PHIL 355E

Cybersecurity Ethics

This course examines ethical issues relevant to ethics for cybersecurity professionals, including privacy, professional code of conduct, practical conflicts between engineering ethics and business practices, individual and corporate social responsibility, ethical hacking, information warfare, and cyberwarfare. Students will gain a broad understanding of central issues in cyberethics and the ways that fundamental ethical theories relate to these core issues.

Course Reflection

Throughout this cyber ethics course, I learned that ethical issues in cybersecurity are not just about whether something is considered legal, technical possible, or useful. Looking back on my work, three topics that stood out to me were privacy and autonomy, professional responsibility in technical work, and loyalty/whistleblowing. My thoughts on each of these topics become more nuanced because I started to see that cyber ethics is not separate from real human consequences.

The first topic that changed by thinking was privacy. Before this course, my thoughts about privacy focused on the secrecy of personal data. For example, I thought mainly of things like passwords, Social Security numbers, and financial details. By studying GDPR and the Google Street View cases, I changed my perspective to see privacy as a broader topic. I’ve come to the conclusion that information which is technically public is not necessarily ethical for organizations or people to gather, organize, evaluate or repurpose. For a specific example, say someone’s house, car, and driveway that is visible from the public road. This visibility does not indicate that owners gave permissions for a company to record, store and provide that information for any person to find. And the same principle is relevant to data on the internet. If a person shares data for one purpose, it should not automatically grant consent for organizations to use that data in other ways.

As I reflected on those points, I realized that privacy is linked to individual autonomy and dignity. For these reasons, individuals require actual control over the ways that organizations use their information, making it significant because corporations and governments possess much more technical capacity than a single individual. In my future career in cybersecurity, those concepts are critical because the protection of data involves more than the prevention of security breaches. It is also necessary to ask if the collection of the data is appropriate in the first place, how long the data remains in stored, who can view it, and how it is kept and if the user has a clear understanding of these data policies. My takeaway for my future self is as follows: Do not treat access as consent. Build and support systems that respect people’s control over their own information.

The second topic that stood out to me was professional responsibility. The Bill Sourour pharmaceutical quiz case made me think differently about what it means to “just write code.” At first, it can be easy to think that a developer, engineer, or cybersecurity worker is only responsible for the technical task they are assigned. However, that case showed me that code is not morally neutral when it shapes people’s choices. The quiz looked like a health tool, but it was designed so that almost every answer led to the client’s drug. That matters because the group of users were vulnerable and could have trusted the recommendation as medical guidance.

My position grew here because I realized that technical professionals often see things that normal users cannot see or think about. A user may not understand the algorithm, the backend logic, or risks behind a system, but the person building or securing the system should. That gives technical workers a special responsibility, it does not mean every worker is equally responsible for every bad outcome, but it does mean we cannot just hide behind “I was just following the job requirements.” In cybersecurity, I may be asked to configure systems, enforce policies, handle sensitive data, or support tools that affect real people. I need to always remember that doing my job well also includes recognizing foreseeable harm and speaking up before it becomes worse. My takeaway here is that: When technical work creates hidden risks for users, raise the concern early, document it, and do not let convenience or pressure replace human care judgement.

The third topic that gained my attention was loyalty and whistleblowing. Before this course, I probably would have thought of loyalty mostly as following rules, protecting an organization, and not exposing internal information. The Manning case made this more complicated. I still understand that leaking classified information can create real risks, but care ethics does not ignore those risks because care means responsibility to everyone affected which includes coworkers, soldiers, and the public. However, I also learned that loyalty is not the same as blind obedience, loyalty often requires you to look at an organization’s deeper values and mission statement to determine if you are acting loyally or not.

This connects strongly to cybersecurity because people in this field may see security failures, privacy abuse, dishonest reporting, or harmful systems before the public does. A good organization should have trustworthy internal channels so people can report concerns safely. But if those channels fail, the ethical question becomes harder. This course helped me see whistleblowing not as automatically betrayal nor automatically heroic, but as more of a serious nuanced moral decision that depends on harm, evidence, responsibility, and whether other options have been attempted. My takeaway here is: Do not confuse silence with loyalty. Real loyalty should protect people and values, not just an organization’s image.

Overall, taking this course allowed me to realize that cyber ethics is not only theoretical but practical as well. These complex tough issues such as privacy, professional responsibility, and loyalty are all related to the kind of individual I strive to become within my professional life. I am hoping to become an individual who is capable of thinking beyond technical tasks and who always cares about vulnerable individuals.

Link to further cyber ethical Case Analyses:
Case Analysis on Whistleblowing: Manning and “Collateral Murder?”

Information Warfare Case Analysis