Journal Entry

Week 2 – Journal Entry

The principles of science have a very close relationship with cybersecurity, since they help to guide the understanding, prevention, and management of digital threats. Very vital in the identification of vulnerabilities and testing of security measures are scientific methods like hypothesis testing, experimentation, and data analysis. It is in cybersecurity that the principles of physics and mathematics are applied in cryptography for the protection of data by encryption and safeguarding communication. Furthermore, the scientific approach is applied in systems theory to assess the interaction of diverse components of a network and how they can all be secured. The principle of observation is central in monitoring suspicious activities or breaches through logging and analysis tools. Science also underpins the continuous improvement of cybersecurity by developing new theories and technologies that help to deal with the fast-changing nature of threats. Said differently, the application of scientific principles goes a long way in developing effective cybersecurity strategies that ensure systems are resilient and adaptive to evolving risks.

PrivacyRights.org hosts a comprehensive, publicly available database of information on data breaches. It details what type of data was compromised, which organizations were involved, and how many people were affected. That means researchers can use this to perform trend analysis of data breaches to determine common attack vectors, which sectors are most vulnerable, and how effective the security controls are over time. Through research into patterns in these breaches, one can garner more information on how breaches develop, what methods hackers utilize, and the long-term effects on consumers and businesses alike. The data involved can contribute to developing more effective preventive strategies, policies, and technologies to protect sensitive information.

Week 3 – Journal Entry

Week 4 – Journal Entry

Maslow’s Hierarchy of Needs applies to many experiences I have had with technology. Physiologically, I depend on it for meeting some of my very basic needs, such as ordering food through delivery apps or seeking health information online. Safety-wise, I use cybersecurity measures such as multi-factor authentication and VPNs to protect my personal data from cyber threats. The level of love and belonging is met by social media, messaging apps, and online games, which help me to keep in touch with friends and family. For esteem, professional networking sites like LinkedIn and personal achievements in online courses contribute to my sense of accomplishment and recognition. At the self-actualization level, I use technology to self-actualize by taking online courses to learn new skills and engaging in creative projects like coding or writing.

Week 5 – Journal Entry

  1. Political: Hacktivism involves cyberattacks driven by political or ideological beliefs. Individuals or groups target entities to promote their agenda, protest policies, or disrupt services they oppose.
  2. Revenge: Personal vendettas can lead individuals to commit cybercrimes aiming to harm reputations or cause distress. Acts like revenge pornography are driven by a desire to inflict emotional pain on specific individuals.
  3. For Money: Financial gain is a primary driver for many cybercriminals. The allure of substantial profits with relatively low risk motivates individuals to engage in activities like ransomware attacks, identity theft, and online fraud.
  4. Recognition: Some hackers seek acknowledgment and respect within certain communities. Successfully breaching a high-profile system can elevate their status among peers, providing a sense of accomplishment.
  5. Multiple Reasons: Cybercriminals may have overlapping motives, such as financial gain combined with political objectives or personal grievances. These multifaceted motivations can make their actions more complex and targeted.
  6. Entertainment: A subset of individuals engages in cyber activities for amusement or curiosity, testing their skills without a specific agenda. While not always malicious, these actions can still cause significant disruptions.
  7. Boredom: Some individuals, especially younger ones, may engage in cybercrimes out of boredom, seeking excitement or a challenge. This motive is less structured and often lacks a clear objective beyond alleviating tedium.

Week 6 – Journal Entry

Cybercriminals create fake websites to steal information and spread malware. Recognizing these sites is crucial for online security. This entry compares three fake websites to real ones and highlights key warning signs.

Fake vs. Real Websites

Fake WebsiteReal WebsiteSigns of a Fake Site
PayPal-secure-login[.]comPayPal.comSuspicious URL, no HTTPS, poor grammar, asks for login info.
Amazon-login-verification[.]xyzAmazon.comOdd domain (.xyz), fake urgency, unprofessional design.
BankofAmerica-security[.]netBankofAmerica.comMimics branding, fake contact details, redirects users.

Warning Signs of Fake Websites

• Suspicious URLs – Extra words, hyphens, or unusual domains like .xyz or .net.

• No HTTPS – A missing padlock or ‘Not Secure’ warning.

• Poor Design & Grammar – Legitimate sites maintain professional quality.

• Fake Urgency – Scammers push users to act fast to steal data.

• Mismatched Contact Info – Often fake or missing support details.

Fake websites are a serious security risk. Checking URLs, security features, and website quality helps avoid scams. Always verify legitimacy before entering personal information.

Week 7 – Journal Entry

1. Analysis: The individual is working late into the night, possibly handling sensitive information. Extended work hours can lead to fatigue, increasing the likelihood of errors and susceptibility to phishing attacks.

Relation to Human Systems Integration: This highlights the importance of considering human factors such as workload and fatigue in cybersecurity protocols to reduce human error.

2. Analysis: The individual is engaged with their smartphone, possibly accessing personal or work-related data. Mobile devices are common targets for cyber threats due to their widespread use and often lax security measures.

Relation to Human Systems Integration: Emphasizes the need for user education on mobile security and the integration of secure design principles in app development.

3. Analysis: The individual is actively typing, possibly entering sensitive information. Without proper security measures, this data could be intercepted.

Relation to Human Systems Integration: Highlights the importance of designing systems that encourage strong password practices and user authentication methods.

4. Analysis: The individual is multitasking across several monitors, which can lead to information overload and potential security oversights.

Relation to Human Systems Integration: Underlines the need for user interface designs that manage cognitive load effectively to prevent security lapses.

5. Analysis: The individual is immersed in their work, possibly unaware of their surroundings. This could lead to overlooking physical security threats or shoulder surfing.

Relation to Human Systems Integration: Stresses the need for awareness training and physical security measures in work environments.

6. Analysis: The individual is interacting with a tablet, possibly accessing cloud services. Without proper security configurations, cloud data can be vulnerable to breaches.

Relation to Human Systems Integration: Highlights the importance of user understanding and control over cloud security settings.

7. Analysis: The individual is likely making an online purchase, which involves entering sensitive financial information. This scenario is a common target for phishing and man-in-the-middle attacks.

Relation to Human Systems Integration: Emphasizes the need for secure transaction systems and user education on recognizing secure websites.

8. Analysis: A generic computer user icon representing any user interacting with a computer system.

Relation to Human Systems Integration: Reflects the common user experience and the importance of designing user-friendly IT support solutions.

9. Analysis: Individuals are participating in a group learning session, possibly on cybersecurity topics. Group settings can enhance learning but may also lead to information overload if not managed properly.

Relation to Human Systems Integration: Highlights the need for effective training methods that engage users and encourage active participation.

10. Analysis: The individual is capturing an image, potentially of sensitive information. Unintentional data leaks can occur if such photos are shared without proper consideration.

Relation to Human Systems Integration: Emphasizes the importance of user awareness regarding data sharing and the potential risks of mobile device usage.

Week 8 – Journal Entry

The media plays an important role on what we assume cybersecurity to be, mixing together some fact and some fiction to entertain. Viewing the video helped me understand that Hollywood exaggerates the hack sequences to look faster and more rapid than real hacks performed for purposes of entertainment value. It fosters misimpression of the level of complexity of cybersecurity and how easy it might be to become a hacker. While some representations, like in Mr. Robot, are more realistic, others create hacking in an inaccurate light as being simple or relying too heavily on flashy graphics. Media representations as a whole may encourage interest in cybersecurity but possibly may also propagate misinformation about its real-world issues and complexities.

Week 10- Journal Entry

According to my responses, my score was 3 on the Social Media Disorder Scale, which means that I did not show disordered use of social media. Looking at the items on the scale, I believe that they form a great model for measuring probable problematic social media use by examining prominent behavioral indicators, including avoidance of other activities and lying about use. Yet, certain of these measures would need to be further tuned in order to reflect the variability of social media usage patterns. Technological availability and cultural variation can have considerable influence on responses, resulting in different social media usage patterns worldwide, and consequently different levels of “disorder” depending on this factor. Furthermore, such usage patterns can be attributed to the norms, values, and socioeconomic conditions that shape social relationships. Lastly, various regions may be using social media to achieve various things and hence influence their “addiction” perceived on the platform.

Week 11 – Journal Entry 11

The article is about social cybersecurity as an emerging discipline that is concerned with how technology is used to regulate human conduct and society, in contrast to information systems as the topic for conventional cybersecurity. The article tells us that social cybersecurity is concerned with cyber-mediated trust, opinions, and transformations of social cohesion, and in reality, that is a national security issue of concern. The article points out that open societies are most exposed to psychological manipulation and disinformation attacks and that they erode institutions and cause citizens to lose confidence in them. Russia’s information warfare campaign is cited as an example of the evolving threats in this context. It reiterates the multi-disciplinary nature of social cybersecurity as the social sciences and computational methods are integrated to deal with these challenges effectively. The article also calls for the military commanders to be taught about social cybersecurity as part of ensuring national security and upholding society stability. This focuses on the importance of preventing such threats in today’s highly networked and digitalized environment.

Week 11 – Journal Entry 11

A number of social themes are revealed in advertising the career of a cybersecurity analyst. Networking comes out as one of the important recipes to success in a career, emphasizing social relationships and communal involvement in the technology sector. The presenter frankly comments attending meetups and joining local communities as a means of relationship building and access to opportunities. In addition, resume tips involve the social construct, as a proposal to restatements of achievement in an attempt to present the most appropriate candidate is the dance of self-presentation in the market. Including salaries in some of the city names also involves the social cost, i.e., cost of living and style preference, how personal values affect selection of environments that affect occupational life. Lastly, the presenter identifies the career opportunity gap in relation to job seekers in the profession as making the profession more accessible to join than other professions such as journalism, with the socio-economic advantages for the career changer.

Week 12 – Journal Entry 12

Economic Theories:
Cost-Benefit Analysis:
The firm would have had to balance the expense of bolstering its cybersecurity (i.e., investing in more secure systems or surveillance) against the risk of harm from a breach. Sadly, the breach is a sign that the cost of prevention was likely underestimated or put off and now carries higher financial and reputational costs after the fact.

Market Failure:
This violation is a failure of the market system whereby the platform provider could not sufficiently secure its systems. When businesses are unable to safeguard consumer data, it sends a ripple throughout the economy as a whole, including lower consumer confidence and higher regulatory scrutiny.

Social Science Theories:
Rational Choice Theory (Sociology):
Both victims and impacted consumers can be explained by rational choice. The victims might have weighed the potential payoffs of stealing card data against the likelihood of getting caught, choosing that the rewards were greater than the potential risk of being caught. Similarly, consumers can make decisions on how to react—checking accounts or switching cards—on what they find most beneficial with minimal inconvenience.

Trust Theory (Psychology/Sociology):
The letter is an effort to regain customers’ trust after it was already lost. Firm transparency, collaboration with the authorities, and suggestions regarding protection are all measures in an effort to regain psychological and social confidence in their brand and Internet security.

Week 12 – Journal Entry 13

Bug bounty programs, in which the participants get rewarded for finding vulnerabilities in a company’s cyber resources, are cost-benefit economics. A study, which compared the data of HackerOne, reached the conclusion that security researchers are not highly price-sensitive, which suggests that they are driven by non-monetary factors like reputation and competence development to participate. This means that low-budget companies can also effectively use bug bounty programs to enhance their cybersecurity position. Additionally, it is revealed that company size, earnings, and reputation of the brand influence the volume of valid vulnerability reports received to a minor extent. This thus brings out the appropriateness of bug bounty programs by firms of varying sizes, further affirming them as effective means of enhancing cybersecurity in most industries.

Week 13 – Journal Entry 14

The five most serious types of online misconduct explained in the article included using unauthorized streaming service, torrenting copyrighted material, distributing personal information about others, VoIP calls without consent, and impersonating someone online. These are very serious, not only because they violate laws, but also because they place individuals and organizations at risk. Unauthorized streaming and torrenting copyright material are both forms of copyright infringement, injuring the content creator and violating intellectual property. Sharing personal information about others without their permission can lead to identity theft, harassment, and very serious violations of privacy. Recording calls without consent violates wiretap laws in many jurisdictions and results in mistrust in digital communications. Impersonating someone online can lead to fraud, defamation, or even cyber stalking, making this use of digital identity very dangerous. While these actions may seem trivial to some users, these actions have real-life consequences that impact others’ safety, privacy and ability to earn a living.

Week 15 – Journal Entry 15

Davin Teo’s path to a career in digital forensics is both inspirational and relatable, because he came from an accounting background to work in a specialized, important field. I found it interesting that his journey suggests that you do not have to go down a technical route to work in digital forensics. Many skills and concepts from disciplines like accounting can be valuable in a field such as digital forensics, and are even usable in digital forensics. The social science connection with digital forensics is quite apparent in Davin’s journey as well. Once you add in an investigation of the technology, we can understand people’s motivations, behaviors, and the social context in which digital evidence is created. As Davin described so eloquently, interdisciplinary initiative is valuable when approaching and solving cases. Overall, I think his career path illustrates the benefits of being open to new opportunities and merging technical knowledge with a deep appreciation of the social sciences in order to solve complicated problems. It represents a great example of how a collection of perspectives/goals, skills, and knowledge in various disciplines can be useful in developing successful careers in new or emerging and developing fields.