Critical Analysis 4

profileJohn_matt
case_study_1.docx

Introduction

            As a result of increased cybercrime in recent years, businesses and nation-states have continued to experience a number of cybersecurity challenges. These cybersecurity challenges are not strictly effecting one specific business or nation, but are impacting countries and businesses around the world (PWC, 2014). To name a few, cyberattacks and data heists have taken place in countries such as South Korea, Germany, Russia, Ukraine, and the United States (PWC, 2014). As a result of this global issue, it is critical for there to be an increase in cooperation on a global scale if these cybersecurity challenges are to be addressed.

            Furthermore, there are a number of political, economic, and social factors that drive global society’s need for cooperation. For instance, as a result of different laws, regulations, and national security standards among nation-states, companies and manufacturers are having difficulties providing security products and equipment to foreign nations due to the lack of global standards in cybersecurity requirements (Friedman, 2013). Furthermore, despite the fact that most nations are attempting to address these cybersecurity challenges, some nation-states continue to commit cyber economic espionage against each other, which is reducing the ability for nations to cooperate with each other (PWC, 2014). Moreover, as a result of global cyberattacks, it is estimated that the global average financial loss due to cybersecurity incidents was 2.7 million dollars in 2014 (PWC, 2014). As a result of these financial losses, economies are suffering.  Furthermore, the economy is also being impacted due to cybersecurity related trade barriers (Friedman, 2013). Importing countries are suffering as a result of exporting nations raising the costs of production, which ultimately forces the importing country to raise the costs for consumers (Friedman, 2013). Lastly, due to the increase in cyberattacks, society as a whole is losing its trust in their government’s ability to secure the Internet (Internet Society, 2015). Moreover, this lack of trust is also due to increasing legislation that allows governments to monitor the cyber activity of its citizens, which is viewed as an infringement of privacy rights by some (Internet Society, 2015). Collectively, these factors demonstrate that it is important to increase global cooperation among nations and companies to address cybersecurity challenges.

Business Need for Global Cooperation

            As a result of the factors mentioned previously, there is an increased business need for cooperation on a global basis. For instance, as a result of non-standardized and ever changing privacy laws, global companies are finding it difficult to fulfill the requirements of each country in which it does business. One example of this is Germany, where due to German works councils and data protection officers (DPOs), businesses are held to higher privacy restrictions than other countries (Otter, Ridder, Casper, & Wesche, 2011). Furthermore, due to import and export restrictions, it can limit the effectiveness of the free market, and can ultimately reduce the amount of competition between businesses competing to provide goods and services to foreign nations (Friedman, 2013). In order to address this issue, globally standardized laws need to be implemented so companies can develop consistent privacy security controls for the areas in which they do business. 

            Businesses are also effected due to insufficient information security programs produced by foreign third-party providers (PWC, 2014). Businesses that rely upon third-party providers for certain areas of their operations may be more exposed to particular security risks as a result (see table 2-1 for real-life examples of security challenges faced by companies). Through global cooperation, international standards can be developed that require all businesses to maintain an agreed upon level of security, which will in turn help assure companies that their third-party providers are maintaining adequate security for safeguarding data and information systems.

            Lastly, companies need global cooperation if they are going to adequately detect and respond to security breaches (International Chamber of Commerce, 2015). Companies are increasingly becoming more worried about the risks of experiencing a security breach (see table 2-1 below).  By ensuring communication from all sectors, industries, and governments, initial security breaches can be addressed efficiently without preventable mistakes being made during the response. Furthermore, this communication will also allow for lessons learned to be communicated throughout the global community, which can in turn prevent the same security breaches from occurring elsewhere (International Chamber of Commerce, 2015).

Table 2-1: Global Businesses and their Cybersecurity Challenges

Global Businesses

Cybersecurity Challenges

Apple Inc.

·      Complying with international privacy laws (Apple Inc., 2015).

·      Loss of information systems could result in a loss of availability for retail stores, a loss of confidentiality, integrity, or availability of company and/or customer data.

·      Malicious threats could lead to exposure of company stored personally identifiable information (PII) (Apple Inc., 2015).

 

Facebook, Inc.

·      Security breaches could lead to a loss of services, or exposure to sensitive customer and company information (Facebook, Inc., 2014).

·      Complying with privacy laws.

·      Inadequate security controls implemented by third-party providers could lead to exposure of the limited information provided to those companies (Facebook, Inc., 2014).

Microsoft Corporation

·      Security breaches could impact the privacy of sensitive customer and business data, disrupt the security of internal systems and applications (Microsoft Corporation, 2013).

·      Complying with privacy laws (Microsoft Corporation, 2013).

Table 2-1

Cooperative Efforts

            In an effort to increase global cooperation and assist with addressing security challenges, there are a number of cooperative efforts, which currently exist.

Interpol

            Interpol is the world’s largest international police organization and is currently associated with 190 countries (http://www.interpol.int/About-INTERPOL/Overview). One area in which Interpol is involved is fighting cybercrime. This organization works with both the private and public sectors to investigate cyber-related crime on a cooperative basis. Through its Global Complex for Innovation (IGCI) located in Singapore, Interpol utilizes global cyber-expertise from police and private sector partners. Each of the 190 members or countries that works with Interpol must maintain a National Central Bureau (NCB), which is staffed by law enforcement officers (http://www.interpol.int/About-INTERPOL/Overview).

International Telecommunications Organization

            The International Telecommunications Organization (ITO) is an organization based on a private-public partnership that is committed to connecting people all over the world by developing international technical standards that ensure networks and technologies interconnect (http://www.itu.int/en/about/Pages/default.aspx). This organization currently partners with 193 countries and almost 800 private-sector entities and institutions. In addition to nation-states, only corporate entities within the ICT sector can apply to become a member. Additionally, all those who are accepted must fill out an application and pay a fee that must then be approved by the nation state through which the company operates. The main functions of this organization include brokering agreements on technologies, services, and allocation of global resources to create universal global communication systems that are reliable (http://www.itu.int/en/about/Pages/default.aspx).

World Trade Organization

            The World Trade Organization (WTO) is a global international organization that addresses rules in regard to trade between countries (https://www.wto.org). The ultimate mission of this organization is to help producers of goods and services, exporters, and importers conduct business. Its key functions include negotiating trade agreements between countries, assisting in settling disputes, and ultimately acting as a mediator for governments involved in trade. As of 2015, there are currently 162 WTO members. Furthermore, any state that has complete independence when conducting trades may become a member, as long as all WTO members agree to allow the state to become a member (https://www.wto.org).

Recommendations

            As a result of the increased number of global cybersecurity challenges that global businesses face, there are a number of recommendations that global companies should consider when attempting to address the cybersecurity challenges identified within table 2-1. For example, in order to address poor security practices by third-party vendors, companies should consider developing contracts with these vendors to ensure they are implementing effective security controls (PWC, 2014). Furthermore, companies should also monitor these third-parties to ensure they are protecting sensitive information, as is specified within the established contract (PWC, 2014). If these third-party companies cannot afford, or lack, the expertise to implement all of the necessary security controls, it may be in the best interest of the global company to consider assisting the third-party with implementing these controls. This in turn could help facilitate cooperation among other companies.

 In addition, in order to reduce the impact of a security breach, companies need to develop response policies and controls (International Chamber of Commerce, 2015). If or when a security breach occurs, companies need to ensure a response plan is in place that helps decision makers determine when it is necessary to seek assistance from specialized third parties to help contain or resolve the security incident, or to assist with investigating the incident. These third parties may include law enforcement, government agencies, or competitors. By seeking the help of third-parties, companies can ensure they maintain an understanding of current and emerging threats, as well establish relationships that can then be utilized when an incident does occur (International Chamber of Commerce, 2015).

Lastly, global companies should consider improving upon the existing public-private partnerships (Information Technology Industry Council, 2011). By partnering with the public sector, organizations can help facilitate information sharing, analysis, and emergency response with governments and other industries (Information Technology Industry Council, 2011).  Although there are a number of items that cannot be addressed by businesses as they rely on policy and legislative changes made by each country, these recommendations can be adopted by organizations to ultimately improve global cooperation in response to cybersecurity challenges in cyberspace.

References

Apple Inc. (2015, October 28). Form 10-K annual report pursuant to section 13 or 15(d) of the securities exchange act of 1934.

Retrieved from http://hoovers.api.edgar-online.com/EFX_dll/EdgarPro.dll?FetchFilingHTML1?

SessionID=RaMreef2QCDAC6F&ID=10973752

Facebook, Inc. (2014, December 31). Form 10-K annual report pursuant to section 13 or 15(d) of the securities and exchange act of

1934. Retrieved from https://www.sec.gov/Archives/edgar/data/1326801/000132680115000006/fb-

12312014x10k.htm#sF5172B7CD90CBCCE67D4AA56A7518F91

Friedman, A. A. (2013, September). Cybersecurity and trade: National policies, global and local consequences. Retrieved from

http://www.brookings.edu/~/media/research/files/papers/2013/09/19-cybersecurity-and-trade-global-local-

friedman/brookingscybersecuritynew.pdf

Information Technology Industry Council. (2011). The IT industry’s cybersecurity principles for industry and government. Retrieved

from http://www.itic.org/dotAsset/191e377f-b458-4e3d-aced-e856a9b3aebe.pdf%20

International Chamber of Commerce. (2015). ICC cyber security guide for business. Retrieved from

http://www.iccwbo.org/Advocacy-Codes-and-Rules/Areas-of-work/Digital-Economy/Cyber-Security-Guidelines-for-

Business/ICC-Cyber-Security-guide-for-business/

Internet Society. (2015, January 22). Internet Society approach to cybersecurity policy. Retrieved from

http://www.internetsociety.org/news/internet-society-approach-cyber-security-policy

Microsoft Corporation. (June 30, 2013). Form 10-K annual report pursuant to section 13 or 15(d) of the securities exchange act of

1934. Retrieved from https://www.sec.gov/Archives/edgar/data/789019/000119312513310206/d527745d10k.htm

Otter, T., Ridder, F., Casper, C., & Wesche, P. (2011, May 11). What every global CIO should know about German works councils and

data protection officers. Retrieved from http://www.doctor-license.com/blog/wp-content/uploads/2012/07/What-every-

global-CIO-should-know-about-German-Works-Council-2011.pdf

PWC. (2014, September 30). Managing cyber risks in an interconnected world: Key findings from the global state of information

security survey 2015. Retrieved from http://www.dol.gov/ebsa/pdf/erisaadvisorycouncil2015security3.pdf