Running Head: IT 659 ad ad ad ad ad ad ad ad ad ad ad ad ad ad a ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad
ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad 1
IT-659-Q1436: Assignment 7-2
IT 659 ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad
ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad 2
Recommendations and Global Considerations
The Notpetya cyberattack affected Maersk business as well as the entire
shipping industry. Here the main recommendations have been done that could have
helped the firm to prevent the incident. Similarly, the global implication of the cyber
incident has been captured to understand how it has affected the global business
setting.
Recommendations
Relevant changes for preventing the cyber attack
Maersk could have prevented the cyber-attack that crippled its shipping
business activities by upgrading the technological infrastructure. The business concern
was considered to have a decent level of protection on the cyber platform as
compared to the other shipping firms with weak security model. In spite of this, its
vulnerabilities were exposed (Lennane, 2018). The dissemination of the attack across
different business units of Maersk indicates that the firm’s level of cybersecurity was
not good enough.
The Blockchain technology could have played a key role and saved the
shipping concern from the Notpetya cyber-attack. The incident could have been
averted if it had shifted from the obsolete electronic data interchange (EDI) to the
‘blockchain-enabled’ technology. According to Antony Abell, the managing director
of TrustMe, such a transition on the technology front could have strengthened the
cyber security model of the shipping concern (Marinemec.com, n.d). The innovative
technology would have increased the security process of the concern multifold as
blockchain runs in a sterile environmental setting.
Reasonable ethical guidelines for cyberattack prevention
IT 659 ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad
ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad 3
The serious cyber incident which compromised the IT infrastructure of Maersk
could have been prevented if the appropriate and reasonable ethical guidelines were
in place. The moral compass of the business was shaky. This is because the
shipping concern had failed to upgrade the cyber infrastructure with the evolving
times. Similarly, Maersk could have increased the awareness and education level of
the employees so that they could have been more conscious and agile before the
incident (Marinemec.com, n.d). The shipping industry is known to have a weak
cyber risk management model which makes the industry and the participants
susceptible to the cyber attackers. The Notpetya attack acted as a major wakeup call
that revealed that there is the need to introduce stringent ethical guidelines so that
the lousy security subsystems can be replaced by technologically-advanced security
models such as the Blockchain technology.
Global considerations
International Compliance Standards
The proper establishment of an effective cybersecurity program is necessary
for all the business undertakings that function today irrespective of the nature of the
industry or the geographic location. In the current times, several regulations have
been introduced urging business firms to navigate the cyber risks and effectively
tackle the online vulnerability (Deloitte, 2018, p 2).
Some of the main international compliance requirements that would be
relevant at the time of the Notpetya incident include the adoption of a risk-based
approach for the purpose of understanding the various cybersecurity threats that arise
in the industrial environments and the establishment of a robust IT governance
structure in order to drive accountability. Similarly, in the current times, business
undertakings always have to be on their toes to identify vulnerable areas so that
IT 659 ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad
ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad 4
the security controls can be upgraded (Deloitte, 2018, p 3). Firms also need to
conduct the frequent monitoring of the information systems (IS) so that they can
identify the instance of a breach or attempted breach. The existence of the
International Compliance Standards and regulations would have naturally persuaded
Maersk to prevent the attack or identify it earlier.
Impact of the cyber-attack on global communication and commerce
The Notpetya cyber-attack was a major incident that not only affected the
Maersk shipping business but exposed the high degree of vulnerability of the entire
shipping industry. It acted as a major wake-up call for the entire industry. The
incident made the shipping concerns that function in the industry conscious about the
Information Technology infrastructure and the management of the IT assets (Deloitte,
2018). ad
After the cyber-attack that crippled the shipping firm has made global
business undertakings understand the gravity of having a robust cyber risk
management model. In order to strengthen the overall survival and sustainability of
business and commerce on the cyber platform, firms are making a sincere effort to
comply with the evolving cyber security standards and policies (Deloitte, 2018). The
objective is to carry out the business activities in a safe way so that the
vulnerability of firms on the cyber platform can be managed and mitigated to a
certain extent. ad
The business concerns that operate in the diverse and dynamic industrial
environment have learnt from no business is indispensable on the cyber platform. In
order to operate in a safe cyber setting, in the present times, organizations are
focusing on establishing a robust cybersecurity model that can enhance the safety
and security of the business (Deloitte, 2018, p 3). Firms in different nations are
IT 659 ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad
ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad 5
imposing strict ‘cyber integrity’ requirements in order to have an edge against the
cyber attackers and online hackers. ad
The relationship between Maersk cyberattack and current global regulatory
standards
After Maersk became a victim of one of the most notorious cyberattacks,
numerous changes have been introduced in the global technology environment so that
business undertakings can function in a safe and secure cyber platform. The incident
has led to the sharpening of the regulatory focus so that the vulnerabilities of the
shipping businesses can be managed in an effective and efficient manner (IHS
Fairplay, 2018). The shipping industry has, in fact, started to brace itself for a
potential robust cyber security regulatory regime so that the online hackers will not
have the scope to cripple the Information Technology systems of the operational
business undertakings.
The serious cyber incident which compromised the security model of the
business has put businesses on their toes. In fact, the regulators have also introduced
stringent standards and rules so that the businesses can be empowered to tackle
against cyber-attacks. The regulatory standards are urging business concerns to adapt
to the digitalized era by implementing fast and formal escalation programs (Deloitte,
2018). This can help them to take fast actions against any kind of unauthorized
activity that is carried out on the network systems of the business firms. ad
In order to help businesses function in a safe setting, the current global
regulatory standards have been designed by taking a cue from the Notpetya
cyberattack. They are urging firms to strengthen the IT backbone so that their cyber
resilience can be enhanced (Moller, 2018, p 8).
IT 659 ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad
ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad 6
References
Deloitte, N. (2018). Global cybersecurity compliance integrity. Retrieved from
https://www2.deloitte.com/content/dam/Deloitte/us/Documents/risk/us-risk-global-
cybersecurity-compliance-integrity.pdf
IHS Fairplay. (2018). Maersk cyber-attack sharpens regulatory focus. Retrieved from
https://fairplay.ihs.com/safety-regulation/article/4289206/maersk-cyber-attack-
sharpens-regulatory-focus
Lennane, A. (2018). Shipping must learn from Maersk cyber attack – tighten security
or be next, warning - The Loadstar. Retrieved from
https://theloadstar.co.uk/shipping-must-learn-maersk-cyber-attack-tighten-security-
next-warning/
Marinemec.com. (n.d). Blockchain would have prevented Maersk cyber-attack.
Retrieved from https://www.marinemec.com/news/view,blockchain-would-have-
prevented-maersk-cyber-attack_48287.htm
IT 659 ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad
ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad 7
Moller, A. (2018). MAERSK 2017 Annual Report. Retrieved from
http://files.shareholder.com/downloads/ABEA-
3GG91Y/6115885668x0x971046/54DA7595-1904-4118-9174-
E741CB7621D4/A.P._Moller_-_Maersk_Annual_Report_2017.pdf