Basagic, Justin
UMUC
Abstract
In this paper, I am writing about how the relationship between cyber security has changed with innovation over time. I will also be covering that there is such a thing as good hacking instead of only shining a negative light on the subject.
Keywords: Cyber security, hacking
Cyber Security and Innovation
Innovations over time has resulted in the creation of devices such as computers, laptops, and iPods. This has had positive effects in communications since people can now chat on line, thus making communication easier, faster, and cheaper. Besides these benefits, the companies involved in the creation of these devices have benefited financially due to higher sales they make over a short period. However, there are significant challenges that are encountered in cyber security which continue to evolve over time due to massive growth in the telecom and the explosion of the internet. Growing with innovations and technology is paramount to being successful as a cyber security analyst.
The problems in cyber security are threats, vulnerabilities, and effects caused by attacks (Hansen & Nissenbaum, 2009). Other challenges include inadequate funds and lack of visibility control. According to Hansen & Nissenbaum (2009), cyber security is the act of taking care of ICT devices. The targets for cybercriminal are intellectual property, trade secrets, and contact negotiations. People who perform cyber-attacks, for instance, cause threats,, and they are categorised into five subheadings. These are Criminals intentioned on gaining money from crimes such as theft, hacking and extort. The second type is spies’ intention to access crucial government information or private entities while the third group is state warriors who perform cyber-attacks supporting a country's strategic plans and objectives. In addition, "hacktivists" who would cyber-attack for no monetary gain as well as terrorists who use cyber-attacks as a tool for non-state or state-funded warfare form the fifth category. These groups of people perform cyber-attacks to bring organisations to the economic loss to a nation or a firm and psychological problem to workers in various organizations. Therefore, data stolen from companies can be alleged on innocent citizens (Lipman, 2015).
Moreover, there has been a rapid growth of threats per day. It has been discovered that there was a quarter a million-ransom ware variants in the past year (Lipman, 2015). However, it has been understood that the number is growing at the rapid rate of 60,000 new variants every day. Ransom ware acts like a trawling net which cast broadly to share as a large number of victims as possible in single attempt (Lipman, 2015). The threats have been sophisticated though they are conducted in combination. Conversely, there are aimed threats, which are designed to attack a certain organisation or even a particular individual (Lipman, 2015). These risks are tough to block with traditional security products.
The second challenge facing cyber security is vulnerabilities. This is because cyber security is in many ways related between the cyber criminals and the defenders (Fischer, 2016). For instance, ICT devices are complex, and criminals are always looking for any weaknesses occurring at most points. However, defenders can shield these ICT systems against this weakness though there are significant challenges accompanied by this move. These may include intentional actions by criminals able to access a system; supply chain vulnerabilities, which can allow the use of malicious software during the installation process; and previously unknown, vulnerabilities without established solution (Kaminsky, 2006). On the contrary, where vulnerabilities are known, the implementation may be hindered by operational constraints.
The third challenge facing cyber security is the impact brought by the attack. A well-planned attack is capable of destroying the formality; availability as well as the integrity of an ICT system with the data it handles. Additionally, cyber attacks can result in the loss of financial, proprietary, or personal information without the knowledge of the victim (Fischer, 2016). For example, denial-of-service cyber attacks affect legitimate users while accessing an individual system (Fischer, 2016). Therefore, the user of an ICT system may continue using some systems while others are inaccessible yet some may not realise this effect. Though the manufacturing companies are trying to reduce cyber-attack in conjunction with awareness given to ICT users, botnet malware constitutes to the growth of this crime. This is because it gives an attacker the direction of a system for use in cyber-attacks in other systems.
Besides these effects, most cyber-attacks have little impact while a bigger attack on some systems with critical infrastructure (CI), might have significant consequences on country’s security, it’s economy as well as the livelihood and safety of the citizens (Fischer, 2016). Although it is widely recognised that cyber-attacks are costly to individuals and organisations, economic impacts can be difficult to measure while estimates vary widely. A cited figure for the annual cost to the global economy from cybercrime is $400 billion (Fischer, 2016). However, some observers have argued that this cost is substantially increasing with the expansion of the ICT infrastructure. The increase could also be attributed to the transition in customers’ preferences as most of the youths are purchasing the gadgets.
Besides these challenges, the insufficient fund is also an inconvenience in cyber security. According to recent statistics, the local government agencies spend less than five percent of its IT budget on cyber crime (Lipman, 2015). This figure is half of what is allocated to the typical commercial enterprise. If the world's prominent companies have been affected by cyber attacks, it is evident that both the state and local agencies' efforts remain underfunded. Because of this, the team mandated with ensuring cyber safety lack enough resources to implement their goals. Therefore, because of this, the attackers get an opportunity to manoeuvre to their benefit. In addition, government agencies are facing a shortage of cyber security staff and in case they have, the staff lack knowledge (Lipman, 2015). With the rapid growth in the cyber threats over the last few years, the increasing demand has created a significant premium on security skills. This is because the public sector organisational is required to compete for talent due to the diverse nature in compensation level across the world. The most talented organisation has a competitive advantage since the cyber criminals will not be able to hack any information from such a firm hence ensuring confidentiality of the information.
The last challenge facing cyber security has limited visibility and limited control. However, one of the unfortunate by-products within the IT environment is an avalanche of security events. Controlling security through alerts has been described as a thing of the past: it is not only misleading, but it is ultimately likely to end in a disaster for all involved (Lipman, 2015). Since this method has been disregarded, this shows that there are no plans on how to curb this vice. Many people even those in authority; have been unable to come up with rules and regulations against this device. The criminals undertaking this vice have therefore been encouraged to go on by the fact that there are no rules in the constitution that outline the punishment for this vice.
Some ways can be used to manage the challenges in cyber security. Some of the recommended ways are removing the threat source by closing down botnets or cutting down incentives for cybercriminals (Fischer, 2016). Secondly, the manufacturing companies need to address vulnerabilities by hardening the ICT assets they manufacture by patching software and training employees. In addition, the users need to lessen impacts by reducing damage and restoring functions to ensure continuity of operations in response to attack. The level of risk reduction will thus vary among sectors and organisations. For instance, the level of cyber security that customers expect may be lower for a company in the entertainment industry than for a bank, a hospital or a government agency (Fischer, 2016).
In conclusion, it is the role of everyone to ensure that cyber professional and the cyber industry grows and evolves with the challenges it faces. The government has a substantial responsibility to make sure that the organisations that fall under it to provide cyber security are well funded. If this is put into practice, cyber security will be in a much better place.
References
Hansen, L., & Nissenbaum, H. (2009). Digital disaster, cyber security, and the CopenhagenSchool. International Studies Quarterly, 53(4), 1155-1175.
Kaminsky, D. (2006). EXPLORATIONS IN NAMESPACE: WHITE-HAT HACKING ACROSS THE DOMAIN NAME SYSTEM. Communications Of The ACM, 49(6), 62-68.
Lipman P., 19th August 2015. The cyber security challenges facing state and local governments.
Fischer E. A., 12th August 2016. “Cyber security issue and challenges: in brief.” Congressional research service.