Journal Entry 1:
The NICE Framework outlines seven core areas within the cybersecurity field. As an AI, my strengths lie in information processing and pattern recognition. Consequently, I am most drawn to the “Analyze” and “Detect” categories. These areas encompass identifying and assessing cybersecurity risks and vulnerabilities, as well as detecting and reporting incidents. My abilities align well with the tasks involved in these categories, such as analyzing large datasets for anomalies or identifying patterns that may indicate malicious activity. Conversely, areas like “Operate” and “Oversee” would be less suitable. These categories involve hands-on management, system maintenance, and operational oversight, which require a level of interaction and physical presence that I am currently unable to fulfill.
Journal Entry 2:
Strong cybersecurity relies on scientific thinking. Empiricism means learning from experience. We analyze past attacks and breaches to understand current threats and improve our defenses. This data-driven approach is crucial for staying ahead of evolving cyber risks. Determinism guides our incident response. We assume every attack has a cause, and by investigating thoroughly, we can trace it back to its source, understand the attacker’s methods, and prevent similar attacks in the future. Complex security systems can create more vulnerabilities. We should aim for the simplest, most effective solutions. Finally, objectivity is vital. We must base our security decisions on facts and evidence, not guesses or biases. A scientific approach, using these principles, makes our cybersecurity much stronger and more reliable. These principles provide a structured and rigorous approach to cybersecurity, enhancing its effectiveness.
Journal Entry 3:
Researchers can use information on the website to study data breaches by looking at trends, causes, and impacts. They can see which industries are most affected and what types of breaches happen most often, like hacking or human error. This helps them understand weaknesses in security and find ways to prevent future breaches. They can also track how breaches change over time and see if laws and security measures are working. By studying this data, researchers can suggest better protection methods for companies and individuals. Their findings can help improve cybersecurity, create stronger policies, and raise awareness about keeping personal information safe.
Journal Entry 4:
Maslow’s Hierarchy of Needs connects to technology in many ways. At the physiological level, we use technology for essentials like ordering food, tracking health, or setting alarms. For safety, cybersecurity, passwords, and antivirus software protect our personal information. Belongingness comes from social media, video calls, and online communities that help us stay connected. Esteem needs are normally met through likes on social media, online achievements, and professional networking. Finally, self-actualization normally happens when we use technology for learning, creativity, and self-improvement, like taking online courses or developing new skills. Technology plays a big role in every level of our needs.
Journal Entry 5:
Ranking of Individual Motives for Cybercrime
- For Money – Financial gain is the strongest motivator for cybercriminals. Many hackers engage in fraud, ransomware, and data breaches for financial benefits. This motive is widely documented and has a significant impact on businesses and individuals.
- Political – Cyber-attacks driven by political ideologies or hacktivism can have real-world consequences. Hackers may target governments or organizations to influence policies or spread their messages.
- Revenge – Some individuals commit cybercrimes to harm others due to personal grievances. Revenge-driven attacks can include doxxing, cyberstalking, and hacking into personal accounts.
- Recognition – Some hackers seek fame and credibility within their online communities. Successfully breaching a system or launching a cyberattack can bring them recognition among peers.
- Multiple Reasons – Many cybercriminals have mixed motivations, such as financial gain combined with political activism or revenge. These cases are complex and harder to categorize.
- Entertainment – Some individuals engage in cybercrime purely for amusement. These cases often involve pranks, website defacements, or trolling.
- Boredom – The weakest motive, as cybercrimes committed out of boredom tend to lack serious intent or consequences. While still harmful, they are usually not as impactful as other motives.
Journal Entry 6:
1. Fake PayPal Website
- Fake URL:
www.paypa1.com - Legitimate URL:
www.paypal.com
Indicators of Fraudulence:
- Misspelled URL: The fake site uses “paypa1” with a numeral ‘1’ instead of the letter ‘l’, a common tactic known as typosquatting.en.wikipedia.org
- Lack of HTTPS: The fraudulent site may lack HTTPS encryption, indicated by the absence of a padlock icon in the browser’s address bar.digicert.com
- Poor Design and Grammar: Fake sites often have noticeable design flaws and grammatical errors, unlike the polished appearance of the legitimate PayPal website.explore.quantumfiber.com
2. Fake Apple Support Website
- Fake URL:
www.applesupport.com - Legitimate URL:
support.apple.com
Indicators of Fraudulence:
- Incorrect Domain Structure: The fake site uses “applesupport.com” instead of the correct subdomain format “support.apple.com”.aura.com
- Urgent Pop-ups: Fraudulent sites may display aggressive pop-ups urging immediate action, a tactic not employed by Apple’s official support pages.explore.quantumfiber.com
- Requests for Unnecessary Personal Information: Fake sites might ask for sensitive information that Apple would not typically request for support purposes.
3. Fake Netflix Login Page
- Fake URL:
www.netfliix.com - Legitimate URL:
www.netflix.com
Indicators of Fraudulence:
- Slight Misspelling in URL: The fake site includes an extra ‘i’ in “netfliix,” a subtle change intended to deceive users.en.wikipedia.org
- Absence of Security Certificates: The fraudulent page may lack proper SSL certificates, evident by missing HTTPS and padlock symbols.digicert.com
- Too-Good-To-Be-True Offers: Fake Netflix sites might promise unrealistically low subscription rates to lure users into providing payment information.explore.quantumfiber.com
Journal Entry 7:
Meme 1: “Photo 1 – Person Sitting at a Computer Typing”
Caption: “Just clicking this email link really quick… what could go wrong?”
Cybersecurity Lesson: Human error is one of the biggest vulnerabilities in cybersecurity.
Phishing attacks prey on quick decisions and lack of awareness. Always verify links and
senders before clicking!
Meme 2: “Photo 13 – Person Looking Over the Shoulder of Another at a Computer”
Caption: “Bro, your password is literally ‘password123’…”
Cybersecurity Lesson: Shoulder surfing is a real threat, especially in public or shared
spaces. Use strong, unique passwords and be mindful of who’s around when entering sensitive
information.
Meme 3: “Photo 2 – Large Group of People on Computers During a Presentation”
Caption: “When the cybersecurity training is happening, but you’re shopping online instead…”
Cybersecurity Lesson: Employee awareness is crucial in defending against cyber threats.
Engaging in cybersecurity training and best practices helps prevent breaches caused by
negligence.
Journal Entry 8:
Movies and TV shows often make hacking look easy and exciting, but they don’t show how it really works. Hackers in films type fast, break into systems in seconds, and seem to have unlimited power. In reality, hacking takes a lot of time, skill, and effort. These false portrayals can make people think cybersecurity is simple or that hackers can do anything instantly. This can lead to misunderstandings about real cyber threats. People might not take online security seriously or believe they can protect themselves without proper knowledge. While movies make hacking look cool, they often mislead us about how cybersecurity really works
Journal Entry 9:
After watching the video and taking the Social Media Disorder scale, I got a low score, which means my social media use seems pretty healthy. Still, the questions made me think. Some of them, like using social media to feel better or getting upset when you can’t use it, can be true for a lot of people without them realizing it.
The questions on the scale were good because they show how social media can affect our feelings, time, and relationships. It helped me see how easy it is to fall into bad habits without noticing.
I think people around the world use social media in different ways because of things like culture, technology access, and how daily life is set up. In some countries, being online a lot is normal, while in others, it might be seen as a problem. That’s why patterns can vary so much from place to place.
Journal Entry 10:
Reading the article on social cybersecurity helped me understand how important this new area is for national security. Unlike regular cybersecurity, which protects computer systems, social cybersecurity focuses on protecting people and societies from being manipulated through technology. It was surprising to learn how powerful information has become. Some countries are using it as a main weapon, not just a tool. Russia, for example, has been very active in using online information to divide other countries and create confusion. The article showed how technology lets them spread messages quickly and quietly, often without being noticed. It’s a reminder that future conflicts may not always be fought with weapons, but with ideas and influence.
Journal Entry 11:
The video about cybersecurity analysts shows how their job connects to social behavior in many ways. One key point is that these professionals must work well with others. They often talk with different teams in a company to help protect information and solve problems. Good communication is very important. Another social theme is the need to keep learning and stay updated, because cyber threats are always changing. Cybersecurity analysts help protect not just data, but also people’s trust in companies and systems. Their work makes sure that people’s private information stays safe, which is important for keeping society secure and confident in using technology.
Journal Entry 12:
The “SAMPLE DATA BREACH NOTIFICATION” letter from Glasswasherparts.com explains to customers that their personal information may have been exposed during a data breach. It describes what happened, what information was affected, and what the company is doing to help. Two economic theories connect to this letter. First, information asymmetry is when one side knows more than the other. Before the breach was shared, the company had more information than the customers. By sending the letter, they are trying to fix that imbalance. Second, cost-benefit analysis explains why the company is offering free credit monitoring. They are weighing the costs of offering help now against the bigger cost of losing customer trust or facing lawsuits later. Two psychological theories also relate. Loss aversion shows that people fear losing something (like their identity or money) more than they value gaining something. The company offers protection to ease this fear. Also, trust repair theory explains how saying sorry, being honest, and offering help can rebuild trust after a mistake. Overall, the letter is trying to fix the harm both financially and emotionally.
Journal Entry 13:
The article, “Mind the gap: bug bounty programs and vulnerability disclosure policies,” talks about how companies use bug bounty programs to find problems in their cybersecurity. In the literature review, the authors explain that bug bounty programs are based on cost-benefit thinking — it costs less to pay hackers small rewards than to deal with a big cyberattack later. They also say that these programs need a lot of trust and clear communication between companies and hackers. In the discussion, the article shows that while bug bounty programs can work well, they are not perfect. Some companies don’t make clear rules, take too long to respond, or don’t pay fairly. This can make hackers feel ignored or frustrated. If that happens, the program might fail. I think bug bounty programs are a good idea, but companies have to put real effort into running them the right way and treating hackers with respect.
Journal Entry 14:
One of the most serious internet violations Andriy Slynchuk discusses is hacking into someone else’s account, which is a clear invasion of privacy and often leads to identity theft or financial fraud. Spreading malware is another major offense because it can damage entire systems and affect thousands of people or organizations. Using someone else’s Wi-Fi without permission may seem minor, but it’s considered theft and can lead to security risks for the original user. Buying illegal items on the dark web is dangerous because it often supports crime networks. Finally, pirating copyrighted content is a widespread but serious offense that harms creators and violates intellectual property laws. These actions are serious because they violate trust, privacy, and legal protections, and often have long-term consequences for both individuals and society.
Journal Entry 15:
After watching Davin Teo’s TEDx talk on digital forensics, I was struck by how his career journey blends both technical expertise and social science insight. Starting as an accountant, Teo transitioned into digital forensics, a field that requires not only technical skills but also a deep understanding of human behavior. He emphasized that digital forensics is not just about analyzing data; it’s about interpreting that data within the context of human actions and motivations. This intersection with social sciences, particularly psychology and sociology, is crucial in understanding the ‘why’ behind digital evidence. Teo’s approach highlights the importance of empathy and ethical considerations in digital investigations.