Chapter 7Step 7: Understand the Human Factor

One common misconception about cybersecurity is that it's all technical. Yes, computer software and hardware are always important factors in preventing and mitigating cyberattacks. Software vulnerabilities succumb to exploitation. Poorly designed hardware is easier to hack. But newcomers to our field tend to overlook the human factor.

Cybercrime groups target human beings and our foolishness. It's much more difficult to acquire malicious access to an internal computer in a network by confusing firewalls and cracking encryption. It's much easier to trick a human being who has the username and password to an account with privileged access.

The majority of cyberattacks my colleagues and I see involve social engineering at some point or another. Social engineering is the art of fooling people, and understanding it is one of the most important areas of cybersecurity.

User interfaces (UIs) are the computer graphics that help you to interact with your favorite software applications. They're the buttons you click and the menus you tap. They run in your operating system, and they exist all throughout the web as well. Interestingly, when user interfaces have poor visual design or confusing wording, those mistakes can cause cybersecurity problems. If your company develops software, I'll explain how crucial it is that you create user interfaces that help users make good security decisions. If your company doesn't develop software, you can at ...

Get 8 Steps to Better Security now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.