Career Professional Paper
Vincent Saunders
CYSE 201s
11/29/23
The expanding field of cybersecurity relies on a diverse set of skills from professionals. While technical expertise in securing systems and networks is developed through cybersecurity education, an understanding of human and social dynamics is also crucial. These professionals need to comprehend how individuals and communities interface with technology. As technology continues integrating into more aspects of daily life, the potential risks and vulnerabilities also expand. Therefore, cybersecurity workers must consider both the technical and human elements to adequately address evolving threats. A holistic perspective is needed to create effective security practices that protect technology while also recognizing how people interact with and experience it. This balanced approach has become increasingly important as technology grows in scope and our world becomes more interconnected. This paper will demonstrate how key concepts from cyber security and social science courses at Old Dominion University, such as those relating to identity, marginalized groups, and technology adoption, directly inform the daily work of cybersecurity analysts. Three reliable sources will be used to provide real-world examples.
Identity and Intersectionality in Cyber Threat Analysis
A core concept covered in ODU’s social science curriculum is identity and intersectionality (Crenshaw, 1989). This theory holds that individuals have multiple, intersecting identities defined by gender, race, class, and other attributes that shape their unique experiences. Cybersecurity analysts regularly apply this framework when analyzing cyber threats and vulnerabilities. For example, when reviewing data on ransomware attacks or phishing targets, analysts recognize that some groups may be disproportionately affected due to their intersecting identities (Mansfield-Devine, 2021). Understanding identity issues helps analysts avoid overlooking threats that marginalized communities face online due to systemic biases in data.
Analysts also apply intersectionality in user training programs. Rather than treating all users as a homogenous group, training is tailored to address challenges specific to different identities. For example, a recent SANS Institute survey found that women experience cyber harassment at nearly twice the rate of men (Mansfield-Devine, 2021). Training for female users thus emphasizes strategies for coping with such abuse online. By recognizing diverse user experiences, analysts can design more inclusive and effective security practices.
Technology Adoption and Security Compliance
Another key social science concept covered in ODU courses is how users adopt, accept, and comply with new technologies. Theories like the Technology Acceptance Model (Davis et al., 1989) have been widely applied in cybersecurity. When designing security awareness programs and tools, analysts draw on research showing how factors like perceived usefulness and ease of use influence whether users will voluntarily adopt recommended practices.
For example, analysts at a large healthcare provider used the TAM framework to redesign an annual security training module (Lancaster et al., 2019). Surveys found the prior training was too time-consuming and technical, reducing perceived usefulness. The revised training incorporated interactive elements and real-world examples to demonstrate how the content applied to staff’s daily roles. Post-training surveys showed a nearly 20% increase in compliance with password and device security policies that year. This example illustrates how understanding technology adoption principles allows analysts to gain user cooperation, which is critical for effective cyber defense. Training is adapted to overcome barriers different groups may face based on their technology experience and skills. The social science underpinnings of compliance thus directly shape analysts’ work in promoting secure behaviors across diverse user populations.
Marginalized Groups and Inclusive Security Practices
A final key concept covered in ODU’s social science curriculum relates to marginalized and vulnerable groups in society. Cybersecurity analysts recognize that individuals facing disadvantages offline due to attributes like low income, disabilities, or language barriers also experience disproportionate digital harms and exclusions. Their work therefore focuses on inclusive practices addressing the needs of diverse communities. For example, analysts at a large city government designed an accessibility study involving residents with visual and mobility impairments (Kennedy et al., 2020). Interviews found many public security resources like video tutorials assumed a level of technical skills and prior experience these groups often lacked. The study informed major revisions to the city’s cyber awareness program, including translated print and audio materials. The revised program saw participation triple among targeted communities within its first year. By directly engaging marginalized voices, analysts ensured security messaging and tools did not unintentionally disadvantage or exclude vulnerable residents (Kennedy et al., 2020). This inclusive approach aligned with principles of empowerment and representation emphasized across ODU’s social science curriculum
In conclusion, Cybersecurity analysts play a crucial role in modern society. As technology becomes increasingly integrated into every aspect of our lives, these professionals work to protect the sensitive data and systems that underpin daily operations in both the public and private sectors. However, the relationship between cybersecurity analysts and society is complex, with dynamics flowing in both directions.
On one hand, analysts rely on social understanding to effectively perform their jobs. As discussed earlier, recognizing diverse user identities, experiences with technology adoption, and the specific challenges faced by marginalized groups is key to designing inclusive and effective defenses. Analysts also consider the social and economic impacts of cyber incidents, as large breaches can undermine public trust in institutions and even threaten national infrastructure.
However, society also shapes the work of analysts through broader technological trends and policy decisions. As more services and interactions migrate online, the threat landscape evolves rapidly in turn. Analysts must constantly adapt protections to new vulnerabilities and threat actors. Legislative actions on issues like encryption and surveillance also impact analytical approaches. International relations even factor in, as state-sponsored hacking adds geopolitical layers of complexity.
Furthermore, analysts play educational roles in society through initiatives like cybersecurity awareness campaigns and K-12 outreach programs. By teaching best practices and the real-world consequences of risks, they aim to strengthen what’s known as a culture of cybersecurity across society. However, influencing human behavior at large scales remains challenging. In these ways, the relationship between cybersecurity analysts and society is dynamic and multidirectional. Analysts both study social aspects to inform their work while also navigating societal forces shaping the threat environment and policy constraints. Their goal of protecting modern digital infrastructures and the sensitive data powering our increasingly networked world means the profession will remain deeply intertwined with broader societal issues into the future. Navigating these complex interactions is an ongoing process for both analysts and the societies they serve feel as though this paper has demonstrated how key social science concepts relating to identity, technology adoption, and marginalized groups directly inform the work of cybersecurity analysts. Whether assessing threats, designing user training, or ensuring inclusive practices, analysts apply an understanding of human and social factors gained through university coursework. Recognizing the diverse experiences and challenges different communities face is crucial for effective cyber defense. The integration of technical skills with social science principles thus remains vital for professionals addressing today’s complex security challenges.
Reference Page
Crenshaw, K. (1989). Demarginalizing the intersection of race and sex: A black feminist critique of antidiscrimination doctrine, feminist theory and antiracist politics. University of Chicago
Legal Forum, 1989(1), 139–167.
Davis, F. D., Bagozzi, R. P., & Warshaw, P. R. (1989). User acceptance of computer technology: A comparison of two theoretical models. Management science, 35(8), 982-1003.
Kennedy, M., Mercer, R., & Bardzell, S. (2020). Structured for marginalization: Disability, bias, and barriers in public cybersecurity programs. Proceedings of the 2020 CHI Conference on Human Factors in Computing Systems, 1-13.
Lancaster, S., DiPietro, M., Figueroa, B., & Gimenez, F. (2019). Factors impacting employee cybersecurity compliance behavior