Cybersecurity Ethics
This course examines ethical issues relevant to ethics for cybersecurity professionals, including privacy, professional code of conduct, practical conflicts between engineering ethics and business practices, individual and corporate social responsibility, ethical hacking, information warfare, and cyberwarfare. Students will gain a broad understanding of central issues in cyberethics and the ways that fundamental ethical theories relate to these core issues.
Course Material
Cybersecurity Ethics Reflection
Before taking this class, I honestly thought cybersecurity ethics was mostly about knowing what is legal and what is not. If something was against the law, I figured it was probably unethical, and if it was legal, then it was probably okay. After going through the different modules and case studies, I have a much different view. I have realized that cybersecurity decisions can be technically correct or even legal and still cause serious ethical problems. Three topics that really changed or deepened my thinking were privacy, corporate responsibility, and whistleblowing.
1. Privacy and Data Collection
The first topic that changed my thinking was privacy, especially from the discussion about Google Street View. At first, I looked at things like Street View mostly as a useful technology. Google was collecting images of public streets, and I originally thought that if something could be seen from a public place, then there was not really a privacy issue. However, the readings made me think more about the difference between something being publicly visible and something being ethically okay to collect, store, and use.
The Google Street View case showed me that technology can change the scale of something in a way that creates new ethical problems. A person might be visible from a street for a few seconds, but having that image recorded, stored, and made available to millions of people is completely different. Using virtue ethics also helped me think about what a responsible company should do, instead of only asking whether Google technically had the right to collect the information.
My position has become more nuanced because I don’t think privacy means that companies should never collect information. Technology needs data to work, and some data collection can be useful. The bigger issue is how the information is collected, what people reasonably expect, and what happens to the information afterward.
Takeaway: Just because I can collect information doesn’t mean I should. In cybersecurity, I want to remember to think about the person behind the data, not just the data itself.
2. Corporate Responsibility and the Equifax Breach
Another topic that really changed my thinking was corporate responsibility. The Equifax breach made me realize that cybersecurity failures are not just technical problems. Before this class, I probably would have looked at a major breach and focused mostly on the hackers and the vulnerability they exploited. After studying the Equifax case, I started thinking more about the company’s responsibility to protect the people whose information it collects.
The breach affected millions of people who did not choose to have their information exposed. Their names, Social Security numbers, and other personal information could potentially be used for identity theft and other types of fraud. What stood out to me was that the people affected were not necessarily customers who had agreed to take a risk. They were people whose information was part of a system that Equifax had a responsibility to protect.
The ideas of Friedman and Anshen also made me think about the balance between making money and having responsibilities to other people. A company obviously needs to make a profit, but cybersecurity showed me that businesses also have responsibilities to employees, customers, and the public. Ethics of Care made this even clearer because it focuses on relationships and the effects our decisions have on other people.
Takeaway: Don’t look at cybersecurity as just protecting systems. Remember that behind every account, record, or database is a real person who could be affected by a security decision.
3. Whistleblowing and Loyalty
The third topic that made me think differently was whistleblowing, especially the case involving Chelsea Manning. Before this course, I probably would have viewed whistleblowing in a pretty simple way. I would either see someone as a hero for exposing wrongdoing or as someone who broke the rules and betrayed their organization. The Manning case showed me that it is not always that simple.
Manning’s situation made me think about the conflict between loyalty to an organization and responsibility to a larger group of people. Someone working for the government has obligations to follow orders and protect sensitive information, but that does not automatically mean that every action taken by the government should be protected from criticism. At the same time, releasing classified information can create real risks, so I don’t think whistleblowing should automatically be considered ethical just because someone believes they are exposing wrongdoing.
My position has changed because I now see whistleblowing as something that requires looking at the circumstances, intentions, consequences, and available alternatives. A person can have good intentions and still make a decision that causes harm. On the other hand, following orders does not automatically make a decision morally right either.
Takeaway: When loyalty and doing what I believe is right conflict, I need to slow down and think about who could be helped or harmed by my decision instead of automatically choosing one side.
Overall, this class changed the way I think about cybersecurity. I came into it thinking ethics was mostly about rules and laws. Now I see that cybersecurity professionals constantly make decisions that affect real people. Privacy, corporate responsibility, and whistleblowing all showed me that there is usually more than one side to an ethical problem. Going forward, I want to remember that being good at cybersecurity is not just about knowing how to protect a system. It is also about understanding the responsibility that comes with having the ability to access, protect, collect, or expose information.