{"id":292,"date":"2026-10-01T16:23:05","date_gmt":"2026-10-01T16:23:05","guid":{"rendered":"https:\/\/sites.wp.odu.edu\/mirandareynolds\/?p=292"},"modified":"2026-10-01T16:23:05","modified_gmt":"2026-10-01T16:23:05","slug":"human-factor","status":"publish","type":"post","link":"https:\/\/sites.wp.odu.edu\/mirandareynolds\/2026\/10\/01\/human-factor\/","title":{"rendered":"Human Factor"},"content":{"rendered":"When referring to the human factor in cybersecurity, it includes people\u2019s actions, habits, <br \/>decisions, and mistakes and how it can affect the security of computer systems and information. <br \/>Even when an organization has strong technical security controls, employees and other users can <br \/>still create risks with the cause of unsafe behavior. Therefore, cybersecurity involves more than <br \/>just technology. It also is dependent on whether people understand security policies and if they <br \/>can recognize threats so that they can make responsible decisions when using organizational <br \/>systems.  <br \/>Human behavior can contribute to cybersecurity incidents in both intentional and <br \/>unintentional ways. Employees sometimes may click a harmful link accidentally, use weak <br \/>passwords, ignore security procedures, or share private information with the wrong person. In <br \/>other situations, an insider may intentionally misuse authorized access. These actions create <br \/>vulnerabilities and give attacks a higher advantage.  <br \/>An important example of a cybersecurity risk to avoid is phishing. Phishing is a form of <br \/>social engineering where an attacker attempts to deceive a person into clicking a link or <br \/>providing information so that they can compromise their system. NIST describes phishing as an <br \/>ongoing cybersecurity threat and puts an emphasis that the user\u2019s context can influence how <br \/>difficult it is to recognize a phishing message to common users (Dawkins &amp; Jacobs). For <br \/>instance, an employee may receive an email that appears to come from a manager or a familiar <br \/>company. The message may create a sense of urgency and ask the employee to respond quickly <br \/>so that the employee thinks the email is of importance. A person who is working under pressure <br \/>or in a time crunch may be more likely to act without carefully verifying or looking through the <br \/>message fully. This shows that cybersecurity behavior can be influenced by psychological and <br \/>organizational factors, not just technical knowledge. <br \/>Another risk is the practice of weak passwords. Employees might choose passwords that <br \/>aren\u2019t difficult to guess or reuse the same password for multiple accounts. These behaviors can <br \/>increase the impact of a compromised account because an attacker who obtains one password <br \/>may be able to access additional systems. Organizations can reduce this risk by using strong <br \/>authentication requirements and multi-factor authentication. NIST also recommends considering <br \/>MFA as part of an organization\u2019s approach to protecting accounts from phishing and other <br \/>attacks.  <br \/>A third example is the insider threat. An insider threat can involve a person who <br \/>intentionally misuses authorized access or unintentionally exposes information from an <br \/>organization. Due to the fact that employees already have authorized access to systems and <br \/>information, their actions can create security risks that are different from those created by an <br \/>attacker from the outside. NIST recommends that security awareness programs teach users how <br \/>to recognize and report indicators of insider threats and social engineering. (NIST,2024) <br \/>Cybersecurity decisions can be affected by stress, distraction, and urgency. For example, <br \/>an employee under pressure may be more likely to overlook warning signs in a phishing email. <br \/>Social factors also influence cybersecurity behavior. People may trust messages that appear to <br \/>come from a supervisor or coworker, which can make social engineering more effective. (NIST <br \/>2024). Organizational culture is also important. When security is treated as everyone\u2019s <br \/>responsibility, employees may be more likely to follow security policies and report any activity <br \/>that seems suspicious. A strong cybersecurity culture can encourage safer behavior (Merrit et <br \/>al.).  <br \/>The human factor is an important part of cybersecurity because people\u2019s actions can <br \/>create security risks. Phishing, weak passwords, and insider threats show how human behavior <br \/>can affect organizations. Clear policies and training can create a strong cybersecurity culture that <br \/>helps prevent these risks.","protected":false},"excerpt":{"rendered":"<p>When referring to the human factor in cybersecurity, it includes people\u2019s actions, habits, decisions, and mistakes and how it can affect the security of computer systems and information. Even when an organization has strong technical security controls, employees and other users can still create risks with the cause of unsafe behavior. Therefore, cybersecurity involves more&#8230; <\/p>\n<div class=\"link-more\"><a href=\"https:\/\/sites.wp.odu.edu\/mirandareynolds\/2026\/10\/01\/human-factor\/\">Read More<\/a><\/div>\n","protected":false},"author":32721,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wds_primary_category":0},"categories":[1],"tags":[],"_links":{"self":[{"href":"https:\/\/sites.wp.odu.edu\/mirandareynolds\/wp-json\/wp\/v2\/posts\/292"}],"collection":[{"href":"https:\/\/sites.wp.odu.edu\/mirandareynolds\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sites.wp.odu.edu\/mirandareynolds\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/mirandareynolds\/wp-json\/wp\/v2\/users\/32721"}],"replies":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/mirandareynolds\/wp-json\/wp\/v2\/comments?post=292"}],"version-history":[{"count":1,"href":"https:\/\/sites.wp.odu.edu\/mirandareynolds\/wp-json\/wp\/v2\/posts\/292\/revisions"}],"predecessor-version":[{"id":293,"href":"https:\/\/sites.wp.odu.edu\/mirandareynolds\/wp-json\/wp\/v2\/posts\/292\/revisions\/293"}],"wp:attachment":[{"href":"https:\/\/sites.wp.odu.edu\/mirandareynolds\/wp-json\/wp\/v2\/media?parent=292"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/mirandareynolds\/wp-json\/wp\/v2\/categories?post=292"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/mirandareynolds\/wp-json\/wp\/v2\/tags?post=292"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}