Cybersecurity Assignment Overview 2025-26
Cybersecurity Assignment Overview 2025-26
Social engineering facilitates cyber attacks by manipulating individuals into divulging sensitive information through psychological tactics such as authority mimicry, urgency creation, and exploiting trust. Techniques like phishing emails or phone scams often impersonate trusted figures or create panic to lower an individual’s defenses, effectively exploiting inherent human vulnerabilities such as the desire to trust or the response to urgency .
Cyber offences refer to wrongdoing that specifically targets computer systems or networks, such as hacking into a computer system without authorization, while cybercrimes encompass broader criminal activity using computers, like identity theft, which involves stealing someone's personal information for fraudulent activities. An example of a cyber offence could be unauthorized system access to deface a website, whereas cybercrime might include using stolen credit card information from a phishing attack to make purchases .
Global enforcement of cyber laws faces challenges such as jurisdictional conflicts due to differing national laws, lack of a unified international legal framework, and varying levels of technological development among countries. These issues impede international cybersecurity efforts by making it difficult to prosecute cross-border cybercrimes, leading to safe havens for cybercriminals, and causing inconsistencies in how cyber regulations are applied and enforced globally .
Insider threats, which involve employees or contractors with access to sensitive information, can lead to cybercrimes through intentional data theft, sabotage, or unintentional security breaches due to negligence. An example includes a disgruntled employee leaking confidential information to a competitor, which can result in financial loss and damage to business reputation. Another instance is an employee inadvertently clicking on a phishing email, leading to ransomware attacks that disrupt operations .
Penetration testing plays a critical role in identifying vulnerabilities by simulating real-world cyber attacks on systems to uncover security weaknesses before attackers can exploit them. It is a critical component of cybersecurity strategy because it helps organizations proactively address security gaps, validates the effectiveness of security controls, and ensures that defenses are capable of withstanding potential threats .
India's cyber laws under the Information Technology Act focus on penalizing cybercrimes but lack comprehensive data protection regulations compared to the General Data Protection Regulation (GDPR) in the EU, which provides rigorous data protection and privacy guidelines. The USA has a sectoral approach with laws like the Computer Fraud and Abuse Act (CFAA) focused on deterring hacking and data breaches across different domains with less uniformity than the GDPR. However, US laws like the California Consumer Privacy Act (CCPA) show advancements in data protection parallel to European standards .
AI and machine learning have transformed the detection and prevention of mobile-based credit card fraud by enabling real-time analysis of transactions for anomalies indicative of fraud. These technologies can analyze patterns across vast datasets to detect unusual behavior, learn from past fraud scenarios to enhance predictive capabilities, and continuously adapt to new fraud tactics, significantly reducing false positives and enhancing the speed and accuracy of fraud detection and prevention efforts .
Major information security threats, such as phishing, ransomware, and advanced persistent threats (APTs), can disrupt business operations by causing financial losses, harming reputation, and leading to theft of intellectual property. For governments, these threats can compromise national security, affect critical infrastructure, and result in the loss of sensitive citizen data. Both sectors face increased costs due to security breaches, including the expenses related to incident response and recovery, legal fees, and regulatory fines .
Mobile authentication methods, such as passwords, biometrics, and two-factor authentication, have varied security implications. Passwords can be easily guessed or stolen, while biometric methods like fingerprint or facial recognition offer higher security but may face privacy concerns. Two-factor authentication considerably enhances security by requiring two forms of verification. These methods address challenges like unauthorized access by increasing the difficulty of credential theft and ensuring that only authenticated users can access sensitive data .
Encryption is crucial for cloud security as it protects data at rest and in transit, ensuring that unauthorized users cannot access sensitive information. Strong encryption protocols, like AES-256, offer significant benefits including data confidentiality, integrity, and compliance with data protection regulations. By encrypting data, organizations mitigate risks of data breaches, safeguard user privacy, and maintain trust with stakeholders .