PHIL 355E

Cybersecurity Ethics

This course examines ethical issues relevant to ethics for cybersecurity professionals, including privacy, professional code of conduct, practical conflicts between engineering ethics and business practices, individual and corporate social responsibility, ethical hacking, information warfare, and cyberwarfare. Students will gain a broad understanding of central issues in cyberethics and the ways that fundamental ethical theories relate to these core issues

End of Course Reflection:

Modern Security, Human Behavior, and Applied Ethics: A Semester Reflection   

Nicholas Duggins 

08/15/2026 

Modern Security, Human Behavior, and Applied Ethics: A Semester Reflection   

As I reflect on this semester’s coursework in Cybersecurity Ethics, my understanding of technology, human behavior, and moral reasoning has transformed significantly. Coming into this class, I viewed security through a strictly technical lens. If keeping systems safe was primarily a matter of strong firewalls, effective software, and clear-cut rules. However, engaging with real-world case analyses, speculative fiction, and foundational ethical tools; from Utilitarianism and Kantian Deontology to Virtue Ethics and Ubuntu, revealed that cybersecurity is fundamentally a human, social, and ethical issue. Three key topics the ethical tensions of state-sponsored cyberwarfare, the intersection of digital forensics with the social sciences, and the broader privacy responsibilities surrounding user data, have reshaped my perspective and provided insights that will guide my future choices. 

Topic 1: The Ethical Dilemmas of Cyberwarfare, Proportionality, and Utilitarianism 

Our analysis of high-profile cyber operations, particularly the Stuxnet attack on Iran’s nuclear enrichment facilities, challenged my straightforward view of ethics in technology. Initially, it was easy to view cyberweapons through a Consequentialist or Utilitarian framework as cleaner, more ethical alternatives to traditional military force because they minimize immediate physical explosives and direct casualties. However, evaluating Stuxnet through deeper ethical frameworks revealed a far more nuanced reality. On one hand, using malware to target Siemens centrifuges delayed a nation-state nuclear program without the immediate loss of life associated with traditional airstrikes. On the other hand, Stuxnet spread far beyond its intended target, infecting commercial entities and releasing sophisticated zero-day exploits into the public domain. Looking at this through Deontology, releasing an uncontrollable weapon fails the test of universalizability because it compromises global infrastructure stability. My perspective shifted from seeing cyberweapons as a “cleaner” solution to recognizing them as unpredictable tools that open Pandora’s box and create massive long-term systemic risk. My takeaway for my future self is to always look beyond immediate outcomes to consider long-term, systemic consequences. Just because a technical solution seems less harmful in the short term does not mean it is ethically sound if it introduces unmanageable collateral risks, compromises broader system integrity, or sets dangerous precedents. 

Topic 2: Big Data Research Ethics and Public Data Misconceptions 

Engaging with the Data Ethics module specifically reading Michael Zimmer’s analysis of the Facebook data release and Elizabeth Buchanan’s study on Twitter research during ISIS monitoring completely reshaped my understanding of data collection. Coming into the course, I operated under the common assumption that if information is already out in the public domain, researchers and analysts have free rein to scrape, analyze, and publish it without ethical friction. Zimmer’s work directly dismantled that assumption by showing how “public” data can easily be re-identified and combined in ways that violate individual trust and user expectations. Furthermore, Buchanan’s research demonstrated how big data analytics on radical groups or sensitive online networks can carry unintended real-world harms for innocent third parties caught in data sweeps. Evaluating these cases through Contractarianism and Ethics of Care helped me realize that accessing user data comes with an implicit social contract and a duty to minimize harm. My perspective shifted from viewing public dataset collection as a neutral technical task to recognizing it as a practice that requires active moral responsibility, contextual integrity, and user protection. My takeaway for my future self is that accessibility does not equal consent. I must never assume that because data is technical, public, or easy to gather, it is ethically free to use, and I must always evaluate the contextual integrity and real-world impact on individuals before analyzing or deploying user data. 

Topic 3: Privacy, Data Ethics, and Informational Friction 

Finally, engaging with the Privacy and Data Ethics modules specifically reading Luciano Floridi’s concept of “informational friction” and Michael Zimmer’s analysis of public data ethics fundamentally altered how I think about user data. I previously held the common view that if data is already public or online, using or analyzing it carries no real ethical harm. Floridi’s work helped me understand that privacy is not just about keeping secrets; it is about respecting the informational friction that protects personal identity and autonomy within the infosphere. Similarly, Zimmer’s work highlighted that just because data is accessible does not mean users gave consent for it to be scraped, analyzed, or exploited. This brought in elements of Contractarianism and the Ethics of Care, emphasizing that tech creators and data handlers have an implicit social contract and duty of care toward users. My perspective evolved from viewing data as neutral bits to recognizing it as an extension of human dignity. My takeaway for my future self is to respect user autonomy and privacy even when technical or legal barriers are absent. I should never assume that “publicly available” means “ethically free to use,” and I must always consider the duty of care owed to individuals and the potential real-world impact on human lives before collecting or analyzing user data. 

Conclusion: Engaging with these ethical theories and case studies throughout the semester has fundamentally changed how I view technology. Security and data management are not isolated technical puzzles; they operate within a complex web of human psychology, organizational structures, legal mandates, and ethical responsibilities. Carrying these takeaways forward will ensure that I approach my future career with a broader, more ethical, and human-centered perspective.