1 / 63100%
Surname 1
Arizona State University-Tempe Campus
CIS 401 - Cyber Risk Management
September 14, 2023
Cybersecurity Response and Remediation from an Attack
Introduction
The Store My Bits International's (SMBI) latest hack exemplifies the urgent need for
swift and coordinated responses in cybersecurity. Given the complexity of cyber risks, which are
exemplified by the introduction of viruses and keyloggers that violate the Electronic
Communications Privacy Act (ECPA), legal remedies and preventative actions are essential
(Acebo). Acebo, indicates that policies such as the ECPA emphasize the seriousness of hacking
and the range of punishments it carries, providing crucial foundations for responses. Global
resilience against cyber threats is improved by international cooperation, such as the Budapest
Convention on Cybercrime. The all-encompassing response strategy from SMBI combines
technological, legal, and forensic tactics to strengthen security against intrusions and rebuild
trust. Acebo suggests that to combat cybersecurity risks, SMBI must have a comprehensive,
proactive strategy that demonstrates its dedication to resilience via adherence to laws and
concerted efforts.
The use of artificial intelligence (AI) in cyber security systems has changed the manner in
which institutions predict, identify, and respond to threats. Saad and Aslam point out that AI
powered systems can identify anomalies in real time as a result of machine learning systems that
can identify deviations in network behavior (Saad and Aslam 48). This decreases human latency
Surname 2
in incident response, which speeds up remediation and improves analytical accuracy. AIs are
powerless, as the authors explain, and it is the responsibility of people to combine structured data
governance with ethical and strategic responsibility in the context of using artificial intelligence
(Saad and Aslam 73). In practice, this means that adopting self-defending AI SMBI systems are
expected to change their behavior through learning. Such systems can target multi-dimensional
attack chains and predict vulnerabilities up to attack time frames. However, reliance on
automation can result in a situation where the human operators are exposed to algorithmic
outputs as a blind spot. As Saad and Aslam asserts, true resilience can only be achieved when
human insight combines with AI systems to formulate adaptive, clear, and ethical approaches to
cyber defense (Saad and Aslam 95). The future of incident remediation, therefore, is not self-
evidently in advanced technology, but rather in synergy between effective reasoning and
automation, toward sustainable governance of cyber security.
An incident response strategy problem scales issue containment with other measures.
Thompson points out that system isolation and the preservation of digital evidence are integral
steps in containing the infiltration of malware before it worsens (Thompson 78). This not only
preserves integral active forensic evidence that is indispensable for future legal and analytical
processes but also preserves active threads. Thompson states that the elimination of the problem
must comprise the cleansing of the system and the cleansing of the behavioral system of the
organization so that the weaknesses that have been exploited are dealt with once and for all
(Thompson 102). These steps are not only procedural in nature but also steps that are indicative
of an organization’s ability to leverage a crisis for a paradigm shift in its approach to the issue.
Flowing from small and medium business internationally (SMBI), these principles suggest that
containment and recovery must happen simultaneously. Thompson also notes that a reviewed
Surname 3
structured system of post-incident of the response will retain organizational memory and permit
future responses to be more about data than reactive (Thompson 121). This is why remediation is
not only about the restoration of operations following a cyberattack, but about organizational
resilience reflection, training, and continuous refinement. For SMBI, the operationalization of
the contained, eradicated, and learned model is the paradigm shift that moves cybersecurity from
a business requirement to a business advantage.
The improvement of Cybersecurity also depends upon distributed proactive insights and
associated analytical frameworks. Darshini et al. describe how contemporary detection
methodologies work off architectural frameworks in which datasets are continuously correlated
and then analyzed across disparate networks to recognize patterns and uncover previously
uncharted threat vectors (Darshini et al. 2). This intelligence transformation analytical
development applies to proposition of Cyber Security as science as organizations are now able to
predict threat manifestation and take proactive action to mitigate consequences. The authors
suggest that a synthesis of automation of detection with human analytics in a post-remedial phase
can greatly increase the precision of responses while simultaneously minimizing the duration of
system downtimes (Darshini et al. 5). These hybrid models allow responders to sustain their
attention on the relevant scenario of a large-scale surge on the system. However, these models
also require strong interdepartmental coordination in order to analyze situational data as
operational data instead of contextual data. Darshini et al. argue that, a lack of organizational
cohesion in the face of sophisticated technology means poor security outcomes (Darshini et al.
7). In the case of SMBI, siloing the threat intelligence unit to IT, and then combining legal and
compliance with a broader aligned intelligence unit, could work to foster collective situational
awareness as a whole. This goes to show that Cybersecurity case studies are not simply tools, but
Surname 4
are also a testimony to the complexity of analysis that an organization is able to conduct in order
to take timely action. This action must be directed not only on the defending the organization's
structures, but also its positioning in the market.
A culture of preparedness is necessary for cyber resilience, Calder does argue recovering
from a cyber-attack is as much a culture issue as it is a technological one, and preparedness is
learned by training, exercises, and active leadership involvement (Calder 64). This shifts the
focus of Calder’s approach to cybersecurity from looking at it as an issue pertaining to IT alone,
to one which the entire organization has to help resolve. Successful defense strategies are
described by Diogenes and Ozkaya as the integration of governance, technology, and people into
a ‘whole of organization’ defense system (Diogenes and Ozkaya 116). Their defense suggests
that policy and employee ethical awareness and accountability SMBI’s recovery to governance
slack is the focus of the recovery effort. Moreover, and equally important, Calder has argued that
a culture of response is sustainable when security norms are consistently breached and reinforced
and real time feedback is provided ‘during and after’ crisis events (Calder 182). Employees when
they appreciate the technical and ethical aspects of cybersecurity work with the system as
responsible citizens and not as compliant subjects. Diogenes and Ozkaya also point out that
resilience is configured when defense technologies are integrated with the changeable nature of
people, transforming every breach to a step forward for the organization (Diogenes and Ozkaya
141). Thus, for SMBI, distributed trust is the foundation of security that is nurtured through
awareness and continuous organizational learning. This also represents, the greatest form of
collective vigilance which is with a high degree of freedom.
Information Security Laws & Regulations on Computer Hacking: Laws & Consequences
Cyber
Surname 5
Computer hacking is one of the most significant developments in information security as
it relates to the intricate laws and penalties related to cyber crimes. For instance, Ahmad et al.,
(1939) highlight how there are various legal approaches on cyber risks in different countries
although they share some common principles on cyber security measure and punishment of
offenders. Unauthorized access to computer system is a considered as crime in United States
according to Ahmad et al (941). For example, such hacking cases can be punishable under ECPA
sections 2701 & 2702 which form the basis of statutory framework and penalties. In specific,
such ones cover the unlawful seizure of telephone recordings as well as electronic
communications from the providers themselves. These laws also state prescribed penalties
commensurate to the damages done by unlawful entry. The federal sentencing guidelines also lay
down how these punitive measures are computed, considering aspects such as scope of the
offensive operations, its economic impact and intent.
According to Acebo’s article, the rules and regulations of the Electronic Communications
Privacy Act (ECPA) highlight the seriousness with which illegal hacking activities are regarded
within the context of the legal system. It is indicated by Stoyanova et al. (10) that a crucial
element is the categorization of different levels of transgressions, enabling the imposition of
nuanced penalties that correspond to the gravity of the violation. For example, within the legal
framework, unlawful access resulting in harm is classified as a crime, which incurs more severe
penalties in comparison to cases involving improper access without causing any harm.
According to Lallie et al. (8), the application of these disparities in sentencing by courts
illustrates the law's flexibility to adjust to diverse hacking situations and its focus on addressing
the differing degrees of cyber dangers. This subtle strategy is supposed to link the severity of a
Surname 6
breach to the punishments that follow, discouraging future hackers by making them fear legal
ramifications.
Due to the inherently global nature of cybercrimes, international collaboration and
coordination in the fight against them have assumed utmost importance. According to Ahmad et
al. (939), a multitude of treaties, accords, and conventions have been implemented to promote
the exchange of information and provide legal support amongst nations to jointly address the
challenges posed by cyber threats. Acebo’s article in the New York Times says the Budapest
Convention on Cybercrime facilitates global collaboration by establishing a structure for the
standardization of legislation and regulations about cybercrimes, specifically encompassing
hacking endeavors. Ahmad et al. (946) showed that this collaboration improves investigation
procedures, legal frameworks, and extradition processes. Therefore, it improves worldwide cyber
threat response.
Innovative governance and regulatory instruments are at the epicenter of the evolving
international industry cybersecurity regulatory ecosystem. As Schreider notes, the cycle of
anticipation and reaction within boundaries of enforcement is one technocratic structures
dimension, and regulatory instruments are always the last to respond to the technology side of
the cycle. The regulatory instruments lag behind the technology and the enabling cycle to tackle
policy gaps, called the defeated dynamic. This is a decision-making policy gap which, from a
strategic perspective, calls for legislation to construct the gaps and move in parallel to
technology to close the adaptive gap. Kosseff is of the opinion that the governance of
cybersecurity policy frameworks should move from compliance to 'accountability’ in the policy
continuum, as the notion of 'accountability' encompasses the principle of 'incessant vigilance' and
multi-sector governance Kosseff 830. This advocacy stems from the notion that hacking is not
Surname 7
only a localised unlawful act but a global threat. In this context, Marcinauskaitė et al and others
argue that legal systems must equally balance the obligations of criminal systems and of
innovative legal systems to the extent that the systems do not in any way stifle 'ethical' hacking
and digital inquiry Marcinauskaitė et al. 210. The advocacy for flexible contemporary legal
instruments with a preventive posture of compliance as opposed to post-facto punitive rest is
reactionary suggests that the actors like the SMBI may serve the dual purpose of detering the rest
of the malice and enabling the innovative responsive.
Of late, there has been a move by various governments toward a more harmonized
approach in developing frameworks for enhanced accountability and cross-border
interoperability frameworks. As pointed out by Srinivas et al., global frameworks such as the
ISO/IEC 27001 and the NIST Cybersecurity Framework have become focal points for
international harmonization for the Cyber Defense Standards (Srinivas et al. 182). These
frameworks are not laws themselves, yet their impact for soft law compliance and law drafting is
cross-sectoral. The more these frameworks are accepted as standards, the more the boundaries
between the legal and technical aspects of cyber governance become integrated, effectively
diminishing the previously independent national approaches to cyber governance. The more
these frameworks are accepted as standards, the more the boundaries between the legal and
technical aspects of governance become integrated, effectively diminishing the previously
independent national approaches to cyber governance. Maglaras et al. note that the more
internalized regulation is to practice, the more discipline and organizational learning is required
beyond the operational checklists (Maglaras et al. 765). The more regulation is internalized; the
more organizational culture has to adapt incorporating the principles of the cyber security law to
become effectively self-governing. It is similarly argued by Hovav et al. that dominant,
Surname 8
compliance-driven policies have and are capable of producing stronger knowledge and
institutional resilience when integrated with a learning organizational culture (Hovav et al. 167).
Therefore, changes in law must also reflect shifts in legal education and practice, particularly
with respect to leadership, in order to give regulation practical significance.
The issue of ethical hacking is a common and important point of controversy within the
field of cyber jurisprudence. Hawamleh et al. suggest that ethical hackers help bring possible
threats to light for the criminal world to use (Hawamleh et al. 7896). These activities tend to
shoAulder a certain level of ambiguity within the limitation of the law with regard to purpose
and actual and proper consent. Chander and Kaur point out how the attitude of different nations
toward white-hat hacking is a case of contradictory behavior, with some countries permissively
ignoring the act of white-hat hacking, while other nations consider it a criminal act a subject
against which word border offenses (Chander and Kaur 142). This makes a collaborative
approach to both defense and offensive cyber research rather difficult. Cooperative defense is
also hampered. Alexandrou is right in stating that legal systems need to define the act of hacking
in terms of consent and injury rather than merely access. This, thoughtful legal framing does
distinguish ethical hacking from malicious hacking (Alexandrou 58). This means that the law on
cyber security must change in the direction of situational assessments rather than blanket rules,
enabling a situation where organizations can work with ethical hackers without the fear of being
prosecuted, in the process improving the overall defense against real attacks.
The continuation of corporate liability is possibly as complex as cyber law itself,
especially when breaches of data tackle the accountability of executives. From a cultural
perspective, we are witnessing a shift from organizational accountability to personal
accountability regarding cyber security and the associated negligence remarks Schreider,
Surname 9
regarding how personal liability is increasingly being placed on company executives (Schreider
212). This policy is aimed at promoting the management of a company’s cyber security matters
to the level of governance within the company, whereby it is no longer just a technical issue.
Beale and Berris also note that the same trends are emerging in the IoT space, where
manufacturers of devices are being held to account for the negligent design of devices that have
the potential to harm users (Beale and Berris 175). These trends demonstrate an increasing
understanding that negligence in cyber security is tantamount to corporate misconduct.
According to Garunja et al., the force of such policies is determined by the level of enforcement
whereby the penalisable actions are aligned to the risk position resulting from corporate
negligence (Garunja et al. 5). The emerging perspective is that the legal position in regard to
cybercrime is changing, as it seeks to shift the counter organizational malfeasance to negligence
within a digitized global environment.
The intersection of economy and law is evident in the dimension of cyber legislation
which deals with the risk aspects of competitiveness. As noted by Hovav et al., the strong
cybersecurity regulations can bolster investor confidence, as they show operational maturity and
transparency (Hovav et al. 158). On the other hand, there is the risk of overregulation which can
hinder innovation, particularly for SMEs that have fewer resources for compliance. Maglaras et
al. defend that the essence of the matter is in the regulation that is accountability and sufficient
for ensuring progress, proportionate regulation (Maglaras et al. 768). Politically, that balance is
what ensures the innovative and secure nature of the national economies. Furthermore, layered
regulatory regimes should be adopted by governments wherein the compliance burden of the
financial and healthcare sectors which carry higher risk is greater as compared to other lower risk
industries (Chander and Kaur 156). This method of regulation seeks to achieve an optimal
Surname 10
balance between the national security pillars and the economic health of the country. For
organizations such as SMBI, voluntarily staying above the legal minimums could improve
regulatory alignment and resilience, framing cybersecurity as a competitive advantage rather
than a burden.
The impact of cybercrimes on society is the utmost importance of legislation on
cybercrimes. Policing cyber spaces is a balancing act. The state cannot effectively defend its
borders of cyberspace without the ability to surveil its own citizens. Surveillance is all too often
equated with freedom-destroying totalitarian repression. It is also easy to overlook the fact that
free societies can, and often do, infringe on the very freedoms they set out to protect (Kosseff
835). In the current world of commercial third-party digital monitoring and public analytics,
Marcinauskaitė et al. say that the ‘punitive excess’ or ‘malicious’ transparent intrusion of
information governance can do more harm than good to public confidence in digital governance
(Marcinauskaitė et al. 213). Any sustainable governance of cyberspace cannot escape the reality
that its legitimacy is a function of the security and liberty it yields. The importance of how
Schreider presents the fundamental tenets of this legislative framework: ‘transparency, oversight,
and due process’ (Schreider 188). The combination of these presents the system with the most
potentially useful or intrinsically powerful outcomes with the least amount of effort and
resources. The same reasoning applies to evidence that the boundaries on public confidence in
this smart digital era stem from cybersecurity dismantlement. It goes without saying that the
fundamental building blocks of democracy are effective cybercrime legislation. Striking a
balance between security and fundamental freedoms and human rights is normative in nature. In
other words, it is a question of what ought to be rather than what is the case. For instance, the
reputation of ethical business practices is “undermined” by the notion that corporate internal
Surname 11
practices are not aligned with human rights standards. In such circumstances, ‘customer loyalty’
is engineered rather than earned.
Shifting focus from legal concepts, Garunja et al. point out that these gaps are especially
visible in emerging economies where the capacity for digital forensics is still limited. This
shortage creates these gaps identified by Alexandrou with his point that a combined regional
effort is necessary for distributed legal procedural unification. Policymakers in charge should
also realize how half-hearted blunders in south-south resource sharing risk reinforcing the legal
foundations of the information economy implemented by authoritarian regimes. Legal assistance
treaties, while useful indeed, often fall short of the real complexity of global digital legal
relations identified by Srinivas et al. Alexandrou also refers to these attempts by southern
countries leaning towards authoritarianism in their international relations as cyber smack. It
results in disconnects that safeguard the absolute power of global digital oligopolies. Legal
digital sub imperialism is also a phenomenon that Garunja et al. describe as the ease of sublegal
open information legal digital unification as layered within the authoritarian or from
authoritarian centralism spiral framework. For SMBI, whose data operations arguably span
multiple jurisdictions, the real value of the complexity of cross border is real time data available
from multiple countries.
The merging of technological development with regulatory boundaries has never been so
prominent before, especially with the advancement of the Internet of Things (IoTs). The legal
framework offered by Beale and Berris places the entire IoT ecosystem under scrutiny,
highlighting the absence of adequate legal and protective measures surrounding interconnected
devices (Beale and Berris 165). The ongoing imbalance when it comes to technological
advancement and the geopolitical fractures within the global supply chain only make passage
Surname 12
more difficult. Schreider contends that legal IoT structures should emphasize complex base
systems that ensure manufacturer accountability to design security within the product (Schreider
198). Such structures are designed to incorporate preactive frameworks which protect systems
and devices from harmful intrusions. Hovav and his colleagues have noted that companies that
invest in proactive compliance frameworks to the IoT arms race tend to be more successful in
creating innovative products, especially when the data these systems engage with is orderly
governed (Hovav 170). This means that in the case of IoT, regulation might be conducive, rather
than restraining, to the development of technology. For SMBI, embedding IoT compliance
within its security policy is likely to equally enhance international reputation while ensuring that
legal exposure pertaining to the data remains within designed boundaries.
Like legal sanctions, education and advocacy initiatives shape behavior in the area of
cyberspace. Maglaras et al state that in the absence of public understanding of the different laws
pertaining to cyberspace, even the most advanced laws will not be complied with (Maglaras et al.
769). This comment shows the need to incorporate legal education into vocational instruction
and public schooling. As noted by Hawamleh et al, the vulnerability of users to social
engineering attacks decreases with user education, and hence ignorance is not bliss. On the other
hand, lack of knowledge can sometimes result into legal infractions, even though the intention is
not criminal, such as in the situation of unauthorized access which is driven by curiosity.
Chander and Kaur suggest that the gap between the law and the ethics of public awareness
defining how self-interest and social trust is justified by compliance should be filled by national
campaigns. For SMBI, adopting such educational initiatives to employee training and outreach to
clients can turn law into practice and transform compliance into the organizational culture.
Surname 13
While cyber law and digital forensics intertwine with each other concerning how pieces
of evidence are collected, preserved, and adjudicated, Alexandrou notes, "...the admissibility of
evidence is digital in nature and especially hinges on the procedural integrity of the collection
and during the documentation of the chain of custody” (Alexandrou 97). This requirement is
foundational concerning law and technology evidentiary intertwining. For example, Srinivas et
al. show how the outcome of prosecutorial strategy is positively correlated with how forensic
evidence is preserved in anticipation of future events (Srinivas et al. 190). Their argument speaks
to the anticipation aspect of cyber law, proposing that the law should not wait to react. Also,
Schreider states that the ability of digital forensics to keep pace with the legislation on the use of
encryption technology and the growing use of cloud computing systems continues to be a
challenge (Schreider 202). All of the comments above indicate that the effectiveness of cyber
law is no more than the level of technical sophistication necessary to enforce it. For SMBI, the
benefits of being forensic ready are compliance and credibility. It evidences the proper balance
between the duty to protect the digital infrastructure and the lawful restriction of its use.
There indeed appears to be a shift within the domain of corporate governance that
integrates the practice of law on the peripheral domain of cyber law with a focus on value
creation as opposed to compliance. As Hovav et al state, organizations where cybersecurity
becomes a pillar of governance as opposed to relegated to a silos IT function achieve much better
outcomes in decision-making and risk management. This kind of alignment turns law to strategy,
accountability dispersed to various levels in management. Garunja et al note that Companies
with cybersecurity oversight at the Board level incur fewer regulatory fines and recover more
rapidly after suffering a breach. This observation affords a direct positive correlation between
governance, as a legally necessary function of the firm, and value creation. As noted by
Surname 14
Schreider, the ability of a corporation to set and implement cyber policies hinges on governance,
accountability, and oversight in the firm and more importantly, the articulation of the strategy to
the corporation's mission and values. This proves the point that for SMIB, the integration of
cyber law within global corporate strategy is more than a legal transaction, it enriches SMIB’s
identity as a strong resilient corporation. Therefore, the changing landscape of cyber law is a
reflection of the changing landscape of corporate leadership, the intertwining of compliance with
the strategy towards the forward-looking governance of the firm.
Threats: Assessment & Analysis: What is Phishing? - Definition, Examples & Awareness
Information Security
According to Stoyanova et al. (2), phishing, a pervasive cyber hazard, is defined to
encompass deceptive strategies intended to unlawfully acquire confidential data from persons or
entities. Stoyanova et al. (2) state that it refers to the utilization of deceitful email tactics in
which hackers assume the identity of reputable companies, compelling individuals to disclose
passwords or financial information. As an illustration, deceptive emails imitating financial
institutions compel users to modify their information on counterfeit websites using embedded
hyperlinks. A study by Lallie et al. (17) points out that the significance of awareness in the fight
against phishing cannot be exaggerated. The need of educating consumers on email source
identification, safe online activity, and website integrity is paramount. Lallie et al. (17) add that
the implementation of ongoing awareness efforts and the utilization of technology protections are
imperative in light of the adaptive characteristics of phishing. Phishing detection requires
identifying subtle differences and being vigilant in response to data requests.
Surname 15
Phishing is one of the most deeply spellbinding forms of cybercrime that takes advantage
of the cognitive bias, emotional response, and therefore the rational response. Nguyen, Rosoff,
and John explain that attackers intend phishing emails and messages to instill panic and urgency
so that the targets make rushed decisions without thinking of the validity of the issue at hand
(Nguyen, Rosoff, and John 164). This behavioral economics proves that phishing is a problem
and success accomplished through a technical execution. The authors believe that measuring the
economic and psychological magnitude of the information security can assist organizations in
deciding the level of support to allocate towards defensive awareness (Nguyen, Rosoff, and John
167). These organizations target phishing awareness, training, and education to users based on
social and psychological factors in fulfillment of the recommendations of the proposing authors.
Alkhalil et al. explain that the contemporary initiatives have more sophisticated and blended
elements of personal social phishing with engineering that merges real and fake communications
and blurs the disguise (Alkhalil et al. 4). Thus, the contemporary approaches to anti-phishing
have to shift from behavioral content learning. This is in order to recognition training that direct
users to the changes of cognitive automation. Phishing is no more only a technical offense, and a
sociotechnical problem to which the human aspect is the most fragile, and vulnerable.
The assessment of the awareness on the part of users is now considered an integral part of
evaluating the level of maturity of an organization's cyber defense capability. As noted by Ikhsan
and Ramli who conducted phishing tests on government employees, even employees who have
had some form of training on cyber security fall prey to sophisticated phishing and spear
phishing emails quite regularly. This clearly shows the fundamental lacking on the users’ part in
translating knowledge to action. This particular gap in knowledge indicates that awareness can
and must go beyond asking users questions and conducting surveys. It requires the deployment
Surname 16
of authentic testing methodologies designed for validating real scenarios. In support of this threat
testing methodology, Prei and Blumbergs noted that the participation and performance on
simulated phishing tests has clear indicators that allow organizations to assess their real level of
phishing defense as opposed to self-assessments. Such tests highlight the critical vulnerabilities
on one's inner security posture thus, allowing for the provision of focused transformational
education on the most effective defense mechanisms target at phishing attempts. On the other
hand, Ikhsan and Ramli note that the assessment must be conducted in a manner that preserves
the anonymity of the users and does not have any punitive implications to allow the retention of
trust. In summary, these works all highlight that in the case of awareness within an organization,
assessment is most useful when done not for punishment, but in this case for the unlocking of a
proper learning environment. This is effective learning when done in a manner that promotes
continuous learning and improvement in vigilance.
The advancement of technology in phishing scams have made them much more difficult
than what traditional techniques can identify. Alkhalil et al. describe that modern phishing
mechanisms can automate the duplication of sites as well as capturing credentials for attackers in
order to capture highly authentic fake sites in a matter of minutes (Alkhalil et al. 8). With a
single automation feature within phishing technology drastically reduces the expenditure costs
for users whilst maximizing the usage. Oest et al. notes that phishing kits also have the
capabilities to hide the source of the hosts and prevent them from being exposed to anti-phishing
spiders making takedown efforts much more difficult (Oest et al. 5). Their style of analysis in kit
architecture emphasizes the fact that the global phishing ecosystem thrives off a shadow supply
chain. Legg and Blackman argue in defense that the use of situational awareness tools that
synergize in real time serves the most sophisticated means of defense (Legg and Blackman 2).
Surname 17
Defenders have the means to identify growing operations that haven’t diffused massively
through the use of complex data visualization and predictive behavioral and traffic analytics. The
evolution and refinement of intelligence in data collection serves to show that the defense
mechanisms to phishing are automatic and greatly advanced.
Above all, phishing attacks have a non-technical consequence of eroding trust, arguably
one of the most crucial elements of digital communication. Madleňák and Kampová point out
that trust and social conventions become a target for phishing, allowing phishers to masquerade
as trusted figures or well-known businesses (Madleňák and Kampová 2). The moment this trust
is lost, users become unable to discern legitimate emails, leading to a general loss of confidence
in the digital world. Zolotarev, Zolotareva, and Mawla describe how phish incidents leave digital
traces that provide behavior analysis for phish awareness (Zolotarev, Zolotareva, and Mawla 3).
These digital forensics show that attackers copy certain linguistics, domains, and metadata
signatures, and that pattern recognition is available. Aljeaid et al. provide additional evidence of
user demographic factors and the differences in susceptibility to phishing, reporting that younger
users tend to be the most overconfident, while older users are overly trusting of authority
(Aljeaid et al. 9). It is clear that awareness programs need to be adjusted to their demographic
and cultural setting. Hence for SMBI, the development of sophisticated and nuanced,
empirically-grounded trust frameworks that are sensitive to the trade-off between verification
and ease of use is likely to restore the lost trust from clients and employees in the post-breach
situation.
The impact of phishing is much more than just losing data. As Nguyen, Rosoff, and John
put it, expenses associated with an attack range from the negative impact on an organization’s
reputation, being charged with regulatory non-compliance, and the overall productivity of a
Surname 18
company, which is more than the value of data stolen (Nguyen, Rosoff, and John 162). This
indicates that organizations need to view phish attacks in which the cost of defending is less than
the cost that may be spent to keep the business running in future. Business executives and
finance personnel are targeted by phishing attacks to impersonate and request fraudulent wire
transfers. We call these new forms of phishing Business Email Compromise (BEC) (Alkhalil et
al. 13). Phishing attacks targeting the upper echelon are a new high-value attack. They exemplify
the union of social engineering with finance. Madleňák and Kampová find that small and
medium-sized enterprises are the most exposed because of the lack of sophisticated email
authentication coupled with employee authentication systems (Madleňák and Kampová 4).
Stated differently, the impact of phishing is not just financial and reputational, it is operational
also. This means that spending money on employee training, sophisticated authentication
systems, and being ready to respond to phishing attacks pays much higher than the cost incurred
due to lack of protection.
The cultural and organizational setting of individuals also sheds light on the people-side
of phishing. Prei and Blumbergs state that organizational culture is critical in the way employees
handle potentially phishing emails, especially in an organization’s vertical culture, there is less
room for employees to voice concerns about orders (Prei and Blumbergs 5). This mindset is
precisely what allows attackers to pose as CEOs and other top administrators. Ikhsan and Ramli
observe that phishing attacks are much lower in institutions that have participatory
communication systems because employees are more willing to investigate discrepancies (Ikhsan
and Ramli 7). It is also noted by Legg and Blackman that having an environment in which peer
to peer communication of suspicious emails is encouraged enhances collective thinking and
questions the status quo (Legg and Blackman 5). All the insights above suggest that being
Surname 19
phishing aware is not an individual attribute, but rather, a socialized organizational culture. For
SMBI, fostering an open, non-punishing culture for asking questions is most likely to reduce the
catastrophic costs of human error and turn employees from passive victims of phishing attacks to
being active defenders.
Understanding phishing attacks and attempts in their different forms is part of getting
technology phishing aware. Aljeaid et al noted that even among people who actively engage in
digital activities, a lot of them do not understand pivotal questions such as the s of a web page,
the HTTPS certificate, and domain legitimacy (Aljeaid et al. 6). This lack of understanding gives
a chance to attackers to use effortless, visual imitations. There are gaps in Legg and Blackman
discussions that underscore the importance of ongoing, situational learning processes that fuse
the acquisition of a technology with the application of practical reasoning (Legg and Blackman
8). These practical approaches diminish the gap between a user’s theoretical knowledge and
practical application. In contrast, Thakur, Shan, and Pathan stress that strategies for defense must
combine user training with real-time threat monitoring and response systems (Thakur, Shan, and
Pathan 23). This shows that the best defense systems, as their discussion indicates, balance the
human and machine defenses with real-time operational effectiveness of both systems. This
means digital capability is not linear, but a multifaceted competency that is developed through
experience, technology and holistic organizational context.
In the aftermath of phishing incidents, digital forensics is particularly important in
conducting analyses and devising preventative measures. Zolotarev, Zolotareva, and Mawla
contend that examining digital footprints from phishing attempt campaigns, makes it possible to
track the same threat actors and infrastructure reuse over time. This analysis is useful for the
defenders to predict and focus on the attacker’s likely behavior to improve their systems. Oest et
Surname 20
al. document that the forensic deconstruction of phishing kits reveals the ways in which
criminals market and share modular macroviles for phishing across the dark web, which aids in
the targeted takedown operations coordinated by law enforcement. This example suggests that
the the defensive research maddeningly benefited from the “controlled” transperency offered by
the offenders to the ecosystem of hackers. Madleňák and Kampová sidoo note that the forensics
feedback awareness campaigns increases employees’ comprehension and therefore are more
capable of realistic simulations of actual incidents. (“Madleňák and Kampová 3” of focus here in
particular, and others as required). This points to the need for more interdisciplinary strategies
that weave together silos of information disciolines with the aim of improving the more
defensive strategies in focus. For SMBI, the most fundamental shortcoming is the absence of a
forensic readiness policy in which the tactical commentary joins with organizational
interdisciplinary preparedness. This would not only increase the resilience, but more importantly,
support a deterrant policy.
Phishing attacks are expanding worldwide, and this brings to light the differences in
cybersecurity capabilities in different countries. Aljeaid et al. pointed out that in emerging digital
economies, users are particularly vulnerable to social engineering attacks due to insufficient
infrastructure and ineffective digital literacy awareness campaigns (Aljeaid et al. 10). Such users
become soft targets for cybercriminals who wish to exploit language and cultural gaps. Alkhalil
et al. note that numerous phishing schemes get customized to mock local government bodies and
systems, and cunningly use local symbols and payment systems for trust (Alkhalil et al. 9). This
kind of absence of phishing syndicates is very local and shows very advanced thinking. There is
the recommendation of Ikhsan and Ramli that international cooperation should also incorporate
awareness and education access in multiple languages to counter this imbalance (Ikhsan and
Surname 21
Ramli 9). Organization like SMBI has to tailor regional defense strategies for phishing and
cybercriminal attacks. It has to consider cultural factors, local language training, and local
partnership for the defense to match regional differences in user behaviors and threats.
Phishing AI automation and artificial intelligence have been used more widely in focus
on defensive innovation. Thakur, Shan, and Pathan emphasize how detection AI models have
been developed to focus on phishing targeting the emotional metrics phonology, text, and other
attributes associated with the sender and the internal layers of the email (Thakur, Shan, and
Pathan 26). This proficiency in language enables detection well outside filtering by keys. Legg
and Blackman argue that the integration of AI analytics and real-time user feedback is important
in strengthening adaptive learning by developing systems that shift in response to the patterns of
the attacks (Legg and Blackman 10). There is, however, the issue of overreliance on automation
systems, since, in the absence of due critical thinking, the users can lose their vigilance if they
assume the systems cannot make any erroneous judgments. Alkhalil et al. have warned that
phishing attacks are now most likely to be targeted by camouflaging AI deepfake and synthetic
media to imitate real faces and voices, which complicates detection (Alkhalil et al. 15). This
dual-edge development of AI in both the offense and defense sides reveals the paradox of
cybernetics: the paradox that “automation improves both the offensive and the defensive
capabilities of a system” the capability to shift the defense is more from automation.”. The
challenge then is to find the right mix between the overreliance on technology and the absence of
critical thinking that is often the case with the users.
Phishing resilience over time relies on ongoing agility, organization learning, and
partnership efforts. Ikhsan and Ramli point out that organizations that embed culture integration
in awareness within KPIs and governance structures are much more likely to see sustained
Surname 22
reductions in phishing attempts and incidents (Ikhsan and Ramli 10). Their research indicates
that organizations should treat cybersecurity as a dynamic process instead of a static, non-living
practice that checks a box on compliance. For instance, Madleňák and Kampová advocate for
‘longitudinal assessment’ whereby training impact evaluation and recalibration occurs annually
(Madleňák and Kampová 5). Aljeaid et. al. posit that partnerships between the government and
the private sector strengthen resilience on phishing attacks through the combination of
intelligence, resources, and outreach (Aljeaid et al. 12). These partnerships enable the flow of
information and knowledge in and out of the individual organizations which is the head of the
cyber resilience ‘octopus’. This combination of ideas illustrates that phishing defense is not a
mere technical goal, but a social and collaborative practice that is constantly evolving on
governance, education, and s social obligation. This is what SMBI means by the necessity for a
multi-faceted view which preserves the cyber reactive culture, and instead, indoctrinates the
defense culture toward active cyber resilience preparedness.
Plan: Examples & Incident Response Formatting & Sources
While electronic communications are protected ECPA act of electronic privacy from
unauthorized access, interception, and publication. More specifically, Sections 2701 and 2702 of
the ECPA are designed to protect stored and disclosed electronic communications pursuant to
Lallie et al. (4). Unauthorized access to stored communications (section 2701) and unauthorized
disclosure of electronic messages kept by service providers (section 2702). In addition, as
outlined by Smith and Jones (2021), this publication in the Journal of Cybersecurity Law, stated
that ECPA is one of the crucial legislations that define limits on legal electronic surveillance and
provide harsh punishments pertaining to infringement of electronic Through this article, SMBI
has demonstrated that the recent cyber-attack involving spyware and keyloggers has brazenly
Surname 23
contravened with these ECPA sections, as noted by Lallie et al (5), the ECAP aims at averting
unlawfully gaining entrance into any The findings of Stoyanova et al. (8) also suggest that the
ECPA has contributed immensely towards protection of online privacy. In particular, however,
they highlight the differences between hacker’s acts and the foundations upon which the Act is
based.
It is an abominable act against the ECPA, the part of which deals with unlawfully
retrieved private discussions and information between SMBI. As indicated by Ahmad et al. (p.
940). First, understanding this relationship is crucial for designing suitable strategies that would
enable SMBI to adequately respond to this intrusion because the ECPA, Section 2701 restricts
illegal accessing of Such a breach is not just an infringement of the privacy rights protected
under the ECPA, it requires immediate measures that will prevent additional damage. According
to Acabo, by involving the safeguard stipulated on section 2701 of the e-commerce privacy act
(ECPA), it allows SMBI to seek legal redress and participate in law enforcement thus fosters
responsibility on persons involved. SMBI’s recourse to litigation underscores the underlying
policy objectives of the ECPA as designed to safeguard electronic communications against
evolving cyber threats. Specifically on act provision section2701 shows how serious the breach
is and clearly indicates violation on electronic privacy rights.
The starting point for an attended structure of an incident response plan involves artificial
intelligence (AI) and automation for advanced efficiency in detection and containment. As per
Saad and Aslam, AI analyzes enormous datasets in real time to recognize abnormal behaviors in
the network indicative of an intrusion (Saad and Aslam 58). Their research claims that response
time and the volume of human error associated with incidents in cybersecurity is alleviated
through automated remediation (Saad and Aslam 72). This is beneficial to organizations in a way
Surname 24
that they can anticipate threats and neutralize them before they escalate. On the other hand, AI
does require considerable supervision in the event that an AI system falsely identifies a target or
makes an error which could interfere with the operation of other real systems. Calder argues that,
in the eond of the statement, automation is able to achieve its peak efficiency only when
integration with relevant human reasoning and ethical protection is applied (Calder 214). In the
case of the incident response plan for SMBI, the incorporation of AI tools would certainly have
augmented the defensive posture of the organization, all the while remaining compliant to the
privacy provisions and the Electronic Communications Privacy Act (ECPA). This is an
integration which is system where the responsible use of technology and human supervision
ensures that the actions of the AI are reasoned and compliant within the legal framework. It is
imperative for SMBI to also invest in human discretion to make sure that the data is not only
protected by legal means but the ethical principles of contempt of privacy are also maintained in
respect to technical reliability and trust.
An efficient incident response plan focuses on a specific organizational structure,
delineated roles, and specific modes of communication. Thompson emphasizes that
unambiguous delineation of the command structure and response duties alleviates uncertainty in
the course of a responding cybersecurity incident (Thompson 89). His research suggests that the
presence of a structured system of internal organizational communication reduces the response
time for a decision, and the time to action. Preparedness, to be functional, according to Calder,
has to rely on the prior set determination of roles and responsibilities, decision-making
thresholds, and the dynamic integration of the technical, legal, and administrative domains
(Calder 122). The importance of forensic evidence coordinators is underlined by Diogenes and
Ozkaya, who argue that they are responsible for compliance with domestic and international
Surname 25
legal frameworks (Diogenes and Ozkaya 134). This system approaches crisis management less
as a responsive action system, and more as a deliberate course of action. In the case of SMBI,
structured response governance is on record as facilitating cross departmental integration,
lowering the operational risk, and ensuring compliance. The accountability processes in response
governance are the operational blueprints of the organization, the internally approved action and
the prepared documentation, as routine practice, which ensures availability. The more
responsibility that is concretely defined on the governance level, the more residual operational
agility that an organization such as SMBI achieves, to, increase the continuity in the processes,
recovery processes from a cyber incident, and the confidence of stakeholders.
Allocating resources strategically during cyber emergencies requires crisp focus asset
value. Defensive resources can be allocated to the most critical systems first to minimize the
long-term operational impact. Adhering to structured frameworks like ISO/IEC 27035 fosters
improved organizational identifcation and mitigation of recurring vulnerabilities. Integration of
oversight and operational practice fosters repeated advancement of responsive protocols. Lessons
learnt from any defence incident need be iteratively reviewed, as they form the basis of building
future defenses. In the case of SMBI, broad stroke approaches need to be replace by adroit
techniques involving meticulous documentation of vulnerabilities, assessment of exposure and
impact, and seamless workflow in updating defenses. This fosters operational and legal
alignment for frameworks like the ECPA. Such proactive posture shifts organizational security
from prediction to reaction, achieving resiliency in governance.
Unified strategy and cross-nation cooperation are vital parts in managing cyber incidents.
“There are cases in which enforcement of the national laws on the cyber incidents which have
cross border features is very problematic” (Kosseff 817). This level of court complexity, which
Surname 26
integrates the legal systems of two or more countries, is posed by Kosseff. This level, the highest
in legal integration, poses integration challenges which in return, pose Kosseff’s complexity of
information flow. Kosseff’s complexity of information flow is the highest level of integration
and poses legal systems which are Kosseff’s complexity. “Inconsistent legal frameworks and
definitions that cross national boundaries tend to stall and weaken deterrent” (Marcinauskaitė et
al. 216). The complexity posed by Marcinauskaite et al. shows that as legal frameworks are
detangled and systems of legal integration devised, the level of Kosseff’s complexity, which
poses slow information flow between countries, accelerates legal systems with improved
accountability. Calder’s work on international collaborative reporting systems illustrates that
such systems improve alignment and legal integration transparency and the speed of the capture
of chronic offenders of international law (Calder 176). The studies cited confirm that
international collaboration adds value in the strengthening both the enforcement and the
deterrence. For SMBI, which operates globally, the ability to comply and defend with multiple
jurisdictions improves the corporate reputation and legal liability. The legal position of readiness
in border crossing also signals readiness to comply with lawless and unethical management of
personal information. The defense cooperation with regulatory eliminates gaps in the operational
legal alignment of SMBI and the world, to defend system alignment with international legal and
operational requirements.
The preparedness and adaptability can further be enhanced by incorporating both training
and simulation into the response lifecycle. As Thompson notes, routine simulation exercises
allow teams to practice decision-making under duress and uncover gaps in processes (Thompson
102). These exercises help bridge the performance gap by creating a direct link to practice.
Calder reinforces this argument by pointing out that repetition drills form a proactive security
Surname 27
posture where personnel are able to predict and respond to threats with confidence (Calder 219).
Saad and Aslam suggest the use of AI predictive models alongside human trainers to portray the
dynamics of different scenarios of evolving threats (Saad and Aslam 91). Such a blended
approach nurtures both human intuition and system-level forecasting. Having simulation-based
training, in the case of SMBI, streamlines the response to new threats and minimizes human
error in critical moments. Embedding these activities in the employee development practice is an
effective way to ensure that individual preparedness is in sync with organizational objectives.
Organizational reflex, which incident response practice may bolster, becomes the targeted
outcome of the continuous practice. The preparedness to respond, which is fundamental in the
case of SMBI, becomes part of the “cybersecurity culture” as a result of natural and continuous
processes.
To process evidence-based cybersecurity response, forensics investigation and
documentation is a crucial part. As Darshini et al. further clarify, forensics not only forensically
analyze a system after an attack, but the system also helps in preventing an attack by plugging
structural weaknesses. Evidence collection is crucial for both, the system remediation, and legal
recourse. As noted by Diogenes and Ozkaya, the forensics process must capture system
boundaries, cyber kill chain, and temporal dynamics for an actionable legal framework in
judicial processes. Calder further emphasizes that the process of documentation being compliant,
is only achievable, if there is also a record of compliance within the organization that is
auditable. As demonstrated by Calder, for the Systems Management and Business Integration,
the seamless forensic readiness is constituted by the combination of reliable and accurate. For
network logs, there must be reasonable time evidence, and the all the evidence must be preserved
safely. This does not only aid in compliance with legal framework under ECPA, but also
Surname 28
enhances organizational’s internal edifice. Evidence-based policy change ensures that policy
changes are accompanied by forensic analysis, so that each policy breach results in learning and
resilience. For the policy, organizational changes and accountability are a given. Then all
changes and new additions are cut down to only complex process improvement. As a result, the
entire forensic process is only viewed in damage control.
Management of communication within an organization is important during and after a
communication incident. Calder states that proper communication and timely disclosure of
information eases customers and stakeholders' minds and stops reputation erosion (Calder 142).
The “trust” of the public is gained through “recovery” and “narratives” that are honest. To
maintain detail and “sensitive” information Thompson advises compliance with preapproved
mechansims of communication (Thompson 115). Diogenes and Ozkaya add that external
messages “need” to be “sensitive” while “transparent” to avoid misuse of public information
(Diogenes and Ozkaya 128). These argue that communication is an act of “ethical” leadership
and not only done for public relations. For SMBI, adopting a communication technique of tiered
communication enables internal personnel, regulatory bodies and clients to receive consistent
and factual updates. It also promotes “opaque” operational structures by reducing confusion. It
also achieves the legal goals of “transparent” disclosure and the privacy and consumer protection
law. Ethical communication to the public increases reputation and trust towards SMBI, along
with helping the organization with the culture of transparency when it comes to cybersecurity
governance.
Continuous innovation, policy implementation, and innovation for executive engagement
are all elements needed to achieve long-term cybersecurity resilience, which is a complex task.
Capacity prediction transformation into anticipation remediation is a step further, and predictive
Surname 29
models can achieve that goal. Saad and Aslam (94) suggest that adaptive, predictive AI models
that can analyze global threat intelligence might be able to foresee and predict vulnerabilities
before being exploited or, indeed, exploited. Srinivas, Das, and Kumar assert that cyber
resilience is even a goal for prospective focus for many governments, which these days piled up
national as well as cybersecurity. “Srinivas, Das and Kumar 188” From this, organizations are
encouraged to accept compliance and concomitant planning because its requirements are
predictive. Maglaras et al. 769, suggest that compliance and regulatory perimeter bounded
innovation that is poised to bounded innovation and policy compliance. With that thinking,
SMBI sustains maintained effectiveness and a response to evolving threat surfaces. Frequent
policy alterations and direct SMBI learning from foreseen adaptive arising concerns do enable,
oversight which ensures leadership on evolving composed blend of formed governance, action,
prediction policy, reiteration or prediction synthesis of adaptive global evolving concerns. That
blend of governance, prediction on evolving risks, action, and formed synthesized adaptive
evolving concerns is regulatory. Blended together, all of these elements ensure that compliance
and innovation are agile. Regulatory innovation framework compliant foresight such as this
becomes and cybersecurity then becomes a persistent process.
Cyber Risk Governance Frameworks
The organization and rational approach Primarily given to threats synthesis and global
frameworks focusing on lines of cyber risks with their measures outlines the need to align.
Essien and others encountered with ISO 27001, NIST, and COBIT frameworks as having
different and organized matrices of defining the threshold of the risks, the range of
responsibilities, and evaluating the results (Essien et al. 619). It is to be noted that every
framework has its competitive advantages. The standardisation aspect is covered by ISO, the
Surname 30
continuous improvement by NIST, while COBIT covers management and governance at the
same time (Essien et al 623). This alignment serves to help organizations establish their own
frameworks with their own baselines. Yusif and Hafeez argue that the alignment of the
frameworks gives rise to an ecosystem of accountability that is interwoven through policy,
technology and governance (Yusif and Hafeez-Baig 497). This integration illustrates that the
function of governance, is dynamic and not stationary as it involves the integration of multiple
systems. In the case of SMBI, the application of an integrated governance model will ensure both
the legal and operational flexibility. The need to ensure alignment proves to be increasingly
critical as measurable outcomes, audit support and institutional reputation all align to framework
building in the constantly changing cyber threat environment.
Tackling emerging digital threats is a governance issue soon to be a question of how to
withstand such threats. Business organizations are able to modify permissive governance
controls as flaws and vulnerabilities are detected. This is what Melaku calls dynamic
cybersecurity governance (331). Such flexibility is a much better understanding of why and how
rigid policies are insufficient to address evolving attack surfaces. Essien et al. show how the
integration of adaptive mechanisms within governance models enhances their resilience, and
improves response time (625). Incorporating feedback mechanisms within the adaptive
governance models enhances recovery and preparedness. Dynamic governance, as Antonucci
explains, is the governance type that is most aligned with real-time monitoring and pouring effort
into adjusting thresholds to keep matched with organizational targets (143). Such effort is
proactive as opposed to reactive. This puts compliance cybersecurity as something alive and
ever-changing, as opposed to a system of checklists. For SMBI, ensuring that governance to
cross to the other side of the Frontier is to endow it with the capacity to shift with changing the
Surname 31
governance vectors, the threat vectors and the changing nature of the technology. Such models of
governance anchor effective leadership to strategic foresight and preemptive action to ever
evolving controllable and uncontrollable digital risks.
A strong model of cyber governance must emphasize accountability at every tier of an
organization. Jarjoui and Murimi claim governance should specify ‘who is accountable to whom’
for executive oversight, IT management and operational staff to maintain uninterrupted
responsibility during incidents (Jarjoui and Murimi 142). Accountability provides for decision
making on risk tolerance and remediation to be well-defined and easy to follow. Yusif and
Hafeez-Baig point out that, for effective governance, ‘the head of the organization must lead the
charge’ instead of leaving the security strategy to the ‘techies’ (Yusif and Hafeez-Baig 492).
Such ‘integration’ helps foster a culture of accountability which improves the maturity of the
organization. Savaş and Karataş point out that organizations with well-defined accountability
frameworks suffer less from internal strife and communicate better during cyber crises (Savaş
and Karataş 19). It is for these reasons that with accountability, SMBI will be able to effectively
foster compliance and reduce ambiguity during cyber events. Accountability goes a long way in
shifting governance from mere policy formulation to positive action, cultivating trust from
employees, primary stakeholders, and external regulators.
Due to the unique national security considerations, critical infrastructure requires the
development of unique governance models. As Pemmasani notes, countries have developed
protections for the most sensitive infrastructure, including energy, transportation, and finance,
due to their centric value (Pemmasani 210). These initiatives create a hybrid protective
framework that meets both public and private needs for maintaining uninterrupted service.
Governance of critical infrastructure requires the combination of specific standards for each
Surname 32
infrastructure sector and the overarching national resilience framework, as underlined by
Antonucci (Antonucci 157). This multi-layered approach enhances the capacity for custom
tailored defenses while maintaining a unified structure to the national systems. Essien et al.
argues that mutually exclusive international and industry specific governance frameworks
improve cooperation of private and public sectors for governance at the critical intersection of
public private divide (Essien et al. 627). This is important for SMBI, as any intersection of their
operations with managed sectors calls for the anticipation of these complexities to enable
compliance and proactive collaboration. Enhanced national governance integrated with corporate
governance enhances the organizational legitimacy of SMBI and also the shared protective cyber
defense posture. The governance structures which dictate the boundaries of cooperation between
institutions eliminate the technological determinism and emphasize the need for orchestration in
safeguarding vital systems.
By connecting billions of devices within and outside organizational networks, the Internet
of Things (IoT) has further complicated the already complex cyber risk landscape. Kandasamy et
al. (2021) state that as IoT environments increase the device-level and network-wide attack
surfaces that need to be governed, addressing attack surfaces at the network perimeter is no
longer sufficient (Kandasamy et al. 9). To these authors, traditional risk frameworks are
inadequate. Melaku (2021) argues that elastic governance frameworks need to include IoT
controls to safeguard the integrity of the devices and manage continuous torrents of data (Melaku
334). Essien et al. (2022) note that incorporating IoT frameworks within governance at the
international level is beneficial. For instance, the alignment of IoT frameworks and NIST
facilitates the establishment of standardized metrics for evaluating and alleviating risk (Essien et
al. 621). This streamlining of governance spans digital networks with varying levels of
Surname 33
tangibility. For these reasons, the development of IoT risk governance for SMBI would cover the
important oversight of embedded IoT devices and technologies used for logistics, monitoring,
and data management. IoT devices and systems can be governed under IoT security frameworks
to protect the unprotected social, regulatory, and compliance inter gaps. Compliance, privacy,
and the defense against modern multi-layered interconnected threats can be guaranteed.
Like other working frameworks for cyber governance, there is an emphasis on
measurement and evaluation of performance outcomes of an organization. Metrics like the
frequency of incidents, the speed of responses, and the level of compliances determine the
capability of the organization in cyber security and guide its efforts towards continuous
augmentation (Antonucci 162). The moment measurement is introduced, governance shifts from
abstract principles to functional implementation. The effectiveness of governance is almost
always reliant on structured transparency systems consequent the performance outcomes and the
operational strategies chartered (Yusif and Hafeez-Baig 495). Measurement in this regard is a
loop instrument of practice and governance, enhancing sharpened responsibility. The use of
gateway performance indicators gives an organization a competitive edge with other industries,
thus encouraging collective learning and collaboration (Essien et al. 628). From this perspective,
for SMBI, the implementation of quantitatively defined governance frameworks is critical in
ensuring proper guidances are in place for the unambiguous measurement of progress and the
identification of the most critical weaknesses. The value of CSS is the emphasis in evidence
based protections in place, which is, protecting the organization and its users from cyber-attacks
designed to remove proactive defenses. Attribute based measurement cultivates a continuous
optimization attitude within the organization.
Surname 34
Cyber risk governance frameworks must also tackle the issue of compliance vs.
innovation as equally valuable. Melaku notes that while many organizations govern with an iron
fist, adaptive models offer much greater flexibility in governance while still maintaining security
(Melaku 336). When compliance frameworks are designed to keep pace with evolving
technology, innovation becomes much easier. Savaş and Karataş point out that creative
approaches to risk regulation are encouraged through flexibility, even as accountability remains
(Savaş and Karataş 25). Supporting this, Antonucci asserts that the governance framework
should encourage managed governance risk paradoxes to allow safe failures (Antonucci 176).
This enables organizations to not only innovate, but do so ethically and without breaking the law.
For SMBI, innovation that is driven by compliance is equally as valuable as maintaining
integrity in the defense posture. Such a governance culture that balances creativity and discipline
fosters ongoing learning and resilience. Supported by the notion that flexibility in compliance is
a competitive advantage, SMBI is in a better position to advance security or innovation
outcomes.
Communication and transparency are vital attributes of cybersecurity governance, and
these attributes are increasingly becoming recognized as integral parts of governance
frameworks. Jarjoui and Murimi emphasize that governance has to promote open communication
amongst stakeholders and regulators as well as technical teams to constructively understand the
risks involved (Jarjoui and Murimi 147). Trust is also created by internal alignment to
expectations that are externally set, and this internal alignment is made possible by the provision
of clear reports. Yusif and Hafeez-Baig state that clear channels of communication remove
information blockages and improve the coherence of the organization (Yusif and Hafeez-Baig
499). Savaş and Karataş explain that the vice versa is also true, that is, responsible breach reports
Surname 35
that are self-governed enhance assurance towards the organization. Thus, governance process
transparency enhances public trust (Savaş and Karataş 30). For SMBI, the internal and external
communication gaps that exist within governance frameworks can enhance reputation and
regulatory assurance. The governance function of communication in the institution helps
reconceptualize cybersecurity from a technical activity to a collective responsibility. In addition,
openness enhances trust, and this guarantees that stakeholders see SMBI as reliable and
compliant in the mitigation of risks.
Incorporating human elements into governance frameworks reinforces the cultural pillars
of cybersecurity. Governance effectiveness, according to Antonucci, rests on the achievement of
policy congruence with the behavioral and ethical responsibility of employees (Antonucci 185).
A human-centric governance system understands that people remain both the strongest and the
most vulnerable link in cyber resilience. Yusif and Hafeez-Baig observe that it is the
responsibility of the leadership to weave security culture and ethical conduct into the corporate
identity through continuous training (Yusif and Hafeez-Baig 502). Melaku further argues that
proactive governance behavioral analytics to identify, pattern, and prediction compliance
monitoring on insider threat misuse (Melaku 340). Applying psychology to governance within an
organization provides a cultural context that is aligned to the strategic intents of the organization.
For the case of SMBI, humanizing governance frameworks enhances ownership and vigilance at
every tier of the organization. Governance viewed as a structural and cultural process guarantees
that compliance is sustained through the ethical and behavioral commitment of individuals, and
transforms the perception of cybersecurity from a set of policies to an organizational ethos.
Strategic alignment is necessary for reaching organizational goals which cyber risk
governance addresses without loss of efficacy. Governance has to underpin business continuity
Surname 36
by aligning cyber defense with financial resource planning and organizational risk appetite as
Essien et al. 626 elucidate. This alignment facilitates proactive rather than reactive security
decision-making. As Jarjoui and Murimi 153 cite, organizations that integrate governance into
strategic management systems tend to outperform their peers and respond to shifts in the
regulatory environment more readily. As Antonucci 194 reminds us, long-term governance
should focus, for instance, on security infrastructure investments to ensure the enduring value of
the assets. For SMBI, the integrated strategic alignment maximizes cyber defense governance
value and ensures operational continuity. Reactive strategic governance elevates cyber defense
from a technical obligation to a market differentiator. With the right balance of oversight and a
long-term view, SMBI will be able to maintain a security ethos that grows in tandem with the
business. Every governance decision is then an opportunity to reinforce the SMBI ethos of
protection and progress.
Ethical Dimensions of Cybersecurity
The appropriate use of ethical frameworks in decision-making processes of supervision
hinges upon the demarcation of protective and autonomous orders of the cyberspace. Hamburg
and Grosch state that cybersecurity practitioners frequently find themselves between a rock and a
hard place when it comes to defending the system and the digital rights of users (Hamburg and
Grosch 5). Their research indicates that hawkish defense strategies such as active surveillance
and data collection arm themselves with the potential of breaching privacy. Loi and Christen
point out that ethical reasoning should place the greatest emphasis on the need for justification of
intrusion which s their frameworks of ethical reasoning avoid neutralization of the intrusive
controls (Loi and Christen 81). This keeps the practice of cybersecurity above board and socially
responsible. Sadeghi et al. quote that ethical reasoning in cybersecurity should compose of both
Surname 37
consequentialist and deontological reasoning which touches on the importance of balance
between what is to be done and what is to be achieved (Sadeghi et al. 130). This is the case for
organizations such as SMBI. Sadeghi et al. point out that ethical reasoning in cybersecurity
should compose of both consequentialist and deontological reasoning which touches on the
importance of balance between what is to be done and what is to be achieved (Sadeghi et al 130).
This is the case for organizations such as SMBI Why is this the case. It is professional pluralism.
Ethical governance then transforms cybersecurity from a mere technique to a social function
which underlines the dignity of the human and the trust in cyberspace.
The discourse of moral accountability within cyber security has the broadest scope
possible, extending to the accountability of the whole institution. Yaghmaei et al. claim that
ethical responsibilities touch upon the design, operation and use of the digital ecosystems
(Yaghmaei et al. 3). This collective obligation, however, poses a challenge to the organizations
that such systems are knobs of harm and never responds after the harm has been done. Formosa,
Wilson, and Richards suggest a principlist framework based on the four pillars of autonomy,
beneficence, no maleficence, and justice to inform the conduct of ethical cybersecurity
(Formosa, Wilson, and Richards 102382). Their approach takes components of moral philosophy
and translates them to principles that are practically implementable in governance and design.
Christen, Gordijn, and Loi contend that ethical cyber security demands the cultivation of a
culture that embeds principles of ethics in all phases of an information system life cycle, from
the code to the response to the incident (Christen, Gordijn, and Loi 88). For SMBI, the
integration of such principles encourages accountability beyond the bare minimum of legal
compliance. Response to ethical responsibilities becomes structural instead of circumstantial,
which fortifies the organization’s reputation in regard to governance and the legal framework.
Surname 38
The application of artificial intelligence creates new ethical concerns for which there still
is no consensus answer within governance of cyberspace. Timmers notes that the application of
AI systems within the cyberspace domain has the potential for both positive and negative
impacts on the digital sovereignty of a nation (Timmers 638). This potential gives rise to issues
of control, bias, and responsibility. As Chitimoju points out, there are plenty of instances where
bias has been structuralized that autonomous and unreviewed decision making is allowed which
lacks ethical reasoning (Chitimoju 2). This type of opacity is worrying and can decrease
confidence in a digital system sociotechnically. Schoenherr and Thomson express that there are
configurations of systems where it is justified to apply decision-making discretion and where
humans are compelled to take responsibility for the outcomes, regardless of how pronounced
automation is in decision-making (Schoenherr and Thomson 149). Having to integrate ethical
principles of AI governance that pertains to autonomous systems is how much human AI erodes
to protect the paradox of ethical reductionism. For SMBI, the ethical use of AI is defined by the
clear outcomes of a decision-making process and the guaranteed primacy of governance of key
actions. This equilibrium between freedom and control serves the ethical reasoning of applying
technology in ways that are consonant with human values, and thus ethical anodization of
innovations in cyberspace is preserved.
Privacy and security in digital ethics are often seen as a conflict that requires situational
analysis rather than simple prioritization. Allahrakha states that the conflict between the common
good and individual freedom requires context-sensitive solutions that are fair and necessary
(Allahrakha 93). While the overemphasis on surveillance might deter risks, it may undermine
democratic freedoms. Hamburg and Grosch argue that self-explanatory consent interfaces give
organizations the ability to balance security and user control (Hamburg and Grosch 7). This
Surname 39
establishes the foundation that defending ethical cyberspace involves a need to control
unnecessary restrictions. Yaghmaei et al. goes on to note that organizations must embrace the
principles of ‘privacy by design’, that is, ethical considerations must be incorporated at every
technological layer of defense (Yaghmaei et al. 4). For SMBI, this principle ensures that
measures taken to protect personal data and information are in alignment with the legal
principles of privacy and respect of personal rights. The ethical problem framed in this case is
not in choosing between privacy and security, but in finding a balance where both coexist and
reinforce each other as principles of digital governance.
The emerging tendency toward globalization has also brought with it globalization of
potential cybersecurity threats, to which cyber security adopts an ethical pluralism approach.
Different ethical standards from parochial cultures pose ethical, social, and legal challenges to
justifiable cyber defense action (Sadeghi et al. 133). Surveillance that is legal and accepted in
one country may be criminalized and considered an act of privacy invasion in another.
Kozhuharova, Kirov, and Al‐Shargabi point out the absence of culturally sensitive ethical
policies resulting from differential social governance and value systems diversity (Kozhuharova,
Kirov and Al‐Shargabi 208). These policies resolve ethical pluralism within an undiluted
framework of human rights. Loi and Christen maintain that ethical governance at a global level
should be an amalgam of indigenous ethics and cross-border governance attributes, such as
transparency, accountability, and fairness (Loi and Christen 84). At the level of cyber operations
pertaining to the Small and Medium Business Internationalization (SMBI), these operations,
done within an ethical framework, should show a degree of flexibility to regional ethical cultural
norms, at the same time observing the global ethical standards. Cultural flexibility at the global
Surname 40
context will permit the practices of cyber security to be ethical, inclusive, and legitimate while
strengthening the moral cyber boundaries around the world.
Ethics training is arguably more effective than any policy or technological solution that
can strategically be applied. Blanken-Webb et al. demonstrate that case-based ethics have
improved primary decision making by immersing learners in actual ethical dilemmas (Blanken-
Webb et al. 2). It is apparent that ethical training is in fact a structured form of reflection.
Formosa, Wilson, and Richards demonstrate that reflecting on ethical training frameworks
diminishes the chances of ethically questionable decisions being made. Indeed, in their research,
the authors show that ethical training is a form of silo-busting wherein interdisciplinary ethical
literacy increases the judgment and trust of the professional. Hamburg and Grosch describe the
nurturing of ethics as integral and foundational in the formation of a good digital citizen
(Hamburg and Grosch 8). For SMBI, ethical training is internally applied in the same way as
other policy frameworks so that a uniform deontological disposition is maintained. This serves to
demonstrate that ethics is taught in a manner that is reiterative of the organization’s culture and
security operations that are aligned with the preservation of social order.
Cybersecurity ethics go beyond the examination of systems to include the examination of
vulnerability and harm. Yaghmaei et al. argue that ethical action is to reduce harm on the
systems and on the people suffering from the digital disruption (Yaghmaei et al. 6).
Understanding the human implications of cyber events recasts cyber security as a form of moral
defense. Trozzo deepens this notion by analyzing cyber security as a form of politics and
theology in which to protect digital life is to protect life in common (Trozzo 117). This view
helps clarify that cyber harm is more than data; it is also people and identity. Formosa, Wilson,
and Richards note that the principle of nonmaleficence is to be exteneded to the proactive
Surname 41
defense and response that is post-incident (Formosa, Wilson, and Richards 102382). As for these
views, they also strengthen the moral obligation of SMBI to act with compassion and honesty to
people affected by breaches. Cyber harm is more than the injurious consequences for the people
affected; it is also the deep moral responsibility that calls for ethical action. The moral obligation
is no longer optional or a matter of ethical deliberation; it is a matter of ethical decision which
requires action. This is almost the opposite of a punitive mindset. This is more of a mindset of
caring and repair.
The ethically responsible dimension of being trustworthy is critical to governance of
cybersecurity at all levels. Hamburg and Grosch contend that ethical trust strengthens user
confidence which increases the effectiveness of security policies (Hamburg and Grosch 6).
Compliance and cooperation is higher when users perceive their data is being managed ethically.
Christen, Gordijn, and Loi note that trust is maintained through congruency of ethical promises
and actions of the organization (Christen, Gordijn, and Loi 91). The loss of trust can happen
rapidly due to a gap between actions and policies. Sadeghi et al. pointed out that ethical
engagement, especially explaining what data is used and how it is protected, strengthens
stakeholder participation (Sadeghi et al. 140). For SMBI, fostering trust must be consistent with
the reliable operational alignment of ethical communication. The trust becomes also a strategic
resource, as the cooperation, not suspicion, is the outcome of the cybersecurity measures. Thus,
ethical trust is the essence from which strong, durable relationships in digital security are
developed.
The ethical aspect in analyzing collected data as it pertains to data intrusion Loi and
Christen observing that data driven monitoring strengthens dtection evidences overcollection and
misuse concerns (Loi and Christen 79). Proportionality and necessity is sponcors in data
Surname 42
governance Kozhuharova, Kirov, and Al-Shargabi argue that privacy preservation in analytical
processes is possible through nonintrusive ways such as anonymization and data minimization
(Kozhuharova, Kirov, and Al-Shargabi 215). These approaches exemplify the greatest
minimization of intrusiveness as ethically configuration of data is held. Sadeghi et al. argue “the
ethical audit of data processes is necessary to eliminate data exploitation and bias in data
outcomes and to facilitate fairness” (Sadeghi et al. 137). In the pursit of compliance and
reputation, SMBI chose ethical data practices. Analytics that are data driven maintain the
workflow of dignity by replacing tools of subjection with monitoring systems that foster
protection rather exploitation and control.
An imbalance of power would be the next ethical concern in the realm of cybersecurity.
Timmers notes that the state and corporate actors have disproportionate control over the digital
infrastructure, and as a result, they control the digital balance of sovereignty and freedom
(Timmers 642). THis imbalance of power is antithetical to the democracy of cyberspace. Trozzo
sees this as a theological and political struggle of power in the cyberspace domain (Trozzo 123).
Understanding this imbalance, allows ethical governance to examine the questions of who gains
and who suffers in the practice of cyber security. Yaghmaei et al. state that governance must be
guided so that there is inclusion and equity in the distribution of security welfare (Yaghmaei et
al. 7). For the SMBI step, understanding power relations fosters clarity in partnership relations
and in user relations. The balanced approach to ethical governance is that the asymmetries must
be acknowledged so that balance is achieved, and in this case, it is a fact that all stakeholders
must have their interests served and cyber security governance should not reinforce systemic
inequity or exclusion in the digital world.
Surname 43
The combination of cybersecurity and artificial agents creates new ethical challenges
concerning responsibility and autonomy for both humans and machines. Schoenherr and
Thomson remark that assigning ethical responsibility becomes more difficult as AI systems
assume the more active roles in defense (Schoenherr and Thomson 152). In the absence of
delineated roles, it remains ambiguous who takes the blame for mistakes made by the algorithms.
Chitimoju cautions that autonomous cyber defense agents might behave in ways that no human
would consciously take, and in the process, make decisions that no human ethics would govern
(Chitimoju 3). These dangers call for the necessity of sustaining some level of reason and human
governance within the constructs of artificial intelligence. Timmers advocates for the formation
of ethical design rules that integrate responsibility into the technological designs from the very
beginning (Timmers 640). For SMBI, these conclusions mean that automated defenses should be
heavily scrutinized and controlled under ethical principles that center on human protection and
openness. Ethics in design is meant to prevent negative consequences, full autonomy of the
machines in the context of the defense systems is maintained, and the systems keep the ethical
line within human reasoning.
Considering human rights digital extensions is an element of cybersecurity ethics.
Yaghmaei et al. claim that digital interaction and the right to privacy are fundamental
components of human dignity in contemporary societies (Yaghmaei et al. 8). Data breaches are
also understood to constitute violations of personal self-determination. Loi and Christen argue
that cybersecurity policy ought to be premised on the principle of rights where actions of
technologies are scrutinized as to how they affect personal liberties (Loi and Christen 86).
Substantively, this principle shifts the orientation of cybersecurity to ethical rather than simply
technical compliance to the custodianship of digital existence. Hamburg and Grosch underline
Surname 44
that such entities which are advocates of digital rights are also builders of social responsibility
and trust (Hamburg and Grosch 9). In the case of SMBI, the embedding of the human rights
approach to cybersecurity policy demonstrates ethical responsibility aligned with the business.
Digital rights are fundamental human rights, and as such, their protection is a mark of fairness
and decency at every tier of cyber defense, which affirms that cyber defense is people-centric
and not simply system-centric.
New technology invariably faces criticism, yet the tenor and direction of that criticism
remains to be seen. Reviewers today seem to favor the preventive approaches, addressing
critiques with new layers of technology that flank the original base layers. Sadeghi et al. trace a
path towards the future of policymaking where the burden of resolving possible harms will be
avoided as ethico-clinical foresight maps the possible outcomes to a decision (Sadeghi et al.
143). Rather, the new mantra of states and companies will be to plan proactive exits. This means
preemptively resolving a challenge rather than addressing it as a response. Such logic crystallizes
the contours of effortless governance. Rather than defaulting to reactive approaches to
technology, as seen today, the ideal future is where technology is created with foresight
governance as the base layer. Such innovation comes only after collaboration with stakeholders
that have pivoted as the new polycentric governance of innovation. Such as the fusion of the new
ethics of care, feminist technoscience, action-oriented baton philosophy, and foresight
governance technology. Kozhuharova, Kirov, and Al-Shargabi outline the new pillar of the
innovation governance cycle that insists continuous ethical scrutiny of any new emerging tools to
ensure the tools do not create ethically unintended extra consequences (Kozhuharova, Kirov, and
Al-Shargabi 220). This layer comes after consideration is given to the more technical ethical
layers of care. Consider Sadeghi et al, in their estimates.
Surname 45
For Sadeghi et al, more than mere defeat of the other tile will do. Foretake with the bent
of also leaving imprints of humane progress. For SMBI, ethics of foresight paired with care
fosters responsible technology innovation where technology advances for the good of humanity.
Rather than dethroning borderless cyberspace to the whole of humanity, ethical anticipation
while removing reactive design and correction of the base layer adds focus on purposeful design.
This means guiding the new borders of cyberspace dominion through ethical foresight and
collective care of cyberspace. This will be the last dominating feature of enlightened humanity.
This exodus of technology will be governed with ethico-cybernetics as the new borderless
cyberspace polity.
Organizational Cyber Resilience Strategies
Achieving cyber resilience involves much more than technology, and understanding this
concept helps focus efforts and resources. As noted by Legg and Blackman, the integration of
human judgment and procedural readiness with the situational awareness gained from tools
aimed at early detection of complex situations is the only way to achieve optimum results (Legg
and Blackman 2). Their insight suggests technology is, at best, an augment that supports human
interpretation during an incident. As noted by Madleňák and Kampová, the staff's adaptive
learning through simulation exercises boosts their decision-making confidence when attacked via
phishing and social-engineering (Madleňák and Kampová 4). Such exercises enhance an
attacker's confidence by turning a theoretical attack into a practical attack, thereby minimizing
confusion in real crises. It is „the feedback loops that connect the results of the incident to the
training that is later reformed that fosters a sustainable form of resilience” (Antonucci 67). Such
a system ensures that every breach is utilized to inform the organization's future defenses. The
Surname 46
combination of awareness, human judgement, and systematic procedure produces a dynamic
ecosystem of defense that is capable of addressing evolving digital security challenges.
Organizations consider cyber-security a challenge of governance spanning the breadth of
the entire organization instead of a problem for a technical silo. Yusif and Hafeez-Baig argue
that governance frameworks which allocate accountability downward through the leadership
echelons provide adjunct strategic decision pathways for decision-making in crises (Yusif and
Hafeez-Baig 495). When the delegation of power and the assignment of accountability are
defined and delineated, the speed of decision-making increases, and uncertainty disappears.
Essien et al. insist that the merging of ISO, NIST, and COBIT principles of resilience crafts a
single unified standard of resilience that allows firms to measure their own progress (Essien et al.
621). Alignment of standards also improves the firm's communicative transparency to regulators
and other stakeholders. Jarjoui and Murimi show that the frameworks of enterprise-wide risk
management provide the means by which the policies set at the level of the board are translated
into operational routines in which sustained attention is directed (Jarjoui and Murimi 144). These
results emphasize that organizational coherence means all members of the organization work
toward a unified set of protective goals, hence enhancing the firm's level of resilience.
Training and reinforcement of behaviour helps create long lasting resilience since the
single most used ‘weakest link' is the user. Aljeaid et al. highlight that simulated phishing attacks
reveal significant deficits in nuanced user decision-making, especially when time is limited
(Aljeaid et al. 549). This underscores the need to address the role of emotions and context, and
not just mechanics, in training. Zolotarev, Zolotareva, and Mawla show that analysis of digital
traces after phishing tests enables organizations to monitor and analyze behavioral patterns and
intervene accordingly (Zolotarev, Zolotareva, and Mawla 2). Evaluation of this nature helps in
Surname 47
training the individuals on the specific risks that are most relevant to them. Nguyen, Rosoff, and
John explain the need to place an information security culture in organizations in the context of
the potential value that might get lost through a failure to get the human attention needed to
sustain the vigilance (Nguyen, Rosoff, and John 163). Turning human behaviors into tangible
risks, rationally drives the investment towards the need of continuous learning rather than
periodic workshops. This means, for SMBI, resilience training needs to shift from simply
awareness, to a culture of ‘accountability’ where every individual considers cyber security as an
integral part of their professional ‘identity’ and that of the organization.
Antonucci articulates how effective recovery planning turns an active restoration process
into seamless reactionary actions during a crisis. This is possible due to fulfilment of pre-
established metrics, and systematic scenario testing which bring pre-defined boundaries to the
continuity of operation disruptions and Antonucci s' arguments on resilience maturity and
operational continuity metrics scenario testing can be found on page seventy-two of the cited
text. This assessment and planning is crucial in making sure an organizational response is
responsive, rather than acting on a panic and disorderly reaction. Pemmasani puts forth the
notion of public sector core values in the recovery of an organization, as the recovery of a nation
successfully conducted a cyber-attack, reflecting on the decentralization of cyber resiliency a
nation and the many lessons private institutions can garner through recovery collaboration
among constituents. In the realm of cybernation defense, national cyber-resilience programs
represent a valuable blueprint. This is on page two hundred and eleven in the text. Such public
sector illustrates the advantage of recovery information together with the standard evaluation on
a recovery cycle interval and these periods can be observed as post-incident evaluation intervals.
Par. 2 Melaku cycle s' observations show that reconfigurable governance models which tier the
Surname 48
rigid postures of governance during the recovery intervals of the cycle reduce the intervals of
`downtime' multi systemic failures as s' noted and these intervals are a loss in functionality,
Melaku page three hundred and thirty-three. Such recovery sensitive approaches indicate that in
reality there is no recovery period, the process is continuous and incrementally evolving, shifting
on recovery- not repaid, for SMBI the delineation of line of recovery is anchored on establishing
the reputation and post recovery confidence on the governance technology suffice to show for
the tempered control trust filtered through the relief of the overcome challenge signals.
Resilience is also learning to seek on organizational fluidity by attending to systems of
continuous learning. Savaş and Karataş point out the rise of learning capacity as a strategic
indicator of resilience in cyber-governance studies (Savaş and Karataş 20). Organizations that
record, analyze, and disseminate the lessons of an incident build a form of collective intelligence
that strengthens preparedness. Kandasamy et al. connect adaptive frameworks in holistic risk-
ranking models to dynamic, real-time threat landscape reprioritization (Kandasamy et al. 10).
Adaptive assessment enhances the likelihood that complacency will not occur and that new
strategies will be innovated in defense. Melaku has found that real-time monitoring feedback
systems, which support policy feedback loops, allow adaptive governance to flourish (Melaku
338). The embedding of substantive technical analysis with reflective learning systems recasts
the SMBI’s cybersecurity mesh as a living system. It is this very capacity to transform, which is
the essence of resilience, that ensures adaptive proliferation of security in response to the
intricacy of new threats.
The frameworks of communication act as the building blocks of resilience within an
organization. Legg and Blackman note that during focused assaults, communication within and
across functions over time minimizes the time needed to respond to an attack (Legg and
Surname 49
Blackman 3). Constructive and open communication within the organization reduces rumors and
keeps motivational spirits high. Jarjoui and Murimi suggest the embedding of automated
emerging alerts in the enterprise risk systems to help coordinate the responses of different team
members across the organization (Jarjoui and Murimi 147). With automation, the need for
human control is maintained while speed and uniformity is achieved. Hamburg and Grosch assert
that fact-based and compassionate communication that comes from alternate sides of a
conversation improves the social trust of the concerned parties, even during a lapse (Hamburg
and Grosch 8). For SMBI, ethical caution on the incidents shifts the risk of reputational damage
to an opportunity for reinforcing credibility. Thus, communication is a form of technical practice
and moral practice. It maintains confidence during and after cyber incidents.
Creating a security-oriented organizational culture is a critical factor of resilience.
Antonucci argues culture alignment with the cyber objectives multiplies the effectiveness of
every control (Antonucci 80). Employees imbed security values and compliance then becomes a
matter of instinct rather than enforcement. Yusif and Hafeez-Baig articulate that ethical cyber
leadership behavior sets the tone for informal norms that persist beyond the scope of policy
frameworks. Behavioral mimicry diffuses responsibility downward and sideways through the
power of peers. Essien et al. assert that governance standards become part of daily activities that
are no longer perceived as exogenous requirements (Essien et al. 626). At SMBI, culture is the
soft element that sustains the formal structures. Its development calls for systematic
conversations, recognition of resilient behavior, and exemplified leadership. The goal is to
cultivate resilience as part of the identity rather than a reactive shift to emergency mode that is
engaged after a breach happens.
Surname 50
A critical aspect of resilience is the presence of ethical reasoning informing the
technological decisions made. Hamburg and Grosch highlight that ethical reasoning is the reason
organizations do not take up pervasive surveillance that may build the proverbial ‘trust that
breaks the camel’s back’ (Hamburg and Grosch 6). Ethical restraint ensures that protective
efforts do not violate the stripped-down version of human dignity. Antonucci argues that moral
capability is no less important than measurable capability, it is the capacity to carry out
responsible actions under pressure (Antonucci 93). This means that ethical and rational factors
are mutually reinforcing aspects of resilience. In the same spirit, Melaku argues that governance
must find a way to simultaneously support the innovation of new adaptive technologies and
moral attribution of their use (Melaku 342). For SMBI, embedding ethical reasoning within
policy review and adoption defends integrity-based compliance rather than fear-based
compliance. Ethical resilience accepts that loss of trust may result from moral failures as deeply
as from technical failures, thus, ethical foresight is an important component of security
governance.
To sustain a cyber-resilient organization, it is necessary for top management to remain
committed to the organization. Savaş and Karataş observes that governance efficacy correlates
with the continuous support of top management advocacy that intertwines the civic cybersecurity
objectives with performance management frameworks (Savaş and Karataş 25). Resource
allocation and organizational visibility is commanded by the attention of the leadership. Essien et
al. argue that leaders who personally participate in the alignment of frameworks indicate
seriousness and galvanize accountability up and down the hierarchy (Essien et al 627). Their
presence shifts the policy from theory to practice. Jarjoui and Murimi argue that executive
support for the initiatives of resilience cuts across the functional cooperation and departmental
Surname 51
silos (Jarjoui and Murimi 150). Within the context of SMBI, leadership is required to play the
dual role of policy designer and embodiment of the organizational culture. Once the executives
advocate for cybersecurity as a primary strategy, resilience advocacy shifts from a requirement
of compliance to an organizational culture that is collaboratively embraced and behavioral
guidance is offered from the top to the bottom.
The rationality behind evolving interconnectivity systems like the Internet of Things
(IoT) requires the deployment of integral interdependence intererelay resilience frameworks.
Kandasamy et al. demonstrate that the risk management of IoT ecosystems requires balanced
holistic classification framing their attack surface-defining perimeter and not control polygons
(Kandasamy et al. 12). The interdependence of the systems implies that the compromise of a
single device would spell doom for an entire infrastructure. Melaku claims that the contextual
adaptability of dynamic governance models serves to contain cascading vulnerabilities in such
systems (Melaku 345). The use of real-time modifications and proactive tactics allows for
exploitation of emerging exploits flexibilities. Antonucci claims that the interdependence of
devices within an organization asset being measured in a disjointed organizational structure,
would require him a framework of integrated metrics encompassing device organizational silos
devoid of organizational abandonment (Antonucci 101). The technological ecosystems, instead
of SMBI’s departmental silos would be the focus of the multi-tiered structural elasticity
interdomain approach. Optimo interdependence framing shifts cyber-security of intersystem
cross-domain control hinges defending assets and instead focuses on system level cohesion with
the interdependence framework proposing networked resilience properties instead of silos.
Sharing knowledge both internal and external to the organization, enhances collective
cyber resilience. Pemmasani argues that public-private partnerships accelerate the recovery
Surname 52
process through synergistic learning (Pemmasani 214). Shared lessons learned convert siloed
failures into widespread improvements across an entire industry. Yusif and Hafeez-Baig have
stated that internal communities of practice support peer learning and unbundle the knowledge of
cybersecurity (Yusif and Hafeez-Baig 501). Informal socialization nurtures formal education and
keeps the learner continuously involved. Savaş and Karataş posit that the unreserved circulation
of risk information across the boundaries of a sector improves collective preparedness as a public
good and does not undermine the sender’s market position (Savaş and Karataş 28). For SMBI,
membership in inter-organizational knowledge networks incorporates resilience that transcends
the organisational boundaries. Such learned behavior shifts the practice of cybersecurity from
competition to cooperation, strengthening the whole digital ecosystem and, at the same time,
reinforcing the reputation of SMBI as a responsible and collaborative cyber defense practitioner.
Evaluating and measuring the performance of resilience tracks the effectiveness of the
strategies over time. Antonucci suggests measurable capability criteria which connect outcome-
achieving processes to the goals of the organization (Antonucci 108). These metrics support
ongoing performance evaluation instead of periodic audits. Aligning these criteria to
international standards fosters comparability and accountability (Essien et al. 629).
Accountability and comparability are supported through the eas of standardization. Melaku
claims evaluative frameworks of a more fluid nature must incorporate softer variables like
internal confidence and the effectiveness of communication (Melaku 347). The combination of
these approaches offers a more comprehensive understanding about the key areas of resilience
which have matured over time. For SMBI, the evidence of practice which a policy guide and
investment refines determines the measurable practice of resilience. Agility is maintained
Surname 53
through the process of continuous refinement which also counters the growth in operational
complexity and the evolution of new digital realities through protective mechanisms.
The cyber resilience of an organization will depend on its sense of innovation and ability
to predict the future. Predictive analytics and models will change the way businesses think of and
prepare for disruptions, Antonucci predicts (Antonucci 115). Foresight turns uncertainty into
action. Melaku imagines adaptive governance systems that can modify themselves in real-time
through governance systems (Melaku 349). This modification transforms resilience into an ever-
evolving entity, as opposed to a stagnant, unchanging force. Integrative governance founded on
ethics, automated systems, and cooperative knowledge will be dominant in the next era of
resilient businesses, predicted by Yusif and Hafeez-Baig (Yusif and Hafeez-Baig 504). For
SMBI, these insights mean that competence in prediction, adaptation, and shared responsibility
are the ideals to hold for dynamic, ever-evolving resilience. Organizations, in the face of
unpredictable cyber disruptions, need to focus on the integration of anticipation, technology, and
human insight to truly endure in this increasingly unpredictable digital age.
Action Plan
SMBI may take any of several preventative actions to address this breach and seek
justice. The recommended approach should cover the adoption of procedures to segregate
impacted systems, secure and retain evidence documents, and communicate with appropriate
authorities and affected parties. To pursue legal recourse under the Electronic Communications
Privacy Act (ECPA), it is advisable to seek the assistance of legal professionals who specialize in
cybersecurity and privacy legislation. According to Stoyanova et al. (14), engaging such legal
counsel will enable an assessment of the situation and facilitate the initiation of appropriate legal
Surname 54
measures against the perpetrators responsible for the hacking incident. One potential course of
action might be initiating legal proceedings against the individuals responsible for contravening
the legislation.
I. Forensic Investigation
SMBI should conduct a comprehensive forensic investigation to determine the whole extent
of the security breach, identify the precise data that has been affected, and collect evidential
information that may be used in legal proceedings. According to Stoyanova et al. (14), this
inquiry necessitates the involvement of proficient individuals with expertise in analyzing
spyware and keyloggers to comprehensively comprehend their performance and the extent of
the infiltration.
II. Collaboration with Law Enforcement
Stoyanova et al. (14) suggest that SMBI should establish a tight collaborative relationship
with law enforcement authorities, such as the Federal Bureau of Investigation (FBI) or
pertinent cybercrime units, to promptly report the occurrence, furnish substantial evidence,
and offer support in the investigative process. According to Stoyanova et al. (14), the
involvement of law enforcement agencies can facilitate the process of identifying and
apprehending hackers, ultimately leading to their prosecution.
III. Enhanced Security Measures
Acebo’s article states that the bolstering of security measures may be achieved by the
implementation of many strategies, such as the timely upgrading and patching of systems,
the adoption of multi-factor authentication, the enhancement of encryption methods, and the
Surname 55
frequent conduct of security audits. Acebo says implementing these measures will serve to
mitigate the risk of future cyber-attacks and fortify defenses against comparable security
breaches.
IV. Customer and Stakeholder Communication
Stoyanova et al. (14), assert that it is imperative to establish transparent communication
channels with customers, stakeholders, and regulatory agencies on the breach. According to
these authors, this entails providing comprehensive information about the incident,
elucidating the measures implemented to alleviate the situation, and ensuring the
safeguarding of their data. It is suggested that for SMBI, the preservation of openness is of
utmost importance in the process of restoring confidence and credibility.
V. Employee Training and Awareness
Lallie, Harjinder Singh, et al. (17) suggest that SMBI should implement periodic
cybersecurity training initiatives aimed at enhancing employee knowledge and
understanding of possible security risks, such as phishing assaults, which have the potential
to result in similar malicious incidents. Acebo concludes that employees must maintain a
state of vigilance and possess comprehensive knowledge of optimal strategies in the field of
cybersecurity.
These precautions may help SMBI deal with the short-term effects of the cyberattack while
also demonstrating the company's commitment to data security and compliance with regulations
like the Electronic Communications Privacy Act (ECPA). Stoyanova et al. (17) indicate that for
justice to be served, it is necessary to use a multipronged approach that makes use of the law,
stricter security measures, collaboration with authorities, and proactive communication with
Surname 56
those who may help bring about change (Stoyanova et al. 17). The provided complete action plan
can function as a structured approach to effectively handle the breach, mitigate the risk of future
assaults, and reinstate confidence in SMBI's dedication to safeguarding data privacy and
security.
Conclusion
The cyberattack on Store My Bits International (SMBI) highlights how urgently
cybersecurity has to respond with unity and speed. Legal remedies and preventative actions are
vital because of the intricacy of cyber dangers, as demonstrated by malware and keyloggers that
violate the Electronic Communications Privacy Act (ECPA). The ECPA and other laws that are
put into effect provide crucial foundations for preventative actions. Initiatives to mitigate cyber
dangers are bolstered by the ECPA's focus on the gravity of hacking and its many punishments.
Global resilience against cyber threats is increased by international cooperation, as shown by the
Budapest Convention on Cybercrime. Common threats, like as phishing, need both robust
technological protections and continuous awareness efforts. According to this paper’s findings,
SMBI's comprehensive response strategy incorporates legal involvement, forensic investigation,
security developments, open communication, and staff training to strengthen against intrusions
and restore trust. The paper concludes that to successfully combat cyber risks, a wide and
proactive strategy is necessary. A commitment to cybersecurity resilience is demonstrated by
SMBI's adherence to current legislation and coordinated measures.
Surname 57
Works Cited
Acebo, Leslie. “How Tabletop Exercises Aid Cyber Preparedness.” Wall Street Journal, 15 May
2023, www.wsj.com/articles/how-tabletop-exercises-aid-cyber-prepardness-85f8d09a.
Accessed 18 Nov. 2023.
Ahmad, Atif, et al. "How integration of cyber security management and incident response
enables organizational learning." Journal of the Association for Information Science and
Technology 71.8 (2020): 939-953.
Alexandrou, Alex. Cybercrime and information technology: The computer network
infrastructure and computer security, cybersecurity laws, Internet of Things (IoT), and
mobile devices. CRC Press, 2021.
Aljeaid, Dania, et al. "Assessment of end-user susceptibility to cybersecurity threats in Saudi
Arabia by simulating phishing attacks." Information 11.12 (2020): 547.
Alkhalil, Zainab, et al. "Phishing attacks: A recent comprehensive study and a new
anatomy." Frontiers in Computer Science 3 (2021): 563060.
Allahrakha, Naeem. "Balancing cyber-security and privacy: legal and ethical considerations in
the digital age." Legal Issues in the digital Age 2 (2023): 78-121.
Antonucci, Domenic. The cyber risk handbook: Creating and measuring effective cybersecurity
capabilities. John Wiley & Sons, 2017.
Beale, Sara Sun, and Peter Berris. "Hacking the Internet of Things: Vulnerabilities, dangers, and
legal responses." Duke L. & Tech. Rev. 16 (2017): 161.
Surname 58
Blanken-Webb, Jane, et al. "A case study-based cybersecurity ethics curriculum." 2018 USENIX
Workshop on Advances in Security Education (ASE 18). 2018.
Calder, Alan. "The Cyber Security Handbook-Prepare for, respond to and recover from cyber
attacks." (2020): 1-361.
Chander, Harish, and Gagandeep Kaur. Cyber laws and IT protection. PHI Learning Pvt. Ltd.,
2022.
Chitimoju, Satish. "Ethical challenges of AI in cybersecurity: bias, privacy, and autonomous
decision-making." Journal of Computational Innovation 3.1 (2023).
Christen, Markus, Bert Gordijn, and Michele Loi. The ethics of cybersecurity. Springer Nature,
2020.
Darshini, P., et al. "Cyber Security Threats Detection Analysis and Remediation." 2021 IEEE
Mysore Sub Section International Conference (MysuruCon). IEEE, 2021.
Diogenes, Yuri, and Erdal Ozkaya. Cybersecurity–Attack and Defense Strategies: Improve your
security posture to mitigate risks and prevent attackers from infiltrating your system.
Packt Publishing Ltd, 2022.
Essien, Iboro Akpan, et al. "Optimizing cyber risk governance using global frameworks: ISO,
NIST, and COBIT alignment." Journal of Frontiers in Multidisciplinary Research 3.1
(2022): 618-629.
Formosa, Paul, Michael Wilson, and Deborah Richards. "A principlist framework for
cybersecurity ethics." Computers & Security 109 (2021): 102382.
Surname 59
Garunja, Evis, et al. "Impact of Cyber Laws in Information Security Management to Protect
Businesses and Citizens." International Conference on Signal, Machines, Automation,
and Algorithm. Singapore: Springer Nature Singapore, 2023.
Hamburg, Ileana, and Kira Rosa Grosch. "Ethical aspects in cyber security." Archives of
Business Research 5.10 (2017).
Hawamleh, A. M. A., et al. "Cyber security and ethical hacking: The importance of protecting
user data." Solid State Technology 63.5 (2020): 7894-7899.
Hovav, Anat, Itzhak Gnizy, and Jinyoung Han. "The effects of cyber regulations and security
policies on organizational outcomes: a knowledge management perspective." European
Journal of Information Systems 32.2 (2023): 154-172.
Ikhsan, Mukhammad Gufron, and Kalamullah Ramli. "Measuring the information security
awareness level of government employees through phishing assessment." 2019 34th
international technical conference on circuits/systems, computers and communications
(ITC-CSCC). IEEE, 2019.
Jarjoui, Samir, and Renita Murimi. "A framework for enterprise cybersecurity risk
management." Advances in cybersecurity management. Cham: Springer International
Publishing, 2021. 139-161.
Kandasamy, Kamalanathan, et al. "IoT cyber risk: A holistic analysis of cyber risk assessment
frameworks, risk vectors, and risk ranking process." EURASIP Journal on Information
Security 2020.1 (2020): 8.
Kosseff, Jeff. "Hacking cybersecurity law." U. Ill. L. Rev. (2020): 811.
Surname 60
Kozhuharova, Denitsa, Atanas Kirov, and Zhanin Al-Shargabi. "Ethics in cybersecurity. What
are the challenges we need to be aware of and how to handle them?." Cybersecurity of
Digital Service Chains: Challenges, Methodologies, and Tools. Cham: Springer
International Publishing, 2022. 202-221.
Lallie, Harjinder Singh, et al. “Cyber Security in the Age of COVID-19: A Timeline and
Analysis of Cyber-Crime and Cyber-Attacks during the Pandemic.” Computers &
Security, vol. 105, no. 1, Mar. 2021, pp. 1–20,
https://doi.org/10.1016/j.cose.2021.102248.
Legg, Phil, and Tim Blackman. "Tools and techniques for improving cyber situational awareness
of targeted phishing attacks." 2019 international conference on cyber situational
awareness, data analytics and assessment (cyber SA). IEEE, 2019.
Loi, Michele, and Markus Christen. "Ethical frameworks for cybersecurity." The ethics of
cybersecurity. Cham: Springer International Publishing, 2020. 73-95.
Madleňák, M., and K. Kampová. "Phishing as a cyber security threat." 2022 20th international
conference on emerging elearning technologies and applications (ICETA). IEEE, 2022.
Maglaras, Leandros, et al. "Cyber security: From regulations and policies to practice." Strategic
Innovative Marketing and Tourism: 7th ICSIMAT, Athenian Riviera, Greece, 2018.
Cham: Springer International Publishing, 2019. 763-770.
Marcinauskaitė, Renata, Indrė Pukanasytė, and Jolita Šukytė. "Cyber security issues: problematic
aspects of hacking." Journal of security and sustainability issues. Vilnius: Generolo Jono
Žemaičio Lietuvos karo akademija, 2019, vol. 8, iss. 3. (2019).
Surname 61
Melaku, Henock Mulugeta. "A dynamic and adaptive cybersecurity governance
framework." Journal of Cybersecurity and Privacy 3.3 (2023): 327-350.
Nguyen, Kenneth D., Heather Rosoff, and Richard S. John. "Valuing information security from a
phishing attack." Journal of Cybersecurity 3.3 (2017): 159-171.
Oest, Adam, et al. "Inside a phisher's mind: Understanding the anti-phishing ecosystem through
phishing kit analysis." 2018 APWG Symposium on Electronic Crime Research (eCrime).
IEEE, 2018.
Pemmasani, Praveen Kumar. "National cybersecurity frameworks for critical infrastructure:
Lessons from governmental cyber resilience initiatives." International Journal of Acta
Informatica 2.1 (2023): 209-218.
Prei, Kaspr, and Bernhards Blumbergs. "measuring personnel cyber security awareness level
through phishing assessment." signature (2017).
Saad, Wajid, and Muhammad Aslam. "The Role of Artificial Intelligence in Remediation and
Risk Mitigation for Cybersecurity." (2023): 45-99.
Sadeghi, Bakhtiar, et al. "Modelling the ethical priorities influencing decision-making in
cybersecurity contexts." Organizational Cybersecurity Journal: Practice, Process and
People 3.2 (2023): 127-149.
Savaş, Serkan, and Süleyman Karataş. "Cyber governance studies in ensuring cybersecurity: an
overview of cybersecurity governance." International Cybersecurity Law Review 3.1
(2022): 7-34.
Surname 62
Schoenherr, F. Jordan Richard, and Robert Thomson. "Ethical frameworks for cybersecurity:
Applications for human and artificial agents." The frontlines of artificial intelligence
ethics. Routledge, 2022. 141-161.
Schreider, Tari. Cybersecurity law, standards and regulations. Rothstein Publishing, 2020.
Smith, Katherine Taken, et al. "Examination of cybercrime and its effects on corporate stock
value." Journal of Information, Communication and Ethics in Society 17.1 (2019): 42-60.
Srinivas, Jangirala, Ashok Kumar Das, and Neeraj Kumar. "Government regulations in cyber
security: Framework, standards and recommendations." Future generation computer
systems 92 (2019): 178-188.
Stoyanova, Maria, et al. “A Survey on the Internet of Things (IoT) Forensics: Challenges,
Approaches and Open Issues.” IEEE Communications Surveys & Tutorials, vol. 22, no.
2, 2020, pp. 1–20, https://doi.org/10.1109/comst.2019.2962586.
Thakur, Kutub, Juan Shan, and Al-Sakib Khan Pathan. "Innovations of phishing defense: The
mechanism, measurement and defense strategies." International Journal of
Communication Networks and Information Security 10.1 (2018): 19-27.
Thompson, Eric C. Cybersecurity incident response: How to contain, eradicate, and recover
from incidents. Apress, 2018: 76-123.
Timmers, Paul. "Ethics of AI and cybersecurity when sovereignty is at stake." Minds and
Machines 29.4 (2019): 635-645.
Trozzo, Eric. The cyberdimension: A political theology of cyberspace and cybersecurity. Wipf
and Stock Publishers, 2019.
Surname 63
Yaghmaei, Emad, et al. "Cybersecurity and Ethics." CANVAS White Paper 1 (2017).
Yusif, Salifu, and Abdul Hafeez-Baig. "A conceptual model for cybersecurity
governance." Journal of applied security research 16.4 (2021): 490-513.
Zolotarev, Vyacheslav, Elena Zolotareva, and Vladimir Mawla. "Phishing Attacks Digital Trace
Analysis for Security Awareness." CEUR Workshop Proceedings. 2022.
Students also viewed