Article Reviews

Article #1 Review

 Cybercrime and its social impact on Suspicious Behavior and Employee Stress

William Gardin

School of Cybersecurity, Old Dominion University CYSE

201S: Cybersecurity and the Social Sciences

2/19/2025

Introduction

The Report “The Impact of Cybersecurity and AI’s Related Factors on Incident Reporting Suspicious Behavior and Employee Stress” investigates how reporting incidents of suspicious behavior improves relationships in the cybersecurity incident management world, as well as how the reports can cause stress for the employees that have to deal with them. It uses things from the social sciences to better explain why certain cybercrimes are being committed, as well as what the social effects of these crimes will do to employees. In this review I will explain how the topic relates to the principles of the social sciences, the study’s research questions/hypotheses, The types of research methods used, the types of data and analysis done, how the topic relates to the challenges of marginalized groups, the overall contributions of the studies to society, and how the concepts from the presentations used in class relate to the report.

Relation to the principles of the social sciences

              This report uses a lot of determinism to get the reader to understand what is causing certain things to happen. For example, in the introduction of the report, it states “Nepal et al (2024) identified that high workloads, time pressure, and lack of support contribute to stress among cybersecurity incident responders” (K. Jaishankar, 2024). This shows that with using determinism, the author is able to express how one event is leading to the other. This report also uses the social science principle of parsimony. You can see the parsimony principle in the beginning of the introduction, the author explains that workplace stress “Refers to the complex interplay between employee stress levels and the propensity for cybercrime,” (K. Jaishankar, 2024). If the reader did not know what workplace stress was before reading the report, it would have been difficult for the reader to get a grasp of what the author was talking about. The report also uses the social principle of empiricism. The reports cited in this report come from people who had created their own experiments and recorded the observations that they made from those experiments.

Research questions and/or Hypotheses

              One hypothesis the author had was that in order for incident reporting models to be successful, they need to have mechanisms in place that give feedback to employees in terms of their statuses of submitted reports (K. Jaishankar, 2024). The hypothesis they used to mitigate employee stress and reduce risky behavior was to provide counselling services and financial advice for the employees (K. Jaishankar, 2024).  The author also states that providing security teams that are focused on analyzing reports and specific descriptions will help with making sure that incident responses are taken care of and look looked over (K. Jaishankar, 2024).

Research methods used

The report uses multiple research methods. One method the authors used was archival research. They gathered multiple sources from credible reports which helped them with conducting their experiment. The other method used was surveys. They gathered 229 different employees from different work fields and gave all of them the same type of structured questionnaire (K. Jaishankar, 2024). Another research method that they used was experiments.  When they were testing the 229 employees, they took their results and put them into a model so they could see if the results lined up with their hypotheses (K. Jaishankar, 2024).

Types of Data and analysis used

              In the report, the quantitative data that they had collected from the 229 employees they questioned were used to help form their analysis. After they were able to talk to everyone, they put the data they had into a model. They used the model to form their analysis. In the analysis, they state that “Emphasizing a comprehensive approach integrating psychological and technical facets in cybersecurity management is recommended to better safeguard employee’s well-being” (K. Jaishankar, 2024). This means that if companies would give their employees resources that would help them such as counselling or financial advice, it would lower the number of things that they are stressed out about during work.

Relation to concepts from class

              I believe that Maslow’s Hierarchy of Needs relates to this report.  In the report, they talk about how employees who deal with incident reporting will usually have higher stress levels due to the number of reports they have to deal with throughout a workday.  To me this can be looked at as a higher-level need. In the Hierarchy of Needs, people will only be able to start focusing on higher-level needs when their lower-level needs are met. If we were able to get the employee’s lower-level needs met by creating a way for them to complete the most important incident reports first, it will help lower their stress levels and also get the reports that will be able to be followed through with finished first.  Neuroticism also relates to this topic. Someone’s emotional instability can cause things such as stress. If they have too much on their plate, it can cause them to become very stressed. A person’s cognitive process might also cause them to be stressed out.  For some people, they let their emotions and their perspective on something do nothing but cause extra stress. This could lead up to workplace stress, which will do nothing but make them start doing things in an illogical way. Conscientiousness is a good way to reduce your stress. If you stay organized, on time, and hardworking, the stress you will have to deal with will lower.

Relation to Marginalized Groups

              This report relates the most to people who are constantly dealing with stress at work. People who are dealing with stress will have a harder time dealing with the workload given to them for the day. It can cause them to fall behind, which will do nothing for them besides add even more stress. Giving them resources such as counselling will help them mitigate the amount of stress they have at work. Allowing employees to have resources like counseling will also help people who are looking for a job. Since there will be a need for counselling, it will allow people who are struggling to find a job have a shot at getting hired for one.

Overall contributions of the report

              Overall, this report has a positive contribution for society. This report doesn’t only go for people within cybersecurity, but for everyone who has a job. People shouldn’t be dealing with stress all the time. Humans are not built for constant stress. Giving employees resources such as counselling and financial advice will ease the amount of stress they have to deal with in a day. Another contribution this study gives to society is that if management shows you that they care about you by giving you resources, it will encourage the employee to work with maximum effort.

Conclusion

In conclusion, this report gives a good solution to people dealing with stress in their workplace. While writing this report, they used principles such as determinism, parsimony, and empiricism. The hypotheses that they brainstormed were easy to understand and were further proved by the research that they conducted. The type of data that they collected was through surveys of 229 employees from various different fields of work. The data they collected from the survey was put into a chart that they used to form an analysis based on the data found. The report was relatable to concepts learned in class, such as Neuroticism and Maslow’s Hierarchy of Needs. This report will end up being very useful for people who are constantly dealing with stress at work, as it gives them a solution to their problem. It would also be useful for people who are struggling to find a job, as this solution they came up with would end up creating jobs for people in the counseling/financial fields. Giving employees resources to things that they need and having management do it in a way where it makes employees feel like they belong are ways that this report gives positive contributions to society.

Sources

https://cybercrimejournal.com/menuscript/index.php/cybercrimejournal/article/view/330/99


Article #2 Review

The Intersection of AI and Cybercrime: Risks, Trends, and Countermeasures

William Gardin

School of Cybersecurity, Old Dominion University CYSE

201S: Cybersecurity and the Social Sciences

4/9/25

Introduction

The article “Investigating the Intersection of AI and Cybercrime: Risks, Trends, and Countermeasures” looks over AI and how cybercriminals are able to use it for their benefit. AI can be looked at as a double-edged sword. Even though AI can be useful to society, it also gives those same advantages to cybercriminals. This article assesses the latest AI tools and cybercriminal techniques through a social engineering lens to explore potential risks and trends of AI-powered cybercrime, as well as countermeasures and policies to address the negative risks and trends seen through this article. In this review I will explain how the topic relates to the principles of social sciences, the article’s research questions/ hypotheses, research methods used, the types of analysis and data done, challenges of marginalized groups, overall contributions of society, and how the presentations from class relate to the article.

Relation to the principles of the social sciences

One principle that the authors used was objectivity. The author says that “While AI can be beneficial to society, it can also be leveraged by cybercriminals to conduct sophisticated and widespread attacks that can generate many victims (Shetty et al.).”  This shows how the author remained unbiased while talking about their topic, which aligns with objectivity and ethical neutrality. Another principle that was used was Empiricism. When the authors of the article were conducting their research, they conducted structured interviews with experts in the field. This is empirical since the information they are getting can be backed up by experts.

Research questions and/or hypothesis

When the authors were conducting interviews with the experts, they asked four complex questions: “What important things might people miss when the media talks about AI, especially regarding staying safe online and how AI affects our daily lives? (Shetty et al.)”, “How are perspectives and attitudes towards AI usage evolving? Should there be stricter or gradual reduction in its deployment to address concerns about ethics, privacy, and safety? (Shetty et al.)”, “How do you perceive the changing perspectives and psychological attitudes surrounding the utilization of AI, and what considerations should inform decision making regarding whether there should be stricter regulation or a gradual reduction in its deployment? (Shetty et al.)”, and “How can the potential consequences of malicious AI usage originating from the dark web be minimized for the clear web? What practical measures can be implemented to mitigate risks as a government, organization, and individuals? Considering the widespread dissemination of information, how can efforts be directed toward addressing victimization effectively? (Shetty et al.)”. The data the authors gathered from these questions were then used to help the authors “identify strategies for enhancing capable guardianship and increasing awareness among suitable targets or internet users (Shetty et al.)”.

Research methods used

This article uses two distinct research methods: Interviews from experts, and research that was done through TOR (The Onion Router) which helped them set up a dataset that comprised of 102 malicious AI prompts within the clear and dark web. With the interviews, they were able to gather qualitative research as they were able to get a point of view of this topic through a legal, technical, and policy-driven lens. With TOR, They were able to get quantitative research which they then turned into a chart for the readers to see.

Types of Data and Analysis used

In the report, they used thematic analysis, which is when you look for recurring themes and patterns. The data that they had gathered from the interviews and their own research was thematically analyzed to understand the connection between AI and cybercrime, as well as how it can be an issue for people worldwide. They also looked at the data through the Cyber RAT Framework (Cyber Routine Activities Theory Framework), which the authors did to “better explain computer crime victimization by emphasizing that the presence of motivated offenders is inevitable due to the internet’s broad accessibility and anonymity it provides (Shetty et al.)”.  When they applied this type of analysis to their research, they were able to find three recurring AI tools that were used in malicious ways. They were: WormGPT 3.0, WormGPT, and ChatGPT. The cybercriminals used these AI tools to create malware, ransomware phishing schemes, and jailbreaking techniques for AI tools. They also found out that the majority of the people who were using tools like WormGPT were mainly using it to find out how to jailbreak ChatGPT. They were also able to find out recurring cybercriminal techniques in these AI tools, such as Cookie stealers, SQL injections, Capturing keystrokes, Carding, Brute force, and Keyloggers.

Relation to concepts from class

The types of social engineering we discussed in class can relate to this article. When the authors collected their quantitative research from TOR, they were able to find out some social engineering techniques cybercriminals were trying to get out of AI tools such as WormGPT. Some of these were social engineering techniques that we talked about in class, such as phishing. Another concept from class that is seen in this article is cyberspace field studies. When the authors were conducting research through TOR, they were reviewing various online forums on the clear and dark web that showed discussions of people using AI to create code that would be used for cybercrime. This can be seen as cyberspace field studies, as researchers are entering cyberspace to study behaviors of certain people. Furthermore, traditional field studies are also seen in this article. When the authors are doing their qualitative research, they decide to interview different experts in this area and ask them various complex questions.  This can be seen as a traditional field study, as they are entering the field to study cybersecurity.  Behavior and risk is another concept that was brought up in class that is also seen in this article. After the authors get all of their analyzed data, they talk about how individuals can increase the risk of cyber victimization, specifically through changes in their online lifestyles. This is the concept of behavior and risk, as changes in people’s online lifestyles can influence the risk of victimization, which in this case, is related to AI-based attacks.

Relation to marginalized groups

This report relates the most to people who do not have good security hygiene. With AI, cybercriminals are able to create very sophisticated social engineering techniques, such as phishing scams. AI can make these scams seem very legit, and if they are not aware of what they are supposed to look for, it can result in them becoming another victim to cybercrime. Giving these people awareness to this problem as well as giving them basic security hygiene such as changing passwords every couple of months, using strong passwords, not using the same password for everything, and previewing a link instead of clicking on one, would help reduce their chances of becoming a victim of cybercrime through AI by a lot.

Overall contribution of the article

Overall, this article has a positive contribution for society. This article allows people to be aware of new ways cybercriminals are trying to get ahold of your information. This article can apply to anybody, whether you are using the cyberspace for work or are just surfing the web. Giving people ways to counter being a victim of AI-related cyber attacks will help lower the total amount of people becoming a victim to one of these attacks. Another contribution this article gives to society is that if you start practicing basic cybersecurity hygiene, you will help with getting rid of cybercriminals as a whole. If cybercriminals stop having success, there would be no reason for them to continue to do what they are doing.

Conclusion

Overall, this article sheds light on a new trend of Cybercriminals using AI tools to improve their cyber-attacks on people. When writing this article, the author uses social principles such as objectivity, ethical neutrality, and empirical research. The questions that the authors gave the experts were essential to their research process, as well as giving the authors empirical research that they can build their article off of. The type of data that they collected through TOR and the interviews were both analyzed through the Cyber RAT Framework and Thematically analyzed to find recurring themes between AI and how cybercriminals use it to commit more sophisticated cybercrimes. The data that they collected through their TOR research was then put into a chart so that the readers can easily access and understand the data that they gathered. The article was relatable to many different concepts that we learned in class, such as social engineering and behavior and risk. This article can be useful for people who do not have good cybersecurity hygiene and for people who are unaware of this issue. It shines light onto a new trend of cybercriminals using AI to make their attacks more sophisticated, as well as give ideas for what to do to counter this issue. The positive contributions that this article gives to society allows people to be less vulnerable to AI-related cyber-attacks, which will ultimately put an obstacle in the way of cybercriminals trying to complete their goal.

Sources

https://vc.bridgew.edu/ijcic/vol7/iss2/3/