Cybersecurity Professional Career Paper:

What is Cybersecurity and Why Does it Matter:
Over the last few decades the internet and technologies have rapidly evolved and expanded, with this expansion into the digital world there has been a subsequent rise of cybercrime and cyber criminals. Cybersecurity is the profession that grew to combat this rise in cybercrime. Cybersecurity professionals use specialized technologies and techniques to protect hardware, software, and data. The importance of these professionals cannot be understated; Without them, personal, government and company data would all be at risk, many operational systems could be at risk of disruptions, and more. While there are many avenues someone can take in their cybersecurity career, this paper will focus solely on the role of a digital forensic analyst and how they use social sciences in their field. The role of a digital forensic analyst, as described by the cybersecurity and infrastructure security agency(CISA), is someone who analyzes evidence and investigates computer security incidents to locate helpful information in support of system/network vulnerability mitigation.

Application of Social Science in Cybersecurity
While cybersecurity is a very technology centered job the majority of security vulnerabilities stem from human error and behaviors. Because of this fact it is crucial that cyber professionals have a strong grasp on a wide range of social science concepts. Understanding how to effectively train employees on the dangers of social engineering attacks, such as phishing, and ensuring people use secure passwords is one way social science is used in cybersecurity. The role of a digital forensic analyst is deeply rooted in social sciences as well. Analysts must have a good understanding of the motivations behind a cyber criminal’s attack, along with their target selection strategies and more. For example, after a large-scale attack a digital forensic analyst may realize that a cyber criminal focused their attack on employees with weak passwords, and passwords that hadn’t been changed in 4-8 few months. With that newfound knowledge, employees can be informed and retrained so a similar vulnerability won’t be utilized again. Professionals also use their understanding of cognitive biases to understand how people fall for social engineering attacks, and predict user and attack behavior. A digital forensic analyst job is not only to find technical evidence of compute security incidents but also to understand how and why they happened, so those same incidents are not repeated.

How Social Science Principles Relate to Cybersecurity
Social principles are weaved into the core of cybersecurity and used in many ways, from
creating user friendly interfaces for employees, to analyzing behavioral patterns. Digital forensic analysts need a strong and varied grasp on multiple principles of social science, such as but not limited to empiricism, objectivity, and relativism. Empiricism is the principle that knowledge should come from the senses, and people should never rely on opinions or guesses. An example of empiricism failing in cybersecurity is highlighted in a journal by Florian Egloff about objectivity in relation to attribution, where a 2014 data breach on the US Office of Personnel Management was referenced. During this attack’s discovery, digital forensic analysts treated unconfirmed data and threat actors as facts, and it resulted in delays to security responses, fines on the company, and more. Relativism is the idea that all things are related to another in some way, and that change scan create more changes. This idea can be used in many technical and social ways for digital forensic analysts; from a technical standpoint new technologies built based on older models can make systems faster, resulting in data logs being analyzed quicker, threats being detected sooner, and more. Objectivity in the principle of being unbiased, and staying rooted in facts. This is vital to any profession but especially to digital forensic analysts, this is because certain findings can turn individuals and groups into potential suspects, so it is imperative that biases don’t cloud judgement. Social principles are weaved into the core of cybersecurity, from creating user friendly interfaces for employees to analyzing behavioral patterns.

How Society is Affected by Cybersecurity
Many people think about digital forensic analysts and cybersecurity professionals as a whole on a small scale. Many people are aware that their data and many businesses are protected by these individuals but fail to realize that the majority of critical infrastructure is also protected by them as well. Hospitals, police stations, factories, and airports all rely on these professionals to protect them from attacks that could disrupt and potentially endanger lives. Digital forensic analysts play a role in this protection by figuring out how an attack happened, who did the attack, and how to prevent it in the future. Overall it’s not just personal data or big corporations that are being protected, it’s also systems keeping healthcare patients alive and planes in the air. Cybersecurity affects society as a whole; But it also affects marginalized groups of people as well. While many people believe cyber crime primarily happens to companies and high income individuals this is far from the truth. An article from WIRED, by Nicole Tisdale, a cybersecurity professional, stated that in 2022 Maryland residents had over 2 million dollars of funds stolen from Electronic Benefits Transfer(EBT) cards by hackers, causing thousands of families to go hungry. Many individuals with no disposable income have both limited access to technology and tools to learn about internet safety. With the rise of more sophisticated scams using deep fake AI technology the number of untrained individuals whose lives will be affected by a scam is unimaginable. There needs to be a refocus in the cybersecurity to not only protect low income communities but also teach them about common cybersecurity practices.