Analyzing Security Threats and Vulnerabilities in Modern Information Systems: Risks, Impacts, and Mitigation StrategiesJonathan Meade
Program: Information Technology: Capstone-Thesis: Master of Science (MS)
Awarded: February 2025
Capstone Instructor: Dr. Mistyjean Brown
Abstract: The rapid evolution of technology in modern organizations has introduced unprecedented efficiencies and operational capabilities but simultaneously opened the doors to ever-sophisticated cyber threats and vulnerabilities. These vulnerabilities—ranging from software misconfigurations to human factors such as social engineering susceptibility—pose severe risks to organizations’ economic stability, operational integrity, and reputational standing. This literature review critically examines the complex interplay between these vulnerabilities and the diverse range of threats exploiting them, including ransomware, data breaches, and phishing attacks. Furthermore, the study highlights evolving cyber threats such as adversarial artificial intelligence (AI) and the misuse of quantum technologies, reflecting an ongoing arms race between attackers and defenders in the digital landscape. The primary goal of this study is to analyze how cybersecurity threats impact organizations and evaluate the effectiveness of mitigation strategies employed across different industries. Using a multi-faceted approach, this paper synthesizes findings from peer-reviewed academic research, government publications, and industry reports to uncover prevailing trends and gaps in the field of information security. Through detailed case studies—spanning healthcare, financial services, critical infrastructure, and technology sectors—the paper illustrates real-world exploit scenarios, their impacts, and the lessons they provide for improving defense strategies. Key findings reveal that while technological measures such as zero-trust architecture and AI-driven threat detection systems play a vital role, human factors remain a persistent challenge. Employee training, continuous awareness programs, and behavioral change are highlighted as indispensable for combating social engineering tactics. Furthermore, the paper underscores the economic and regulatory repercussions of cybersecurity incidents, emphasizing the need for organizations to adopt a holistic risk management approach that integrates technical solutions and strong governance practices. This review concludes by proposing a comprehensive, interdisciplinary cybersecurity framework that integrates technical defenses, organizational policies, and human-centric strategies to achieve resilience. Recommendations also highlight emerging technologies—such as blockchain for secure transactional systems and the development of post-quantum cryptography—as potential game changers in the future of cybersecurity. By combining current research and actionable insights, the study aims to serve as a foundational resource for practitioners, policymakers, and researchers seeking to fortify information systems against evolving cyber threats.