Abstract
The increasing threat of cyber-attacks is a significant concern for organizations, particularly those in the USA. To mitigate these risks effectively, organizations must employ competent IT security professionals to implement effective security controls. However, there is a shortage of cyber security talent in the job market, necessitating extensive education and training. A good cyber security education program should be supported by a cyber security lab equipped with various software, equipment, and tools used by real professionals in the industry. This paper proposes a model of a cyber security lab equipped with honeypot and SIEM systems to enhance the quality of cyber security education. The research provides students with experience analyzing the behavior of hackers, while the SIEM system aggregates logs data of the Campus Network Firewall in real time. Security information and event management (SIEM) is a security solution that helps organizations recognize and address potential security threats and vulnerabilities before they disrupt business operations. SIEM systems help enterprise security teams detect user behavior anomalies and use artificial intelligence (AI) to automate many of the manual processes associated with threat detection and incident response. This research study aims to explore the defensive security strategies needed by small businesses in the USA to protect their information assets. Many businesses lack proper security tools, policies, and procedures, leaving them vulnerable to cyber-attacks. The research question is what strategies cyber security managers need to improve their cyber defense in small businesses in the USA.

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.