Dalarna University's logo and link to the university's website

du.sePublications
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • chicago-author-date
  • chicago-note-bibliography
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
The Human Element of Cybersecurity: A Literature Review of Social Engineering Attacks and Countermeasures
Dalarna University, School of Information and Engineering.
Dalarna University, School of Information and Engineering.
2023 (English)Independent thesis Basic level (degree of Bachelor), 10 credits / 15 HE creditsStudent thesis
Abstract [en]

Social engineering attacks pose an escalating threat to organizations. This thesis conducted a semi-comprehensive literature review using the PRISMA method to address common attack methods, reducing susceptibility among employees, and the need for awareness training. Findings highlight severe consequences, exemplified by Yahoo and Sony data breaches. Phishing and spear-phishing are prevalent attack methods, exploiting the human element and bypassing high-techsecurity systems. To mitigate risks, organizations should adopt a multi-layered approach, combining technological solutions with employee awareness training. By enhancing employees' ability to identify and respond to social engineering attempts, susceptibility to attacks can be significantly reduced. Ongoing research and updated defense strategies are crucial to countering evolving attack vectors. The study emphasizes the collective responsibility in cybersecurity, combining technical and non-technical measures effectively. This thesis contributes to knowledge by providing insights into attack methods, countermeasures, and the importance of employee awareness training. The rigorous PRISMA method ensures a transparent approach, offering valuable guidance for organizations aiming to enhance their security posture against social engineering attacks. 

Place, publisher, year, edition, pages
2023.
Keywords [en]
Social engineering, attack, employee awareness, framework, policy
National Category
Computer and Information Sciences
Identifiers
URN: urn:nbn:se:du-46204OAI: oai:DiVA.org:du-46204DiVA, id: diva2:1768174
Subject / course
Microdata Analysis
Available from: 2023-06-15 Created: 2023-06-15 Last updated: 2025-10-09

Open Access in DiVA

fulltext(319 kB)3546 downloads
File information
File name FULLTEXT01.pdfFile size 319 kBChecksum SHA-512
bc3e9f3a8743cb03500647ceeb540f236c9fcaf78ef1a659329c0a8b0e4cb06dcc66587fa7e96432ea9d055e8b0e6cb85a820d376cf390509306c2b5aea9c49c
Type fulltextMimetype application/pdf

By organisation
School of Information and Engineering
Computer and Information Sciences

Search outside of DiVA

GoogleGoogle Scholar
Total: 3551 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 2200 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • chicago-author-date
  • chicago-note-bibliography
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf