Discussion: Understanding the Cybersecurity Landscape (150+150 = total 300 words)

profiledk1913
Discussion2Ravi.docx

Cyber security incidents refer to different threats like data breach, data leaks, phishing attacks and so on. These incidents can lead to expose the sensitive data of the company to hackers who use this data to harm the organization or the people whom the data belongs to. Some of the biggest data breaches revealed those mistakes which lead to the exposure of the data which belongs to millions. In the year October 2017, Yahoo has been a victim of such security breach where the data of almost 1 billion users was compromised. The breach was reported official in December, 2016 and henceforth Yahoo was questioned on their security encryption policies. Over 3 billion users then shifted from Yahoo to other companies who provided similar service. This incident not only impacted the people who’s data was leaked but this also compromised the reputation of the company and lost it their users having been one of the biggest data breach to happen in the history. LinkedIn was another such victim of data breach where the sensitive data of 700 million users of the LinkedIn was up for sale on the dark web in June 2021. (The 57 Biggest Data Breaches (Updated for 2021) | UpGuard, 2021)

Because of the cyber threats that organizations have faced mitigation of cyber risks has become a key issue. Risk mitigation separates the elements of prevention, detection and remediation. 

1. Conducting a risk assessment to determine vulnerabilities – risk mitigation strategy should conduct a risk assessment to access the loopholes in the security of the organization. It helps the organization by providing an insight in those areas of improvement. 

2. Implement firewalls and antivirus - Installation of such firewalls and antivirus software will help them defend and identify potential threats. 

3. Establish access control - It is important that the company establish network access control which will help the company in minimizing the possibility of risk as well as the impact of the attack. (Hewitt, 2021)