CYSE 200T

Cybersecurity, Technology, and Society

Assignment Showcase: Write Up – The Human Factor in Cybersecurity

THE HUMAN FACTOR IN CYBERSECURITY
Balancing Limited funds as a CISOAs a CISO the most important thing to keep up with is arguably funding, without fundinga company isn’t able to run at all. Another thing is figuring out what to use the funding for;some things to consider what you should use funding on is training staff and technologicaladvancements.
TrainingWhen it comes to training in cybersecurity, many employees are undertrained and lackawareness on cybersecurity procedures and what to look out for when in a workplaceenvironment. According to the Harvard Business Review, cybercriminals scammed $26billion between October 2013 and July 2019 with the “Business Email Compromise” scamthat, using deceptive and manipulative social engineering techniques, lured employeesand individuals into divulging their credentials and eventually making unauthorizedtransfers or funds.” If every employee in a company was trained in cybersecurity and howto be secure in the workplace, then the chance of an internal attack goes down by acopious amount. Not only do the chances go down but employees collectively get ageneral understanding of cybersecurity. This creates a more knowledgeable environment ifan employee were to spot something they could immediately send it over to thecybersecurity department to inspect it.
TechnologyWhen it comes to technology in cybersecurity, you can’t go without it. If a company’sdatabase is running without strong security, it likely won’t survive very long. Many thingsthat are good to have as a company are Role Based Access Control (RBAC) which limitsusers only to what they are assigned to, Firewalls that act as a barrier between trusted anduntrusted networks, and two factor authentication (2FA) which is a form of multi factorauthentication that makes sure the user is the correct user before allowing access to adatabase. There are many more forms of technology that a CISO should spark interest inbut those three are really the foundation to ensure the company is secure.
ConclusionUltimately, as a CISO you have to balance limited funds between training employees ofthe company and technology to strengthen the company. Training employees cansignificantly reduce the risk of human error which is a major part of cybersecurity
breaches. By educating employees on what to look out for companies can create a secureworkplace environment where cybersecurity is a normal practice. On the other side ofthings, investing in technologies like Role Based Access Control (RBAC), firewalls, and twofactor authentication (2FA) is important to overall protect the company’s databases.Overall, the best way to balance funds and keep your company secure as a CISO is bycombining training and technology as it creates strong security against cyber threats.