Chapter 2 :Literature Review

profileAaronbrady
CHAPTER2.literaturereviewFINAL.docx

CHAPTER 2: LITERATURE REVIE 2

2

Cyber Security Education to Enhance prevention skills in Information Technology

INTRODUCTION

Over time the world of technology has changed; with sophisticated technological innovations like machine learning and artificial intelligence taking over, cyber education is crucial because cyber threats are not stopping. Instead, they are advancing and becoming more sophisticated regularly. The practice of protecting computers, servers, intelligent applications, telecommunication technologies, databases, and information from security threats is identified as cyber shielding. It's also recognized as electronic data security or info technology security. The idea is employed in a numeral way, vacillating different industries to the current mobile technology. The exercise of shielding the systems of a communication company from trespassers, whether beleaguered invaders or unprincipled malware, is also known as network fortification.

The term "cyber security" refers to a set of technology, procedures, management processes, and principles that are critical to keeping data safe (Choo, 2011). Alternatively, it promotes the tradition of safeguarding information systems resources to shield them from unwanted employees, information destruction, information leakage, and information modification, thus protecting information security and honesty (Von Solms and Van Niekerk, 2013). Data integrity is described as "protecting information from insufficient information alteration or destruction to ensure adequate information" (Gordon and Loeb, 2006). "Integrity" refers to "protecting information from inappropriate information modification or destruction to ensure adequate information" (Gordon and Loeb, 2006). (Jouini, Rabai and Aissa, 2014). Confidentiality is defined by a limited access mechanism, a protecting access mechanism, and a declaration that includes the safeguarding of proprietary knowledge and personal privacy. Last but not least, there is availability, which guarantees timely and decisive access to accessing the information appropriately (Wang et al., 2010).

As the number of people who depend on smartphone connections to perform tasks concerning their private information and privacy grows, information security is becoming more widely recognized than ever before. Popular cyber-attacks by felons and extremists worldwide have raised consciousness about the importance of solid safety arrangements to protect secrecy and information safety. The research will focus on a comprehensive examination of mobile devices and their effect on society. Understanding the figures demonstrating the rise of cyber-attacks and the advent of mobile computation to substitute conventional individual computers necessitates a brief examination of the history of mobile devices. The papers are organized into categories based on the areas of debate that have been investigated. This is in addition to the fundamentals that play a role in how mobile devices affect cyber security. Malicious purpose, unprotected mobile device use, and organizational and IT professional negligence are all contributing factors. The study of the rise in cyber-attacks on mobile devices includes additional information on why these gadgets are further vulnerable to safety matters than supplementary forms of undeveloped technological set-ups such as Personal Computers (Hoffman, 2008). The utmost emphasis should be placed on programs and distinct structures popular in Personal computers but not on many smartphones. Many smartphone users tend to buy devices, start storing and using sensitive information, and then forget to install the necessary security features. Spoofing unprotected mobile devices allows people with malicious intent to access the data stored on the computer.

The purpose of systems, networks, and severs fortification is to preserve applications and gadgets benign from bouts. A scythed program could permit contact to information it is trying to protect from unauthorized access. Security begins at the strategy stage, where every possible risk is looked into, before software or system deployment (Bulgurcu, B., Cavusoglu, H., & Benbasat, I 2010: Caldwell, T. 2013: Barnum, S. 2012: Chan, H., & Mubarak, S. 2012). Data integrity and confidentiality are safeguarded by data fortification at both preservations and in service. In operation security, all procedures and decision-making processes are carefully thought of to come with practical ways of managing and maintaining information assets. Also, it involved the process of deciding data and location storage, as well exchanging, accessing, and approving user authentication when connected to the servers and networks (Beuran et al., 2016: Parrish et al., 2018).

Catastrophe retrieval and corporate endurance are rapports employed in defining how a corporation responds in the occasion of a security breach or an occurrence that consequences in the forfeiture of operations or data. Catastrophe retrieval policies describe how an entity restores procedures and information to the equivalent functioning ability as previously before the tragedy. Commercial steadiness is the plan that a corporation habits when incapable of functioning due to a deficiency of resources. End-user edification tackles the utmost unpredictably erratic facets of cyber-security: entities. By failure to trail proper safety protocols, anybody can involuntarily inject a virus into an otherwise benign computer or system. It is critical for any establishment's security to explain to handlers how to eradicate unauthorized unsolicited emails, not insert unexplained USB devices, and a variety of other valued instructions (Bada et al., 2019).

Any company is vulnerable to a cyber-attack. Cyber-attacks on businesses cost the United Kingdom economy more than £10 billion in 2017, with seven out of ten enterprises being victims of a cyber-attack or hack. In the event of a Chief Executive Officer facing a cyber-attack or data leak, he or she becomes concerned with their technology's weaknesses, and they fail to consider the people who use such systems every day - their staff. More than 90% of cyber-attacks can be sketched back to human fault, according to the 2017 Data Breach Investigations Study, implying that human error both inductees and intensifies the menace of cyber-crime and the harm it causes to productions. The most effective technique for corporate executives, CEOs, and directors to battle this danger is to develop a risk-aware office ethos, which begins with cyber security consciousness.

Cyber safety consciousness is defined as the familiarity and accomplishment taken to guard a corporation's info resources. As employees at a company are cyber protection cognisant, it implies they comprehend what cyber intimidations are, the probable outcomes a cyber-attack could have on their establishment, and the procedures required to alleviate hazards and prevent cyber-crime from discerning their online workshop. Generating a philosophy of cyber safety cognizance in the workroom does not guarantee that the company will be entirely free of the threat of information theft and leakage. Malware has increased, and it is becoming more erudite with each new-fangled strand created, and we assume cyber-threats and malware to continue to evolve and spread. Every day in 2005, 123 new malware strains were discovered, according to reports. Ten thousand of those attacks were new malware strains during that year. In Q3 of 2016, research revealed that four new strainings of malicious malware were revealed every second - it's important to note that these were the tensions that cyber security companies had announced and reported. As new-fangled malware strains emerge, businesses must guarantee that they are applying the necessary safety procedures, training their staff, and mitigating any vulnerabilities that could make them exposed to an attack. Social error is a heinous crime that can result in hefty penalties and irreparable harm to a company's reputation.

Cyber security

Cyber security protects networked systems, such as files, applications, and hardware, from cyber criminals. Companies and individuals use it to shield their data and operating systems from unwanted entry. Malware protection: Hackers inject different forms of malware into the device in order to steal all of the data and documents. Preventative steps such as Fortinet's FortiGate Firewall will help to escape ransomware and keep data safe in the workplace. Antivirus software, which cleans the device by deleting viruses, can be used for routine testing and bug fixes. Users should restrict their access to information and material in the community sphere to protect their data from malware and spyware (William, 2018).

Large companies toil on their web pages, and if the databases or sites are compromised, they will be shut down, resulting in the loss of records, revenue, resources, and confidence. As a result, cyber protection aids in the prevention of data breaches and the efficiency of workers. It also helps increase total efficiency by safeguarding information and optimizing market performance.

Internet of things

The Internet of Things (IoT) is a network of organized automatic, alphanumeric, and computation devices that use specific identifiers to transfer data and information to the network without the need for human-computer interaction (Morgan, 2019). Through linking various users, objects, and ecosystems and developing the company's overall operations, the Internet of Things adds significant value to businesses.

Improves productivity: By integrating IoT data, Artificial Intelligence, and machine learning together, IoT assists in tracking and managing business operations, allowing for the optimization of different operating practices and thereby increasing productivity and job performance (Andrew, 2019).

Predictive Analysis: IoT's innovative tools aid in analyzing repeating patterns in vast amounts of data, which leads to predictive analysis, which is mainly used for maintenance purposes. The data collected would aid in the improvement of customer services and other procedures. It also aids in developing new goods and services by using data gathered by IoT devices, assessing consumer preferences, and preparing accordingly, resulting in the creation of new revenue sources for a company.

Typical response: The Internet of Things (IoT) allows for real-time and remote control of devices. It vastly improves the efficiency of maintenance interventions and gives businesses an edge in tracking demand trends (Reed, 2019).

Lowers human errors: The Internet of Things incorporates artificial intelligence, which reduces human errors that may occur as a result of job stress or repetitive activities. The Internet of Things (IoT) assists businesses in making more informed decisions and boosting their overall results. Furthermore, in a dynamic environment, it has strategic advantages.

Opens up new possibilities: IoT aids in collecting network data, which can then be used for applied analytics and the discovery of new industry insights and opportunities. By handling physical items such as sensors and mobile devices also lowers operating costs and increases monitoring behavior (Siemen, 2019).

Cyber Security Attributes

In today's world, the importance of information security is paramount for virtually any organization (Wells et al., 2014). In the past, information was guarded, but in recent years, different organizations have accessed specialized encryption technologies from other countries or organizations (Von Solms and Van Niekerk, 2013). However, three characteristics of Cyber Security can make it unlikely (Gordon and Loeb, 2006). First, information security is the gathering of influences, to which most organizations are applied varies from other organizations (Kumar, 2003).

Srivastava and Lazarevic (2006; Srivastava and Lazarevic (2006)). The level of information protection given to the environment in which business is conducted and the geographic location and type of information management systems used by the company. They are putting together (Wells et al., 2014). Second, Cyber Security affects any aspect of an organization's behavioral and systemic factors (De Borchgrave et al., 2001). They are owing to insufficient compliance procedures, which forecast identity theft incidents (Choo, 2011). Finally, any person, whether a member of management, an employee or even an employer, is a part of this Cyber Security scheme (Gordon and Loeb, 2006).

The cyber-magnitude threat's

The worldwide cyber menace is hastily sprouting, with a growing numeral of data fissures every year. According to Risk Based Security, “data fissures exposed 7.9 billion information throughout the first nine months of 2019. This is far extra than duple (112%) the volume of credentials uncovered in the same period the previous year (Bijlsma et al., 2020).

The utmost outbreaks befell the medical care, retail, and government divisions, with malevolent hackers’ presence responsible for most of the incidents. Subsequently, they collect financial and medical information. Some of these businesses are more striking to cybercriminals, but any corporation that uses systems and networks can be targeted for customer data, business espionage, or client threats (Sobiesk et al., 2020).

“The International Data Corporation approximates that global expenditure on computer safety resolutions will hit a monstrous $133.7 billion by 2022, as the size of the cyber challenge continues to rise. Policymakers worldwide have delivered guidelines to support industries in advance appropriate cyber-security policies to counter attacks to the increasing cyber threats (Bijlsma and Rutledge,2020: Moşteanu, 2020).

The National Institute of Standards and Technology (NIST) in the United States has placed a cyber-security system. The system advises constant, authentic surveillance of all computing infrastructure to counteract the spread of malicious code and help in early detection (Švábenský et al., 2020).

The value of device monitoring is echoed in the United Kingdom government's National Cyber Security Centre's "10 measures to cybersecurity" guidance. The Australian Cyber Security Centre (ACSC) publishes advice on how organizations should regularly combat cyber-security threats in Australia (Rahman et al., 2020).

In terms of cyber security threats, what is the relationship between mobile devices and PCs?

Computer viruses are a significant effect of cyber vulnerability on many electronic devices, so the study must concentrate on them. Computer bugs have been described as potentially harmful threats in a commercial computer environment, according to Faiz and Maqsood (2009). In addition to crashed mail servers, malicious applications can manipulate users' private information. Fight, trapdoors, passcode capturer, Lucidity Tripwire, Bacteria, Trojan horses, and network worms are all potential threats to the data kept on these mobile gadgets. Since the new architectures of mobile devices are identical to those of PCs, they are vulnerable to cyber-attacks. They have data analysis capabilities, spreadsheet editors, text editors, and operating systems, among other things. Due to their ability to bind to the internet, users of mobile devices can also share files that are quickly executed. Mobile e-commerce and other exciting possibilities have been made possible by modern wireless technology (online financial transactions). There have been instances of personal details being exchanged while making an online transaction. As a result, in these types of mobile device deliverables, protection becomes the most significant consideration. Identifying the relationship between the latest cohort of apps for smartphones, the internet, and cloud computing is critical throughout the study. (Al Haddad., et al. 2012) state that current and expanded security risks, as well as a new wave of malicious apps, accompany the increased use of digital technology malware (Al Haddad et al., 2012) investigated the complications of being exposed to nasty malware in popular app environments such as Google Chrome, Mozilla Firefox, Google search Engine application, Facebook, Google Android, and Apple iOS. The academicians performed a proof-of-concept analysis to explain how cell phones have raised cyber security problems. They created malicious programs that stole personal information from mobile users, for example. Confidential Credit card information passcodes and other online credentials can all be accessed by hacking Gmail accounts. Much of this makes it easier to obtain keywords for sensitive accounts like internet banking purchase credentials, making cyber threats more likely.

Mobile Devices in Overabundance and the Network Intrusions They Pose

The proliferation of various and inexpensive mobile applications should also be considered when determining how cyber threats affect mobile devices. According to Lu (2013), unwary consumers of mobile gadgets guilty because they are the scrawniest link in the cyber-security shackle. This is because they unwittingly aid in propagating incoming threats, thwarting attempts to maintain stable networks and systems. Long says that ordinary users of mobile-device platforms should not be held responsible because they cannot foresee the safety consequences of their conduct, such as installing apps, uploading content to their phones, and blindly visiting websites. To combat cyber-attacks, a focus on protecting networks and applications should be placed on removing or reducing instances where consumers of mobile devices unwittingly propel external attacks and exploits. The platform of online browsing has expanded exponentially due to the higher consumer development of mobile computing as a result of the launch of smartphone apps. There has also been a rise in the number of dominant threats, such as ransomware. In the World Wide Web, infections continue to spread. Higher numbers of cyber threats have also been attributed to rogue websites and drive-by downloads. The explanations for the increased cyber security risks associated with introducing tablets and smartphones should also be investigated in this study. According to Palmer (2014), cyber protection threats are amplified as mobile gadgets are crammed with transferred applications and paraphernalia. According to a survey undertaken by Cenzic (an organization based in the United States that provides application safety intelligence), 96 percent of downloadable applications contain a middling of fourteen attacks. Augmented cyber security risks might be closely linked to mobile device owners' neglect. Several companies have discovered that existing mobile system use threats are tied to fraudster-created entities (Palmer, 2014). Cyber risks are not the same as the problems that businesses face daily when it comes to technology. As a result, it is significant that the threats are addressed at the board level. Chief executive officers agree that Information Technology agencies are not to fault for the risks that mobile gadgets stance to cyber safety and the business's overall security.

The ever-increasing threat to cyber safety as an outcome of the proliferation of mobile gadgets is a problem that cannot be overlooked. As a result, it's critical to identify the steps that various market actors have taken to help tackle cyber security issues. According to CTIA (nd), the market for mobile devices is at an unprecedented pace. According to market research, mobile sales outnumbered smartphones, notebooks, and desktops for the first time in history. By 2015, more persons (more especially Americans) would be able to access the internet via mobile communications rather than personal computers, according to predictions. With today's high rate of wireless smartphone use in the United States, maintaining protection and privacy for communications and mobile data requires everyone's utmost effort to further the nation's interests in terms of cyber security. Everyone's best benefits are served when addressing the topic of cyber security. When it comes to managing emerging cyber risks, everybody should be included in the response.

User Contribution to Cyber Security Threats on Mobile Devices

It is necessary to examine the advent of a new generation of workers in various organizations worldwide. According to Ruggiero and Foote (2011), the millennium and the Y-generation have reached adulthood and fortify jobs across multiple business settings. This generation has welcomed the introduction of digital technologies, indicating their willingness to use smart devices in official capacities. Employees' handheld devices perform the same functions as their personal computers, necessitating replacing malfunctioning computers with smartphones. To demonstrate the extent of mobile devices' impact on cyber-attacks, it is necessary to regulate the consequences of cyber-attacks on organizations or individuals. Currently, businesses are embracing the use of mobile devices in their day-to-day activities. Tablets, laptops, and other electronic devices are distributed to employees to improve connectivity and knowledge flow between various divisions of the organization or industry. The emphasis of the study will be on the details of why businesses are substituting conventional technology with intelligent mobile applications and tablets. Since companies are looking for new ways to reduce costs, cost savings may be considered. The study would look at the individual and corporate reasons for using personal mobile devices like smartphones in the workplace and the problems that come with them, such as data storage and privacy issues for all stakeholders. Individuals' primary motivations for using personal mobile devices in the office, according to Chigona et al.,2012), is accessibility, accessing emails, and effortlessness of use. Employees now have higher demands for their privacy. Mobile devices, such as smartphones, pose a threat to businesses and organizations' data security. Employees' right to privacy for information stored on their electronic gadgets is also violated. According to Chigona et al. (2012), companies should rethink their employee privacy and data protection practices to address potential conflicts between employee confidentiality and data safety.

Hackers' Exposure to Cyber Security Incidents Caused by the Use of Mobile Devices

The study needs to get a new perspective on how to pact with the effects of cell phones on cyber security. The emergence of smartphone malware has been described as a result of the growing popularity of mobile devices. Attackers target valuable consumer information and take advantage of the flaws of these mobile environments. However, with the rise of ransomware, smartphone app developers have taken steps to create stable mobile platforms that do not pose a hazard to cyber security. Gelenbe et al., 2013) found a scheme developing innovative encryption solutions for boundless service provision in the mobile environment in their research. These systems, also known as NEMESYS, aid in enhancing mobile network defense by gaining a better view of the world of cyber security and threats. The technology is culpable of dealing with cyber safety risks because it collects and analyses info about the characteristics of cyber-attacks aimed against mobile networks and consumers (Gelembe et al., 2012).

The problem of cyber criminals having informal admittance to mobile gadgets is something that this study should look at. According to Wharton University of Pennsylvania (2013), as wireless devices convert more unified into people subsists, they expose them to a greater security risk. For attackers, such machines serve as a point of entry. Furthermore, they have a higher risk of being hacked than personal computers. This is since more users are avoiding or unaware of protecting their tablets and smartphones with antivirus apps.

Similarly, many mobile device users refuse to take basic security measures such as allowing passwords. According to studies, only about half of wireless computer customers use personal identifying records or passcodes on their computers (Wharton University of Pennsylvania, 2013). According to research, this is a much lower proportion as compared to machine usage. Half of those who use their mobile devices to conduct online banking do so without using authentication tools or data protection services. Just one-third of mobile gadget owners engaging in internet purchases or finance have antivirus apps built on their smartphones, likened to 91 percent of laptop possessors who make sure their devices have antivirus and automated updates.

Another area that needs to be further examined is the tactics used by criminals to gain easy access to mobile computer networks. According to some sources, cyber vulnerability is exacerbated by criminals who use both old and modern tactics to access information on unwitting users' devices. As a leading edge of the modern age of cyber technology, smartphones can be quickly exploited from a distance of multiple meters without having to see the system itself. In the Wall Street Journal, Yadron (2014) reported that a spiteful person (the name was withdrawn) is accomplished of taking control of a mobile gadget—a smartphone—from thirty feet away without having to notify the phone provider or the owner. The explanation for this point is simple: the security of individual digital helpers and smartphones has not been up to par with conventional computer safety systems. High-tech security measures such as encoding, antivirus, and firewalls are not usual on mobile computer operating systems and mobile phones. Furthermore, the operating systems do not get the regular updates that are characteristic of home and office computers.

The COVID-19 disease has had a significant effect on improvement, resulting in an unexpected increase in inaccessible and online education. While the transformation has compelled numerous institutes to adopt creative technologies, it has also exposed severe flaws in their cybersecurity policies, particularly worrying that institutions have developed a new priority for cyber offenders.

One major issue is that cybersecurity has never been a top priority in education, long before the pandemic. Schools have simple machine set-up bugs or left old problems unpatched due to a shortage of resources and qualified staff. These disparities can now be much more detrimental due to the mass digital movement, and learning institutions are rapidly finding that they necessitate the expertise and upgraded technical resources to endure virtual erudition in the long run safely. According to Won, Ok-Ran, Chulyun, and Jungmin (2011), fraudsters are gradually targeting people who use educational institution networks since they are mostly accessible. They take advantage of security vulnerabilities in these networks and use malicious software such as ransomware to initiate attacks. Human errors put most educational institutions, including those that use distance learning and eLearning, at risk. This weakness is exacerbated by the rapid adoption of Internet of Things (IoT) technologies in mobile education and connected gadgets. Users are gradually accessing educational material from their institutions' repositories, even without implementing the proper protocol. The focus on cyber-attacks is mostly on corporations, which overlooks that education and healthcare facilities are still vulnerable.

According to Elliot (2010), cyber-attacks are also a concern in the teaching and health care sectors, where they jeopardize the confidentiality and honor of rational possessions and enduring and apprentice data. On the other hand, these agencies are the feeblest link in the cybercrime chain; they make it easy for hackers to steal confidential records, financial data, intellectual property, and communal safety statistics. According to Quirolgico et al. (2015), Mobile applications face significant security risks because they can include technical flaws that allow for attacks. According to Elhai & Hall (2016) and McGuire & Dowlin (2013), cyber-attacks can take several types. For example, malicious software intended to steal intellectual property or user identities is one type of cyber threat. When the network's AUP is old or non-existent, according to Doherty et al. (2011), websites can collect personal data, including bank account passwords. Liang and Xue (2010) summarize how security issues in IoT, connected devices, and mobile learning affect the education market. Their perspective is critical in comprehending the gravity of the problem and serves as a foundation for academics who want to dig deeper into the topic.

Different types of cyber-threats

Cyber-security counters three types of threats:

1. Cybercrime refers to individuals or organizations that attack networks for monetary benefit or to create havoc.

2. Ideologically biased data collection is common in cyber-attacks.

3. cyberterrorism aims to trigger panic or fear by undermining electronic networks.

Ways on how criminals gain access to computer systems and networks.

Malware

Malware denotes malicious software or program. Malware is a program coded by a cybercriminal or hacker to incapacitate or extinguish a genuine remote account. Malware is a common and popular security menace. Malware, which is frequently disseminated over an uninvited encrypted file or a valid download, can be employed by malicious cybercriminals to earn cash or in diplomatically obsessed cyber-attacks (Švábenský et al., 2020).

Malware comes in a variety of shapes and sizes, including:

Virus: A self-replicating code that infects files with malicious code after attaching itself to a new file and spreading within a personal computer.

Trojans

Trojans are a form of malware that masquerades as a legitimate program. Users are duped into downloading Trojans onto their computers, which then cause harm or collect data.

spyware

Spyware is a type of software that remotely monitors what a recipient does so that fraudsters can leverage it. Spyware, for example, may capture account information or even credit card data.

Ransomware

Ransomware is a form of malware that encodes a user's documents and data and threatens to delete it unless a ransom is charged.

Adware is a form of marketing software that can be employed in the distribution of malware.

Botnets are malware-infected communication networks that malicious hackers use to execute criminal activities online without the user's consent.

Injection of SQL

Structured language query intrusion is a form of cybercrime that permits a hacker to assume control of an information database and steal data. Using a malicious SQL statement, cybercriminals manipulate vulnerabilities in data-driven applications to inject malicious code into a database. This provides them with access to the database's confidential details (Bijlsma et al., 2020).

Phishing

When attackers send emails that seem to be from a genuine company asking for classified material, this is known as phishing. Phishing activities are frequently employed to deceive victims into disclosing confidential data such as credit card numbers and passcodes (Švábenský et al., 2020).

Spear-phishing is a phishing outbreak that uses a malicious email spoofing attack to access apps by downloading malicious malware via an attachment. The perpetrators aim to obtain unauthorized access to confidential information by targeting particular organizations or individuals. If the recipient of the email opens the file, malware is transferred to a user’s device. This allows cyber criminals to access the organization's software, allowing them to travel laterally to pursue confidential and valuable data. It's rare for spear-phishing trials to be launched by arbitrary cyber criminals with no specific target in mind; instead, they're more expected to be carried out by fraudsters looking for monetary gain, business confidence, or confidential details.

Although spear-phishing can appear to be a simple act, it has evolved in recent ages, becoming tremendously problematic to distinguish - mainly if no prior awareness or spear-phishing security application is in place. The personal information that victims post on the internet is used to harass them. A worker’s mail address, preferences, work title, topographical position, and any posts about innovative items they've recently acquired, for example, could all be found on their online accounts and could be accessed by a hacker. With all of this data, the criminals impersonate an acquaintance or a conversant entity and direct their aim to a powerful yet deceptive and hateful message. Victims have been queried to open a mean addon or attach on a connection that revenues them to a hoaxed web page where they are requested to key in passcodes, Bank account detail as on their credits, PINs, and access codes in some cases.

A threat by a man-in-the-middle

A man-in-the-middle attack is a safety threat in which a hacker hijacks correspondence between two people in an attempt to decrypt messages. For instance, an intruder might seize data passing between the target's computer and the system on an unsafe Wireless connection.

A denial-of-service (DoS)

Denial-of-service event befalls when scammers deluge a computer system's network servers with traffic, segregating the computer from executing authentic traffic. This fails the computers, barring an organization from executing critical responsibilities (Švábenský et al., 2020).

Most recent cyber-threats

over the last decade, several cyber-attacks have happened. that is, in government institutions and even companies. some of them include.

Dridex

The leader of an orchestrated computer crimes organization was prosecuted in December 2019 by the united states Department of Justice (DoJ) for his involvement in an international Dridex data breach. This disruptive operation had a global impact on the public, governance, economy, and corporation. Dridex is an economic trojan that can do a lot of things. It has been corrupting devices since 2014, afflicting them via phishing emails or established viruses. It has triggered significant financial losses totaling tens of millions of dollars by obtaining passwords, banking records, and user information to be used in unauthorized charges (Crumpler, W., & Lewis, J. A. (2019). 

The National Cyber Security Centre in the UK advises the public to "ensure computers are patched, anti-virus is switched on and up to date, and data are backed up" in response to the Dridex attacks (Švábenský et al., 2020).

Scams encompassing romance.

In February 2020, the Federal Bureau of Investigation issued an alert to Americans about loyalty fraud committed by fraudsters through online dating, social networking, and applications. Victims are duped into giving away personal information by attackers who prey on people looking for new mates. According to the FBI, dating cyber threats impacted 114 people in New Mexico in 2019, resulting in $1.6 million in losses (Lallie et al., 2021).

Emotet

The Australian Cyber Security Centre issued an alert to multilateral agencies in late 2019 about a significant global cyber danger posed by Emotet malware. Emotet is a versatile trojan that has the effect of disadvantaging data as well as deploy another ransomware. Emotet flourishes on simple passwords, which reinforces the benefit of maintaining a safe password to safeguard from computer hackers (Rahman et al., 2020).

Equifax

The Equifax cybercrime distinctiveness fraud incident distressed about 140 million Americans and 400,000-44 million Britons and 19,000 Canadians. Equifax's stock fell thirteen percent indirect exchange the day after the hack, and the company was hit with a slew of litigation as an outcome of it. Not to mention the harm is done to Equifax's credibility. Equifax and the Federal Trade Commission reached an agreement on July 22nd, 2019, encompassing a more than $250 million endowment for victim reimbursement, $175 million for states and terrains, and $100 million in penalties.

eBay

eBay suffered data in 2014 involving encrypted passwords, forcing all of its more the$140 million users to recalibrate their passcodes. To advance admittance to this treasure trove of client’s information, the invaders employed a limited collection of workers' authorizations. Coded keywords and other personally identifiable information, such as credentials, e-mail credentials, physical location addresses, mobile and home phone numbers, birth details, were among the data taken. Following a month-long inquiry by eBay, the violation was made public in May 2014.

Adult Friend Finder

In October 2016, cyber criminals gained access to six databases containing 20 years of data for The FriendFinder Network, including names, email addresses, and passwords. “Adult Friend Finder, Penthouse, Cams, iCams, and Stripshow are among the websites in the FriendFinder Network. The feeble SHA-1 shredding algorithm was used to encrypt the majority of the passwords, which meant that a good percent of them had been fragmented by the time the LeakedSource website released its assessment of the complete information set on November 14.

Yahoo

A group of hackers passed Yahoo’s firewall in August 2013, tampering over half a million accounts. The company also said that Safety queries and ripostes were also compromised in this case, posing amplified jeopardy of identity hold-up. Yahoo first announced the break on December 14, 2016. All pretentious clients were forced to update their passcodes and re-enter any unencrypted safety queries and answers to make them encoded in forthcoming unforeseen events. By October of 2017, however, Yahoo had revised its approximation to 3 billion accounts. According to an investigation, the plain text passwords, payment card records, and bank details of users were not stolen. Nonetheless, this is one of the most significant data breaches in history.

Importance of cybersecurity education

The worthiness of cybersecurity is increasing. Patently, the world is more advanced technologically, and this expansion demonstrates no signs of deceleration. Security breakages that can lead to capturing and identifying cyber criminals and hackers are now being paraded online. Social security credentials, credit card data, and banking records are directly deposited in cloud servers such as Dropbox, Google Drive, and one drive (McCormac et al., 2017).

From a personal perspective, or a small corporation, or a big corporation, one relies on software applications in executing daily tasks. When one combines this with the spread of cloud computing, insecure cloud computing, smartphones, and the Internet of Things (IoT), one has a slew of latent fears that were not in the picture generations earlier. Even though the expertise is becoming more comparable, we must comprehend the difference between cybersecurity and data assurance (Kim, N., & Lee, S. 2018).

All people are vulnerable.

Cyberattacks are now so frequent that a device in the United States is hacked every 39 seconds! Millions of citizens may be injured if an attack occurs. State-run institutions may be stopped, and residents may be denied services. Atlanta, for example, was targeted by the notorious SamSam ransomware. The criminals demanded $51,000 in ransom. The SamSam ransomware was so dangerous that it knocked Atlanta off the grid for five days. Several major citywide activities were suspended as a result of this. It ended up costing $17 million to rebound. Every day, ransomware is used to infiltrate over 4000 enterprises (Lallie et al., 2021).

Hackers can infiltrate government agencies on a worldwide platform, resulting in cyber espionage. The National Cyber Security Centre (NCSC) has issued a warning to companies and communities worldwide that Russia is attempting to hack communications organization gadgets like routers. The purpose is to set the stage for potential occurrences on the vital structure, including power plants and energy grids Crumpler, W., & Lewis, J. A. (2019). 

It is a menace that nuclear power plants might be threatened, resulting in a fissile catastrophe that would kill millions of people. Stuxnet, a Stuxnet worm, targeted one of Iran's nuclear facilities, destroying one-fifth of the country's atomic strainers. These digital viruses triggered ballistic missiles to overheat, potentially leading to an explosion that ravaged humanity (Bijlsma et al., 2020).

Broadband access at a higher speed.

Through the introduction of the 5G network. “5G networks thus establish a massively extended, multifaceted cyberespionage vulnerability,” according to The Brookings Institute. The recalibrated nature of modern networks "ecosystem of ecosystems” necessitates a significantly reinterpreted cyber strategy,” it has to be noted that with the rise in program cybersecurity incidents, retooling how corporations protect the most normative stakeholder of the twenty-first century will be difficult (Lallie et al., 2021).

Effective cyberattack technologies that can optimize the attempt.

The introduction of new technologies, for instance, the Internet of Things (IoT), is increasingly rising digitization. It is estimated that, by the end of 2020, there were more than 200 billion connected devices all over the world. This has paved the way for Hackers to employ artificial intelligence (AI) and machine learning to introduce computerized cyberattacks that can effortlessly breach protected networks without the need for interaction and intervention by any human, whereas cyberwarriors are improving their skills. These computerized cybercrimes are a worldwide concern, for they can be executed in large numbers Crumpler, W., & Lewis, J. A. (2019). 

Cloud computing can be used more often.

According to Catalyst's new global market report, cybersecurity strategies for communal cloud and "as a service" intensified in the first quarter of 2019. Year over year, those deployment models increased by 46 percent. As agencies increase their use of cloud computing, the GAO finds cyber threats. The Office of Management and Budget (OMB) needs federal agencies to collaborate with the Federal Risk and Authorization Management Program (FedRAMP) to approve their use of cloud computing technology (Taylor-Jackson et al., 2020).

Business destruction and job losses

In recent years, there has been an upsurge in the number of attacks and breaches involving well-known brands. It costs hundreds of thousands of dollars in damages and fines to recover the data. Due to the corporation's cost-cutting efforts, not only C-level officials but also associates could lose their jobs due to these losses (Bada et al., 2020).

Over $540 million usage data were revealed to Amazon's cloud storage service by Facebook, the social media behemoth.

Equifax, a multinational credit reporting service, agonized a massive data breakage that wedged $147 million consumers. The cost of repairing the damage caused by the hack was recently reported to be $439 million (Bijlsma et al., 2020). A cyber-attack at First American Organization leaked $885 million documents, including bank account details, social security information, wired transactions, and loan details.

The NHS in the United Kingdom was briefly plunged into chaos by rudimentary ransomware, culminating in suspended procedures and high clean-up costs. Yahoo, the internet monstrosity, was hacked. This affected every single account of its more than three billion users. The security breach cost the company more than $300 million in direct costs (McGettrick, A. (2013).

A new venture

The education sector is particularly appealing to cyber criminals due to a large amount of data. It contains personnel and learners’ information, ex-students databases, supplier information, and academic data – all of which are highly useful. Cybercriminals are also aware that as schools adopt digitalization, they will have many ways to take advantage of the change, as many schools do use outdated technologies that are not designed to handle new, advanced attacks. In particular, the United Kingdom National Cybersecurity Core released a clear alert round the increased numerals of ransomware occurrences targeted at universities during the pandemic. These attackers intercept or erase data from users' systems before making the device or computer unavailable and seeking monetary payments in exchange for access and data. Remote Desktop Protocol (RDP), insecure applications and computer hardware (characteristically from third-party merchants), and phishing emails that hoax users into exchanging confidential data are presently some of the most common ransomware intrusion vectors.

Another problem is that students are constantly connecting to school networks using personal computers, which are more likely to breach systems because they provide many entry points for hackers to exploit. Since personal computers sometimes do not comply with system protocols and safeguards, whole networks may become insecure.

Internet of things and cyber security

Many scholars have recently researched how to protect Internet of Things systems against growing cyber fears. They've shown up in a variety of places. This part of the literature review offers an outline of recent studies in IoT defense in the face of rising cyber-attacks. Long Chen suggested a methodology he called "the Layered-security control architecture" in his dissertation "Security management for the Internet of Things," published in 2017. This method aims to give you a better understanding of how to secure your IoT devices. It also recommends that a solid security monitoring system be put in place. Four layers are present in the proposed structure. According to Long Chen, various security functions are required at different levels, so a layer of security should be developed. Each layer has its own set of features, and the functionality of each is chosen following pre-existing protocols. Layers should provide borders to ensure that data flows as efficiently as possible between device edges. The number of deposits defined should correspond to the deposits of the Internet of Things classifications in such a technique that distinct protection roles are not reputable in the same layer of the Internet of Things system (Chen, 2017)

Iqbal et al. (2017) investigate the causes of poor safety requirements and provide recommendations for resolving IoT systems issues. They offer excellent guidance for developers who want to create more secure IoT systems. Three main restrictions distinguish IoT systems from conventional computation, according to the authors. They divide these limits into three categories: bandwidth, transmission, and power use. After that, the paper moves on to identifying alternatives to the established Internet of Things problems. Cooper (2015) investigated potential protocols for IoT devices and performed studies on protection status in the IoT. His paper emphasized the importance of three technologies: radio frequency identification (RFID), internet protocol version six (IPv6), and wireless sensor networks (WSN). Besides, the research examines connectivity protocols and suggests alternatives to authentication safety problems.

There has been extensive literature on secrecy, honesty, authenticity, and non-repudiation, according to Cooper (2015). Furthermore, the authors contend that there are appropriate solutions to alleviate security concerns with these modules. More research is required, however, to develop advanced cryptographic measures that are both effective and efficient. Lisa Goeke's paper "Internet of Things Security Issues" discusses approaches to protect IoTs as well as security challenges that should be addressed. “Wireless Sensor Networks (WSN), Near-Field Communication (NFC), and Radio Frequency Identification (RFID) are among the IoT components discussed in this article (RFID).” Basic RFID tags, according to the author, are insufficient in stopping assailants from siphoning information from a label and exposing its data while it is running. The author argues that terminating the tag will solve these types of security issues. She claims that NFS is vulnerable to the same kinds of threats that supplementary related wireless technologies face, such as denial-of-service attacks and data injection spying. Data will, nevertheless, be safely transmitted by using a secure connection. Cryptography and authentication can aid in securing NFC and RFID apparatuses from severe outbreaks; nonetheless, they cannot be used to protect Wireless sensor networks (Goeke, 2017).

The Interface, conferring Jonckers (2016) in their research "A security framework for IoTs in a smart home setting," can be employed to improve the safety and safety of IoT users. He correspondingly discusses how to build the gateway building and integrate authorization, anonymity, substantiation, and concealment policy. The research also highlights procedure definition terminology, which allows users to specify specifications for their contact channels and devices, especially when using machines or networks outside of the residential. The interface model aids designers in the creation of IoT security systems.

According to Gao et al. (2012), connectivity protocols should be developed specifically for RFID systems. Names, RFID middleware, and readers can all be included in the protocols. Electronic product codes should be unique for each object. Besides, the authors suggested an SPAP protocol with XOR, a single-way hash purpose, and proportional encryption. Implementing self-managed defense cells (SMSC), according to De Leusse et al. (2009, June), is a strategy that consists of some components aimed at improving decentralization, contextualization, automation, and interoperability.

According to Renu (2022), electronics can be protected using a technique that employs radio frequency recognition. Tools that allow contact have frequency identifications built in. This method, however, does not guarantee data security. Mattias, Gebie, and Habtamu (2017) supported risk-grounded substantiation and adaptive verification strategies in their paper "Risk-Based Adaptive Authentication of IoT in Smart Home eHealth." Adaptive authentication is a security mechanism that dynamically changes its actions depending on the current situation—this aids in protecting the machine against a variety of attacks. The technique constantly tracks the environment, analyses the conditions in the background, and adapts strategies as required to protect against unknown risks. The method employs nave Bayes machine learning algorithms to categorize numerous channel variations among sensor nodes and gateways.

Homeland security is also investigating how to improve safety in this region. The division highlights concepts that can be applied to strengthen IoT defense from conception to implementation in its paper "Strategic Principles for Securing IoT." According to the Department, these standards can be tailored and implemented by risk-based techniques that take into account the nature of each sector and the particular risks and impacts that can arise from circumstances involving network-connected devices, networks, or structures. The guidelines include integrating security elements at the design stage, using modern operating systems to strategize IoT systems, and incorporating specific names and passwords by default (The U.S. Department of Homeland, 2016, November).

As the Internet of Things (IoT) grows in popularity, it can become more embedded into people's everyday lives. The Internet of Things (IoT) will now become an essential part of national infrastructure. As a result, it is vital to protect it. Integrity, secrecy, authenticity, non-repudiation, and utility elements of information can all be considered when securing IoT. Information's robustness, durability, security, survivability, and reliability should also be taken into account. In the IoT, which comprises complex cyber-physical networks, it's imperative to understand both of these elements (McGuire & Dowlin (2013).

Cybersecurity is crucial right now more than ever because of vulnerabilities incurred by many.

Not only are countries and companies at risk from attackers' acts and motives, but persons are also in danger. Data breaches, in which criminals obtain an individual's private data and convert it for profits, are a significant problem.

This often jeopardizes an individual's and his or her family's protection. This has occurred on many occasions, costing the victim millions of dollars. In other cases, after stealing their identity, hackers use bribery and extortion to claim hostage cash in exchange for not taking any extra action. This is remarkably accurate in cases of high-profile distinctiveness hold-ups involving superstars or high-net-worth individuals. Cybercriminals have targeted home security cameras like the Ring, invading other user privacy. This raises serious privacy issues, as attackers can communicate with people who live inside the house and ask for ransom (Rahman et al., 2020).

Smart cities, smart devices, intelligent houses, and many other applications depend on the Internet of Things. Despite this, there are a few cyber security issues for IoT, one of the primary problems for consumers. Many smart devices and computers have been hacked in recent years, putting consumers' and organizations' confidence in jeopardy.

Out-of-date applications and hardware: As IoT technologies grow, vendors are focusing more on designing innovative gadgets and less on protecting these gadgets (Abomhara & Kien, 2015). When using the devices, they get little to no updates, and they become exposed to attack as quickly as the perpetrator discovers vulnerabilities and safety flaws. Companies and customers are also vulnerable to cyber-attacks and data breaches where security and hardware problems are not addressed by proper updates (Luis, 2018).

Using default or poor passwords: When marketing their goods, most businesses have default credentials such as an admin username. It is simple to crack the system's default username and passwords and then use a brute-force bout to infect the gadget. The Mirai Botnet assault is the most substantial illustration of cyber-attacks occurring when computers were configured with default passwords.

Malware and ransomware: Through the exponential propagation of Internet of Things (IoT) gadgets worldwide, it is becoming more challenging to anticipate cyber-attacks. Users' computers are being locked by cybercriminals using a variety of technologies. Hackers attempt to encrypt the system, preventing users from accessing sensitive data and information stored on their computers. They can demand a large sum of money from users in exchange for unlocking their devices and recovering their data, resulting in ransomware (Crinon, 2017).

Attacks that are difficult to predict: It is not only necessary to detect flaws to protect computers from cyber-attacks, but it is also necessary to anticipate and address future threats in advance. Defending connected computers from cyber threats is a long-term problem. For forecasting and addressing potential cyber-attacks, cloud providers employ strategies such as AI-powered analytics and surveillance tools, as well as threat intelligence. Adopting these tools for IoT is problematic since the machines attached to them would necessitate regular data analysis.

Challenges in data privacy and security: The whole planet is becoming more interconnected, making it more impossible to secure data on the network as it is transmitted to other users in a matter of seconds. The data is stored on the user's phone one minute, then downloaded to the internet the next, and finally to the cloud in a matter of seconds. Since all networks are insecure and hackers can easily access them, this data transfer can result in a data leak, resulting in a breach of the right to data protection and privacy (Kinker, 2019).

Home security: Many IoT devices and networking occur in today's homes and offices, such as IoT devices, which infrastructure developers commonly use to power apartments. Not everyone is aware of the cyber risks that occur in IoT linked devices, such as IP addresses being compromised, allowing hackers to gain access to users' residential addresses and personal information, which can be used for malicious purposes, posing a risk to smart homes (Watson, 2019).

Different scenarios

From the previous century, technology has advanced tremendously. Australians are affected by the growth in both positive and negative ways. Smartphones, notebook computers, watches, and tablets, for example, can be helpful in daily life. On the other hand, some children are unaware of some of the responsibilities or risks connected with such gadgets. The problem of cyber safety is not new-fangled; it has been evolving for more than five decades. For example, in 1968, West Germany detained an East German infiltrator who had planned to obtain material from the Western correspondence using IBM (Kahn, 2014). Equally, high school learners were hampered after gaining entree to unorganized military systems, according to reports. Cyber safety is more than a technical problem; it is a complex topic that involves states and governments. The literature review will focus on cyber-crime principles that are relevant to current academic debates. The idea of cyber security is linked to the broader concept of cybercrime. Scholars have classified cyber security into many categories, each with its own set of consequences for children and adults.

According to Dunn-Cavelty (2010), cyber-crime is the ability of a person or organization to access information illegally through the use of cyberspace. Keeping the network safe, in this case, necessitates the application of both technical and nontechnical activities. Cybersecurity, according to Dunn-concepts, Cavelty's isn't just a technological concern, as some researchers have stated in previous studies. Cybersecurity is a complicated topic that necessitates a more comprehensive discussion. Cybersecurity is recognized by Australia's national security as a concern for knowledge that poses a danger to the economy. According to Australia's national security, cybersecurity programs secure people, organizations, and organizations from computer interference and disseminating malicious code by organized crime. The organization also recognizes cybersecurity as a blurring of the lines between threat sources such as organized crime networks, hackers, and spies on industrial sites. As a result, the body asserted Dunn-argument Cavelty that cybersecurity encompasses three interconnected cybersecurity discourses. Technical debate, in this case, refers to issues involving viruses, worms, and other bugs. The term "cyber espionage" relates to issues involving online criminals and digital spies. Military debate, on the other hand, includes cyber conflict and the defense of critical systems.

Cybercrime in Australia: How Common Is It?

In the last decade, the number of people who use the internet has grown. The number of internet users in Australia tripled in 2015, marking the start of a new trend. For example, the number of users in Australia has surpassed 21 million. Fourteen million people have already signed up for Facebook and other social media sites out of the total number of internet users. As a result, as the use of social media becomes more vulnerable, so does the incidence of cybercrime. Cybercrime has spread rapidly among the Australian population because of the internet's widespread use. E-commerce has accelerated the evolution of deep web-based economies due to the transformation of global connectivity (Dunn-Cavelty, 2010). Australian internet users registered over 39491 instances of cybercrime to the Australian Crime Online Reporting Network (ACORN). According to the network, more than 3500 cases of cybercrime were identified to the police in just one month. According to the Australian police, the majority of people who register cyber-crime happenings in Australia are between the ages of 20 and 40. The administration, in particular, has incurred a significant loss as a result of specific countermeasures. However, due to the ever-increasing advances of the internet of things through generations, the massive sums spent will not fix the current issue.

Malware is a form of malicious software that is used by cybercriminals to target computer systems. Viruses, worms, rootkits, and spyware are all examples of malware. For victims, uninstalling and repairing the device is costly. Malware detects flaws in a computer network and takes advantage of them. The program can also be downloaded from an email or a website by the victim. Malware can also be used to shut down a computer device by catching and modifying the access credentials. After gaining entree to the mainframe system, the hackers may employ the program to remove data, infected vitals files, or gain admittance to personal information. The Melissa viruses, for example, propagate by extension files on websites and emails (Rao & Nayak, 2014). The bugs initially appeared in 1999 and quickly spread all over the globe, infecting millions of computers. While it is illegal to use malware to defraud internet users, not all countries have made the software's development illegal. Some countries have measures in place to deal with issues such as malware and hacking on the internet. Offenders use software that spreads quickly through many computer systems by using extensions.

The most popular form of cybercrime associated with technology is hacking. Hacking refers to users' ability to gain unauthorized access to a mainframe network's network. Cybercriminals are people who have a broad understanding of mainframes, computers, and technological gadgets in general. According to the Australian Institute of Criminology, cybercrime cases are on the rise in Australia. According to the institute, one out of every five Australians has had their details stolen due to cybercrime. According to the institution, at least seven percent of the incidents were registered in 2013. The majority of individuals are unaware of the belligerent behavior before their computer malfunctions. When a device does not have an antivirus, most people believe that the machine is secure due to a lack of warning. When a hacking occurs, the cybercriminal informs the victim that a ransom will be demanded to disclose the access key code. In just 12 months, according to the 2012 commercial victimization survey, 180000 cases of cyber-crime were recorded in businesses.

The proportion of adult internet users has decreased in recent years, allowing children to take their place. Computer malware, on the other hand, is the utmost form of cybercrime identified in Australia. The number of hacking incidents has increased as a result of the launch of new spyware on the market that is designed to steal money from victims (Mc Guire & Dowling 2013). In 2011, over 31% of adult Australian internet users said they had been infected with viruses while using the internet. The authors also say that this year's virus cases are lower than last year's. According to the Centre for Children's Social and Emotional Wellness, the percentage of children and adults who reported infiltration of their online privacy was higher than the proportion who reported the virus. According to figures from 2011, 7% of adult internet users registered unauthorized access to their profiles. However, as compared to the previous year, the figures were two points higher. In 2011, 3% of adults said they had lost money during the last year. Virus and hacking incidents, on the other hand, were not classified as illegal activities in the papers.

Both public and private companies have been hit by hacking and virus attacks. Most cybercrime cases were directed at businesses with large computer networks. In this instance, the hackers transfer a spam email with the malware's leeway attached as an attachment. When a business organization's employee opens the extension, the malware spreads to the rest of the network's computer systems. Accessing the files can cause the computer system to lock up or deny access to the organization's private and critical files. The hacker then sends a pop-up message to the company, alerting them to the potential entry. The business organization could suffer financial losses or the loss of essential information in this situation. In 2012, 12% of business organizations said they had been hacked as a result of cyber-crime. Until an employee reports this type of assault, it can go unnoticed.

The cybersecurity education gap

Because of the skill gap in the cybersecurity world, new challenges have resulted in job roles that the current workforce cannot adequately handle and the increasing demand for tackling cybersecurity predicaments. Also, fresh graduates of cybersecurity are not prepared enough for cybersecurity requirements in different working environments. In most developing countries, inadequate and below-average infrastructure provides a breeding ground for cybercrimes (Rahman et al., 2020).

According to the (ISC)2 2020 Cybersecurity Labour force Report, the estimate of cyber safety experts needed to close the security skills gap has decreased from 4.07 million to 3.12 million. While this is a positive move forward, there is still a significant distance. Data indicates that employment in the sector needs to rise by about 41% in the United States and 89 percent globally (Moşteanu, 2020).

Empowering cybersecurity practitioners to extend their skill sets and continue expanding beyond their current positions is one way for companies to close the skills gap. Organizations should consider Non-traditional applicants who can change careers in a security regardless of their prior experience or history. Both options necessitate ongoing education and professional development (Bijlsma et al., 2020). To help individuals navigate their educational journey from training to careers and help organizations upskill employees to meet changing needs, Fortinet's NSE Training Institute has developed education pathways. These pathways encourage people to traverse their academic career from practice to profession and allow communities to strategize workers to accept evolving requirements.

Cyber security implementation bottlenecks

The essence of technology's rapid evolution is a double-edged sword. Although you might be able to solve complicated issues more quickly, cyber attackers may be able to use modern methods to hack into the infrastructure, steal valuable information, and inflict irreversible harm. You must maintain the security infrastructure daily to secure sensitive data. Many entrepreneurs are inexperienced in the field of cyber security. Many people fail to recognize the fundamentals of internet security and find it difficult to put measures in place to secure data around the enterprise. Companies used to rely on their in-house IT team for tech and hardware upgrades, and they needed them to shield them from any cyber threat. However, with the advancement in technology in the twenty-first century, times have changed. A wide range of operating activities and procedures are effectively streamlined across the cloud, which can or may not result in system vulnerabilities.

As a result of having distinguishing characteristics, different cyber security problems have arisen (Wang et al., 2010). The most important of them all is stakeholder cooperation and coordination at the global level (Von Solms and Von Solms, 2005). As a result, a complete substructure is considered necessary to ensure a coordinated response, knowledge exchange mechanisms, intelligence, and rehabilitation and accountability of multiple departments and governments, and task transparency (Jouini, Rabai, and Aissa, 2014). There has been a dearth of designated sector roles in private-public partnership models (Gordon and Loeb, 2006). At a global level, the lack of globally agreed guidelines presenting cooperation across jurisdictions to hunt down cyber criminals has been creating challenges for law enforcement bodies, resulting in a substantial delay in the successful prosecution of cyber criminals (De Borchgrave et al., 2001). In most countries, there is a lack of adequate preparation and information among law enforcement officers and the courts, which is critical in understanding the reliability of facts provided by cyber forensic professionals and cyber criminals (Wells et al., 2014).

One of the most pressing issues of recent times proved to preserve vital information technology (Gordon and Loeb, 2006). Traditionally, the sole responsibility of the government is vested in the National Security policies (Choo, 2011). In the face of a growing number of hack attempts/cyber-attacks, the current burden of protecting classified information resources has undoubtedly become a matter of national security's purview (O'Connell, 2012). However, this brand-new obligation should not apply only to the government sector (Wells et al., 2014). Furthermore, since the bulk of the owners of confidential information technology setups are privately owned, the private sector must play an important part (Von Solms and Von Solms, 2005).

Nonetheless, private sector spending in the defense sector is motivated by corporate needs rather than national security risks (Gordon and Loeb, 2006). No, is there some way for the government to get involved? Is it better to encourage or manage the private sector? A discussion is taking place to determine which direction countries will take (Wang et al., 2010). Many people believe that business institutions would not deliver the necessary actions and commitments to ensure national security and public safety (Kumar, Srivastava, and Lazarevic, 2006). On the other hand, others believe that expanded government intervention by numerous legislations could undermine company effectiveness (Gordon and Loeb, 2006). We haven't found a satisfactory solution to the dilemma yet.

The ICT Global Supply Chain has emerged as yet another source of concern, owing to nations' over-reliance on ICT products, which has caused them to question their credibility, as they are widely used in the growing realization of cyber risks and in operating critical sectors, with the fear of their adversaries introducing harmful functions/codes to perform secretive scrutiny (De Borchgrave et al., 2001). Attenuating those fears and questions to continue receiving profits/benefits from the ICT chain is regarded as a significant obstacle faced in the cyber world for quite some time. While a few countries are attempting to meet this challenge by developing national and global capabilities that can work to assess supply chain risks in a way that does not jeopardize legitimate trade flows and global competitiveness, the others are concentrating on developing native/local products to reduce over-rating (Gordon and Loeb, 2006) effectively.

Lack of information and expertise of risks faced in cyber security setups and the need to enforce best practices is yet another significant issue that affects anyone from senior government leaders and business executives to school children (Kumar, Srivastava and Lazarevic, 2006). Frequently, using a relaxed attitude results under challenging circumstances. As a result of a lack of understanding and needed skills among various users, danger occurs more regularly (Gordon and Loeb, 2006). Due to a lack of information, one is at risk of becoming a victim of ongoing cyber threats, forgery email correspondence, phishing pages, and other forms of fraud (Von Solms and Von Solms, 2005). Person diligence and sensitivity may potentially prevent a significant portion of these assaults (Jouini, Rabai, and Aissa, 2014). Other tremendous hurdles to addressing cyber security risks at the corporate level include the portrayal of safety as a cost center, the absence of a multi-departmental organized roadmap, the complexity of estimating Return on Investment (ROI) for investment portfolios, and the lack of high-quality product growth (Kumar, Srivastava and Lazarevic, 2006).

Effective technologies for automating controls: Online presence security isn't something that can be done in isolation. You need the right tools to track and manage the security status at any point, from checking the security state of any device to firewalls and routers. You can identify, access, and prioritize threats using automated software.

Integrate tools and assess their performance: When you've put the right resources in place, you can evaluate their usefulness daily to see any flaws in the procedure. For the security infrastructure to run correctly, you must combine all of your software. Cyber security researchers can analyze meaningful information from vast amounts of data with machine learning and data processing aid and use this information to anticipate potential attacks.

Getting staff to follow instructions: One of the most challenging aspects of enforcing cyber protection is ensuring that all employees follow the security codes. To avoid some attack, any association member should learn and obey the specified set of rules regardless of their role. Any minor blunder, such as possessing a private pen drive or sending spam email, will expose the company to unknown threats and render all attempts to secure sensitive data ineffective.

The price is Installing the appropriate tools, actively tracking security conditions, and automating the procedure all necessitate the assistance of a knowledgeable cybersecurity expert. Even if the facilities are expensive, one can still outsource the work and get it done reasonably.

Insufficiently educated personnel: Once you've put the resources in motion, you begin to believe that the company is fully secure and that you'll be safe from future threats. However, no company can be confident that it would be safe from cyber-attacks 100 percent of the time. To detect any vulnerabilities or continuing threats, you'll need well-trained personnel to support the apps and regularly track the security situation.

The Internet of Things underpins intelligent cities, smart devices, smart homes, and a slew of other technologies. Despite this, there are a few data protection concerns with IoT, one of the significant challenges for users. Many mobile devices and machines have been compromised in recent years, jeopardizing the confidence of both customers and businesses.

Applications and hardware that are no longer supported: Vendors are focused increasingly on developing new applications as the adoption of IoT technology increases, rather than securing existing products. When the computers are in use, they get few to no updates, making them vulnerable to attack as soon as a hacker finds bugs and security holes. Technology and hardware issues are not resolved with proper updates, companies and users are vulnerable to cyber-attacks and data breaches.

Using static or insecure passwords: Most companies use default keys, such as an admin username when selling their products. It's easy to infect a computer by cracking the system's default username and passwords and then using a brute-force attack. The Mirai Botnet attack is the most egregious example of cyber-attacks since computers were set up with default passwords.

Ransomware is a type of computerized virus that scrambles files and holds them hostage. It's getting more challenging to anticipate cyber intimidations as the Internet of Things (IoT) gadgets grow exponentially across the planet. Cybercriminals use some different tools to lock users' devices. Hackers want to encrypt the system, making it impossible for users to access confidential data and information stored on their machines. They will demand a tremendous amount of money from users in return for accessing their computers and retrieving their files, which is what ransomware is all about.

Difficult-to-predict attacks include: To secure computers from cyber-attacks, it is not only necessary to find vulnerabilities, but it is also necessary to predict and resolve potential risks ahead of time. The challenge of protecting wired devices from cyber-attacks is a long-term one. Cloud services use AI-powered monitoring and surveillance software and threat intelligence to anticipate and react to possible cyber threats. Even if these methods could be adapted for IoT, it would be not easy since the computers connected to it would necessitate routine data processing.

Data privacy and security challenges include the following: Since the whole world is becoming more distributed, it is becoming more difficult to protect data on the network as it is distributed to other users in seconds. The data is first saved on the user's phone, then transferred to the internet, and eventually uploaded to the cloud in seconds. Since all networks are vulnerable and hackers can easily access them, this data transfer may result in a data leak, resulting in a violation of the right to privacy and data security.

Household safety: In today's homes and businesses, a wide variety of IoT devices and networking can be seen, such as IoT devices, which infrastructure engineers frequently use to power apartments. Not everyone is cognisant of the cyber hazards linked with IoT-connected systems, such as infected IP addresses, which enable hackers to access users' residential addresses and personal information, which can be used for malicious purposes, posing a threat to smart homes.

Cybersecurity criticism

We are now confronted with a critical situation that has turned cybersecurity into an enemy rather than an ally (Choo, 2011). It is currently out of our control, prompting people to question whether the private sector and government value civil liberties (O'Connell, 2012). Both the private sector and the government have been storing vast amounts of data and information outside of their office premises since the development of cloud technologies, leaving them more vulnerable to cyber-attacks ( Solms and Niekerk, 2013). The adversaries can damage the data almost as effectively from inside the enterprise as they can from the outside (Choo, 2011).

Wikileaks, a well-known example of hacking, was made up of classified data from all over the world relating to embassy correspondence and was downloaded and collected by J. Kirk Wiebe, a United States soldier, took a photo that he later spread around the world (De Borchgrave et al., 2001). Second, Edward Snowden, a well-known whistle-blower from NASA, carried out yet another government leak in the United States, in which he was able to gather thousands of categorized files, which were striking from inside NASA, to prove to the world what he was thinking, that other countries' privacy (Riley) and the United States government in citizens were over-reaching in numbers (O'Connell). The rivalry shown by both the private and public sectors to alleviate the shortage of cybersecurity experts has resulted in expertise and capital conflict, creating problems for the affectionate side of the tech industry to improve in its structure (Wang et al., 2010).

The government is still pursuing these cyberwarriors while still in school, attempting to join a private enterprise (De Borchgrave et al., 2001). What is the procedure for this? They begin paying scholarships, salaries, books, and fees. Victor Piotrowski, who is a front-end program analyst at the National Science Foundation for Cyber Corps, states, "Contrary to other government initiatives, the budget of Cyber Corps has been tripled to about $45 million per year, over the last three fiscal years." According to Lawrence, “in 2013, about 4 out of 10 IT slots were left vacant,” according to a study of 500+ organizations conducted by the Institute of Ponemon, which studies data safety, information-security management, and privacy ( Solms and Niekerk, 2013). Employees from the public sector are often persuaded to join private firms because of the high wages they deliver (Choo, 2011). “Government has been under pressure when it has struggled to maintain most of its qualified cyber workers, as they want to leave government sectors because they are not safe enough in closely monitoring US nationals without their knowledge (Wells et al., 2014)” Lawrence says. Because of these barriers, cybersecurity seems to be more of an enemy than a companion (O'Connell, 2012).

Soon, several new challenges in the cyber sector will emerge (Kumar, Srivastava, and Lazarevic, 2006). No one could have predicted 70 years ago that internet media would modernize our lives to the point that it would improve interaction habits and the world's outlook; it was too impossible to imagine (Solms, 2005). However, shortly, we will theorize this definition (Solms and Niekerk, 2013). Cybersecurity has also started to cause problems with technologies like smartphones, which will only worsen as time goes by (De Borchgrave et al., 2001). Mobile phones are enticing targets for the viewer because they can access sensitive information such as classified work papers, photographs, location, and credit card accounts (Solms, 2005).

De Borchgrave et al. (2001) report that a substantial number of hackers have started to attack this emerging network. It was recorded that during the timeframe from the second quarter of 2012 to the end of the year, there was a significant spike, more than 30 times to be precise, in the identification of various types of threats on areas like Google’s Android and that the same is expected to reach the value of 1 million soon (O'Connell, 2012). Since cybersecurity and the internet have been around for a much shorter amount of time, they have dramatically altered the means and ways in which businesses, people, and governments communicate (Choo, 2011). Cybersecurity began as a welcoming medium, working to protect the then-available source of intelligence over the internet. Currently, a wrong side of it, formulated for the safety of US people, has drastically modified the way the US government implements cyber protection (Kumar, Srivastava and Lazarevic, 2006). Other states and US residents have been taken aback by the realization that their cellular calls and data have been revealed and open to scrutiny by the US government at any moment. Organizations such as WikiLeaks and Edward Snowden have begun to campaign to restore harmony between cybersecurity and civil liberties (Jouini, Rabai, and Aissa, 2014). While the future of this critical problem has yet to be published, it is clear that cyber world hackers will continue to grow more advanced, necessitating increased vigilance to ensure citizen protection (Wells et al., 2014).

The development of rare and modern viruses, as well as the proliferation of digital weapons, could very well change the balance of power among countries, posing an unwelcome threat to our lives (Gordon and Loeb, 2006). Mercantilism used to make it possible for countries with the most significant land holdings to have the most power, but that is no longer the case. In today's world, the nation with the most wealth and digital warriors will emerge triumphant (Choo, 2011). The cyber protection system was developed to assist people in protecting and safeguarding their valuable information; however, things have changed dramatically (Wang et al., 2010). The majority of Americans believe that the nation was built on universal human rights and that these rights are now in grave jeopardy due to the evolution of digital security (De Borchgrave et al., 2001). Knowledge sharing patterns are expected to be slowed by security concerns in the cyber domain (Kumar, Srivastava, and Lazarevic, 2006). Organizations will appear to retaliate against their opponents by creating intricate contact networks devoted to forbidding passage to the planet, so the global connectivity simplicity of the www period may well become a thing of the past. The open platform built by the whole world is now being demolished from the inside out (Gordon and Loeb, 2006).

Individuals and organizations (such as businesses, educational and financial institutions, corporations, the government, and the military) in today's advanced era recognize the importance of incorporating adequate cybersecurity measures that help store and gather large amounts of sensitive and private information on personal computers, which is then sent to various organizations.

In terms of households, protecting family members from the dangers of such offenses have risen to the top of the priority list ( Solms, 2005). It is critical for anyone's social life information and personal information to be appropriately safeguarded (Wells et al., 2014). The internet has made many informative posts readily accessible, but it still has its drawbacks (Choo, 2011). Videos, images, and other personal details posted by a person on social media pages such as Twitter and Facebook may be quickly exploited, resulting in the worst nightmare scenario for that individual (Kumar, Srivastava and Lazarevic, 2006). Social networking sites have developed as the most common means of exchanging thoughts, information, and socializing with others. However, those forums have led to an uptick in cybercrime, data leakage, and stolen personal identity (Wells et al., 2008).

The year is 2014. As a result, people need to be aware of how to defend themselves from such dangers and be mindful of the physical and virtual worlds (Gordon and Loeb, 2006). One should be aware of how to protect sensitive information to prevent it from being hacked and engage in certain online practices to learn more about the threat of cybercrime, resulting in a much safer online world (Jouini, Rabai, and Aissa, 2014). The steps introduced into cyber protection are essential for federal, central, and municipal governments since these organizations have a comprehensive archive of highly confidential consumer information and documents relating to state residents (Kumar, Srivastava, and Lazarevic, 2006). However, due to insufficient budgets, a lack of safety familiarity, and a lack of proper resources, many governmental organizations face challenges protecting their sensitive data (Solms and Niekerk, 2013). Digital hacking and the theft of private and confidential information from government companies will continue to pose significant threats to a country (O'Connell, 2012). As a result, enforcing cyber protection policies for government agencies has its importance that cannot be overlooked, as it plays a critical role in the nation's security (De Borchgrave et al., 2001).

Because of the number of internet users on social media and other sites, data protection is becoming increasingly important (Kumar, Srivastava, and Lazarevic, 2006). The growing number of cyber intimidations, such as phishing scams, cyber vulnerabilities, and sstealing of data, necessitates users to enhance their security and become even more vigilant online (Jouini, Rabai, and Aissa, 2014). As a result, it's critical to understand the various forms of cyber-threats that have become increasingly prevalent on the internet (De Borchgrave et al., 2001). Each user must exercise extreme caution when accessing some unknown internet channel, and they must also exercise extreme caution when exchanging essential and confidential information over the Internet (Von Solms and Van Niekerk, 2013).

Conclusion

the technological world has changed significantly over time, with cybercrime also following suit. In the contemporary world, companies and organizations must prepare their workers on how to handle cyber-attacks. Since it has been established that most of the graduates coming into the working market are not well equipped to deal with cybersecurity scenarios. In cybersecurity, humanity is the weakest connection.' People have been labeled as reckless users who fall prey to cyber scams and malware installs in the last decade. This has repercussions of humans being incompetent and inept as well. If you agree or disagree, this method of people becoming reckless must end; it is not only ineffective, but it often fosters an atmosphere where workers are unable to disclose threats to professional IT staff.

Instead of 'putting up with' human mistakes, businesses should concentrate on training their employees. Humans are only really "the weakest link" when cybercriminals deliberately target them. As a result, it stands to reason to educate the workforce to safeguard them and businesses. It's never been a better time to start training the populace. It's an excellent way to consider technology as digitalization movements get started (distributing initiatives much more like the Internet of Things and carrying your device culture). Instead of seeing it as a warning, businesses must see it as an idea that comes with the modern generation. Of course, investing in security education is necessary, specifically if it is ongoing. That being said, when compared to the cost of an assault, it's a small price to pay.

Staff members would benefit from skills and retraining, mainly if seminars are held regularly. They will help recognize attack vectors and take more care while accessing links or installing them in their daily lives. They would also improve their password management and be more conscious of firmware upgrades. Overall, education prepares employees with the knowledge and skills necessary to make minor adjustments that will help protect businesses. Also, if a 'phish condition arises, they are not hesitant to report it. This is because they would have the requisite experience, authority, and knowledge of the protocol.

The significance of enforcing proper cybersecurity initiatives is inevitable today, as it is essential to national security and should become a necessary part of any government’s policies. If threats begin to become more complex, even more, stable and robust platforms, need to be developed to address those threats effectively. Besides government agencies, public sector agencies should cooperate with public defense and enterprises to adequately enforce policies of cyber defense mechanism, which further includes testing and deployment of security steps as there has been a significant advancement in the application of social media and the internet, so the necessity of bringing cybersecurity initiatives to effect has become unavoidable. Increasing security threats such as cyber vulnerabilities, identity stealing, and malicious scams have made consumers recognize the worth of making their information appropriately secured. The understanding of different danger styles within the field of the internet is essential. Each user must be extra careful when using the internet for sharing information, including their confidential or social communication; they should demonstrate additional caution when engaging with others over the internet.

Three questions necessitate further investigation. Device swarms are a part of the latest generation of IoT computers. To ensure better protection in IoT settings, it's essential to understand swarm attestation at a deeper level. The second area that needs further investigation is safe system control. Even though system demand is on the increase, current IoT protection mechanisms are not scalable. It is necessary to develop new methods that are not dependent on bilinear coupling, which is expensive and consequences in short monikers. It should correspondingly be simple to implement the new approach. Access management regulations should be reformed to promote scalability following this. Finally, and perhaps most significantly, research into the convergence of cloud and IoT surroundings is needed. Information fusion, in-cloud statistics storage, and cloud safety auditing are fields where further research is needed to guarantee improved safety for the Internet of things. (Sadeghi, Wachsmann & Waidner, 2015).

Significant cybersecurity incidents have occurred even in large companies with world-class talent and substantial resources dedicated to cybersecurity—corporations without such skills or capital face even more significant consequences. More highly trained staff in cybersecurity positions will help the country adapt more effectively to its cybersecurity challenges. Both organizations must comprehend their threat climate and the threats they face and solve their cybersecurity issues, and recruit the best people for the job.

Individuals and organizations must be aware that data can potentially be compromised since cybercriminals are constantly attempting to spoof Internet of Things authenticated data. As a result, implementing encryption is critical to avert data fissures and secure sensitive information of both the public and employees. Companies are attempting to protect data and knowledge by implementing emerging technology and being one step ahead of hackers. However, consumers continue to place a lower priority on data security, leaving the door open for data theft. Cybercriminals have many openings in the IT departments of the healthcare and life science sectors to steal data for medical reports and other valuable intellectual resources linked to drug production. In an environment where cybercrime is on the rise, it's become more important than ever to protect this sort of data. Healthcare organizations must also comprehend the worth of a patient's information and take action to guarantee the protection necessary to avoid a data fissure (Point & Mcgee, 2016).

Since data is stored in the system or networks, it is critical to ensure cybersecurity. Data can be destroyed or altered due to a cyber assault, which can disrupt company operations. Cybersecurity measures are to ensure that unwanted entry from some other device is prevented. Since operational and IoT security are relatively recent, active personnel must learn new programming languages to address security concerns. Daily preparation for the cybersecurity team is also needed to identify modern threats and security initiatives (Zennie, 2019).

IoT system makers must focus on protection from the start, such as protecting hardware and keeping it tamper-proof, delivering constant device updates, and doing routine monitoring. On the other hand, system engineers would concentrate on ensuring the security of software creation and integration. People working on the system's development should focus on validation and hardware safety (George, 2019). Similarly, operators must insist on conveyance routine apprises to deter malware and viruses from infecting the system and safeguarding credentials.

References

1. Abawajy, J. (2014). User preference of cybersecurity awareness delivery methods. Behaviour & Information Technology33(3), 237-248.

2. Ahlan, A. R., Arshad, Y., & Lubis, M. (2011, July). The implication of human attitude factors toward information security awareness in Malaysia public university. In International Conference on Innovation and Management (pp. 12-15).

3. Al-Daeef, M. M., Basir, N., & Saudi, M. M. (2017). Security awareness training: A review. Lecture Notes in Engineering and Computer Science.

4. Aloul, F. A. (2012). The need for effective information security awareness. Journal of advances in information technology3(3), 176-183.

5. Alotaibi, F., Furnell, S., Stengel, I., & Papadaki, M. (2016). A review of using gaming technology for cyber-security awareness. Int. J. Inf. Secur. Res.(IJISR)6(2), 660-666.

6. Assante, M. J., & Tobey, D. H. (2011). Enhancing the cybersecurity workforce. IT professional13(1), 12-15.

7. Bada, M., Sasse, A. M., & Nurse, J. R. (2019). Cyber security awareness campaigns: Why do they fail to change behaviour?. arXiv preprint arXiv:1901.02672.

8. Barnum, S. (2012). Standardizing cyber threat intelligence information with the structured threat information expression (stix). Mitre Corporation11, 1-22.

9. Bauer, S., Bernroider, E. W., & Chudzikowski, K. (2013, December). End user information security awareness programs for improving information security in banking organizations: preliminary results from an exploratory study. In AIS SIGSEC Workshop on Information Security & Privacy (WISP 2013), Milano.

10. Bauer, S., & Bernroider, E. W. (2015, August). The effects of awareness programs on information security in banks: the roles of protection motivation and monitoring. In International Conference on Human Aspects of Information Security, Privacy, and Trust (pp. 154-164). Springer, Cham.

11. Beuran, R., Chinen, K. I., Tan, Y., & Shinoda, Y. (2016). Towards effective cybersecurity education and training.

12. Bijlsma, A., & Rutledge, L. W. (2020). Information Security Awareness of bank employees: how differences between headquarter and branch employees affect ISA program design.

13. Bulgurcu, B., Cavusoglu, H., & Benbasat, I. (2010). Information security policy compliance: an empirical study of rationality-based beliefs and information security awareness. MIS quarterly, 523-548.

14. Caldwell, T. (2016). Making security awareness training work. Computer Fraud & Security2016(6), 8-14.

15. Caldwell, T. (2013). Plugging the cyber-security skills gap. Computer Fraud & Security2013(7), 5-10.

16. Cappelli, D. M., Moore, A. P., & Trzeciak, R. F. (2012). The CERT guide to insider threats: how to prevent, detect, and respond to information technology crimes (Theft, Sabotage, Fraud). Addison-Wesley.

17. Chan, H., & Mubarak, S. (2012). Significance of information security awareness in the higher education sector. International Journal of Computer Applications60(10).

18. Chen, C. C., Shaw, R. S., & Yang, S. C. (2006). Mitigating information security risks by increasing user security awareness: A case study of an information security awareness system. Information Technology, Learning & Performance Journal24(1).

19. Cherdantseva, Y., Burnap, P., Blyth, A., Eden, P., Jones, K., Soulsby, H., & Stoddart, K. (2016). A review of cyber security risk assessment methods for SCADA systems. Computers & security56, 1-27.

20. Conteh, N. Y., & Schmick, P. J. (2016). Cybersecurity: risks, vulnerabilities and countermeasures to prevent social engineering attacks. International Journal of Advanced Computer Research6(23), 31.

21. Crumpler, W., & Lewis, J. A. (2019). Cybersecurity Workforce Gap. Center for Strategic and International Studies (CSIS).

22. De Bruijn, H., & Janssen, M. (2017). Building cybersecurity awareness: The need for evidence-based framing strategies. Government Information Quarterly34(1), 1-7.

23. Eminağaoğlu, M., Uçar, E., & Eren, Ş. (2009). The positive outcomes of information security awareness training in companies–A case study. information security technical report14(4), 223-229.

24. Etzioni, A. (2011). Cybersecurity in the private sector. Issues in Science and Technology28(1), 58-62.

25. Fielder, A., Panaousis, E., Malacaria, P., Hankin, C., & Smeraldi, F. (2016). Decision support approaches for cyber security investment. Decision support systems86, 13-23

26. Flores, W. R., & Ekstedt, M. (2016). Shaping intention to resist social engineering through transformational leadership, information security culture and awareness. computers & security59, 26-44.

27. Goodman, S. E., & Lin, H. S. (2007). Committee on Improving Cybersecurity Research in the United States Computer Science and Telecommunications Board Division on Engineering and Physical Sciences.

28. Gupta, B., Agrawal, D. P., & Yamaguchi, S. (Eds.). (2016). Handbook of research on modern cryptographic solutions for computer and cyber security. IGI global.

29. Kim, N., & Lee, S. (2018). Cybersecurity breach and crisis response: An analysis of organizations’ official statements in the United States and South Korea. International Journal of Business Communication, 2329488418777037.

30. Knowles, W., Prince, D., Hutchison, D., Disso, J. F. P., & Jones, K. (2015). A survey of cyber security management in industrial control systems. International journal of critical infrastructure protection9, 52-80.

31. Korpela, K. (2015). Improving cyber security awareness and training programs with data analytics. Information Security Journal: A Global Perspective24(1-3), 72-77.

32. Lallie, H. S., Shepherd, L. A., Nurse, J. R., Erola, A., Epiphaniou, G., Maple, C., & Bellekens, X. (2021). Cyber security in the age of covid-19: A timeline and analysis of cyber-crime and cyber-attacks during the pandemic. Computers & Security105, 102248.

33. McCormac, A., Calic, D., Butavicius, M., Parsons, K., Zwaans, T., & Pattinson, M. (2017). A reliable measure of information security awareness and the identification of bias in responses. Australasian Journal of Information Systems21.

34. McCormac, A., Calic, D., Parsons, K., Butavicius, M., Pattinson, M., & Lillie, M. (2018). The effect of resilience and job stress on information security awareness. Information & Computer Security.

35. McGettrick, A. (2013). Toward effective cybersecurity education. IEEE Security & Privacy11(6), 66-68.

36. Moşteanu, N. R. (2020). Challenges for Organizational Structure and design as a result of digitalization and cybersecurity. The Business & Management Review11(1), 278-286.

37. Nagarajan, A., Allbeck, J. M., Sood, A., & Janssen, T. L. (2012, May). Exploring game design for cybersecurity training. In 2012 IEEE International Conference on Cyber Technology in Automation, Control, and Intelligent Systems (CYBER) (pp. 256-262). IEEE.

38. Newhouse, W., Keith, S., Scribner, B., & Witte, G. (2017). National initiative for cybersecurity education (NICE) cybersecurity workforce framework. NIST special publication800(2017), 181.

39. Olayemi, O. J. (2014). A socio-technological analysis of cybercrime and cyber security in Nigeria. International Journal of Sociology and Anthropology6(3), 116-125.

40. Parrish, A., Impagliazzo, J., Raj, R. K., Santos, H., Asghar, M. R., Jøsang, A., ... & Stavrou, E. (2018, July). Global perspectives on cybersecurity education for 2030: a case for a meta-discipline. In Proceedings Companion of the 23rd annual aCM conference on innovation and technology in computer science education (pp. 36-54).

41. Parsons, K., McCormac, A., Butavicius, M., Pattinson, M., & Jerram, C. (2014). Determining employee awareness using the human aspects of information security questionnaire (HAIS-Q). Computers & security42, 165-176.

42. Pfleeger, S. L., & Caputo, D. D. (2012). Leveraging behavioral science to mitigate cyber security risk. Computers & security31(4), 597-611.

43. Rahman, A., Sairi, I. H., Zizi, N. A. M., & Khalid, F. (2020). The importance of cybersecurity education in school. Int. J. Inf. Educ. Technol10(5), 378-382.

44. Rowe, D. C., Lunt, B. M., & Ekstrom, J. J. (2011, October). The role of cyber-security in information technology education. In Proceedings of the 2011 conference on Information technology education (pp. 113-122).

45. Safa, N. S., Von Solms, R., & Furnell, S. (2016). Information security policy compliance model in organizations. computers & security56, 70-82.

46. Safa, N. S., & Von Solms, R. (2016). An information security knowledge sharing model in organizations. Computers in Human Behavior57, 442-451.

47. Sobiesk, E., Blair, J., Conti, G., Lanham, M., & Taylor, H. (2015, September). Cyber education: a multi-level, multi-discipline approach. In Proceedings of the 16th annual conference on information technology education (pp. 43-47).

48. Shackelford, S. J., & Craig, A. N. (2014). Beyond the new digital divide: Analyzing the evolving role of national governments in internet governance and enhancing cybersecurity. Stan. J. Int'l L.50, 119.

49. Singer, P. W., & Friedman, A. (2014). Cybersecurity: What everyone needs to know. oup usa.

50. Syed, Z., Padia, A., Finin, T., Mathews, L., & Joshi, A. (2016). UCO: A unified cybersecurity ontology. UMBC Student Collection.

51. Sun, C. C., Hahn, A., & Liu, C. C. (2018). Cyber security of a power grid: State-of-the-art. International Journal of Electrical Power & Energy Systems99, 45-56.

52. Švábenský, V., Vykopal, J., & Čeleda, P. (2020, February). What are cybersecurity education papers about? a systematic literature review of sigcse and iticse conferences. In Proceedings of the 51st ACM Technical Symposium on Computer Science Education (pp. 2-8).

53. Taylor-Jackson, J., McAlaney, J., Foster, J. L., Bello, A., Maurushat, A., & Dale, J. (2020, February). Incorporating psychology into cyber security education: a pedagogical approach. In International Conference on Financial Cryptography and Data Security (pp. 207-217). Springer, Cham.

54. Vogel, R. (2016). Closing the cybersecurity skills gap. Salus Journal4(2), 32-46.

55. Wachter, R. (2016). Making IT work: harnessing the power of health information technology to improve care in England. London, UK: Department of Health.

56. Wilson, M., & Hash, J. (2003). Building an information technology security awareness and training program. NIST Special publication800(50), 1-39.