Human Factor

When referring to the human factor in cybersecurity, it includes people’s actions, habits,
decisions, and mistakes and how it can affect the security of computer systems and information.
Even when an organization has strong technical security controls, employees and other users can
still create risks with the cause of unsafe behavior. Therefore, cybersecurity involves more than
just technology. It also is dependent on whether people understand security policies and if they
can recognize threats so that they can make responsible decisions when using organizational
systems.
Human behavior can contribute to cybersecurity incidents in both intentional and
unintentional ways. Employees sometimes may click a harmful link accidentally, use weak
passwords, ignore security procedures, or share private information with the wrong person. In
other situations, an insider may intentionally misuse authorized access. These actions create
vulnerabilities and give attacks a higher advantage.
An important example of a cybersecurity risk to avoid is phishing. Phishing is a form of
social engineering where an attacker attempts to deceive a person into clicking a link or
providing information so that they can compromise their system. NIST describes phishing as an
ongoing cybersecurity threat and puts an emphasis that the user’s context can influence how
difficult it is to recognize a phishing message to common users (Dawkins & Jacobs). For
instance, an employee may receive an email that appears to come from a manager or a familiar
company. The message may create a sense of urgency and ask the employee to respond quickly
so that the employee thinks the email is of importance. A person who is working under pressure
or in a time crunch may be more likely to act without carefully verifying or looking through the
message fully. This shows that cybersecurity behavior can be influenced by psychological and
organizational factors, not just technical knowledge.
Another risk is the practice of weak passwords. Employees might choose passwords that
aren’t difficult to guess or reuse the same password for multiple accounts. These behaviors can
increase the impact of a compromised account because an attacker who obtains one password
may be able to access additional systems. Organizations can reduce this risk by using strong
authentication requirements and multi-factor authentication. NIST also recommends considering
MFA as part of an organization’s approach to protecting accounts from phishing and other
attacks.
A third example is the insider threat. An insider threat can involve a person who
intentionally misuses authorized access or unintentionally exposes information from an
organization. Due to the fact that employees already have authorized access to systems and
information, their actions can create security risks that are different from those created by an
attacker from the outside. NIST recommends that security awareness programs teach users how
to recognize and report indicators of insider threats and social engineering. (NIST,2024)
Cybersecurity decisions can be affected by stress, distraction, and urgency. For example,
an employee under pressure may be more likely to overlook warning signs in a phishing email.
Social factors also influence cybersecurity behavior. People may trust messages that appear to
come from a supervisor or coworker, which can make social engineering more effective. (NIST
2024). Organizational culture is also important. When security is treated as everyone’s
responsibility, employees may be more likely to follow security policies and report any activity
that seems suspicious. A strong cybersecurity culture can encourage safer behavior (Merrit et
al.).
The human factor is an important part of cybersecurity because people’s actions can
create security risks. Phishing, weak passwords, and insider threats show how human behavior
can affect organizations. Clear policies and training can create a strong cybersecurity culture that
helps prevent these risks.

Leave a Reply

Your email address will not be published. Required fields are marked *