Following an increase in the frequency and ingenuity of attacks launched against critical information infrastructures with the intention of causing service disruption, there is a strong need to understand the level of awareness among employees working in these environments, the cybersecurity awareness programs and training activities that are in place as well as the methods used in order to measure cybersecurity and privacy awareness of these employees. The organizational resilience against cybersecurity relies on robust data governance policies spanning from data security, privacy and IT infrastructure security among others. While these strategies have offered protection against traditional cyberattacks (e.g., Distributed Denial of Service (DDoS)), the emergence of threats, such as ransomware (e.g., WannaCry) attacks have shown a tremendous increase in the frequency of data breaches in Critical Information Infrastructures (CIIs). Moreover, traditional risk assessment methods have focused on evaluating the security profile of IT systems but the emergence of social engineering dictates the need of better understanding of the cyber risks impact caused by insecure human behavior. Authors’ aim is to present to the reader a clear overview of social engineering and the importance of counting human vulnerabilities as a critical cybersecurity problem that needs close attention and better understanding of the cyberattacking methods used as well as the actions could be taken in order to prevent, manage and eliminate them.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Social Engineering: The Human Behavior Impact in Cyber Security Within Critical Information Infrastructures

  • Sokratis Nifakos,
  • Krishna Chandramouli,
  • Natalia Stathakarou

摘要

Following an increase in the frequency and ingenuity of attacks launched against critical information infrastructures with the intention of causing service disruption, there is a strong need to understand the level of awareness among employees working in these environments, the cybersecurity awareness programs and training activities that are in place as well as the methods used in order to measure cybersecurity and privacy awareness of these employees. The organizational resilience against cybersecurity relies on robust data governance policies spanning from data security, privacy and IT infrastructure security among others. While these strategies have offered protection against traditional cyberattacks (e.g., Distributed Denial of Service (DDoS)), the emergence of threats, such as ransomware (e.g., WannaCry) attacks have shown a tremendous increase in the frequency of data breaches in Critical Information Infrastructures (CIIs). Moreover, traditional risk assessment methods have focused on evaluating the security profile of IT systems but the emergence of social engineering dictates the need of better understanding of the cyber risks impact caused by insecure human behavior. Authors’ aim is to present to the reader a clear overview of social engineering and the importance of counting human vulnerabilities as a critical cybersecurity problem that needs close attention and better understanding of the cyberattacking methods used as well as the actions could be taken in order to prevent, manage and eliminate them.