WEEK TWO DISCUSSION POST
1. Explain whether the above statement is TRUE or FALSE
The statement is true because cyber threats vary across professions and industries depending on
the nature of their operations, information assets, and technology infrastructure. The Week 2
material explains that threat actors target organizations according to their motives, such as
financial gain, political interests, ideology, or competitive advantage. For example, banks are
frequently targeted for financial theft, while government institutions may face state-sponsored
attacks seeking strategic information. Healthcare organizations are often targeted for sensitive
patient data. Therefore, although all organizations face cyber risks, the specific threats,
likelihood of attack, and potential impacts differ significantly between industries.
2. Which cyber threat(s) do you believe are universal across all professions and industries?
Phishing and malware are cyber threats that are universal across virtually all professions and
industries. Phishing attacks use social engineering techniques to deceive users into disclosing
sensitive information such as usernames, passwords, or financial details. Similarly, malware,
including viruses, worms, ransomware, and Trojan horses, can affect any organization that uses
digital systems. These threats exploit both technical vulnerabilities and human error, making
them widespread and difficult to eliminate completely. Regardless of industry, organizations
depend on employees and information systems, making phishing and malware persistent threats
that can compromise confidentiality, integrity, and availability.
3. In your profession or industry, describe and contextualize a particular security
vulnerability that can be a point of entry for a targeted cyber-attack.
In the information technology and security management field, one significant vulnerability is
employee susceptibility to phishing emails. Staff members often have access to sensitive
organizational data and critical systems, making them attractive targets for attackers. A phishing
email disguised as legitimate communication can trick an employee into revealing login
credentials or downloading malicious software. Once access is gained, attackers may escalate
privileges, move laterally across the network, or steal confidential information. This vulnerability
highlights the importance of security awareness training, multi-factor authentication, and access
control measures to reduce the likelihood of a successful targeted cyber-attack.
References
Whitman, M.E. and Mattord, H.J. (2013) Management of Information Security. 4th ed. Boston:
Cengage Learning.
Chapple, M., Stewart, J.M. and Gibson, D. (2018) CISSP Certified Information Systems Security
Professional Official Study Guide. 8th ed. Indianapolis: Wiley.
UEL-CN-7014 Security Management, Week 2 Reading Material: Cybersecurity Threats.