Career Paper

The Cybersecurity Policy Analyst is a job description that has many different subsections, however, revolve around the same key objectives. These Analysts are in charge of creating regulations and policies for an organization that revolve around its cybersecurity infrastructure. They are not only in charge of making them, but they review current trends with other companies and update new policies as time goes on. This job can be done in any field that has a cybersecurity infrastructure but can be especially seen with larger organizations such as the medical field, businesses or government institutions.

Gathering information and staying up to date on the latest news surrounding cybersecurity is a must for this job since it is their responsibility to enforce the rules set in place. Social Science research and principles are an important key to doing this job that goes beyond technical expertise in the cybersecurity field. For example, creating incident reports for how a company reacts to a breach needs an understanding of the human error aspect of the initial problem. Learning how human awareness can be exploited or employed to help reduce such incidents can lead to greater success in this field. A study from a scholarly article1 deduces that there is a correlation between having cyber awareness and the reduced risk of being as susceptible to risk s from threat actors. Findings such as these can give these analysts incite on what policies can be included that inform workers of potential risks such as spoofing in a way that guarantees greater success. Learning concepts related to optimism bias and low observability can aid in producing policies that avoid human error.

With human error being the biggest cause of cyber risk, elements such as the motivations for threat actors to attack certain organizations are also important. A Cybersecurity Policy Analyst who works for a political entity can run into a particular type of attacker such as Hacktivists or state sponsored attackers. State sponsored attackers are of extreme importance when looking at cybersecurity’s role in the international wars in the last few years. Two articles2,3 in particular highlight the use of cybersecurity in war efforts over the last few years. One2 dives into how cyberwar was conducted in the Russo-Ukrainian war and how the rippling effects is still affecting multiple levels of laws regarding the use of deepfakes in general (but especially in war efforts) while explaining the concept of cognitive liberty in which one has a right to their own mental space. These new restrictions and views on deep-fake laws will directly influence what is viable to put into policies as well as what possible tools that could be utilized by these analysts. The other article3 is from an army soldier explaining how countries such as Russia are developing sophisticated cyber threats through utilizing Social Science techniques in mathematical algorithms. These algorithms are mainly used for the spread of disinformation that would slowly cause division in a country during wartime in order to defeat them. Similarly to the other articles these create obstacles for these analysts due to creating problems that exploit human error in an organization. Constant research and sharing of cyber threat intelligence would have to be employed to properly navigate the current tools utilized by threat actors to create training plans and countermeasures.

When it comes to marginalized groups and social science research/principles there are lot of nuances that these analysts must consider. Social science research can fall victim to bias and underrepresentation such as darker skinned people failing to show up on certain facial recognition protocols. An analyst must take into account what tools could exclude certain groups before making policies since they contain social bias. Another thing to consider is that crime is never equally distributed. It is very important to know who you work for and what types of groups can be more susceptible to being targeted by certain threat actors. Policies on recovering financial losses can be important since there are less avenues for poorer groups of people to get their money back or bounce back from such losses. On a positive note, social research can aid in finding the motivations and reasonings for why certain marginalized groups are targeted creating a map for analysts who work in sectors such as social serves or organizations that are LGBTQ run. Victim Perception can be a strong tool especially when dealing with groups like the elderly who can fall victim to the rapid evolution of technology beyond their time so creating policies that keep their susceptibility in mind does wonders. Neutralization theory can also be used for seeing justifications for crimes against certain groups such as the elderly being targeted specifically for money since they are “closer to dying anyway”.

References

  1. McGregor, R., Reaiche, C., Boyle, S., Corral de Zubielqui, G. (2025). Consumer perceptions of personal cyber awareness, knowledge, and risk, Journal of Cybersecurity, Volume 11, Issue 1, tyaf029, https://doi.org/10.1093/cybsec/tyaf029
  2. Kuźnicka-Błaszkowska, D., Kostyuk, N. (2025). Emerging need to regulate deepfakes in international law: the Russo–Ukrainian war as an example, Journal of Cybersecurity, Volume 11, Issue 1, tyaf008, https://doi.org/10.1093/cybsec/tyaf008
  3. Beskow D.M., Carley K.M. (2019, March19) Social Cyber Security An Emerging National Security Requirement. Military Review. https://www.armyupress.army.mil/Journals/Military-Review/English-Edition-Archives/Mar-Apr-2019/117-Cybersecurity/b

Leave a Reply

Your email address will not be published. Required fields are marked *