Career Paper

Brandon Vuono 

CYSE201S  

Trin Woodbury 

26 April 2026 

Cyber Career Paper 

Human Factors beyond technology: How Social Science Shapes Cyber Security 

When people today think of cybersecurity, many people picture fast coding breaking down firewalls and getting great access to important information. This is the way Hollywood has glorified technology and the world of attackers. In reality cybersecurity is eqaully about people as it is about binary bits. Cyber security analysts are the backbone of the career profession. They spend a lot of time dealing and working with human behaviors, as well as decision making and understanding deeper social patterns. Cyber-attacks succeed not because the system is extremely weak but more often due to the influence on the individual who was manipulated by an easy tactic. With this social science principles such as objectivity, relativism, determinism and parsimony play an important role in the social and cyber relationship. Understanding these concepts will help a cybersecurity analyst do their job better and help them make the right decisions. This will protect not only systems but people at large.  

One of the most important principles in cybersecurity to understand is objectivity. Making decisions based on evidence rather than personal bias is key to understanding the problem they face and a clear min on how to fix it. Security analysts rely heavily on evidence when investigating an incident. An example of this is if unusual activity appears on their network; analysts cannot assume who might be doing the activities. They must relentlessly trace the breadcrumbs left behind to identify the person. This ensures that their conclusions are accurate and fair. Objectivity is critical because biased decisions can lead to missed threats or false accusations, both which have serious consequences (Anderson, 2020). 

Another key concept is relativism. This suggests that behavior must be understood within its specific context. In cybersecurity context, it matters a lot. If an employee logging in from another country may seem suspicious at first glance depending on a virtual private network or the foreign country’s IP address. If the employee is traveling for work with notice, the cyber security analyst must sort through weather or not; the activity is legitimate. This context is imperative for not having false alarms. Without this perspective, analysts could miss understanding the login and make a harmless action as dangerous as an unauthorized user on the network.  

Determinism is also a major factor for cybersecurity professionals and those of the cyber analyst career. Determinism is the idea that behavior is influenced by underlying causes such as psychological or social factors. Cyber criminals prey on human behavior that is predictable to get the intended end state they are after. This can be seen with attacks such as phishing emails that are designed to be trustworthy and enticing to the victim. This creates the urgency to click the email or link associated giving the attacker that avenue they’re looking for. Cybersecurity analysts study these patterns to understand why people fall for these scams regardless of the number of years that they have at the job. By recognizing behavior is influenced by certain triggers, analysts can develop better training programs and security systems (Hadnagy, 2018). The training of teaching employees to scan each email with high scrutiny is key for protection.  

In addition to these few concept cybersecurity analysts apply a much broader scope when it comes to the social sciences. Socialization affects every aspect of our lives. Cybersecurity takes this into perspective of protecting their network and education for the end users of the network.  If the workplace culture does not prioritize cybersecurity, employees may ignore best practices from the cyber community. Analysts work tirelessly to create a culture that lives and breathes security. The cybersecurity professionals in most settings represent the form of authority over their craft and those who use it to do the job. This helps influence the best practices to keep the network safe. This in turn builds deeper layers of trust. End users must trust their security systems and warnings to follow the guidelines put in place for protection. 

Another challenge that security analysts deeply study is the victims that are targeted by cyber attackers.  Elderly individuals, for example, are constantly targeted for scams. Scams that range from phishing emails to financial scams attempting to get money from wire transfers. Lower income communities are also seen to be at a higher risk of attacks. Not having the means to get the most up to date systems, this creates easy attack vectors. These issues show that cybersecurity is not just a technical field. The social aspect of the profession needs to be addressed and understood.  

The relationship between cybersecurity analysts and society is complex and constantly changing. As society becomes more ingrained and dependent on technology, the role of cyber security analysts becomes more important. They help protect systems that people rely on every day such as banks, hospitals, and communication systems. If these systems become compromised, they would have effects that could be widespread on a whole nation. Society also plays a large role in influencing cybersecurity analysts. For example, many people choose simple passwords that are easy to remember. Research shows that users often ignore security advice when it feels inconvenient, which highlights the importance of understanding human behavior in cyber security (Herley, 2009). This became such a problem with passwords and requirements that has since changed. The recommendation used to be random letters and characters with special letters and numbers. This usually resulted in what was known as the keyboard walk password. This made it easy to brute force to attack the password. It is now recommended to use long passphrases that are easily remembered and to remove the thirty-to-sixty-day password resets. This shows that society has a hold on the cyber security profession and the changes it makes.  

In conclusion, cyber security analysts rely heavily on social science principles in their daily work. Concepts such as objectivity, relativism, and determinism help them analyze threats. These professionals must also consider much broader lense on social issues. Including inequality in marginalized groups. As well as how continence has a hold on the population technology serves. All these concepts show how cybersecurity and society are deeply connected to one another. Both shaping and being shapped by human behaviors. As technology advances, the human factor will remain a limiting factor of cybersecurity. Making social science an essential component to the profession of cybersecurity.  

References 

Anderson, R (2020) Security engineering: A guide to building dependable distributed systems 

Hadnagy, C (2018) Social engineering: The science of human hacking 

Herley, C (2009) So long, and no thanks for the externalities: The rational rejection of security advice by users. Proceedings of the New Security Paradigms Workshop, 133–144.