1 / 6100%
Running Head: IT 659 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 1
IT-659-Q1436: Assignment 7-2
SNHU
IT 659 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 2
Recommendations and Global Considerations
The Notpetya cyberattack affected Maersk business as well as the entire shipping
industry. Here the main recommendations have been done that could have helped the firm to
prevent the incident. Similarly, the global implication of the cyber incident has been captured
to understand how it has affected the global business setting.
Recommendations
Relevant changes for preventing the cyber attack
Maersk could have prevented the cyber-attack that crippled its shipping business
activities by upgrading the technological infrastructure. The business concern was considered
to have a decent level of protection on the cyber platform as compared to the other shipping
firms with weak security model. In spite of this, its vulnerabilities were exposed (Lennane,
2018). The dissemination of the attack across different business units of Maersk indicates that
the firm’s level of cybersecurity was not good enough.
The Blockchain technology could have played a key role and saved the shipping
concern from the Notpetya cyber-attack. The incident could have been averted if it had
shifted from the obsolete electronic data interchange (EDI) to the ‘blockchain-enabled’
technology. According to Antony Abell, the managing director of TrustMe, such a transition
on the technology front could have strengthened the cyber security model of the shipping
concern (Marinemec.com, n.d). The innovative technology would have increased the security
process of the concern multifold as blockchain runs in a sterile environmental setting.
Reasonable ethical guidelines for cyberattack prevention
The serious cyber incident which compromised the IT infrastructure of Maersk could
have been prevented if the appropriate and reasonable ethical guidelines were in place. The
moral compass of the business was shaky. This is because the shipping concern had failed to
upgrade the cyber infrastructure with the evolving times. Similarly, Maersk could have
IT 659 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 3
increased the awareness and education level of the employees so that they could have been
more conscious and agile before the incident (Marinemec.com, n.d). The shipping industry is
known to have a weak cyber risk management model which makes the industry and the
participants susceptible to the cyber attackers. The Notpetya attack acted as a major wakeup
call that revealed that there is the need to introduce stringent ethical guidelines so that the
lousy security subsystems can be replaced by technologically-advanced security models such
as the Blockchain technology.
Global considerations
International Compliance Standards
The proper establishment of an effective cybersecurity program is necessary for all
the business undertakings that function today irrespective of the nature of the industry or the
geographic location. In the current times, several regulations have been introduced urging
business firms to navigate the cyber risks and effectively tackle the online vulnerability
(Deloitte, 2018, p 2).
Some of the main international compliance requirements that would be relevant at the
time of the Notpetya incident include the adoption of a risk-based approach for the purpose of
understanding the various cybersecurity threats that arise in the industrial environments and
the establishment of a robust IT governance structure in order to drive accountability.
Similarly, in the current times, business undertakings always have to be on their toes to
identify vulnerable areas so that the security controls can be upgraded (Deloitte, 2018, p 3).
Firms also need to conduct the frequent monitoring of the information systems (IS) so that
they can identify the instance of a breach or attempted breach. The existence of the
International Compliance Standards and regulations would have naturally persuaded Maersk
to prevent the attack or identify it earlier.
Impact of the cyber-attack on global communication and commerce
IT 659 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 4
The Notpetya cyber-attack was a major incident that not only affected the Maersk
shipping business but exposed the high degree of vulnerability of the entire shipping industry.
It acted as a major wake-up call for the entire industry. The incident made the shipping
concerns that function in the industry conscious about the Information Technology
infrastructure and the management of the IT assets (Deloitte, 2018). f
After the cyber-attack that crippled the shipping firm has made global business
undertakings understand the gravity of having a robust cyber risk management model. In
order to strengthen the overall survival and sustainability of business and commerce on the
cyber platform, firms are making a sincere effort to comply with the evolving cyber security
standards and policies (Deloitte, 2018). The objective is to carry out the business activities in
a safe way so that the vulnerability of firms on the cyber platform can be managed and
mitigated to a certain extent. f
The business concerns that operate in the diverse and dynamic industrial environment
have learnt from no business is indispensable on the cyber platform. In order to operate in a
safe cyber setting, in the present times, organizations are focusing on establishing a robust
cybersecurity model that can enhance the safety and security of the business (Deloitte, 2018,
p 3). Firms in different nations are imposing strict ‘cyber integrity’ requirements in order to
have an edge against the cyber attackers and online hackers. f
The relationship between Maersk cyberattack and current global regulatory standards
After Maersk became a victim of one of the most notorious cyberattacks, numerous
changes have been introduced in the global technology environment so that business
undertakings can function in a safe and secure cyber platform. The incident has led to the
sharpening of the regulatory focus so that the vulnerabilities of the shipping businesses can
be managed in an effective and efficient manner (IHS Fairplay, 2018). The shipping industry
has, in fact, started to brace itself for a potential robust cyber security regulatory regime so
IT 659 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 5
that the online hackers will not have the scope to cripple the Information Technology systems
of the operational business undertakings.
The serious cyber incident which compromised the security model of the business has
put businesses on their toes. In fact, the regulators have also introduced stringent standards
and rules so that the businesses can be empowered to tackle against cyber-attacks. The
regulatory standards are urging business concerns to adapt to the digitalized era by
implementing fast and formal escalation programs (Deloitte, 2018). This can help them to
take fast actions against any kind of unauthorized activity that is carried out on the network
systems of the business firms. f
In order to help businesses function in a safe setting, the current global regulatory
standards have been designed by taking a cue from the Notpetya cyberattack. They are urging
firms to strengthen the IT backbone so that their cyber resilience can be enhanced (Moller,
2018, p 8).
IT 659 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 6
References
Deloitte, N. (2018). Global cybersecurity compliance integrity. Retrieved from
https://www2.deloitte.com/content/dam/Deloitte/us/Documents/risk/us-risk-global-
cybersecurity-compliance-integrity.pdf
IHS Fairplay. (2018). Maersk cyber-attack sharpens regulatory focus. Retrieved from
https://fairplay.ihs.com/safety-regulation/article/4289206/maersk-cyber-attack-
sharpens-regulatory-focus
Lennane, A. (2018). Shipping must learn from Maersk cyber attack – tighten security or be
next, warning - The Loadstar. Retrieved from https://theloadstar.co.uk/shipping-must-
learn-maersk-cyber-attack-tighten-security-next-warning/
Marinemec.com. (n.d). Blockchain would have prevented Maersk cyber-attack. Retrieved
from https://www.marinemec.com/news/view,blockchain-would-have-prevented-
maersk-cyber-attack_48287.htm
Moller, A. (2018). MAERSK 2017 Annual Report. Retrieved from
http://files.shareholder.com/downloads/ABEA-
3GG91Y/6115885668x0x971046/54DA7595-1904-4118-9174-
E741CB7621D4/A.P._Moller_-_Maersk_Annual_Report_2017.pdf
Students also viewed