Chapter 1 for Ethical Hacking Research Topic in Financial industry

profilemamatha8186
Chapter1Introductionraju13261.docx

CHAPTER1 1

CHAPTER 1 5

Ethical Hacking Among IT Security Professionals in the Financial Industry of Virginia

Ethical Hacking Among IT Security Professionals in the Financial Industry of Virginia

Chapter 1: Introduction

For a long time, financial institutions have been lucrative targets for criminals of all sorts. As early as the 1900s, banks were targeted by bank robbers. An example of a duo that terrorized the financial sector more, so banks were Bonnie and Clyde. The pair was notorious for staging bank robberies where they left bank employees and customers locked up in bank vaults as they got away with the stolen money. A century later and still, financial institutions are the most targeted by criminals. Criminals have evolved with technology and, for that reason, have been able to keep up and stay ahead of most security measures implemented to prevent loss by financial institutions. The allure that criminals will benefit significantly if they manage to penetrate financial institutions has led to as many people and institutions as possible targeting financial institutions. In today's era, most crimes targeting financial institutions are not physical crimes; instead, they are virtual crimes (Leukfeldt et al., 2017). Financial institutions are losing much more money in the technological era compared to the bank robbery era. To prevent further losses, financial institutions are looking into identifying potential loopholes in their operating system and security systems and seal them before they are exploited by criminals that operate in the virtual world cybercriminals. The intention to protect financial systems has seen the rise of ethical hackers. By studying and understanding what ethical hacking, one can make a case for or against ethical hacking among IT security professionals in the financial industry as a measure of curbing cybercrime targeting the financial sector. The above statement sets the foundation for this paper; ethical hacking is the key for IT security professionals in the financial industry's fight against cybercrime.

Hacking

One can define hacking as activities geared at compromising digital devices such as tablets, smartphones, computers, and even entire networks (Khan & Salah, 2018). In most cases, hackers are motivated by personal gain. There are three main types of hackers. The first type is black hat hackers who are also known as crackers. Black hat hackers hack to gain unauthorized access to a system and harm its operations or steal sensitive information. The act is illegal because of its ill intent, which covers stealing corporate data, damaging hacked systems, violating privacy, and blocking network communication. The second type of hackers is called grey hat hackers. Grey hat hackers act without malicious intent but for fun. Just as in the case of black hat hackers, grey hat hackers exploit security weaknesses in a network or computer system without the owner's permission and knowledge. Grey hat hackers intend to bring to the attention of system or network owners or administrators of the weaknesses to get appreciation or even a little bounty from the owners the last main type of hackers as white hat hackers known as ethical hackers.

One can define ethical hacking as the accepted practice of bypassing set security systems to identify potential threats and data breaches in a network (Radholm & Abefelt, 2020). The main aim of ethical hackers is to investigate networks or systems for loopholes or weak points that malicious hackers or cybercriminals can exploit for entry or destruction. Ethical hackers are hired by institutions and organizations that want to protect their systems and networks from cybercriminals or malicious hackers. Ethical hacking is not illegal, and surprising, is one of the most demanding jobs in the IT industry. Ethical hacking is part of penetration testing and vulnerability assessments that organizations can carry out.

For hackers to accomplish a perfect hack, they implement a variety of techniques. There are five main types of techniques that are used by hackers. Top on the list is the use of rootkits. Rootkits refer to software tools or programs that make it possible for threat actors to access remotely a computer system connected to the internet. Initially, the rootkit was developed as a way for system developers and IT maintenance to open a backdoor in a system to fix software issues. Rootkits are installed in a victim's network in two ways: phishing attacks and social engineering.

The second common technique is in using keyloggers. According to Bhardwaj and Goundar (2020), keyloggers are tools that record or log every key pressed on a system. Keyloggers cling to the application programming interface to record every keystroke. Consequently, hackers who use this technique get to store data like usernames, passwords, website visit details, and opened applications, screenshots that can be leveraged to gain access to a network or a computerized system.

The third common technique used by hackers is the use of vulnerability scanners. Ethical hackers mainly use vulnerability scanners or assessment tools. The scanners allow hackers to detect and classify system weaknesses in communication systems, computers, and networks. Ethical hackers use vulnerability scanners to identify potential loopholes and fix them before being abused by cybercriminals or malicious actors. At times, black hat hackers use vulnerability scanners and assessments to check systems for weak points to exploit the systems.

The fourth technique is a structured query language (SQL) injection attack. SQL injection attacks are designed to exploit data housed in a database. Hackers use SQL statements to trick database systems into hacking usernames, passwords, and other information. In most cases, hackers use SQL injections on websites or web applications that are poorly coded. The last technique is the distributed denial-of-service (DDoS) attack. This type of attack distorts regular traffic from entering a server or floods network traffic, resulting in an owner's lack of service.

Problem Statement

Financial losses have hard hit the nation's financial sector due to data breaches as cybercrime. In the last fifteen years, the country has been heavily affected by cybercrime targeting financial institutions. There are three notable cybercrimes in the industry that are worth mentioning. To start, the list is JPMorgan Chase bank; the largest bank in the nation reported a data breach that affected 76 million households and seven million small businesses (Tripathi & Mukhopadhyay, 2020). The bank assured the public that no financial data was lost or compromised. It insisted that only the emails, names, and addresses of account holders were affected by the breach. According to the bank's report in 2014, the black hat hackers gained access to the bank's systems and obtained a list of programs and applications that the bank used (Tripathi & Mukhopadhyay, 2020). The data gained served as potential exploitation points for the applications and programs.

The second financial institution that suffered huge losses due to cybercrime activities is the Heartland Payment Systems Organization. The organization handles over 11 million transactions daily from over 250,000 business locations in the nation. In 2008, the organization reported that its systems had been hacked. The hack affected over 130,000,000 multiple credit card types and customers. The company had to spend over $140,000,000 to deal with the breach. The company paid approximately $60,000,000 to settle with Visa, $3,500,000 to settle with American Express, and $26,000,000 on legal fees. The organization also had to set aside $42,800,000 for potential litigation and settlements in the future related to the hack (Mitchell, 2018).

The third financial institution in the nation that suffered immensely from cybercrime activities was Equifax Inc. The company reported that over 143,000,000 United States accounts were compromised in its most significant data breach (Mitchell, 2018). Additionally, the breach affected as many as 400,000 British accounts as well. According to the company, the breach led to the compromise of customers' names, birthdates, email addresses, and social security numbers. The hackers exploited an unpatched Apache Struts vulnerability. Unfortunately, the financial giant did not detect the hack for approximately two and a half months after it had happened.

The state of Virginia is an example of a state that has suffered from cyber-attacks targeting its financial industry. An example of a known financial institution that was attacked by hackers is the National Bank of Blacksburg. Hackers were able to breach the bank twice in eight months and stole $2,400,000 in 2016. According to Krebs (2018), the first attack happened in May 2016, where an employee of the bank fell victim to a phishing email. The email gave the intruders access to install malware on the victim’s machine and a second computer in the bank. The second attack happened in January 2017, and just like the first time, the hackers used a phishing email to enter the bank's systems.

In the four real-life examples shared above, the financial institutions were the biggest losers. The institutions lost millions of dollars in dealing with litigation as well as in settlements. Furthermore, the institutions had to spend a lot of money hiring forensic experts to identify how the hacks were possible and prevent similar future attacks. Moreover, the institution's credibility as secure means of financial transaction agents was dented, the institutions lost many customers, which had adverse effects on their businesses. Also, the trust people had in the security of financial institutions was shaken.

The loss of money, businesses, and reputation continues haunting the affected financial institutions. The desire to protect not only Virginia's financial institutions but also the nation's financial industry pushes for the need to understand how ethical hacking works and how beneficial it can be to the industry. There is a need to enhance the security protocols and measures implemented in the financial industry to secure the industry and protect the public from losses or damages that may result from cyber-related crimes. Specifically, there is a need to protect Virginia's financial institutions from further cybercrime lest the state's financial industry becomes an easy target for cybercriminals.

Conceptual Framework

In this study, particular emphasis will be placed on why ethical hacking is ideal for financial institutions to protect themselves against cyberattacks or malicious hacks. The variables in this study are ethical hacking or white hacking and security. The study is geared at providing an understanding of the relationship or the link between the two variables. Five supporting reasons support ethical hacking, and the grounds make a case for ethical hacking as a reliable security measure

Cyber Attacks

In all the industries that exist, three sectors are under constant threat of cyber-attacks, and the industries are the health industry, the financial industry, and government agencies. The health sector is highly targeted for phishing attacks, with 77% of email attacks on the industry having malicious links. In reference to a report published by IBM-Force that highlights the cybersecurity threat intelligence index, the financial sector, more so banking institutions, is the most attacked industry in the last five years. A report by Verizon on data breaches investigation corroborates the findings by IBM. According to the report, out of the 2000 breaches in 2019, approximately 10% of the breaches stemmed from the financial service s sector. Comment by Jess Schwartz: Citation needed Comment by Jess Schwartz: What report? Put in the citation after IBM-Force (if it’s by the ibm-force, then just add in the year in parentheses) Comment by Jess Schwartz: Citation needed

An analysis of how the majority of the nation's hacks have happened reveals that the hacks could have been prevented if measures had been put in place to protect the breached systems. Most of the hacks in the nation happened due to existing loopholes. Hackers exploited vulnerabilities in the methods and took advantage of the lack of human knowledge as concerns system security. By having ethical hackers scan systems for vulnerabilities, the organizations and the institutions affected greatly by the cyber-attacks would have stood a better chance of withstanding the attacks.

Ethical Hacking

Ethical hackers intrude on web applications, servers, end services, and systems to provide a defensive layer against cyber-attacks (Thomas et al., 2019). With a defensive layer on a network, organizations and institutions can monitor malicious activities continually. Ethical hackers review antivirus software and other anti-malware software updates. In simple terms, ethical hackers find vulnerabilities before they do. Ethical hackers help organizations strengthen their security measures before their data and systems are compromised.

Ethical hacking has a direct relation to security measures. By having many instances of ethical hacks taking place, organizations' security measures improve. Organizations that do not carry out ethical hacking are more likely to be negatively affected by cyber-attacks. On the other hand, organizations that conduct many ethical hacking instances are more likely to be prepared to counter hack attacks targeting their systems than organizations that have not run as many ethical hacking instances.

Cloud Technology

The advancements of technology have led to the development and adoption of cloud computing. Many businesses are continuing to adopt cloud services to streamline their services as well as speeding up their processes. It is not only the good and honest individuals that have leveraged technological advancements; unfortunately, cybercriminals and actors with ill intent have also leveraged technological advancements. Technological advances such as cloud computing have made it possible for cybercriminals to easily access the organization's systems if they can access cloud service providers.

Organizations are easy targets for cybercriminals by not having reliable security measures to counter cyberattacks targeting cloud service providers and cloud solutions. Two of the measures that have been identified to be effective at limiting cyber-attacks on cloud services and technology are vulnerability scans and ethical hacking. Ethical hacking offers organizations an opportunity to identify their weaknesses and vulnerabilities as concerns cloud services. Organizations that conduct ethical hacking can better secure themselves by placing measures to counter possible attacks by hackers.

Based on the above information, there is evidence that ethical hacking and security measures have links or direct relationships. The lack of ethical hacking directly impacts the security threats that an organization is under threat of. The regular conducting of ethical hacking increases the likelihood of an organization surviving and withstanding a hack attempt.

Risk of Liability

Ethical hacking or white hacking has been identified to reduce the risk of system and data breaches and reduce the risk liability from a breach. Their customers or clients more trust organizations that have certified ethical hackers on board. Additionally, organizations known to use ethical hackers are less likely to be made to pay settlements or compensations if there are data or system breaches. Such organizations are deemed to have put in place as many measures as possible to prevent them from being hacked.

An analysis of the above reason for ethical hacking for protecting financial organizations against cyber-attacks confirms the relationship between the two variables under study. Ethical hacking is directly related to better security measures and also less risk of liability. The reason supports why most financial organizations should adopt ethical hacking as a preventive mechanism against cyber-attacks.

Reducing Losses in Breaches

Ethical hackers have been identified to save organizations by reducing losses in breaches in two main ways. The first way is the location of vulnerabilities fast to prevent ongoing attacks. The second way is by ethical hackers, suggesting insurance that can reimburse organizational losses due to employees' insider activities. Organizations cannot stay up to date with the latest security trends; however, by employing ethical hackers' services, organizations can rest assured that they are practicing the newest security methodologies and techniques (Nicholson, 2019).

An analysis of the last reason for ethical hacking confirms the direct relationship between the two variables; security measures and ethical hacking. Whenever organizations employ ethical hackers, they cement and solidify their security protocols. Ethical hackers test the existing security measures and can reveal possible loopholes that can be exploited by cybercriminals.

Research Questions

To confirm or dispel the research thesis statement of ethical hacking is the key for IT security professionals in the financial industry in the fight against cybercrime, five research questions will be used.

RQ1: How does ethical hacking enhance system and data security for financial organizations?

The first research question focuses on providing information on how ethical hacking can prevent breaches in the financial sector. The research question stems from the hypothesis that ethical hacking is a reliable preventive measure against cybercriminals. By getting answers to the first research question, it will be possible for the researcher to know whether ethical prevents breaching or not.

RQ2: What are the measures that IT security professionals in the financial industry put in place to improve their security protocols?

The second research question exists to do away with the possible bias of the study. There is a big focus on ethical hacking as a reliable security measure; however, it might not be the best preventive measure. By getting answers on the types of measures that IT security professionals in the financial sector have implemented and their reliability, it will be possible to gauge and classify the ethical hacking preventive measure's effectiveness.

The second research question is pegged on the hypothesis that IT security professionals in the financial industry implement security in-depth to protect their data and systems. By answering the research question, the researcher will have more knowledge of the security measures that IT security professionals in the industry implement. Consequently, it will be possible to gauge the effectiveness of ethical hacking in enhancing information technology security in the financial sector.

RQ3: What are the features of ethical hacking that make it ideal for supporting security protocols in the financial sector?

The third research question exists to probe the researcher on doing more research on ethical hacking and its processes. The question is concerned with the features of ethical hacking and how they work to improve system and data security in financial institutions in Virginia. The research question's expected answers will contribute to the conclusion on whether ethical hacking is critical for IT security professionals in the financial industry in the fight against cybercrime. The third research question stems from the hypothesis that ethical hacking is a reliable preventive measure against cybercriminals.

RQ4: What preventive measures can organizations in the financial sector adopt to protect their systems and data?

The fourth research question is curious. The question is meant to trigger the researcher to think of other security mechanisms adopted in the financial sector to enhance industry security. The question is geared at the analysis of emerging trends in system and data security. The question will probe the researchers to look at artificial intelligence, cloud computing, and machine learning, amongst other emerging trends.

The answers gotten from the fourth research questions will prove whether ethical hacking is a security measure for the current issues or whether it is a security measure for various security issues regardless of the era. The fourth research question stems from the hypothesis that ethical hacking is a security framework just as risk assessment instead of a one-time security solution. The answers from this research question will confirm whether ethical hacking is critical for IT security professionals in the financial industry in the fight against cybercrime.

RQ5: Is ethical hacking an essential requirement for systems security, or is it a complementary security measure?

The last research question stems from the hypothesis that ethical hacking is a complementary security measure instead of an essential requirement for systems security. The researcher will know how financial institutions have adopted much ethical hacking by answering the last research question. Additionally, the researcher will understand how IT security personal view of ethical hacking. The answers to the question will confirm or dispel the notion that ethical hacking is critical for IT security professionals in the financial industry in the fight against cybercrime.

Significance of the Study

Financial institutions all over the world are under the threat of cybercriminals. Banks, insurance companies, transaction agents, and investment companies are always under threat due to the allure that if a criminal is successful in hacking their systems, they will reap heavily. Consequentially, financial institutions in Virginia and other parts of the nation and the world invest heavily in securing their systems and data. Despite considerable investments in security measures, the financial sector is still under threat from cybercriminals. There are four main benefits that financial organizations stand to gain by confirming the effectiveness of ethical hacking in the protection of the industry that they operate in.

By conducting the study, financial organizations will know whether to adopt ethical hacking to measure security threats from cybercriminals fully. Not all IT security professionals agree that ethical hacking is an excellent preventive measure. There are some IT security professionals that do not believe ethical hackers to be a ‘real’ profession. The above-mentioned IT professionals are hesitant to commission external parties to check vulnerabilities in their systems. They are afraid that the hackers might exploit the vulnerability assessments they carry out for future hacks.

Furthermore, they believe that exposing their institution’s systems and data to potential hacks is a risk by itself. They believe trade secrets might be lost in the process. By confirming indeed that ethical hacking is a reliable preventive measure, the hesitant IT professionals will be a bit more welcoming to the adoption of ethical hacking as a reliable preventative measure.

The second significance of the study is that it will play a vital role in securing the systems and data in the financial industry. The study's findings, regardless of whether they are in line with the research statement or not, will contribute to the existing information technology security knowledge. Suppose the study results are that ethical hacking is the key for IT security professionals in the financial industry in the fight against cybercrime. In that case, more institutions will be compelled to adopt ethical hacking to improve their security protocols. For example, suppose the study's findings contradict the statement ethical hacking is the key for IT security professionals in the financial industry in the fight against cybercrime. In that case, it will be more apparent that ethical hacking is not a reliable security measure. Consequentially, more financial organizations will restrain from commissioning ethical hackers as part of their preventive measures.

The third significance of the study is that it will provide more information on how hacking takes place and its impact on organizations, more so financial organizations. Considering that hackers or cybercriminals do not share how they carried out hacks or how they could penetrate tried and tested security systems of financial institutions, the study will open the hacking world for all interested to know how hacking works. The study will reveal the techniques used in hacking, and consequentially, mechanisms to counter the techniques can be implemented to protect financial organizations against cybercrime.

The last significance of the research is that it will provide crucial information on information technology security to IT security professionals and the general public. In most cases, the security mechanisms employed for banks and other financial institutions are availed on a need to know basis. However, this research will provide crucial information to the general public. Consequentially, the general public will learn how their data is at risk of being accessed. In effect, the general public will hold financial organizations more accountable for data loss or financial loss. By holding financial organizations accountable, it will be possible to improve financial institutions' security not only in Virginia but all over the nation and the world. Financial institutions will conduct more research and, as a result, develop reliable security measures for their systems and the data that they hold or possess.

Research Approach

For proper and accurate findings of the research, the study will employ a mixed-methods approach. The research will use both qualitative and quantitative data collection and analysis methods. The mixed-methods approach has three main strengths that will be leveraged for the study. The first strength is that it offers strong evidence for a conclusion through convergence. The second strength is that the method uses the strengths of either of the methods to overcome the limitations of the other method (Creamer, 2017). The last strength of the mixed approach is that it provides evidence for the corroboration of findings through triangulation.

Two qualitative and two quantitative data collection methods will be used in the research. For qualitative data collection, the research will utilize the interview method and the case study method. In the use of the interview method, the researcher will interview IT security professionals in the financial industry of the state of Virginia. The security experts that will be interviewed will consist of IT, forensic experts, and system administrators. The security experts that will be interviewed will either be employees of banks, insurance companies, investment agencies or organizations, and transaction agents. For the case study data collection method, cases on ethical hacking in the financial sector will be reviewed. The case studies will reveal whether IT security experts are safe, adopting ethical hacking as a preventive mechanism against cyber-attacks.

For quantitative data collection, the data collection methods that will be used are questionnaires and surveys. The questionnaires will be directed to the IT security specialists that are identified for the interview. The survey method will collect information from financial institutions in Virginia to gather information on whether ethical hacking has been effective at improving system and data security. The data collected will be studied and analyzed using thematic analysis and descriptive analysis.

Definitions of Key Terms Comment by Jess Schwartz: Every single one of these terms needs an in-text citation. Comment by Jess Schwartz: I saw some other key terms you could include here, such as gray hat, cloud technology, etc plus I believe there are more concepts presented in chapter 2 that can be included here. Please include many more key terms as applicable Maybe rootkits, keyloggers, sql injection, etc?

Cybersecurity: Refers to the practice of defending servers, computers, electronic systems, mobile devices, networks, and data from malicious attacks. The term is also known as information technology security.

Cyber threats: Refers to malicious acts that damage data, disrupt digital life, or steal data. Cyber threats consist of threats like denial of service attacks, data breaches, and computer viruses.

Ethical hacking: Refers to the accepted practice of bypassing set security systems to identify potential threats and data breaches in a network.

Cloud technology: Refers to an emerging technology that allows users to access files and services via the internet from any location in the world (Rashid et al., 2018).

Encryption: Refers to the process of encoding data to prevent access to data after it is compromised without a key (Rashid et al., 2018).

White hack: Refers to a network's breaching or a system to gain sensitive information with the owner’s permission or consent.

Black hack: Refers to a network's breaching or a system to gain sensitive information without the owner's permission or consent.

Summary

The chapter is divided into seven sections. The first section is the introduction of the chapter. The introduction is divided into two subsections. The first sub-section focuses on the introduction of the impact of cybercrime in the financial sector. According to the section, the allure that criminals will benefit significantly if they manage to penetrate financial institutions has led to as many people and institutions as possible targeting financial institutions. In today's era, most crimes targeting financial institutions are not physical crimes; instead, they are virtual crimes. Financial institutions are losing much more money in the technological age compared to the bank robbery era. To prevent further losses, financial institutions are looking into identifying potential loopholes in their operating system and security systems and seal them before they are exploited by criminals that operate in the virtual world cybercriminals.

The second subsection analyzes what hacking is and how it is done. According to the subsection, there are three main types of hackers. The first type is black hat hackers who are also known as crackers. Black hat hackers hack to gain unauthorized access to a system and harm its operations or steal sensitive information. The act is illegal because of its ill intent, which covers stealing corporate data, damaging hacked systems, violating privacy, and blocking network communication. The second type of hackers is called grey hat hackers. Grey hat hackers act without malicious intent but for fun. Just as in the case of black hat hackers, grey hat hackers exploit security weaknesses in a network or computer system without the owner's permission and knowledge. Grey hat hackers intend to bring to the attention of system or network owners or administrators of the weaknesses to get appreciation or even a little bounty from the owners. The last main type of hackers is white hat hackers who are also known as ethical hackers.

There are five main types of techniques that are used by hackers. Top on the list is the use of rootkits. The second common technique is in using keyloggers. The third common technique used by hackers is the use of vulnerability scanners. The fourth technique is the use of structured query language (SQL) injection attacks. The last technique is the distributed denial-of-service (DDoS) attack.

The second section of the chapter is the problem statement. The section highlights why cybercrime targeting financial institutions is a problem. According to the section, in the last fifteen years, the country has been heavily affected by cybercrime targeting financial institutions. The loss of money, businesses, and reputation continues haunting affected financial institutions. The desire to protect the financial industry pushes for the need to understand how ethical hacking works and how beneficial it can be to the industry. The need to enhance the security protocols and measures implemented in the financial industry to secure the industry and protect the public from losses or damages pushes for the research to be conducted.

The third section in the chapter is the conceptual framework section, and it focuses on why the variables for the study are appropriate for the study. According to the section, ethical hacking is supported by five supporting reasons, and the reasons make a case for ethical hacking as a reliable security measure. The first reason is that organizations are under constant cyber-attacks. The second reason is that ethical hacking enables organizations to stand offensive against cyber-attacks. The third reason is that most of the financial organizations' adoption of cloud technology demands increased security. The fourth reason is that ethical hacking limits an organization’s risk of liability, and the last reason is that ethical hacking reduces loss in the event of a breach.

The fourth section of the chapter is the research questions sections. Five research questions are identified to help in conducting the research. The first research question is, how does ethical hacking enhance system and data security for financial organizations? The second question is, what are the measures that IT security professionals in the financial industry put in place to improve their security protocols? The third question is, what are the features of ethical hacking that make it ideal for supporting security protocols in the financial sector? The fourth research question was, what are preventive measures can organizations in the financial industry adopt to protect their systems and data? The last research question was, is ethical hacking an essential requirement for systems security, or is it a complementary security measure? Comment by Jess Schwartz: You don’t need to paste in the questions verbatim here. Just give a brief overview about the research questions being discussed earlier in the chapter.

The fifth section is the significance section, and it focuses on the importance and the value addition that the study promises to offer. There are four main benefits that financial organizations stand to gain by confirming the effectiveness of ethical hacking in the protection of the industry that they operate in. By conducting the study, financial organizations will know whether to adopt ethical hacking to measure security threats from cybercriminals fully. The second significance of the study is that it will play a key role in securing the systems and data in the financial industry. The study's findings, regardless of whether they are in line with the research statement or not, will contribute to the existing information technology security knowledge.

The third significance of the study is that it will provide more information on how hacking takes place and its impact on organizations, more so financial organizations. Considering that hackers or cybercriminals do not share how they carried out hacks or how they could penetrate tried and tested security systems of financial institutions, the study will open the hacking world for all interested to know how hacking works. The last significance of the research is that it will provide crucial information on information technology security to IT security professionals and the general public.

The last section of the chapter is the research approach used and the terms that will be used in the research. For proper and accurate findings of the investigation, the study will employ a mixed-methods approach. The research will use both qualitative and quantitative data collection and analysis methods. Two qualitative and two quantitative data collection methods will be used in the research. For qualitative data collection, the research will utilize the interview method and the case study method. For quantitative data collection, the data collection methods that will be used are questionnaires and surveys. Several keywords were defined in the chapter. A deeper discussion of the literature relevant to this study will be discussed in Chapter Two.

References

Bhardwaj, A., & Goundar, S. (2020). Keyloggers: silent: cybersecurity weapons. Network Security2020(2), 14-19. Retrieved from https://www.sciencedirect.com/science/article/abs/pii/S1353485820300210

Creamer, E. G. (2017). An introduction to fully integrated mixed methods research. Sage Publications.

Khan, M. A., & Salah, K. (2018). IoT security: Review, blockchain solutions, and open challenges. Future Generation Computer Systems82, 395-411. Retrieved from https://www.sciencedirect.com/science/article/abs/pii/S0167739X17315765

Krebs, B. (2018). Hackers Breached Virginia Bank Twice in Eight Months, Stole $2.4, M. Krebs, on Security (July 18, 2018)–https://krebsonsecurity.com/2018/07/hackers-breached-Virginia-bank-twice-in-eight-months-stole-2-4m.

Leukfeldt, E. R., Lavorgna, A., & Kleemans, E. R. (2017). Organized cybercrime or cybercrime that is organized? An assessment of the conceptualization of financial cybercrime as organized crime. European Journal on Criminal Policy and Research23(3), 287-300. Retrieved from https://link.springer.com/article/10.1007/s10610-016-9332-z

Mitchell, J. (2018). The Biggest Hacks and What They Can Teach Us. ITNOW60(4). Retrieved from https://web.a.ebscohost.com/abstract?direct=true&profile=ehost&scope=site&authtype=crawler&jrnl=17465702&AN=133263214&h=sXSvRzphoR%2fwPzBCmV4R3V%2f%2buHypFDwkTYN7Ob6y9WhL954oNixqX%2fXw0%2frt3vIvpGlrSHAEQ7IMG9a%2bHXuijw%3d%3d&crl=c&resultNs=AdminWebAuth&resultLocal=ErrCrlNotAuth&crlhashurl=login.aspx%3fdirect%3dtrue%26profile%3dehost%26scope%3dsite%26authtype%3dcrawler%26jrnl%3d17465702%26AN%3d133263214

Nicholson, S. (2019). How ethical hacking can protect organizations from a more significant threat. Computer Fraud & Security2019(5), 15-19. Retrieved from https://www.sciencedirect.com/science/article/abs/pii/S1361372319300545

Radholm, F., & Abefelt, N. (2020). Ethical Hacking of an IoT-device: Threat Assessment and Penetration Testing: A Survey on Security of a Smart Refrigerator. Retrieved from https://www.diva-portal.org/smash/record.jsf?pid=diva2%3A1464454&dswid=8243

Rashid, A., Danezis, G., Chivers, H., Lupu, E., Martin, A., Lewis, M., & Peersman, C. (2018). Scoping the cybersecurity body of knowledge. IEEE Security & Privacy16(3), 96-102. Retrieved from https://ieeexplore.ieee.org/abstract/document/8395134

Thomas, G., Burmeister, O., & Low, G. (2019). The Importance of Ethical Conduct by Penetration Testers in the Age of Breach Disclosure Laws. Australasian Journal of Information Systems23.

Tripathi, M., & Mukhopadhyay, A. (2020). Financial loss due to a Data Privacy Breach: An Empirical Analysis. Journal of Organizational Computing and Electronic Commerce, 1-20. Retrieved from https://www.tandfonline.com/doi/abs/10.1080/10919392.2020.1818521