{"id":79,"date":"2026-05-05T21:35:23","date_gmt":"2026-05-05T21:35:23","guid":{"rendered":"https:\/\/student.wp.odu.edu\/rblac007\/?page_id=79"},"modified":"2026-05-05T21:35:23","modified_gmt":"2026-05-05T21:35:23","slug":"cybersecurity-and-social-sciences","status":"publish","type":"page","link":"https:\/\/student.wp.odu.edu\/rblac007\/cyse-201s-course\/case-studies\/cybersecurity-and-social-sciences\/","title":{"rendered":"Cybersecurity and Social Sciences"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">Introduction <\/h2>\n\n\n\n<p>Looking at the Vercel security incident, what stands out to me is that this wasn\u2019t just a<br>technical failure\u2014it started with how people interact with systems. Vercel confirmed<br>unauthorized access to internal systems after a threat actor claimed they were selling stolen data,<br>including API keys, credentials, and employee account information (Underhill, 2026).<br>From my perspective, especially working through Blue Team labs and real-world<br>scenarios, this is exactly how things escalate. One weak point is that it doesn\u2019t stay isolated.<br>Vercel sits in the middle of development workflows, so once access is gained, it can impact<br>pipelines, deployments, and multiple environments. That\u2019s the risk when everything is built<br>around a central system.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Analysis <\/h2>\n\n\n\n<p>At a technical level, this points to identity and access management issues. But that\u2019s not<br>the real problem\u2014the real problem starts with behavior. What I\u2019ve been learning through my<br>labs is that people naturally take the fastest path. Credentials get reused, tokens don\u2019t get rotated,<br>and access becomes broader than it should be. That\u2019s not because people are careless\u2014it\u2019s<br>because systems are designed for speed and convenience.<br>From a team perspective, everything is built around collaboration. Multiple users need<br>access, things move fast, and there\u2019s pressure to deliver. That creates an environment where trust<br>is assumed instead of verified. What also stands out is how attackers are operating now. They\u2019re<br>not just targeting individual users\u2014they\u2019re targeting platforms that everything runs through.<br>Once they gain access, they\u2019re not just inside one system\u2014they\u2019re in a position to move across<br>multiple systems.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Solutions <\/h2>\n\n\n\n<p>From how I see it, fixing this is not just about adding more tools\u2014it\u2019s about tightening<br>both the system and how people use it. On the technical side, least privilege needs to be<br>enforced, credentials need to be rotated consistently, and short-lived tokens should be standard<br>(Underhill, 2026). Monitoring has to be active, not reactive. A zero-trust approach makes<br>sense\u2014assume something is compromised and limit what it can do.<br>On the human side, people need to understand the impact of their actions. From my own<br>experience learning this material, small decisions\u2014like not rotating credentials or providing too<br>much admin access\u2014create real vulnerabilities. The biggest barrier is culture. Teams want<br>speed, and security feels like friction. Systems are also complex, which makes visibility harder.<br>The way around that is building systems where secure behavior is the default. If the secure<br>option is the easiest option, people will follow it.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span style=\"text-decoration: underline\">Reflection<\/span><\/h2>\n\n\n\n<p>What this reinforces for me is that cybersecurity is not just about tools\u2014it\u2019s about<br>understanding people. As I\u2019ve been working through labs and real-world scenarios, I\u2019m starting<br>to see that strong systems alone are not enough. If people misuse access or trust systems too<br>much, the risk is still there. Psychology explains why people take shortcuts. Sociology explains<br>why teams operate the way they do. Without that understanding, you\u2019re only solving part of the<br>problem.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span style=\"text-decoration: underline\">Conclusion<\/span><\/h2>\n\n\n\n<p>The Vercel incident shows that cybersecurity issues come from both system design and<br>human behavior. Focusing only on the technical side is not enough. From my perspective, real<br>security comes from controlling both\u2014how systems are built and how people actually use them.<br>That\u2019s where real protection starts, and that\u2019s what I\u2019m working toward as I continue developing<br>in this field.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span style=\"text-decoration: underline\">Reference<\/span><\/h2>\n\n\n\n<p>Underhill, K. (2026, April 20). Vercel confirms security incident as threat actor claims stolen<br>data for sale. eSecurity Planet.<\/p>\n\n\n\n<p><br><br><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Introduction Looking at the Vercel security incident, what stands out to me is that this wasn\u2019t just atechnical failure\u2014it started with how people interact with systems. Vercel confirmedunauthorized access to internal systems after a threat actor claimed they were selling&#8230; <a class=\"more-link\" href=\"https:\/\/student.wp.odu.edu\/rblac007\/cyse-201s-course\/case-studies\/cybersecurity-and-social-sciences\/\">Continue Reading &rarr;<\/a><\/p>\n","protected":false},"author":32119,"featured_media":0,"parent":17,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"_links":{"self":[{"href":"https:\/\/student.wp.odu.edu\/rblac007\/wp-json\/wp\/v2\/pages\/79"}],"collection":[{"href":"https:\/\/student.wp.odu.edu\/rblac007\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/student.wp.odu.edu\/rblac007\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/student.wp.odu.edu\/rblac007\/wp-json\/wp\/v2\/users\/32119"}],"replies":[{"embeddable":true,"href":"https:\/\/student.wp.odu.edu\/rblac007\/wp-json\/wp\/v2\/comments?post=79"}],"version-history":[{"count":1,"href":"https:\/\/student.wp.odu.edu\/rblac007\/wp-json\/wp\/v2\/pages\/79\/revisions"}],"predecessor-version":[{"id":80,"href":"https:\/\/student.wp.odu.edu\/rblac007\/wp-json\/wp\/v2\/pages\/79\/revisions\/80"}],"up":[{"embeddable":true,"href":"https:\/\/student.wp.odu.edu\/rblac007\/wp-json\/wp\/v2\/pages\/17"}],"wp:attachment":[{"href":"https:\/\/student.wp.odu.edu\/rblac007\/wp-json\/wp\/v2\/media?parent=79"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}