1 / 7100%
Running Head: CASE ANALYSIS f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 1
IT-659-Q1436 : Case Analysis & Incident Impacts
SNHU
CASE ANALYSIS f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f
f f f f f 2
Maersk was the victim of a serious cyberattack that jolted the entire shipping industry.
The attack was big news back then. The ethical issues and legal issues that led to the situation
have been analysed here. Similarly, the social and cultural impact of the event has been
thoroughly examined. The impact has been categorized into cultural impact, standards and
regulations impact so that a holistic picture can be drawn in the process. The cyberattack
incident is regarded to be one of the most catastrophic occurrences that jolted the shipping
industry.
Ethical Issues in Maersk cyberattack
A number of loopholes existed in the IT infrastructure of Maersk due to which the
computer network of the shipping business undertaking was compromised. The NotPaytya
cyberattack affected the shipping business since the online assets of the firm were totally
unprotected. The interconnectedness of a large number of computer systems further
intensified the vulnerability of the shipping business (Ship-technology.com, 2018). The main
ethical issue that gave rise to the cyberattack was the lack of a proper security system.
Legal Compliance issues within the Maersk organization
The magnitude of the cyberattack on Maersk was high since there existed a number of
legal loopholes that needed to be filled (Theregister.co.uk, 2018). The malware was placed in
a malicious update in one of the most popular accounting software that was used by the
shipping concern. Since the software was not checked by the firm, it was not able to identify
the anti-element that existed in its computer networks (Marinemec.com, 2018). In spite of the
high level of connectivity of various computer networks and communication systems, the
business undertaking did not have the highest of level automation process that is expected
from a global ship business. Even though a concern can never be 100 percent secure in the
vast cyber space, Maersk could have averted the attack by updating its software with the
CASE ANALYSIS f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f
f f f f f 3
relevant security fixes that were produced by Microsoft (Economictimes.indiatimes.com,
2018).
The societal and cultural impact of the compliance issues
Maersk’s cyberattack incident affected the shipping industry as the business was one
of the most reputed and prominent market participants at the time of the incident (Saul,
2017). The impact of the attack has reverberated across the entire shipping industry and now
the shipping firms are increasing their investment to strengthen their information technology
infrastructure (Saul, 2017). The objective is to control such kinds of cyber-attacks that can
outrage the computer network of the organizations.
Due to the compliance issues that arose in the case of the Maersk shipping business, it
cost the business USD 300 million and affected its social status and reputation (Novet, 2018).
The NotPetyaayttack showed that when it comes to online threat, there exist no cultural or
social boundaries.
Impact of the incident with ethical and legal IT regulations of the time
After the cyberattack incident that jolted the shipping industry, various shipping firms
including Maersk are working on new security measures so that the online assets can be
safeguarded on the cyber platform. For instance, Maersk is working with the IBM
organisation so that it can incorporate a new and effective Blockchain solution. The incident
has made the shipping firm conscious to maintain a safe and secure IT infrastructure so that
their operations and activities will not be compromised in any manner.
After the incident, most of the shipping firms started working on introducing stronger
and effective security measures that could protect their business as well as the online assets.
Changes have been introduced in the IT regulations (Marinemec.com, 2018). Prior to the
cyberattack, the main attention was given to the voluntary guidelines and instructions from
the shipping industry but after the attack that affected the business activities of Maersk, new
CASE ANALYSIS f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f
f f f f f 4
and stringent regulations are being introduced so that the ship business firms can be protected
from dangerous cyber incidents.
The link between the industry standards and the standards in existence for information
technology
The cybersecurity in the shipping industry has been quite lenient prior to the
cyberattack incident. The main factors that come into play and influence the level of security
in the industrial setting include automation, integration, The capability to “ship to shore” that
communicates through monitoring and the connectivity via the internet. The industry
standards relating to cybersecurity were limited to a certain extent.
The security measures that were followed by Maersk at the time of the incident was
below par. For instance, the safety net of the business undertaking was not upgraded due to
which the unauthorized people had access to the computer network. Thus it can be said that
the shipping industry’s standards relating to cyber security were lacking and at the same time,
the security approach of Maersk also contained loopholes.
Cultural Implication
The cyberattack that affected Maersk and its shipping business had a major cultural
implication as it showed that the social-cultural conflicts can give rise to technology-based
conflicts and cyber issues. The incident, in fact, acted as a catalyst and gave rise to the culture
of cyber security (Gandhi et al., 2011).
Since people generally tend to think in form of groups, the Maersk cyberattack
highlighted the fact that the shipping industry is not safe and it is highly vulnerable in the
online platform. The incident was a major happening that took place on the cyber platform
and reshaped the regulations and standards that have been existing in the shipping industry
for a long period of time (Gandhi et al., 2011). The cyber breach that not attacked the IT
system of the business but also and crippled its It infrastructure increased the collective
CASE ANALYSIS f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f
f f f f f 5
consciousness of the industry participants and the government about a robust cyber security
model.
The cyberattack that was experienced by the shipping giant Maersk revealed that the
cyber attackers and cyber hackers are on their toes at all times and they are regularly looking
out for vulnerabilities of business concerns. The magnitude of the cyber incident could have
been controlled to a certain extent if the business had a stronger ethical and legal model of
cyber security. But the incident has opened the eyes of the shipping industry participants due
to which they are trying to safeguard their IT infrastructure and abide by the latest rules and
standards concerning cyber security.
CASE ANALYSIS f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f
f f f f f 6
References
Economictimes.indiatimes.com. (2018). Maersk says global IT breakdown caused by cyber
attack. Retrieved from
https://economictimes.indiatimes.com/news/international/business/maersk-says-global-
it-breakdown-caused-by-cyber-attack/articleshow/59341860.cms
Ship-technology.com (2018). Did the Maersk cyber attack reveal an industry dangerously
unprepared? - Ship Technology. Retrieved from https://www.ship-
technology.com/features/maersk-cyber-attack-reveal-industry-dangerously-unprepared/
Gandhi, R., Sharma, A., Mahoney, W., Sousan, W., Zhu, Q., & Laplante, P. (2011).
Dimensions of cyber-attacks: Cultural, social, economic, and political. IEEE
Technology and Society Magazine, 30(1), 28-38.
Marinemec.com (2018). Shipping got off lightly in first cyber security attacks, say legal
experts. Retrieved from http://www.marinemec.com/news/view,shipping-got-off-
lightly-in-first-cyber-security-attacks-say-legal-experts_49273.htm
Marinemec.com (2018). Blockchain would have prevented Maersk cyber-attack Retrieved
from http://www.marinemec.com/news/view,blockchain-would-have-prevented-
maersk-cyber-attack_48287.htm
Novet, J. (2018). Shipping company Maersk says June cyberattack could cost it up to $300
million. Retrieved from https://www.cnbc.com/2017/08/16/maersk-says-notpetya-
cyberattack-could-cost-300-million.html
Saul, J. (2017). Global shipping feels fallout from Maersk cyber attack.
Theregister.co.uk (2018). IT 'heroes' saved Maersk from NotPetya with ten-day reinstallation
bliz.. Retrieved from
https://www.theregister.co.uk/2018/01/25/after_notpetya_maersk_replaced_everything/
CASE ANALYSIS f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f
f f f f f 7
Students also viewed