INFT1060 Cybersecurity Fundamentals

  • Subject Code :  

    INFT1060

  • Country :  

    AU

  • University :  

    The University of Newcastle

Answers:

Introduction 

Today, the uses of business technologies and information systems are growing rapidly and many companies are moving towards emerging technologies for leading business performance and effectiveness. Securing data is a difficult task for companies while using information technologies and systems because the hackers develop malicious codes and transfer them to the networks that reduce the privacy of data. The presence of unauthorized activities enables the cyber-criminals to target communication networks and devices used by the companies. It is important for the government communities to identify the security risks and attacks linked with the computer networks so that chances of hacking can be managed significantly. The purpose of this report is to find the security threats and attacks faced by the organization and develop significant security strategies against cyber-attacks.

Risk Identification 

In the field of businesses, hackers target computing networks and channels that enable them to gain login credentials and sensitive data without their permission. Alassafi, et al., (2017) reported that many business industries are suffering from cyber-attacks and threats due to the use of emerging technologies and internet-based systems. There are major three risk factors producing security threats and problems in businesses for example lack of awareness, improper plans against security attacks, and misconfiguration of the networks. In business communities, many team members are not capable to detect and handle security vulnerabilities and risks transferred by hackers because of this data breach problems can be suffered by the companies. There are numerous cyber-attacks that occur in businesses which are described below:

Malware Attack 

It is one of the common security attacks performed by the hacker that has the ability to target the computer systems of the companies and perform hacking-related processes easily. Allodi and Massacci, (2017) reported that in the case of malware attacks, the hackers develop malicious codes and unwanted signals which are capable to decrease the performance and security of the web servers and networks of the companies. By targeting computing networks through malware threats, criminals can obtain the personal data of the employees including login details, profile details, and many more. Mainly, the hackers produce viruses and worms in the malware attack due to their ability to spread from one server to another easily and lead the chances of cyber-attacks significantly. Therefore, it is significant for the management to detect and identify the malware signals shared by the criminals so that confidentiality can be improved.

Phishing Attack 

Phishing refers to the cyber-attack which is used for gaining accessibility or log-in details of the computer systems in the businesses. Today, most of the employees access to email for data communication where hackers perform phishing attacks in order to decrease privacy and lead the chances of data loss significantly. Baskerville, Rowe, and Wolff, (2018) reported that email phishing is a common security attack performed by cyber-attackers and share spam or fraud emails to the team members which are not experienced about such threats and provide accessibility to the hackers. More than 60% of the companies worldwide are suffering from phishing attacks and employees are accessing spam emails that deliver a platform to the hackers for obtaining login credentials of the computer systems and communication accounts. Therefore, it is significant for employees to detect and address spam signals and mails from the systems in order to protect sensitive data.

Ransomware Attack 

It is a part of the malware attack that has the potential to access business networks, plans, and personal data stored in database systems and computing devices. In the last 5 years, the rate of ransomware attacks has increased rapidly that perform malicious codes in computer devices using unauthorized activities and fake internet networks. Deshpande, Nair, and Shah, (2017) agreed and reported that ransomware attacks transfer malicious codes and traffic signals to the networks and employees are not able to address such risks or vulnerabilities due to which login details of the computing devices can be lost easily. After obtaining accessibility, the hackers perform encryption processes that convert data files and systems into codes through private keys by which the users cannot access their computers. In order to access their systems, the victims require paying some ransom to the hackers due to which hackers perform ransomware attacks on the largest business communities and SMEs.

MITM attack and DDoS Attack 

MITM refers to the “man in the middle” attack that allows the cyber-attackers to target business networks and devices used by the companies and reduce the security of sensitive data. Martellini, et al., (2017) determined that in the case of a MITM attack, the hackers interrupt the current communication networks without the knowledge of the employees. After transferring the unwanted signals, the criminals can obtain private details including profile details, name, contact number, banking details, and financial data. DDoS is another leading cyber-attack that directly impacts on the performance of the communication networks and web servers easily. DDoS refers to the distributed denial of service attack that mainly transfers traffic that is capable to produce security risks and vulnerabilities in the workplace. Mirari botnet is a part of a DDoS attack performed by hackers that targeted thousands of computer devices and networks for obtaining personal data.

Security Strategies 

There are the following security strategies and approaches that can be applied for mitigating security risks and improving the privacy of SMEs:

Provide Training To Employees 

It is examined that many employees are not able to understand and examine the malware signals from the computer systems due to which it is difficult for the enterprises to manage internal threats and vulnerabilities. It is recommended that small and medium enterprises should propose training programs for the employees in order to deliver proper knowledge about cyber-attacks and security threats. By providing training programs can enable the companies to manage internal threats and unauthorized activities performed by the cyber-attackers effectively. Moreover, security experts should be hired that can help to develop more effective training programs and suggest the employees include strong and complex passwords to their communication systems and devices.

Propose Risk Assessment Plans And Policies 

A risk assessment is a kind of security approach that has the ability to find security risks and targeted devices by the hackers so that assessment and prevention-related activities can be performed effectively (Sadeghi, et al., 2017). It is suggested that SMEs should include an IT security risk assessment model in the workplace and apply their stages in the businesses such as identification, assessment of the risks, mitigate and prevention against cyber-attacks. Moreover, GDPR and NIST security frameworks should be followed in order to develop significant security policies in businesses.

Implement Anti-Malware/Anti-Phishing Tools

It is found that many hackers target email-based communication channels used by the employees and transfer spam signals for decreasing security levels. It is recommended that SMEs should install anti-malware or anti-phishing tools to the communication networks so that frauds and spam signals can be identified. With the help of such security control, the companies can protect sensitive data and login details from cyber-criminals effectively (Tuna, et al., 2017). Moreover, the SMEs should include backup plans in order to secure more effective and sensitive data from hackers and protect collected data from internet servers.

Develop Firewall And Encryption Based Programs 

A firewall is one of the common security controls used for handling security risks and issues occurred in web servers and computing networks. It is suggested that SMEs should implement package filtering which is a type of firewall that has larger effectiveness to detect traffic and malware signals from networks and servers significantly so that DDoS, phishing, malware, and other cyber-attacks can be managed. Moreover, AES encryption programs should be applied which are capable to convert data into cipher codes so that transmitted data can be received more securely. Therefore, all these are effective security strategies and controls that should be obtained and implemented by small and medium enterprises.

Conclusion 

From the above evaluation, it may be summarized that due to improper security plans and controls, SMEs are not able to secure computer systems and databases from hackers. This research delivered a way to find security threats and risk factors leading to cyber-attacks in SMEs and also suggested significant security strategies. It is demonstrated that various cyber-attacks and threats are linked with SMEs for example malware, phishing, DDoS, MITM, and many more. It is recommended that small and medium enterprises should propose training programs for the employees in order to deliver proper knowledge about cyber-attacks and security threats. Moreover, GDPR and NIST security frameworks should be followed in order to develop significant security policies in businesses.

References

Alassafi, M.O., Hussain, R.K., Ghashgari, G., Walters, R.J. and Wills, G.B., (2017) Security in organizations: governance, risks and vulnerabilities in moving to the cloud. In Enterprise Security, pp. 241-258.

Allodi, L. and Massacci, F., (2017) Security Events and Vulnerability Data for Cybersecurity Risk Estimation. Risk Analysis, 37(8), pp.1606-1627.

Baskerville, R., Rowe, F. and Wolff, F.C., (2018) Integration of information systems and cybersecurity countermeasures: An exposure to risk perspective. ACM SIGMIS Database: the DATABASE for Advances in Information Systems, 49(1), pp.33-52.

Deshpande, V.M., Nair, D.M.K. and Shah, D., (2017) Major Web Application Threats for Data Privacy & Security–Detection, Analysis and Mitigation Strategies. Under review in International Journal of Scientific Research in Science and Technology PRINT ISSN, pp.2395-6011.

Martellini, M., Abaimov, S., Gaycken, S. and Wilson, C., (2017) Vulnerabilities and Security Issues. In Information Security of Highly Critical Wireless Networks, pp. 11-15.

Sadeghi, A., Jabbari, M., Alidoosti, A. and Rezaeian, M., (2017) Vulnerability and Security Risk Assessment of a Thermal Power Plant Using SVA Technique. Journal of Integrated Security Science, 1(1), pp. 6-10.

Tuna, G., Kogias, D.G., Gungor, V.C., Gezer, C., Ta?k?n, E. and Ayday, E., (2017) A survey on information security threats and solutions for machine to machine (M2M) communications. Journal of Parallel and Distributed Computing, 109, pp.142-154.

Online exams can be a pain in the head. But, you needn’t worry since our online exam help is here at your disposal. No matter how tough the questions are, we have the right team of experts to help you out. The team guides you through all the questions are you struggling to find an answer to. We will provide you with credible study and research material as well, depending on the question. Besides online exam help, we also provide unmatched quality essay writing services and custom writing assistance. You can also hire qualified ghostwriters from our team and get rid of all academic burdens easily.

Why Student Prefer Us ?
Top quality papers

We do not compromise when it comes to maintaining high quality that our customers expect from us. Our quality assurance team keeps an eye on this matter.

100% affordable

We are the only company which offers qualitative and custom assignment writing services at low prices. Our charges will not burn your pocket.

Timely delivery

We never delay to deliver the assignments. We are very particular about this. We assure that you will receive your paper on the promised date.

Round the clock support

We assure 24/7 live support. Our customer care executives remain always online. You can call us anytime. We will resolve your issues as early as possible.

Privacy guaranteed

We assure 100% confidentiality of all your personal details. We will not share your information. You can visit our privacy policy page for more details.

Upload your Assignment and improve Your Grade

Boost Grades