnel over the Internet, allowing secure remote access to a private network. (See Networks & Remote Access for the armoured-van analogy and a worked example.)
- Hides your IP address and location
- All data is encrypted — safe on public Wi-Fi
- Used by companies for remote workers to securely access internal systems
Risks of Allowing Remote Access to a Company Network
Letting employees connect to the company network from home or on the road introduces risks that don't exist when everyone works from a secured office network:
- Weaker home networks: an employee's home Wi-Fi is usually far less secure than the office network (weak passwords, outdated router firmware), making it easier for an attacker to intercept data or gain access to the connection.
- Lost or stolen devices: a laptop or phone used for remote access that is lost or stolen can give an unauthorised person direct entry into the company network, especially if it isn't password/PIN protected or its access isn't revoked quickly.
- Unsecured public Wi-Fi: connecting from a coffee shop or airport network makes it easier for someone else on that same network to intercept data.
This is exactly why VPNs, MFA and strong device security matter more for remote workers than for on-site staff.
Encryption & Security
| Concept | Description |
|---|---|
| Encryption | Converts readable data into unreadable code. Only someone with the correct key can decrypt it. |
| SSL/TLS | Protocol securing communication between browser and server (HTTPS). Uses public/private key pairs. |
| Digital certificate | Issued by a trusted Certificate Authority. Verifies the website is legitimate. |
| Firewall | Filters incoming and outgoing traffic based on security rules |
| MFA | Multi-Factor Authentication — requires password + second factor (OTP, fingerprint) |
| OTP | One-Time PIN — valid for one login only; prevents replay attacks |
Other Security Strategies (Besides MFA and SSL)
- Strong password policies: requiring long, complex passwords that are changed regularly, and never reused across accounts.
- Regular software/security updates: patching known vulnerabilities before attackers can exploit them.
- Staff security-awareness training: teaching employees to recognise phishing emails and other social-engineering attempts, since people are often the weakest link, not the technology.
- Access control / user rights management: giving each user only the access they actually need for their job (the "principle of least privilege"), so a compromised account can't be used to reach everything.
Email & Messaging Security
| Concept | Description |
|---|---|
| Spam filtering | Automatically detects and quarantines unsolicited/junk email before it reaches the inbox |
| Email encryption | Encrypts the message content so only the intended recipient's key can decrypt and read it |
| End-to-end encryption | Used by apps like WhatsApp/Signal — only the sender and recipient can read the message, not even the service provider |
| Digital signature | Confirms a message really came from the claimed sender and was not altered in transit |