Why Are We So Bad at Cybersecurity? – Dr. Spock vs. Homer Simpson

Blog | Publication date: 3 Oct 2023

With great freedom comes great responsibility

Our world is becoming increasingly digital, and technology is advancing at lightning speed. The Internet is like a universe—endless and uncontrollable—and absolutely wonderful! Search engines, websites, and social media have opened many doors for society and individuals. The freedom, accessibility, and convenience of sharing and accessing information have never been greater. Of course, there’s no turning back; we won’t give up our freedom. But we need to manage the risks of confidential information falling into the wrong hands.

Throughout October—Cybersecurity Awareness Month—Softronic will be sharing insights on security, the threats that exist, and what you need to do to protect yourself and your information.

In this first blog post, Sanaz Babaeian, one of Softronics’ cybersecurity experts, explains what cybersecurity is and the different types of cyber threats that exist.

Cybersecurity has never been more important.

Valerie McNiven, of the U.S. Department of the Treasury, claimed that cybercrime as an “industry” generates approximately $105 billion annually. Claims regarding revenue from cybercrime versus the drug trade are being questioned – TechWorld (idg.se)

Cybercriminals essentially run businesses that provide customer service and financial lending to their “customers”—that is, those who fall victim to cybercrime. Information is clearly valuable! To protect ourselves, our loved ones, and our businesses, it’s crucial to raise awareness and knowledge about cybersecurity at home and in the workplace.

Why Are We So Bad at Cybersecurity? – Dr. Spock vs. Homer Simpson

The short answer is: deadlines, stress, and juggling too many things at once! We make quick decisions and take shortcuts whenever we can to get everything done.

The longer answer involves Nobel Prize winner Daniel Kahneman, who has researched the brain’s “System 1” (reflexive/instinctive decision-making) and “System 2” (more thoughtful/analytical decision-making) in his book *Thinking, Fast and Slow*. However, the entertainment value is heightened by Daniel Cawdron’s ( CEO & Creative Director at Discoure) playful comparison of the systems: Mr. Spock vs. Homer Simpson.” (Cawdron’s article on LinkedIn: Mr. Spock Versus Homer Simpson (linkedin.com))

Our brains have two different decision-makers: one is Dr. Spock and the other is Homer Simpson. The difference between these two characters is that Homer Simpson is a character who loves doughnuts, he gladly takes the easiest and most convenient path in life without giving it a second thought; he lacks both foresight and common sense, and his choices often lead him to take shortcuts and go for the tastiest and cheapest donuts—for which he’ll end up paying dearly anyway.

Dr. Spock, on the other hand, thinks everything through one more time, running calculations and risk analyses to make the most logical and best decisions. Dr. Spock probably spends far too much time on the simplest decisions and could have been more efficient at times.

In the real world, we all make the majority of our decisions like Homer Simpson; it’s difficult and inefficient to analyze everything because we’re so incredibly stressed in our daily lives. On the other hand, when we’re aware that a bigger and more important decision is coming up, we often take the time to analyze our options and arrive at the best decision in a completely different way. The key is to stay aware of when you can take a shortcut with your “Homer Simpson brain” and when you should pause and activate the energy-intensive “Dr. Spock.”

The next time you’ve had a very stressful day with lots of deadlines and decisions to make, your inbox is full, and you want to get through them before the weekend—turn on Dr. Spock!

What Is Cybersecurity?

Cybersecurity is about protection. Protecting the digital world from threats and threat actors. It’s about protecting networks, systems, computers, and data. Essentially, it’s about protecting information from:

  • Access by unauthorized persons (confidentiality)
  • Destroyed or made inaccessible (accessibility)
  • Changes without being noticed (accuracy)

In one way or another, we all leave a digital footprint. This happens directly when we post data or images that are accessible to everyone or to a specific group or person. We also share our data indirectly when government agencies, companies, and/or organizations store data about us. In some cases, we have no choice—for example, when it comes to the information that government agencies store about us. In other cases, a customer offer is so good that we can’t resist sharing our data in order to take advantage of the offer or join a loyalty program.

The need for cybersecurity is growing, but security measures and knowledge are lagging behind. Many of us would be completely unable to handle everyday tasks if we lost our cell phones. Just think about how much of our lives we have stored in “THE CLOUD” and what unauthorized individuals could do with that information. Also consider how much data government agencies and companies store “out there”—about us, about others, and about themselves—and what could happen if it fell into the wrong hands.

The Most Common Cyber Threats:

Malware

Malware, or malicious software, that can infect computers and IT systems, steal data, and cause significant damage.

Phishing

A form of cyber fraud in which the threat actor or attacker attempts to trick users into revealing sensitive or confidential information, such as passwords or credit card details. Phishing often takes the form of fake emails containing links to fraudulent websites. For example, emails purporting to be from Microsoft may lead users to believe they are logging in to a legitimate Microsoft site with their login credentials, but in reality, they have logged in to a fake site, allowing the attacker to obtain their login credentials. As a user, you rarely notice any difference, but you end up unwittingly and unknowingly sharing your login credentials.

Ransomware

In Swedish, “ransomware” refers to a type of malicious software designed to encrypt files, lock, or otherwise damage digital systems that businesses or individuals rely on, and to extort money by demanding a ransom to unlock files or restore systems to working order.

Top 5 Ransomware Strains, 2023

  • Lockbit
  • ALPHV
  • Malas
  • C10p
  • Play

Distributed Denial of Service (DDoS)

A denial-of-service (DoS) attack is a type of cyberattack in which an attacker attempts to overload a website, a server, or a network. The attackers flood a website with traffic, causing it to perform very poorly, become sluggish, or go offline entirely. This type of attack has increased significantly and has affected several key societal actors, such as banks, financial institutions, government agencies, the mass media, and gaming and betting companies. Cyber warfare, retaliation, or extortion have been identified as closely linked to the unrest we have experienced—and continue to experience—around the world in recent years.

Data Breach

A data breach occurs when an attacker attempts to gain unauthorized access to networks, systems, computers, and their contents in order to steal or leak confidential data—such as personal information, user data, or corporate data—that can be used or resold on the black market.

Social Engineering

When an attacker attempts to use manipulation to trick a user into revealing information they have about an organization or business. “Skilled” attackers may have been studying their victim for some time before striking by searching for information about the user on social media and identifying common ground that can provide a way in to deceive the user.

Insider Threat

Threats from individuals within the organization who abuse their authority or access to information in a way that could harm the organization. This could involve, for example, sharing information with a competitor.

Next blog post

In the next blog post, Sanaz Babaeian will explain more about what you need to do to protect yourself as an employee, as well as what you, as a manager, need to do to protect confidential information within an organization.

If you have any questions or concerns, please feel free to attend our security event on October 18. There, we’ll share more about the current threat landscape. Read more below.

Blog post written by: Sanaz Babaeian.

Sanaz's Profile