Skip to main content
Essay Undergraduate 865 words

Computer Security Threats, Malware, and Cybercrime Defense

~5 min read
Abstract

This paper provides a structured overview of three interconnected areas of computer security: threat and vulnerability assessment, malware identification and prevention, and organizational cybercrime defense. It defines security threats and vulnerabilities, categorizes common threat types such as errors and omissions, fraud, and sabotage, and introduces the DREAD risk assessment model for evaluating potential losses. The paper then surveys the major forms of malware and outlines a layered approach to protection. Finally, it addresses the responsibilities of IT managers, recommending best practices — including the principle of least privilege, regular software updates, and encryption — to safeguard organizational information in an increasingly dangerous digital environment.

Key Takeaways
  • Security Threats and Vulnerabilities: Defines threats, vulnerabilities, and common threat categories
  • Understanding Losses and the DREAD Model: Categorizes security losses using the DREAD framework
  • Malware: Types and Protective Strategies: Surveys malware forms and layered prevention methods
  • Cybercrime and the IT Manager's Role: Examines cybercrime scope and IT manager responsibilities
  • Organizational Best Practices for Information Security: Lists actionable security protocols for organizations
✍️ How to write this paper — guide, tools & examples

What makes this paper effective

  • Uses numbered and categorized lists to present technical information clearly and accessibly, making complex security concepts easy to scan and reference.
  • Grounds abstract concepts — such as vulnerability and loss types — in concrete examples drawn from both technical standards (NIST) and real-world organizational contexts.
  • Moves logically from foundational definitions to applied recommendations, giving the paper a practical orientation suited to an IT management audience.

Key academic technique demonstrated

The paper demonstrates applied synthesis: rather than simply defining terms, it connects each concept (threat, vulnerability, loss, malware, cybercrime) to operational consequences and actionable responses. By citing authoritative sources such as NIST and Bishop's Computer Security: Art and Science, it bridges academic definitions with practitioner guidance.

Structure breakdown

The paper is organized into three clearly delineated parts. Part 1 defines security threats, vulnerabilities, and loss categories using the DREAD model. Part 2 focuses on malware — its forms and a layered prevention strategy. Part 3 addresses the broader cybercrime landscape and concludes with an IT manager's checklist of best practices. Each section builds on the previous, moving from theory to application.

Security Threats and Vulnerabilities

A security threat is a potential event that may have an undesirable effect on a system, its resources, or the organization as a whole. A vulnerability is the weakness that makes it possible for a threat to occur. There are a number of threats that can occur on a system, and they are usually grouped together because some overlap. Common categories include:

Errors and Omissions — Data entry errors, data verification failures, and programming bugs.

Fraud and Theft — Skimming and controlling access to the system for profit.

Employee (or Outside) Sabotage — Destroying information, planting viruses, or stealing proprietary data or customer information (NIST, 2012).

Understanding Losses and the DREAD Model

There are a number of losses that can occur based on threat and vulnerability; some are more serious than others, and all are somewhat dependent on the type of organization under analysis. For instance, a bank's security loss may differ from an academic institution's, but both constitute a form of data loss. Losses may result in:

1) Data or information loss — customer information, financial records, personal data; 2) Time — downtime, data reconstruction, and human resource costs; 3) Reputation — loss of business due to security incidents or fraud; 4) Legal vulnerabilities — HIPAA compliance for medical organizations, privacy regulations, and related obligations; 5) Equipment — damage to technical or physical assets.

An acronym that helps frame these losses comes from a Risk Assessment model called DREAD: (D)amage, (R)eproducibility, (E)xploitability, (A)ffected Users, and (D)iscoverability (Bishop, 2003).

Malware: Types and Protective Strategies

Malware is a shortened name for malicious software — software used to disrupt computer operations or gain access to private information. Malware may appear in many forms: code, scripts, content, or standalone software. It is a general term for hostile or intrusive software that includes viruses, ransomware, worms, Trojans, dialers, spyware, adware, and other hostile programs. Malware can be guarded against, detected, or removed depending on the approach taken. Most experts believe that even on the simplest of systems, a layered approach to security is necessary (Kassner, 2009).

Because malware attacks are now so frequent, there are several ways to help protect against intrusion:

1) Anti-virus and/or anti-malware software; 2) Backup and recovery strategies (regular and robust); 3) Website security scans; 4) Elimination of over-privileged code (streamlining software for security); 5) Password security (changed regularly with strong security measures enforced); 6) System updates applied when needed — critical updates often include anti-malware properties; 7) A system of firewalls to protect against threats before they occur.

Additionally, many computer security experts recommend that Active X security settings be regularly adjusted from their default to a higher protection level. These same experts advise maintaining a backup browser in case a primary browser is compromised. Finally, it is advantageous to disable auto-run and auto-fill functions and to exercise extreme caution about what is downloaded and from where (MajorGeeks.com, 2010).

2 locked sections · 240 words
Sign up to read the full analysis
Cybercrime and the IT Manager's Role130 words
Today, most everyone has access to a computer or smartphone. The Internet has provided an unpatrolled opportunity to reach out globally,…
Organizational Best Practices for Information Security110 words
Several best practices should be embedded in an organization's manual and safety protocols:
Read the full paper →
Plus 130,000+ examples & all writing tools

References

Best Practice for Computer Security. (2011). University Information Technology Services. Retrieved from http://kb.iu.edu/data/akln.html#polp

Bishop, M. (2003). Computer Security: Art and Science. Boston, MA: Pearson Education.

Brenner, S. (2010). Cybercrime. Santa Barbara, CA: ABC-CLIO.

Kassner, M. (2009, August). 10 ways to detect malware. TechRepublic. Retrieved from

MajorGeeks.com. (2010). How to protect yourself against malware. Retrieved from http://forums.majorgeeks.com/showthread.php?t=44525

National Institute of Standards and Technology. (2012). Threats to computer security. Retrieved from

Key Concepts in This Paper
Security Threat Vulnerability DREAD Model Malware Layered Defense Principle of Least Privilege Cybercrime Data Loss Risk Assessment IT Management
Cite This Paper
PaperDue. (2026). Computer Security Threats, Malware, and Cybercrime Defense. PaperDue. https://www.paperdue.com/study-guide/computer-security-threats-malware-cybercrime-88796

Always verify citation format against your institution’s current style guide requirements.