1 / 6100%
Running Head: IT 659 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 1
IT-659-Q1436 Cyberlaw and Ethics
Carlos Delapaz
SNHU
IT 659 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 2
IT business model of Maersk:
Digital transformation is considered as the most notable aspect for every business in
the recent years and in the year 2017, the shipping industry experienced many drastic
transformations. First of all, the world witnessed the first autonomous ships traversing the sea
and furthermore, the industry was also plagued by the threats of digitalization such as hacks,
malware attacks and cyber attacks. The primary highlight in the case of new IT business
model introduced by Maersk is the consideration for transforming the customer experience
and operational processes implemented in the organization.
The new model clearly cascades each of the functional aspects in the business model
and the ways in which the functions work and network with each other alongside addressing
the expansion of the organization’s margin. The IT business model of Maersk could be
identified as prominently focused on transport and logistics department. A clear evaluation of
the way in which the business model has been changed with reference to digital
transformation could provide clear insights into the definition and evaluation of the IT
business model of Maersk.
The present maritime industry in which Maersk operates is considerably associated
with digital transformation strategy which is focused on operational processes and safety
oriented activities. Another noticeable factor that can be identified in the case of IT business
model of Maersk is its emphasis on human resources as crucial components of the
transformation process (Cyber Security: A Legal Requirement, 2018). The following
assessment would provide a risk analysis report with references to the specific cyber security
laws, state statutes, criminal and civil laws and ethical guidelines in context of Maersk and
the existing regulations followed by the organization (Nkuna, 2017, p 25). The assessment
would also include cyber-law crimes and the existing information system security approaches
IT 659 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 3
that have been implemented by Maersk as well as the existing cyber laws that safeguard the
data of an organization from external intrusion (Nkuna, 2017,p f 26).
Existing regulations and precedents:
The cybercrime laws which have been outlined in the US and can be considered as
valid in the case of Maersk could be explicitly identified in two categories which include
substantive cybercrime laws and procedural cybercrime laws. In the case of Maersk, the
procedural cybercrime laws can be taken into focus as they are profoundly associated with
preventing unauthorized access to electronic data by third parties that also include internet
service providers, authority for searching electronic evidence and authority for interception of
electronic communication.
The procedural cybercrime laws are identified in 18 USC §§ 2510-2522, 2701-2712
and 3121-3127 (Rees, 2018). The substantive cybercrime laws could also be considered as
relevant regulations that could be applicable to the case of the NoPetya attack on Maersk that
crumpled its operations across many terminals. The substantive cybercrime laws are
profoundly associated with laws pertaining to prohibition of online identity theft, hacking and
intrusion into intellectual property and computer systems of an individual or organization.
The specific substantive cybercrime laws that can be mentioned in context of Maersk
include 18 USC § 1028 which focuses on prevention of any fraud or similar activity
implemented in relation to authentication features, information and identification documents.
The similar implications could be found in 18 USC § 1029, 1030 and 1037 which deal with
fraud and other related activity with respect to access devices, electronic mail or computers
(Rees, 2018). The substantive law of 47 USC 605 could also be accounted in this case as it
deals with unauthorized publication and use of communication. f f
Current cyber laws, regulations and policies in Maersk:
IT 659 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 4
The policy statement issued by Maersk in 2018 depicts the organization’s formidable
commitment to ensure security and implementation of necessary policies for preventing
security breaches. The security considerations are emphasized on equal terms with
operational and commercial factors in business management. The particular example of
Maersk’s recovery from the attack with its contingency plans could be assumed as a
validation for the same (Seacurus Bulletin, 2018, p 5).
The evaluation of the information systems security framework of Maersk also
suggests that the lack of frequent security updates was a notable cause for leading to the
detrimental impacts of the hacking attack. The attack was realized with an employee clicking
on an attachment with a virus which could have been prevented by resolving the SMB
vulnerability through the application of Microsoft security updates and patches (Seacurus
Bulletin, 2018,p 4). This setback in the company’s information system security approach
could have been resolved by observing and implementing the patch which was issued after
the ‘Wannacry’ ransomware attack on the National Health Service in UK.
Cyber law crimes:
The most common approach to follow in the identification and investigation of
cybercrimes within an organization is the conventional one in which the business impact of
the crime is evaluated first and check for severity of the incident such as compromise of
confidential information. The security personnel should be able to identify the systems or
servers which have been affected alongside recognizing the possibilities of data loss upon
abruptly shutting down system or a computer. The use of forensic imaging is the next course
of action to investigate cybercrime in which the recording of affected system and related
components could be observed (Fcw.com, 2018). The investigation of different information
sources such as external devices, log files and virtual machines as well as cryptographic
security of evidence are also significant security investigation measures.
IT 659 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 5
The formidable impact of cybercrimes like the NoPetya attack on Maersk is observed
in the form of downtime that is far worse than any other loss to the organization. The
information system structure of an organization could be substantially compromised with
notable concerns being vested in duplication and redundancy of information as well as loss of
vital information regarding the organization’s business operations.
The appropriate information security measures that should be followed to deal with
cybercrime are to emphasize prominently on translation of information security policies into
action. The specific human resources in responsibility of information security should
frequently update with the changing laws and regulations in the domain of cybercrimes.
Cybercrime and ecommerce:
According to claims made by Maersk, it has been able to recover from the attack
within ten days by the reinstallation of almost 4000 servers, 2500 applications and 45000
PCs. This clearly reflects on the installation of a new infrastructure to deal with the
consequences of the NoPetya attack. In order to improve its cyber resilience the organization
also implemented many long term and immediate initiatives with the aim for strengthening
the IT infrastructure platforms as well improve the IT service continuity and reinforcement of
business continuity plans (Safety4sea, 2018). The company has also opted for cyber
insurance in order to refrain from negative fiscal impacts of any future cyber-attacks.
As discussed in the earlier sections, the substantive and procedural cybercrime laws
are at the disposal of Maersk to deal with unauthorized intrusion into its information systems
by hackers (Cimpanu, 2018). Furthermore, the USCG has issued a cybersecurity strategy
which outlines the best practices and voluntary measures which can be employed by
organizations like Maersk in the shipping industry. The introduction of HR 3101
Strengthening Cybersecurity Information Sharing and Coordination in Our Ports Act 2017
could also be considered as a promising respite for Maersk in terms of regulations.
IT 659 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 6
References
Cyber Security: A Legal Requirement. (2018). Retrieved from
https://knect365.com/shipping/article/8a7a100b-542c-45c2-8b0f-b22bb579fca8/cyber-
security-a-legal-requirement
Cimpanu, C. (2018). Maersk Reinstalled 45,000 PCs and 4,000 Servers to Recover From
NotPetya Attack. Retrieved from
https://www.bleepingcomputer.com/news/security/maersk-reinstalled-45-000-pcs-and-
4-000-servers-to-recover-from-notpetya-attack/
Fcw.com (2018). Managing a cyber crime scene -- FCW. Retrieved from
https://fcw.com/articles/2014/12/18/managing-a-cyber-crime-scene.aspx
Nkuna, N. (2017). Understanding the motives for digital transformation in the container
shipping sector.
Rees, A. (2018). CYBERCRIME LAWS OF THE UNITED STATES. Retrieved from
https://www.oas.org/juridico/spanish/us_cyb_laws.pdf
Seacurus Bulletin. (2018). Retrieved from
http://www.seacurus.com/newsletter/Seacurus_Issue_73.pdf
Safety4sea. (2018). Maersk Line: Surviving from a cyber-attack. Retrieved from
https://safety4sea.com/cm-maersk-line-surviving-from-a-cyber-attack/
Students also viewed