Cybersecurity Ethics
This course examines ethical issues relevant to ethics for cybersecurity professionals, including privacy, professional code of conduct, practical conflicts between engineering ethics and business practices, individual and corporate social responsibility, ethical hacking, information warfare, and cyberwarfare. Students will gain a broad understanding of central issues in cyberethics and the ways that fundamental ethical theories relate to these core issues.
Course Material
In PHIL 355E, I learned that ethics regarding cybersecurity is more than simply following laws, policies, or technical rules. It is also about thinking carefully about the impact of technology on people and working out the responsibilities that professionals have when their work can cause harm. Three topics that really changed or deepened my thinking were professional responsibility, whistleblowing, loyalty, and cyber warfare and information warfare. Each of these topics helped me understand cybersecurity decisions as moral rather than purely technical ones. # Professional Responsibility and Codes of Ethics.
Professional responsibility. That was one thing that changed my mind. Before this course, I thought an employee was doing their job correctly if they followed company policy and did the work they were assigned. The professional ethics readings taught me that this is not always sufficient. The ACM, IEEE, and engineering codes focused on responsibilities to do no harm, be honest, protect privacy, assess risks, and consider the public good.
The case of Bill Sourour made this idea especially clear to me. Sourour told the jury that he created a pharmaceutical website that appeared to offer health information but was designed to get users to recommend the company’s drug. It was his job; it was a company-approved project, but the design could still be misleading to people. This case taught me that moral responsibility cannot be completely delegated by professionals to managers, employers, or legal departments. A system may be legal, but deceptive or harmful.
These matters to me as someone entering cybersecurity because cybersecurity professionals have access to sensitive data and powerful systems. Sometimes an employer may ask someone to do something they believe raises privacy, security, or fairness issues. I now think that it is the duty of professionals to ask questions and raise concerns, rather than to assume that if a supervisor has approved an action, it is ethical.
Message to my future self:
When working in cybersecurity, I want to remember that “I was just following instructions” isn’t enough. I must consider who could be harmed by what I do and if my decisions keep people safe from avoidable harm. Loyalty, Speaking Up and Whistleblowing
I also changed a lot in my views on whistleblowing. Before this course, my understanding of loyalty to an employer was to keep the organization’s information confidential and not to speak negatively about it in public. Vandekerckhove, Commers, Oxley, and Wittkower’s readings gave me a more complex idea of loyalty.
Vandekerckhove and Commers discuss **rational loyalty**. This concept holds that loyalty should be directed towards an organization’s legitimate mission, values, and ethical commitments, rather than simply following managers’ commands unquestioningly. Oxley and Wittkower also describe **critical loyalty**, in which someone may challenge an organization because they care about it and want it to live up to higher values. Those ideas changed the way I thought about cases like Edward Snowden and Chelsea Manning. Even if I don’t agree with every decision in a whistleblowing case, I recognize that whistleblowing does not automatically mean someone is disloyal.
I also learned that whistleblowing should be a matter of good judgment. Armstrong’s talk on confidentiality demonstrated that confidentiality is important, but not absolute. Sometimes disclosure may be justified by serious risks to the public, especially when internal solutions are ineffective. At the same time, disclosure can cause further harm, so professionals need to consider the evidence, alternatives, and the extent of information that needs to be disclosed.
This could be a very real cybersecurity issue. It might be a serious vulnerability that goes unnoticed, customer data being exploited, unsafe security practices, or misconduct within an organization. One of the hardest ethical decisions for a professional is when to stay confidential and when to speak.
Lesson for my future self:
Loyalty does not mean protecting wrongdoing. I want to remember that true professional loyalty sometimes means respectfully challenging an organization when it acts in ways that contradict its values or put others at serious risk.
Info & Cyber Warfare
The third issue that made me reflect a lot was warfare in the digital environment. Before taking this class, I thought war was about weapons, soldiers, and destruction. The cyberconflict and information-warfare modules taught me that serious harm could be done without any bombs or direct physical violence.
Taddeo’s discussion of cyberwarfare made me see that harm to information systems can have moral significance. An attack on electricity, communications, banking, emergency warning systems, or other critical infrastructure can affect hospitals, public safety, transport, and ordinary civilians. The Stuxnet case also taught me that a cyberweapon may appear more limited than a conventional military strike. However, it can still spread beyond its intended target, creating risks that are difficult to control.
The information-warfare material added a new dimension to this understanding. Prier demonstrated how social media, bots, algorithms, propaganda, and pre-existing political divisions can be used to influence entire populations. Morkevičius demonstrated to me how deception and mass disinformation can be especially harmful, because they destroy social trust. Cases involving foreign influence operations also revealed that an attack does not have to change voting machines to threaten a democratic system. Playing on people’s beliefs, inventing fake identities, and purposefully spreading more distrust can interfere with how people make political decisions.
It also made me think more deeply about ethical consistency. It is easy to condemn an adversary for using deceptive information tactics, but the same ethical principles should apply when our own government contemplates using similar techniques. Cybersecurity ethics requires us to judge the action itself, not to decide that something is okay because our side is doing it. Letter to my future self: Digital actions can cause real human and social harm, even when there is no immediate physical damage. Regarding cybersecurity, I always need to consider the broader impact of technology on privacy, trust, critical infrastructure, and people’s ability to make informed decisions.
Overall, this course made cybersecurity ethics seem much more practical to me. I now understand that technical ability brings responsibility. I want to remember that the people affected by those decisions should remain at the heart of my thinking, whether I am protecting data, responding to security incidents, assessing a vulnerability, or deciding how to use technology.