Research paper Summary

profileJB12345
Response1.docx

Cybersecurity is not looked at as a form of security at a particular point of the transaction rather it has several fronts where the Information Technology systems experts rely on sophisticated technologies, strategies, access management and/or a combination of all of these to establish a secure system to protect an enterprise and its information systems from hacking activities such as data abuse, system abuse, etc. Enterprises such as insurance, eCommerce and healthcare industries heavily rely on the customer data which cannot be risked to be exposed as it consists of privileged information on the customers and leaving the systems unprotected, which manage this sensitive data, would damage the businesses and can cause huge financial losses questioning the existence of the enterprise itself. Cybersecurity systems analyze existing risks and identify vulnerabilities in the existing information systems and help the Information Technology professionals to design risk mitigation steps to either completely eliminate or reduce the amount of risk imposed in case of an attack (Rindell & Holvite, 2019).

 Cybersecurity is more about safeguarding the integrity, confidentiality, and availability of the data and this cybersecurity is important as the data is transmitted across various networks and to different devices. One data breach can make a big difference to the organization and a major range of devastating consequences for the organization. Being non-compliant with data protection regulations can affect the organization. Some of the types of cybersecurity that need to be used by the organizations are network security, Data Loss Prevention, Cloud Security, Intrusion Detection Systems, and Identity Access Management. These principles can protect the hardware, software, and the data produced or collected from cyber threats. Common types of cyber threats are Malware, Ransomware, Social engineering and phishing. Various challenges in cybersecurity can be through hackers, data loss, privacy and these issues continually emerged in different ways as new technologies started to emerge and different ways to attack the data are noticed. Due to the continual changes in updating the security and continual challenges started to increase (Alsmadi, 2020).

Risk management includes the process of identifying risks or problems in the data which includes system-level, network, and operations level. Identification of these problems will help the business owners to avoid risks and minimize the impact. The risk management process includes steps of identifying the risk, risk analysis considering probabilities, risk control, and risk treatment. This plan should include clearly defined roles, responsibilities and accountability of the team members. Some of the benefits using this risk management plan are to save valuable resources like time, income, employees, properties, and to create a safe environment for the staff, clients and customers. Having a risk management plan for cybersecurity allows limiting the devices, anti-virus programs, automated patches and element level security. This risk management process can be an ongoing process (Rindell & Holvite, 2019).