A human-centric approach to cyber risk mitigation
Ediomo Udofia · 2024
This chapter explores a stretch of human-centric behaviors that pose cyber risks and, in most cases, are exploitable by cybercriminals. The human factor plays a very significant role in cyber defense. Therefore, adequate awareness and training for users are crucial and inevitable. Cybersecurity aims to eliminate or significantly reduce the number of successful cyberattacks or data breaches. Humans are the weakest links to illegally gain access to highly secured systems – hackers know this. Therefore, they often implement their footprinting and reconnaissance around the individuals with legal access to the systems they want to exploit. This chapter presents modern-day best practices and approaches for different categories of individuals to build a better cyber defense with our everyday human behaviors in the corporate environment and our private lives. These categories of individuals include end users in the corporate space, system administrators, cybersecurity experts, software developers, other IT professionals, business owners, or senior executives, etc. Organizational policies and workplace culture are relevant instruments that can help shape human behaviors toward achieving cyber-safe practices. IT managers, administrators, and cybersecurity professionals must frequently evaluate their IT security and data protection frameworks to ensure that their policies and strategies reflect the evolving cyber threats to help the organization maintain an excellent cybersecurity posture. This chapter provides various key areas, principles, and concepts to implement for a good human-centric defense against cyberattacks.