1 / 9100%
PEOPLE AND RISK
1
People and Risk Assignment
Erin Dilbeck
School of Education, Liberty University
PEOPLE AND RISK
2
Abstract
Today, the Internet is the fastest-growing infrastructure in everyday life. In the world of
information technology, cyber threats and attacks continue to be on the rise. Retail business
organizations need to be vigilant in a digital age where access to information on the Internet is at
individuals' fingertips. Big box retailer Target ensures customer protection through a
cybersecurity team that analyzes and assesses threats around the clock to protect information and
third-party risks. Retail organizations should implement systems and structures to mitigate cyber
threats and attacks. Retailers must implement a plan to provide continuous employee training.
Software security systems should be in place. Network security systems such as cyber threat
intelligence will support mitigating potential threats and risks. Retail organizations should make
sure that there is a continuous backup of data and secure information. Third-party risks can pose
significant threats, and organizations should persistently assess and analyze these threats. This
paper will recommend how retail organizations can minimize information technology risks,
threats, and attacks. A biblical perspective will be provided.
Keywords: people, risk, security, risk management
PEOPLE AND RISK
3
Introduction
Information technology is critical for all organizations in today's business environment.
All organizations revolve around the information provided through the use of the Internet. While
information technology has improved the business world, it also poses risks to individuals within
the society and the business as an entire institution, specifically the risk of cybersecurity. Internet
access is at the end of our fingertips, and those individuals choose to take advantage of the ease
of access. Today, the Internet is the fastest-growing infrastructure in everyday life. Many of the
latest technologies are changing the face of humankind (Prathyush & Kumar, 2022). Cyber risks
are not geographically confined; hackers can target any nation or organization, regardless of
location (Radanliev, 2024). Organizations must develop a plan to decrease the threat of
cyber-attacks and mitigate the potential risks. By creating a risk management plan, organizations
can assess the probability of a cyber attack and information that a possible attack will leak. A
risk management plan will allow organizations to assess the likelihood of associated cyber-attack
costs. Security breaches can occur from within the organization by individual employees or from
outside an organization. A security breach occurs when information assets and systems'
confidentiality, integrity, or availability are endangered (Ahsan et al., 2022). When a security
attack is identified within an organization, the organization must have a plan to divert the
probability of an attack. Employing an information technology team within an organization
allows the team to investigate and respond to potential attacks. Cybersecurity is a significant
concern for businesses worldwide because cyber attackers constantly target corporate data and
information technology (Saeed et al., 2023). It is recommended that retail organizations provide
continuous employee training, enforce advanced security and network measures, implement a
backup system, and assess third-party risk.
PEOPLE AND RISK
4
There is a rising threat to cyber security for big box retailers such as Walmart and Target.
Many retailers offer buy online, pick up in-store options for their customers. BOPIS orders pose
an easy target for fraud, potentially stealing customers' information. These orders require
minimal customer information to purchase online and pick up inside the retailer. There is often
no shipping address to verify against the cardholder address; thus, the potential risk for fraud
becomes the retailer's risk. Many retailers also rely on Internet of Things (IoT) systems. These
systems lack the security measures necessary to eliminate a cyber attack. Vulnerabilities are
inherent in retail payment systems, often stemming from the vast array of software, hardware,
and cloud-based components needed to power them. These vulnerabilities are easily exploited by
cybercriminals seeking to deploy malware on devices or through back-end cloud services,
enabling them to access internal information systems, launch attacks, and steal customer data.
Big box retailers, like Target, employ a cybersecurity team to provide twenty-four-hour, seven
days a week, protection for its customers against fraud and cyber-attacks. Target has a cyber
fusion center where employees analyze the latest threats, assess risk, and engineer innovative
solutions. The team of employees investigates and responds to potential threats and attacks.
Target is a recognized retail industry leader in threat intelligence. Retail organizations must take
the necessary measures for their organizational systems and customers.
Employee Training
Retailers must implement a plan to provide continuous employee training focused on
cybersecurity. Organizations should put policies into place that keep information and data safe.
Organizational management should inform employees regarding possible cyber threats and
information accountability. Cybersecurity crimes are estimated to have cost the global economy
just under USD 1 trillion in 2020, increasing more than 50% since 2018 (Cremer et al., 2022).
PEOPLE AND RISK
5
One successful cyber attack can cause a decrease in customer trust and result in a fall in retailer
value. Providing employees with training regarding cybersecurity reinforces the security
mechanisms of retail organizations.
Advanced Security Software
Advanced security software provides thorough protection to organizations, decreasing the
potential for cybersecurity threats. Trend Micro Network security is a possible solution to
mitigate cybersecurity attacks. The system delivers network detection and response (NDR) to
analyze high-risk, otherwise invisible networks. The filter service detects and prevents breaches,
allowing organizations to respond to potential threats and attacks.
Network Security
Cyber threat intelligence (CTI) is a potential solution for mitigating cyber threats. CTI is
a process of gathering, analyzing, and distributing information to identify, monitor, and anticipate
cyber threats. CTI can help businesses become more proactive in cybersecurity by identifying
vulnerabilities before attackers exploit them (Saeed et al., 2022). For example, suppose a cyber
threat attacker has been known to attack an organization using a specific method of attack.
Organizations that utilize CTI could identify the pattern of the threat actor and intervene to
prevent the attack. CTI uses specific security plans to identify cyber attacks' mannerisms to
prevent, detect, and respond to potential cyber threats and attacks. As a response to the benefits it
provides and the present market trend, CTI has attracted the attention of most organizations
(Saeed et al., 2022).
Secure Backup and Recovery
Retail organizations can use backup and recovery strategies to mitigate potential threats.
Backup and recovery allows organizations to duplicate data and store it in a secure location in
PEOPLE AND RISK
6
case of a data breach. In the case of an information data breach, the organization can restore the
data to the organization or an alternative location. This allows the information to be used again
within the retail organization. There are three types of backup solutions. A full backup is the
most basic method organizations use, sending all data to an alternate location. An incremental
backup supports all the files that have changed since the last backup. Last, a differential backup
only backs up copies of files that have changed since the last backup occurred.
Third-Party Risk Assessment
A third-party risk management process involves the retail organization identifying critical
third-party vendors, continuously monitoring vendor security, and remediating security threats
and attacks before the risks develop into cybersecurity breaches. These are often seen in the
business world as third-party data breaches. To mitigate third-party risks, retail organizations
must conduct thorough due diligence prior to onboarding suppliers and vendors within the retail
organization. This may include background checks, security controls, reputation, and the
financial stability of the vendor or supplier. Retailers can mitigate this risk by analyzing data
flow, assessing how third parties safeguard data, and following retail industry best practices and
standards.
Recommendations
Retail organizations must take proactive measures to protect retail systems, customers, and the
organization's reputation. Such measures include:
●Continuous Employee Training: Retailers must invest in cybersecurity training for
employees in connected omnichannel environments and create a robust cyber culture
within the organization.
●Advanced Security Software: Implement robust systems that deliver retail network and
detection response (NDR) capabilities. Trend Micro Network security is a possible
PEOPLE AND RISK
7
solution for advanced security software that can help mitigate potential threats and
attacks.
●Network Security: Cyber Threat Intelligence (CTI) allows retail organizations to identify
vulnerabilities and cyber threats proactively.
●Secure Backup and Recovery: Regularly back up data, utilizing full, incremental, or
differential backup.
●Third-party Risk Assessment: Evaluate the security practices of third-party vendors by
analyzing data flow, assessing how third parties safeguard data, and following retail
industry best practices and standards.
Wright (2017) explains that the United States created the federal Computer Fraud and Abuse Act
to decrease the number of cyber crimes. This was in response to cyber crimes that targeted banks
and financial institutions. Criminals can be located anywhere, as the nature of their cyber world
means they can be everywhere (Wright, 2017).
Evidence of Critical Thinking and Biblical Perspective
Evidence of critical thinking is demonstrated through support throughout the paper with
scholarly articles as well as Biblical integration focused on risk management. The Old Testament
provides numerous examples of excellent risk management. The biblical example of Joseph, in
Genesis 30-50, depicts his enduring faith and spiritual wisdom. Joseph is known as one of the
most resilient persons in biblical times. God had warned Pharaoh of an impending seven-year
famine in a dream he had. Through a series of events orchestrated by God, Joseph was lifted up
from prison to proactively manage this extreme risk to the survival of Egypt and its neighbors.
Joseph's example of spiritual faith shows Christians that when we fix our gaze on our Lord and
Savior and choose to rely on him, even the heaviest situations and potential risks can be made
lighter. The bible teaches us in Romans 8:28 that “God causes everything to work together for
the good of the Christians who love him” (Standard English Version, 2021).
Summary of Major Points
PEOPLE AND RISK
8
In today's technology-driven world, cybercrimes continue to rise. Retail organizations
must take the necessary measures to protect their organizational systems and customers.
Retail organizations must ensure systems and structures are in place to mitigate threats and
attacks. Possible solutions include employing an information technology team that focuses on
analyzing possible threats, assessing risks, and employing possible solutions. Organizations
should employ a team focusing on cybersecurity, providing around-the-clock supervision.
Retailers must implement a plan to provide continuous employee training. Software security and
network security systems should be in place. Retail organizations also make sure that there is a
revolving backup of data and secure information. Lastly, third-party risks and threats should
continuously be assessed and analyzed.
Conclusion
Cybersecurity crimes continue to show an upward trend within organizations each year.
With positive technological development came the use of it for criminal purposes (Wright, 2017).
In order to mitigate cyber attacks, retail organizations must develop structures and systems to
eliminate threats and attacks. Big box retailers like Target are an example of mitigating threats by
employing a cyber fusion center, working around the clock to analyze threats, assess risks, and
provide possible solutions. In today's technological world, cybercrime can be located anywhere
and occur within any organization. Organizations must ensure they have the proper tools in place
to mitigate threats. Christians can learn from Joseph, an example of resilience in the face of risk
and a faithful follower of the Lord.
PEOPLE AND RISK
9
References
Ahsan, M., Nygard, K., Gomes, R., Chowdhury, M., Rifat, N., & Connolly, J. (2022).
Cybersecurity threats and their mitigation approaches using machine learning: A Review.
Journal of Cybersecurity and Privacy, 2(3), 527-555.
Cremer, F., Sheehan, B., Fortmann, M., Kia, A., Mullins, M., Murphy, F., & Materne, S. (2022).
Cyber risk and cyber security: A systematic review of data availability. The Geneva
Papers on Risk and Insurance, 47(3) 698-736.
Praythyush, G. & Kumar, G. (2022). A study of cybersecurity and its role in information
technology along with the emerging trends and latest technologies. International
Journal of Advanced Research in Science, Communication and Technology, 2(1), 854-
858.
Radanliev, P. (2024). Cyber diplomacy: defining opportunities for cybersecurity and risks for
artificial intelligence, IoT, blockchains, and quantum computing. Journal of Cyber
Security Technology.https://doi.org/10.1080/23742917.2024.2312671
Saeed, S., Suayyid, S., Al-Ghamdi, M., Al-Muhaisen, H., & Almuhaideb, A. (2023). A
systematic literature review on cyber threat intelligence for organizational cybersecurity
resilience. Sensors, 23(16), 1-27.
Wright, L. (2017). People, risk, and security. In Palgrave Macmillan UK eBooks.
https://doi.org/10.1057/978-1-349-95093-5
Powered by TCPDF (www.tcpdf.org)
Students also viewed