Running Head: CASE ANALYSIS ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac
ac ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac 1
IT-659-Q1436: Assignment 9-2
CASE ANALYSIS ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac
ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac 2
Maersk was the victim of a serious cyberattack that jolted the entire shipping
industry. The attack was big news back then. The ethical issues and legal issues that
led to the situation have been analysed here. Similarly, the social and cultural impact
of the event has been thoroughly examined. The impact has been categorized into
cultural impact, standards and regulations impact so that a holistic picture can be
drawn in the process. The cyberattack incident is regarded to be one of the most
catastrophic occurrences that jolted the shipping industry.
Ethical Issues in Maersk cyberattack
Several loopholes existed in the IT infrastructure of Maersk due to which the
computer network of the shipping business undertaking was compromised. The
NotPaytya cyberattack affected the shipping business since the online assets of the
firm were totally unprotected. The interconnectedness of a large number of computer
systems further intensified the vulnerability of the shipping business (Ship-
technology.com, 2018). The main ethical issue that gave rise to the cyberattack was
the lack of a proper security system.
Legal Compliance issues within the Maersk organization
The magnitude of the cyberattack on Maersk was high since there existed a
number of legal loopholes that needed to be filled (Theregister.co.uk, 2018). The
malware was placed in a malicious update in one of the most popular accounting
software that was used by the shipping concern. Since the software was not checked
by the firm, it was not able to identify the anti-element that existed in its computer
networks (Marinemec.com, 2018). In spite of the high level of connectivity of various
computer networks and communication systems, the business undertaking did not have
the highest of level automation process that is expected from a global ship business.
Even though a concern can never be 100 percent secure in the vast cyber space,
CASE ANALYSIS ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac
ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac 3
Maersk could have averted the attack by updating its software with the relevant
security fixes that were produced by Microsoft (Economictimes.indiatimes.com, 2018).
The vulnerability that was identified and addressed by the hack was the poor and
redundant cybersecurity model of Maersk. The business had failed to replace the
cybersecurity framework with the evolving technological setting which allowed the
attackers to invade the IT setting and cripple the online assets. The cybersecurity
frameworks such as NIST, CIS/SANS 20 or ISO 27001 introduce best practices and
procedures that can help firms to assess the IT security model.
The business did not follow the PCI cybersecurity framework has been
designed to secure the online payment activities that are conducted by businesses. In
the case of Maersk, the business did not follow this framework even though it has
taken the Credit Card numbers to make payment for games services. Thus, there
existed numerous loopholes in the cybersecurity model of the shipping firm which
increased its vulnerability.
The societal and cultural impact of the compliance issues
Maersk’s cyberattack incident affected the shipping industry as the business
was one of the most reputed and prominent market participants at the time of the
incident (Saul, 2017). The impact of the attack has reverberated across the entire
shipping industry and now the shipping firms are increasing their investment to
strengthen their information technology infrastructure (Saul, 2017). The objective is to
control such kinds of cyberattacks that can outrage the computer network of the
organizations.
Due to the compliance issues that arose in the case of the Maersk shipping
business, it cost the business USD 300 million and affected its social status and
CASE ANALYSIS ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac
ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac 4
reputation (Novet, 2018). The NotPetyaayttack showed that when it comes to online
threat, there exist no cultural or social boundaries.
Impact of the incident with ethical and legal IT regulations of the time
After the cyberattack incident that jolted the shipping industry, various
shipping firms including Maersk are working on new security measures so that the
online assets can be safeguarded on the cyber platform. For instance, Maersk is
working with the IBM organisation so that it can incorporate a new and effective
Blockchain solution. The incident has made the shipping firm conscious to maintain a
safe and secure IT infrastructure so that their operations and activities will not be
compromised in any manner.
After the incident, most of the shipping firms started working on introducing
stronger and effective security measures that could protect their business as well as
the online assets. Changes have been introduced in the IT regulations
(Marinemec.com, 2018). Prior to the cyberattack, the main attention was given to the
voluntary guidelines and instructions from the shipping industry but after the attack
that affected the business activities of Maersk, new and stringent regulations are being
introduced so that the ship business firms can be protected from dangerous cyber
incidents.
The link between the industry standards and the standards in existence for
information technology
The cybersecurity in the shipping industry has been quite lenient prior to the
cyberattack incident. The main factors that come into play and influence the level of
security in the industrial setting include automation, integration, The capability to
“ship to shore” that communicates through monitoring and the connectivity via the
CASE ANALYSIS ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac
ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac 5
internet. The industry standards relating to cybersecurity were limited to a certain
extent.
The security measures that were followed by Maersk at the time of the
incident was below par. For instance, the safety net of the business undertaking was
not upgraded due to which the unauthorized people had access to the computer
network. Thus it can be said that the shipping industry’s standards relating to
cybersecurity were lacking and at the same time, the security approach of Maersk
also contained loopholes. ac
Cultural Implication
The cyberattack that affected Maersk and its shipping business had a major
cultural implication as it showed that the social-cultural conflicts can give rise to
technology-based conflicts and cyber issues. The incident, in fact, acted as a catalyst
and gave rise to the culture of cybersecurity (Gandhi et al., 2011).
Since people generally tend to think in form of groups, the Maersk cyberattack
highlighted the fact that the shipping industry is not safe and it is highly vulnerable
in the online platform. The incident was a major happening that took place on the
cyber platform and reshaped the regulations and standards that have been existing in
the shipping industry for a long period of time (Gandhi et al., 2011). The cyber
breach that not attacked the IT system of the business but also and crippled its It
infrastructure increased the collective consciousness of the industry participants and
the government about a robust cyber security model.
The cyberattack that was experienced by the shipping giant Maersk revealed
that the cyberattackers and cyberhackers are on their toes at all times and they are
regularly looking out for vulnerabilities of business concerns. The magnitude of the
cyber incident could have been controlled to a certain extent if the business had a
CASE ANALYSIS ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac
ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac 6
stronger ethical and legal model of cyber security. But the incident has opened the
eyes of the shipping industry participants due to which they are trying to safeguard
their IT infrastructure and abide by the latest rules and standards concerning
cybersecurity.
Recommendations and Global Considerations
The Notpetya cyberattack affected Maersk business as well as the entire
shipping industry. Here the main recommendations have been done that could have
helped the firm to prevent the incident. Similarly, the global implication of the cyber
incident has been captured to understand how it has affected the global business
setting.
Recommendations
Relevant changes for preventing the cyber attack
Maersk could have prevented the cyber-attack that crippled its shipping
business activities by upgrading the technological infrastructure. The business concern
was considered to have a decent level of protection on the cyber platform as
compared to the other shipping firms with weak security model. In spite of this, its
vulnerabilities were exposed (Lennane, 2018). The dissemination of the attack across
different business units of Maersk indicates that the firm’s level of cybersecurity was
not good enough.
The Blockchain technology could have played a key role and saved the
shipping concern from the Notpetya cyber-attack. The incident could have been
averted if it had shifted from the obsolete electronic data interchange (EDI) to the
‘blockchain-enabled’ technology. According to Antony Abell, the managing director of
TrustMe, such a transition on the technology front could have strengthened the cyber
secutity model of the shipping concern (Marinemec.com, n.d). The innovative
CASE ANALYSIS ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac
ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac 7
technology would have increased the security process of the concern multifold as
blockchain runs in a sterile environmental setting.
Reasonable ethical guidelines for cyberattack prevention
The serious cyber incident which compromised the IT infrastructure of Maersk
could have been prevented if the appropriate and reasonable ethical guidelines were in
place. The moral compass of the business was shaky. This is because the shipping
concern had failed to upgrade the cyber infrastructure with the evolving times.
Similarly, Maersk could have increased the awareness and education level of the
employees so that they could have been more conscious and agile before the incident
(Marinemec.com, n.d). The shipping industry is known to have a weak cyber risk
management model which makes the industry and the participants susceptible to the
cyber attackers. The Notpetya attack acted as a major wakeup call that revealed that
there is the need to introduce stringent ethical guidelines so that the lousy security
subsystems can be replaced by technologically-advanced security models such as the
Blockchain technology.
Global considerations
International Compliance Standards
The proper establishment of an effective cybersecurity program is necessary for
all the business undertakings that function today irrespective of the nature of the
industry or the geographic location. In the current times, a number of regulations
have been introduced urging business firms to navigate the cyber risks and effectively
tackle the online vulnerability (Deloitte, 2018, p 2).
Some of the main international compliance requirements that would be relevant
at the time of the Notpetya incident include the adoption of a risk-based approach for
CASE ANALYSIS ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac
ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac 8
the purpose of understanding the various cybersecurity threats that arise in the
industrial environments and the establishment of a robust IT governance structure in
order to drive accountability. Similarly, in the current times, business undertakings
have to be on their toes at all times to identify vulnerable areas so that the security
controls can be upgraded (Deloitte, 2018, p 3). Firms also need to conduct the
frequent monitoring of the information systems (IS) so that they can identify the
instance of a breach or attempted breach. The existence of the International
Compliance Standards and regulations would have naturally persuaded Maersk to
prevent the attack or identify it earlier.
The ISO PCI DSS, NIST, CIS/SANS 20 or ISO 27001 standards must also be
considered by Maersk as they have been designed to help firms introduce the most
effective IT security frameworks. They could act as the guiding tool that would help
the shipping concern to evaluate the existing maturity of the Information Technology
infrastructure and establish goals to improve the same. These standards would be
crucial for the shipping concern as they would help it to identify the weakest link of
the technological framework and strengthen it in the process.
Impact of the cyber-attack on global communication and commerce
The Notpetya cyber-attack was a major incident that not only affected the
Maersk shipping business but exposed the high degree of vulnerability of the entire
shipping industry. It acted as a major wake-up call for the entire industry. The
incident made the shipping concerns that function in the industry conscious about the
Information Technology infrastructure and the management of the IT assets (Deloitte,
2018). ac
After the cyber-attack that crippled the shipping firm has made global business
undertakings understand the gravity of having a robust cyber risk management model.
CASE ANALYSIS ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac
ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac 9
In order to strengthen the overall survival and sustainability of business and
commerce on the cyber platform, firms are making a sincere effort to comply with
the evolving cyber security standards and policies (Deloitte, 2018). The objective is to
carry out the business activities in a safe way so that the vulnerability of firms on
the cyber platform can be managed and mitigated to a certain extent. ac
The business concerns that operate in the diverse and dynamic industrial
environment have learnt from no business is indispensable on the cyber platform. In
order to operate in a safe cyber setting, in the present times, organizations are
focusing on establishing a robust cybersecurity model that can enhance the safety and
security of the business (Deloitte, 2018, p 3). Firms in different nations are imposing
strict ‘cyber integrity’ requirements in order to have an edge against the cyber
attackers and online hackers. ac
The relationship between Maersk cyberattack and current global regulatory
standards
After Maersk became a victim of one of the most notorious cyberattacks,
numerous changes have been introduced in the global technology environment so that
business undertakings can function in a safe and secure cyber platform. The incident
has led to the sharpening of the regulatory focus so that the vulnerabilities of the
shipping businesses can be managed in an effective and efficient manner (IHS
Fairplay, 2018). The shipping industry has, in fact, started to brace itself for a
potential robust cyber security regulatory regime so that the online hackers will not
have the scope to cripple the Information Technology systems of the operational
business undertakings.
The serious cyber incident which compromised the security model of the
business has put businesses on their toes. In fact, the regulators have also introduced
CASE ANALYSIS ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac
ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac 10
stringent standards and rules so that the businesses can be empowered to tackle
against cyber-attacks. The regulatory standards are urging business concerns to adapt
to the digitalized era by implementing fast and formal escalation programs (Deloitte,
2018). This can help them to take fast actions against any kind of unauthorized
activity that is carried out on the network systems of the business firms. ac
In order to help businesses function in a safe setting, the current global
regulatory standards have been designed by taking a cue from the Notpetya
cyberattack. They are urging firms to strengthen the IT backbone so that their cyber
resilience can be enhanced (Moller, 2018, p 8).
Summary
In order to analyse the cybersecurity incident that jolted the shipping industry,
especially the Maersk shipping concern, the cybersecurity policies and principles acted
as the main foundation. These elements helped to identify the major loopholes that
existed in the Information Technology framework of the business concern. In the
current times, cyber attackers and hackers are desperately trying to identify the
weakest IT link so that they can gain unauthorised access into the technology-based
infrastructure of a concern and cripple the business activities (Klein & Rothwell,
2009, p 7). The practices and application of the cybersecurity framework were weak
in case of the Maersk business undertaking.
The application of the updated cybersecurity principles and policies helped to
understand that the online security model of the business was old and redundant to a
certain degree. The shipping undertaking had not made the suitable upgrades of the
cyber infrastructure which gave an unfair advantage to the cyberattackers. This is why
the business became the victim of the NotPetya attack.
CASE ANALYSIS ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac
ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac 11
In the present times, technology is evolving and expanding at a rapid pace,
and this is also leading to the changes in the cybersecurity standards and principles.
The business undertakings need to be on their toes at all the times so that they can
safeguard the online assets from the unauthorized intruders that are always on the
lookout to target organizations. Maersk had not enhanced the cybersecurity
architecture and cybersecurity operations (Ng, Kankanhalli & Xu, 2009, p 11). Due to
the poor preparation on the part of the business undertaking, the people processes and
technology had taken a backseat and this was evident while applying the new
cybersecurity policies and standards. There were no control points in place which
could have protected the business undertaking and its IT assets. Thus for every
business, the cyber incident that affected Maersk must act as an eye-opener This can
help them to introduced cybersecurity models that are governed by the evolving
cybersecurity guidelines and principles.
References
Deloitte, N. (2018). Global cybersecurity compliance integrity. Retrieved from
https://www2.deloitte.com/content/dam/Deloitte/us/Documents/risk/us-risk-global-
cybersecurity-compliance-integrity.pdf
CASE ANALYSIS ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac
ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac 12
Economictimes.indiatimes.com. (2018). Maersk says global IT breakdown caused by
cyber attack. Retrieved from
https://economictimes.indiatimes.com/news/international/business/maersk-says-global-
it-breakdown-caused-by-cyber-attack/articleshow/59341860.cms
Ship-technology.com (2018). Did the Maersk cyber attack reveal an industry
dangerously unprepared? - Ship Technology. Retrieved from https://www.ship-
technology.com/features/maersk-cyber-attack-reveal-industry-dangerously-unprepared/
Gandhi, R., Sharma, A., Mahoney, W., Sousan, W., Zhu, Q., & Laplante, P. (2011).
Dimensions of cyber-attacks: Cultural, social, economic, and political. IEEE
Technology and Society Magazine, 30(1), 28-38.
IHS Fairplay. (2018). Maersk cyber-attack sharpens regulatory focus. Retrieved from
https://fairplay.ihs.com/safety-regulation/article/4289206/maersk-cyber-attack-
sharpens-regulatory-focus
Klein, N., & Rothwell, D. R. (2009). Maritime Security and the Law of the Sea. In
Maritime Security (pp. 48-62). Routledge.
Lennane, A. (2018). Shipping must learn from Maersk cyber attack – tighten security
or be next, warning - The Loadstar. Retrieved from
https://theloadstar.co.uk/shipping-must-learn-maersk-cyber-attack-tighten-security-
next-warning/
Marinemec.com (2018). Shipping got off lightly in first cyber security attacks, say
legal experts. Retrieved from http://www.marinemec.com/news/view,shipping-got-
off-lightly-in-first-cyber-security-attacks-say-legal-experts_49273.htm
CASE ANALYSIS ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac
ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac 13
Marinemec.com (2018). Blockchain would have prevented Maersk cyber-attack
Retrieved from http://www.marinemec.com/news/view,blockchain-would-have-
prevented-maersk-cyber-attack_48287.htm
Marinemec.com. (n.d). Blockchain would have prevented Maersk cyber-attack.
Retrieved from https://www.marinemec.com/news/view,blockchain-would-have-
prevented-maersk-cyber-attack_48287.htm
Moller, A. (2018). MAERSK 2017 Annual Report. Retrieved from
http://files.shareholder.com/downloads/ABEA-
3GG91Y/6115885668x0x971046/54DA7595-1904-4118-9174-
E741CB7621D4/A.P._Moller_-_Maersk_Annual_Report_2017.pdf
Ng, B. Y., Kankanhalli, A., & Xu, Y. C. (2009). Studying users' computer security
behavior: A health belief perspective. Decision Support Systems, 46(4), 815-825.
Novet, J. (2018). Shipping company Maersk says June cyberattack could cost it up to
$300 million. Retrieved from https://www.cnbc.com/2017/08/16/maersk-says-
notpetya-cyberattack-could-cost-300-million.html
Saul, J. (2017). Global shipping feels fallout from Maersk cyber attack.
Theregister.co.uk (2018). IT 'heroes' saved Maersk from NotPetya with ten-day
reinstallation bliz.. Retrieved from
https://www.theregister.co.uk/2018/01/25/after_notpetya_maersk_replaced_everything/