{"id":290,"date":"2026-09-28T00:08:53","date_gmt":"2026-09-28T00:08:53","guid":{"rendered":"https:\/\/sites.wp.odu.edu\/erickhernandez\/?p=290"},"modified":"2026-09-28T00:08:53","modified_gmt":"2026-09-28T00:08:53","slug":"the-human-factor-in-cybersecurity","status":"publish","type":"post","link":"https:\/\/sites.wp.odu.edu\/erickhernandez\/2026\/09\/28\/the-human-factor-in-cybersecurity\/","title":{"rendered":"The Human Factor in Cybersecurity"},"content":{"rendered":"\n<p>When I think about cybersecurity, the first things that come to mind are usually hackers, firewalls, passwords, and protecting computer systems. After going through the Module 5 readings, I think the human factor is just as important as the technology. The human factor is basically the role that people&#8217;s actions, choices, and behavior play in cybersecurity. Payne and Hadzhidimova explain that cybersecurity is not only a technical issue because human behavior is also involved in offending, victimization, and prevention. This means an organization can spend a lot of money on security technology, but one person making a bad decision can still create a way for an attacker to get in (Payne &amp; Hadzhidimova, 2020).<\/p>\n\n\n\n<p>One of the best examples of this is phishing and social engineering. Social engineering stood out to me because an attacker does not always have to break through the technology. Sometimes it is easier to convince a person to give them what they need. An attacker could send an email that looks like it came from a boss, bank, or another trusted source and create a sense of urgency so the person clicks a link or gives up information. The Module 5 chapter explains that social engineering works by taking advantage of things like trust, human psychology, and a lack of knowledge (Oesteraas, n.d.). To me, this shows why people can still be one of the biggest security risks no matter how advanced technology gets.<\/p>\n\n\n\n<p>Psychology also plays a big part in why these attacks work. People do not always stop and think about cybersecurity when they are busy doing their normal jobs. If an email looks important or says something needs to be done immediately, someone might react before checking whether it is real. Fear, curiosity, trust, and even wanting to be helpful can all affect the decision a person makes. This is what makes social engineering dangerous because the attacker is really targeting the person instead of just the computer.<\/p>\n\n\n\n<p>Another risk related to human behavior is the insider threat. Employees need access to systems and information in order to do their jobs, but that access can also become a security problem. An employee could intentionally steal information, but an insider threat does not always have to be someone trying to hurt the organization. Someone could use a weak password, share an account, open a bad attachment, or send sensitive information to the wrong person by mistake. Payne&#8217;s discussion of white-collar cybercrime also shows how cybercrime can overlap with occupational crime because people may use access or knowledge from their jobs when committing an offense (Payne, 2018). I think this makes insider threats harder to deal with because the person may already have legitimate access to the system.<\/p>\n\n\n\n<p>Workplace culture can make these problems better or worse. If employees think cybersecurity is only the IT department&#8217;s responsibility, they may not take security policies seriously. The same can happen when training is treated like something people just click through once a year. I think organizations should make cybersecurity part of everyday work instead. Employees should understand why the rules matter and see examples that actually relate to situations they might encounter. Regular phishing exercises, password requirements, and reminders about protecting sensitive information can help keep security in people&#8217;s minds.<\/p>\n\n\n\n<p>Communication is also important. Employees should feel comfortable reporting a mistake instead of trying to hide it because they are afraid of getting in trouble. For example, if someone clicks a phishing link and reports it right away, the cybersecurity team may have a better chance of stopping the attack before it spreads. If the employee hides the mistake, the situation could become much worse. This is why I think a good security culture should hold people accountable but also encourage them to speak up when something goes wrong.<\/p>\n\n\n\n<p>Overall, the human factor shows that cybersecurity is not something technology can solve by itself. People can create vulnerabilities through mistakes, poor decisions, or intentional actions, but people can also help protect an organization when they are properly trained and understand their responsibilities. The Module 5 readings helped me see how cybersecurity connects with psychology, criminal justice, and workplace behavior. In my opinion, organizations need strong technology, but they also need to pay attention to the people using that technology. No matter how advanced security becomes, human decisions will continue to have a major effect on whether cybersecurity succeeds or fails.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>When I think about cybersecurity, the first things that come to mind are usually hackers, firewalls, passwords, and protecting computer systems. After going through the Module 5 readings, I think the human factor is just as important as the technology. The human factor is basically the role that people&#8217;s actions, choices, and behavior play in&#8230; <\/p>\n<div class=\"link-more\"><a href=\"https:\/\/sites.wp.odu.edu\/erickhernandez\/2026\/09\/28\/the-human-factor-in-cybersecurity\/\">Read More<\/a><\/div>\n","protected":false},"author":32758,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wds_primary_category":0},"categories":[1],"tags":[],"_links":{"self":[{"href":"https:\/\/sites.wp.odu.edu\/erickhernandez\/wp-json\/wp\/v2\/posts\/290"}],"collection":[{"href":"https:\/\/sites.wp.odu.edu\/erickhernandez\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sites.wp.odu.edu\/erickhernandez\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/erickhernandez\/wp-json\/wp\/v2\/users\/32758"}],"replies":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/erickhernandez\/wp-json\/wp\/v2\/comments?post=290"}],"version-history":[{"count":1,"href":"https:\/\/sites.wp.odu.edu\/erickhernandez\/wp-json\/wp\/v2\/posts\/290\/revisions"}],"predecessor-version":[{"id":291,"href":"https:\/\/sites.wp.odu.edu\/erickhernandez\/wp-json\/wp\/v2\/posts\/290\/revisions\/291"}],"wp:attachment":[{"href":"https:\/\/sites.wp.odu.edu\/erickhernandez\/wp-json\/wp\/v2\/media?parent=290"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/erickhernandez\/wp-json\/wp\/v2\/categories?post=290"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/erickhernandez\/wp-json\/wp\/v2\/tags?post=290"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}