IT Security and Cyberattack Prevention in Organizational Systems
Main Article Content
Abstract
Digital transformation has increased the exposure of organizational systems to threats capable of compromising the confidentiality, integrity, and availability of information. Therefore, this study aimed to analyze the main threats, vulnerabilities, and preventive strategies applicable to information security management. A qualitative literature review was conducted using a non-experimental design, an exploratory scope, and a descriptive-analytical approach through the selection of scientific literature and technical documents published in English and Spanish, with priority given to recent publications. The information was organized in a documentary analysis matrix and examined through thematic content analysis and narrative comparison. The findings showed that cyberattacks commonly arise from the convergence of technical vulnerabilities, inadequate configurations, compromised credentials, unsafe practices, and management weaknesses. Likewise, defense-in-depth strategies, enhanced authentication, network segmentation, continuous monitoring, verified backups, ongoing training, and institutional leadership were identified as factors that strengthen preventive capacity. It is concluded that cybersecurity should be managed as a strategic and sociotechnical responsibility based on the integration of technology, organizational culture, governance, planned incident response, operational recovery, and continuous improvement.
Downloads
Article Details
Section

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.
How to Cite
References
Alshaikh, M. (2020). Developing cybersecurity culture to influence employee behavior: A practice perspective. Computers & Security, 98, 102003. https://doi.org/10.1016/j.cose.2020.102003
Andrade-Díaz, K. V. (2024). Integración de tecnologías de realidad aumentada en campañas publicitarias interactivas. Revista Científica Ciencia Y Método, 2(4), 26-37. https://doi.org/10.55813/gaea/rcym/v2/n4/51
Carpio-Velasco, F. J., & Garcés-Beltrán, G. M. (2025). Comparación de Estrategias de Control de Temperatura: Controlador PID y Redes Neuronales. Revista Científica Zambos, 4(2), 185-196. https://doi.org/10.69484/rcz/v4/n2/113
Casanova-Villalba, C. I., & Casanova-Villalba, L. A. (2024). Uso de análisis de datos avanzados para la detección de fraudes financieros. Revista Científica Ciencia y Método, 2(3), 1–12. https://doi.org/10.55813/gaea/rcym/v2/n3/44
Castelo-Vinueza, E. M. (2025). Problemas de la investigación tecnológica y su aplicación en la generación de innovación. Journal of Economic and Social Science Research, 5(1), 146–160. https://doi.org/10.55813/gaea/jessr/v5/n1/166
Celi-Párraga, R. J., Boné-Andrade, M. F., Mora-Olivero, A. P., & Sarmiento-Saavedra, J. C. (2023a). Ingeniería del software I: Requerimientos y modelado del software. Editorial Grupo AEA. https://doi.org/10.55813/egaea.l.2022.21
Celi-Párraga, R. J., Mora-Olivero, A. P., Boné-Andrade, M. F., & Sarmiento-Saavedra, J. C. (2023b). Ingeniería del software II: Implementación, pruebas y mantenimiento. Editorial Grupo AEA. https://doi.org/10.55813/egaea.l.2022.20
Chávez-Rendón, S. D., Pillasagua-Yépez, T. M., Moreira-Noboa, S. M., & Zamora-Mayorga, D. J. (2025). Análisis del funcionamiento tecnológico del ECU 911 de Quevedo en la gestión pública de la seguridad ciudadana. Revista Científica Ciencia Y Método, 3(3), 181-193. https://doi.org/10.55813/gaea/rcym/v3/n3/71
Choez-Calderón, C. J. (2024). Realidad aumentada y su aplicación en la educación a distancia. Revista Científica Ciencia Y Método, 2(3), 26-38. https://doi.org/10.55813/gaea/rcym/v2/n3/46
Connolly, L. Y., Wall, D. S., Lang, M., & Oddson, B. (2020). An empirical study of ransomware attacks on organizations: An assessment of severity and salient factors affecting vulnerability. Journal of Cybersecurity, 6(1), tyaa023. https://doi.org/10.1093/cybsec/tyaa023
da Veiga, A., Astakhova, L. V., Botha, A., & Herselman, M. (2020). Defining organisational information security culture—Perspectives from academia and industry. Computers & Security, 92, 101713. https://doi.org/10.1016/j.cose.2020.101713
European Union Agency for Cybersecurity. (2025). ENISA threat landscape 2025. https://www.enisa.europa.eu/publications/enisa-threat-landscape-2025
Galarza-Sánchez, P. C., Agualongo-Yazuma, J. C., & Jumbo-Martínez, M. N. (2022). Innovación tecnológica en la industria de restaurantes del Cantón Pedro Vicente Maldonado. Journal of Economic and Social Science Research, 2(1), 31–43. https://doi.org/10.55813/gaea/jessr/v2/n1/45
García-Peña, V. R. (2023). Desarrollo y Uso de Aplicaciones Móviles en el Contexto Ecuatoriano. Revista Científica Zambos, 2(3), 1-15. https://doi.org/10.69484/rcz/v2/n3/46
Giraldo-Burgos, G. Y., Avilés-Tinitana, V. V., Palacios-Rodríguez, A. M., & Zamora-Mayorga, D. J. (2024). Desafíos de adopción frente a plataformas digitales externas en la biblioteca de la Universidad Técnica Estatal de Quevedo. Revista Científica Ciencia Y Método, 3(3), 194-212. https://doi.org/10.55813/gaea/rcym/v3/n3/67
Khando, K., Gao, S., Islam, S. M., & Salman, A. (2021). Enhancing employees information security awareness in private and public organisations: A systematic literature review. Computers & Security, 106, 102267. https://doi.org/10.1016/j.cose.2021.102267
Mina-Bone, S. G. (2024). Evolución del derecho penal económico frente a los delitos financieros digitales. Revista Científica Ciencia y Método, 2(3), 52–66. https://doi.org/10.55813/gaea/rcym/v2/n3/50
National Institute of Standards and Technology. (2024). The NIST cybersecurity framework (CSF) 2.0 (NIST CSWP 29). https://doi.org/10.6028/NIST.CSWP.29
Nelson, A., Rekhi, S., Souppaya, M., & Scarfone, K. (2025). Incident response recommendations and considerations for cybersecurity risk management: A CSF 2.0 community profile (NIST Special Publication 800-61, Revision 3). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-61r3
Pascoe, C., Quinn, S., & Scarfone, K. (2024). The NIST cybersecurity framework (CSF) 2.0 (NIST Cybersecurity White Paper 29). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.CSWP.29
Picoy-Gonzales, J. A., Huarcaya-Taype, R., Contreras-Canto, O. H., & Omonte-Vilca, A. (2023). Fortalecimiento metodológico de la seguridad informática en posgrados: Análisis y estrategias de mejora. Editorial Grupo AEA. https://doi.org/10.55813/egaea.l.2022.56
Prümmer, J., van Steen, T., & van den Berg, B. (2024). A systematic review of current cybersecurity training methods. Computers & Security, 136, 103585. https://doi.org/10.1016/j.cose.2023.103585
Prümmer, J., van Steen, T., & van den Berg, B. (2025). Assessing the effect of cybersecurity training on end-users: A meta-analysis. Computers & Security, 150, 104206. https://doi.org/10.1016/j.cose.2024.104206
Ramos-Secaira, F. M. (2023). Seguridad Cibernética en Empresas Ecuatorianas: Prácticas y Retos Actuales. Revista Científica Zambos, 2(3), 16-28. https://doi.org/10.69484/rcz/v2/n3/47
Robalino-Latorre, M. C., Ramirez-Klinger, W. N., Guadalupe-Copa, R. C., & Cuello-García, S. A. (2023). Aplicación del Método Montecarlo en flujo de potencias a través del Software Octave. Journal of Economic and Social Science Research, 3(1), 31–47. https://doi.org/10.55813/gaea/jessr/v3/n1/60
Rodriguez-Vizuete, J. D., Viteri-Ojeda, J. C., & Villa-Feijoó, A. L. (2024). Adopción de tecnologías sostenibles en infraestructuras de tecnologías de la información. Revista Científica Ciencia Y Método, 2(1), 55-67. https://doi.org/10.55813/gaea/rcym/v2/n1/3
Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero trust architecture (NIST Special Publication 800-207). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-207
Ross, R., Pillitteri, V., Graubart, R., Bodeau, D., & McQuaid, R. (2021). Developing cyber-resilient systems: A systems security engineering approach (NIST Special Publication 800-160, Vol. 2, Revision 1). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-160v2r1
Saeed, S., Suayyid, S. A., Al-Ghamdi, M. S., Al-Muhaisen, H., & Almuhaideb, A. M. (2023). A systematic literature review on cyber threat intelligence for organizational cybersecurity resilience. Sensors, 23(16), 7273. https://doi.org/10.3390/s23167273
Sánchez-Caguana, D. F., Philco-Reinozo, M. A., Salinas-Arroba, J. M., & Pico-Lescano, J. C. (2024). Impacto de la Inteligencia Artificial en la Precisión y Eficiencia de los Sistemas Contables Modernos. Journal of Economic and Social Science Research, 4(3), 1–12. https://doi.org/10.55813/gaea/jessr/v4/n3/117
Sangacha-Tapia, L., González-Cañizalez, Y., & Rivas-Herrera, J. (2025). Optimización de Criterios de Búsqueda avanzada para Nuevas Tendencias en la Académica mediante Machine Learning. Revista Científica Zambos, 4(2), 197-211. https://doi.org/10.69484/rcz/v4/n2/114
Snyder, H. (2019). Literature review as a research methodology: An overview and guidelines. Journal of Business Research, 104, 333–339. https://doi.org/10.1016/j.jbusres.2019.07.039
Solano-Gutiérrez, G. A. (2024). La Tecnología en la Educación a Distancia: Revisión de Progresos y Obstáculos a Superar. Revista Científica Zambos, 3(2), 48-73. https://doi.org/10.69484/rcz/v3/n2/17
Sutton, A., & Tompson, L. (2025). Towards a cybersecurity culture-behaviour framework: A rapid evidence review. Computers & Security, 148, 104110. https://doi.org/10.1016/j.cose.2024.104110
Uchendu, B., Nurse, J. R. C., Bada, M., & Furnell, S. (2021). Developing a cyber security culture: Current practices and future needs. Computers & Security, 109, 102387. https://doi.org/10.1016/j.cose.2021.102387
Zwilling, M., Klien, G., Lesjak, D., Wiechetek, Ł., Cetin, F., & Basim, H. N. (2022). Cyber security awareness, knowledge and behavior: A comparative study. Journal of Computer Information Systems, 62(1), 82–97. https://doi.org/10.1080/08874417.2020.1712269