How Can Cyber Capacity Building Help Nations Protect their Homelands?
How Can Cyber Capacity Building Help Nations Protect their Homelands?
In an increasingly interconnected world, cyber capacity building is an essential tool for nations to protect their homelands and citizens. As more and more critical infrastructure and economic activities move online, the need to create robust global cybersecurity policies has never been greater. Cybersecurity is not only a question of national security, but increasingly a matter of international security as well and it is becoming increasingly clear that the only way for nations to successfully protect themselves from global cyber threats is through developing a global partnership to share best practices and technologies, as well as create new cyber defenses.
This research paper will explore how nations can collaborate on cyber capacity building to strengthen their defenses against possible cyber-attacks. We will discuss how public-private partnerships and government-to-government cooperation can help build cyber capacity in both wealthy countries and developing countries in order to better protect against emerging cyber threats such as cybercrime, terrorism and other malicious actors. Finally, we will consider the importance of international cooperation when it comes to creating a unified global response system in the event of a major attack.
Introduction to Cyber Capacity Building
Cyber capacity building is an important and increasingly common way for nations to protect their homelands and citizens from cyber threats. It involves enhancing a nation’s ability to detect, prepare for, deter, respond to, and mitigate cyber threats by improving its technical infrastructure, human capital development, monitoring capacity, legal frameworks, and policies. In order for nations to effectively use cyber capacity building to protect their homelands from the increasing prevalence of global cyber threats, it is essential that wealthy nations foster public-private partnerships as well as government-to-government cooperation to build robust cyber capacity at the national level.
Through public-private partnerships and government-to-government collaboration on cyber capacity building initiatives, nations can work together on defending against the threat of cyberattacks originating from anywhere in the world. This collaborative approach is especially important in helping developing countries with limited resources increase their cyber defense capabilities while at the same time helping wealthier countries improve their response capacity in countering cybercrime and thwarting other forms of cybersecurity threats such as those arising from cyber terrorism.
The Benefits of Global Cybersecurity Efforts
When it comes to protecting their homelands, nations across the globe are battling a common enemy: cyber threats. As technology becomes more sophisticated and pervasive, nations are increasingly vulnerable to malicious actors using the internet to cause harm. Cyber capacity building is a critical step in the fight against cyber threats, helping nations develop the necessary knowledge, skills, and infrastructure to protect their citizens and economic interests. Cyber capacity building involves equipping nations with the technological skills and resources to respond to and mitigate cyber-based threats. It includes training in hardware and software solutions, such as firewalls and malware protection, as well as developing the legal and regulatory frameworks needed to successfully prosecute cyber criminals. As nations become increasingly reliant on the internet for communication and commerce, the need for cyber capacity building becomes even more pressing (Creese et al., 2021).
At the same time, however, it is important for countries to consider the impact of cyber capacity building efforts on other nations. Cyber security threats are a global issue, and efforts to protect one nation from cyber threats can inadvertently put others at risk if not undertaken in full cooperation with other nations. To this end, there has been an increased focus on international cooperation when it comes to cyber security. The United Nations, for example, has launched several initiatives to facilitate the sharing of knowledge and resources among member nations in an effort to raise the level of cyber defense around the world (Creese et al., 2021).
The benefits of greater global cybersecurity efforts are numerous. By cooperating through international initiatives and public-private partnerships, countries can better protect their critical infrastructure and digital assets. Cyber capacity building also allows companies to respond more effectively to cyberattacks, cybercrime prevention, and the threats arising from cyber terrorism. Moreover, robust cybersecurity efforts can generate global economic growth by providing access to secure financial transactions, improving communication infrastructure and raising user trust in online services.
Additionally, these international initiatives encourage the development of common standards and best practices for dealing with cyber threats. By sharing cybersecurity insights and resources, nations can identify weaknesses in their systems that can be quickly remedied with enhanced defenses. Furthermore, technologically advanced countries are able to help less-resourced nations establish adequate security measures by offering expertise and resources. These initiatives can also lead to increased information sharing between countries intelligence communities which further strengthen global security measures (Creese et al., 2021).
Role of Public-Private Partnerships in Cyber Capacity Building
Public-private partnerships (PPPs) have emerged as an effective form of collaboration for different actors dealing with cybersecurity. PPPs are arrangements in which the public and private sectors cooperate to achieve mutual goals. Such partnerships can provide an environment for developing capacity building initiatives that allow countries to create positive cyber assurance and help build resilience against cyber threats. PPPs can lead to economies of scale, operational optimization, and improved coordination between the different stakeholders involved in cybersecurity activities (Matviyenko & Petushkova, 2022). Additionally, PPPs often foster innovation through the joint development of technological solutions and research initiatives. As such, they can be used to help nations develop effective strategies for threat intelligence; incident response; risk assessment; vulnerability testing; cloud security; system architecture review; risk monitoring; data protection; secure code development; certification of products, services and personnel; and education and training programs tailored for national needs (Homburger, 2019).
Government-to-Government Cooperation for Improved Global Response to Cyberattacks
Government-to-government approaches to cyber capacity building can help countries address issues such as cybercrime prevention and cyber terrorism. These approaches involve the sharing of technology, best practices and resources between nations for improved global response to cyberattacks. For example, the US Department of Defense has worked with the European Commission’s Joint Research Center (JRC) to develop a framework for cooperation in cyber defense. These agreements are designed to help countries strengthen their own defenses against cyber threats as well as helping them work together with other nations to protect their homelands from such dangers. The agreements also provide a platform for the sharing of resources such as tools and training materials, allowing countries to learn from each other’s experience in addressing cyber threats. This type of knowledge sharing helps reduce risk and improve overall global cybersecurity efforts. Furthermore, public-private partnerships can play a role in building cyber capacity at the national level. By working together, governments and private organizations can leverage each other’s experience and expertise to create more effective strategies for protecting their digital infrastructure and data networks against malicious actors (Kostyuk & Brantly, 2022).
Cybercrime Prevention and the Risk of Cyberterrorism
The danger of cyber threats has grown exponentially in recent years, leading to an increased focus on cybercrime prevention at the national level. Public-private partnerships and government to government cooperation can help nations increase their cyber capacity and build a robust response to both traditional cybercrime and emerging threats such as cyber terrorism. For example, public-private partnerships can provide access to expertise and resources that nations may not possess on their own. They also allow for the sharing of best practices and the creation of networks that are better equipped to respond to large-scale attacks. Government-to-government collaboration is also key to improving global cybersecurity efforts. Through bilateral agreements, nations can share strategies, policies, and information on global threats, making them better equipped to defend against cyberattacks. Finally, investing in cyber capacity building can help nations prioritize the areas that are most vulnerable. By addressing critical infrastructure vulnerabilities, identifying potential points of attack, and establishing security protocols, governments can ensure their homelands are better protected against cyber threats (Pretorius & Ngejane, 2019).
Risks to Affluent Nations not Working Cooperatively
The rapid proliferation of the internet and its associated technologies has presented both opportunities and risks for nations across the world. As computer systems continue to gain complexity and sophistication, nations must recognize the importance of cultivating their trained, skilled, and professional cybersecurity personnel to help defend their homelands from cyber threats. Whether it is a nation state actor or a criminal organization launching an attack, cyber capacity building for more affluent countries could serve as a critical foundation for global cybersecurity efforts. There are several risks to affluent nations if they do not aid in creating or improving the cyber incident response capacities of other countries. These risks can be divided into three main categories: Lack of International Cooperation: Nations that have a lack of international cooperation, or are challenged by limited resources and a lack of personnel, are likely to be vulnerable to cyber-attacks (Kostyuk & Brantly, 2022). If the wealthier countries do not step in and help the poorer countries build their cyber capacity, then they will remain vulnerable and create more opportunities for malicious actors. Security Implications: Nations that fail to develop their own cyber capacity also present security implications for the world as a whole. Without adequate expertise and resources, poorer nations will not be able to defend themselves against cyber threats which could eventually spread even further. Conflict Escalation: Finally, without proper support from affluent nations, poorer countries can be more susceptible to conflicts that could arise due to poor cybersecurity resources. This could easily escalate into greater regional conflict and further destabilize the international security landscape.
Benefits of Working Cooperatively
The need for international cooperation has never been greater with regard to the mutual protection against cyber threats. To this end, there are several tangible benefits to be had from working together. First, coordinated efforts contribute to the development of a higher caliber of cybersecurity personnel. With the availability of training, education and technical assistance, countries can bolster their own cybersecurity forces, in turn allowing them greater autonomy in defending their networks and systems against adversaries. Second, cooperative efforts can help create a more level playing field when it comes to cyber warfare capabilities around the world. By helping other nations build up their cyber incident response capacity, affluent countries can ensure that their neighbors have the skillsets and equipment necessary to counter potential cyber-attacks in an effective manner. Thirdly, these collaborative efforts promote international norms and best practices in cyber security among different nations. By building capacity together, countries can begin to recognize existing security frameworks and reinforce universal standards for protecting network infrastructures.
Barriers to Creating Cyber Capacity
When establishing cyber capacity, nations must consider the possible barriers that could impede progress. Here are some of the known barriers to creating a cyber capacity. Creating cyber capacity is very costly. In that, many nations lack the financial resources required to produce the sophisticated software and hardware needed for effective cyber defense. This is especially true for developing countries. Additionally, many countries are unable to afford a qualified and experienced staff of cybersecurity professionals to ensure that their systems are secure. Other nations, lack technological infrastructure – such as access to the internet and outdated telecommunications networks – to ensure efficient cyber defense response teams can work without disruption or delay. Without proper infrastructure, these nations may not be able to quickly identify or respond to potential threats in a timely manner. Other nations may also face cultural challenges when developing a cyber defense force. These can include language barriers, varying cultural norms and customs, and other cultural issues that can hinder collaborative efforts. Additionally, governments may be resistant to allowing international organizations or private businesses into their country in order to assist with creating better cybersecurity measures (Pretorius & Ngejane, 2019).
Recommendations for International Cyber Capacity Building
As the world continue to tackle the ever-evolving global cybersecurity challenge, it is essential to consider how nations can strengthen their own cyber capacity building efforts. We must be proactive in developing and implementing strategies that focus on both the immediate and long-term issues of security, with consideration given to the significance of international relations. With this in mind, it is essential to undertake an analytical review of current cyber capacity-building initiatives to identify potential areas of improvement and inform an effective strategy for international cooperation.
In recent years, nations across the world have undertaken various efforts to strengthen their cyber capacity building strategies. According to a study published by the First Foundation, these efforts can be divided into two broad categories – operational and policy. In general, operational strategies focus on developing technologies and procedures to identify and detect threats, while policy approaches mainly focus on creating legal frameworks, international cooperation and collaboration between stakeholders. On the operational level, most countries have established national cyber security agencies and organizations responsible for coordinating government-level approaches to cyber protection. These organizations are usually tasked with managing national cyber security initiatives such as developing best practices for data protection, providing staff training in cyber security, and monitoring malicious actors. In addition, governments are also focusing more on strategic defense mechanisms, such as improved encryption methods for storing sensitive data (Pretorius & Ngejane, 2019).
Regarding policy measures, international agreements and collaborations have been developed to facilitate knowledge sharing between stakeholders from different nations. For example, countries like the United Kingdom and Germany have worked together in efforts to create a shared intelligence platform that enables better communication between security forces in an effort to protect both countries against cyber threats. Additionally, many nations have also joined together to create unique “cyber diplomacy” teams that are responsible for building international relationships in cyberspace as well as coordinating joint responses against cross-border attacks. Therefore, it is clear that various measures are already being taken towards enhancing nation’s cyber capacity building capabilities; however, there is still much room for improvement in both operational and policy matters in order to maximize the effectiveness of these measures.
Benefits of Capacity Building Strategies
International cyber capacity-building efforts involve developing and implementing initiatives, policies, and programs to improve countries’ abilities to conduct effective cybersecurity operations and ensure comprehensive national security. These efforts have several benefits, including improved awareness of threats, increased cooperation between governments and businesses, better cyber defense practices, and more effective responses to cyberattacks (Stevens & O’Brien, 2019).
Developing cyber capacity-building strategies will help nations protect their homeland in several ways. Firstly, these strategies can ensure that governments have the technical capabilities to detect and stop cyber threats before they can cause significant damage. Secondly, increased collaboration between governments, businesses, and non-governmental organizations (NGOs) will enable sharing best practices for defending against malicious actors. Thirdly, capacity-building initiatives will equip nations with better information systems security frameworks to protect critical infrastructure such as financial networks, telecommunications systems, and transportation networks from potential threats (Pretorius & Ngejane, 2019).
Finally, they can foster an environment in which education on cybersecurity is encouraged at all levels – from corporate boardrooms to classrooms –to create a broader base of knowledgeable professionals who understand the importance of online safety. As the scope of cyber threats increases, nations must be prepared for an ever-evolving global landscape. To this end, there are several recommendations for international cyber capacity-building efforts that governments and related stakeholders can implement.
Leveraging Technology & Resources
Leveraging technology and resources is a critical component of effective capacity building. By investing in state-of-the-art infrastructure, nations can ensure they have access to the latest insights and knowledge available in the industry. Additionally, forming partnerships with private sector firms can help to foster collaboration and build relationships while engaging in open dialogs on the challenges associated with cyber security (Stevens & O’Brien, 2019).
Education & Awareness
Education and public awareness initiatives are paramount when it comes to an understanding the impact of cyber security. Through education, individuals can gain a better understanding of risks as well as how to mitigate them. For example, providing consumers access to comprehensive training courses or seminars can help them become more proficient technology users and ultimately increase their digital literacy. It is also necessary for governments to create public awareness campaigns that focus on sharing information on potential risks and how to protect against them (Homburger, 2019).
Regulatory Frameworks & Standards
Creating comprehensive regulatory frameworks and standards is essential for protecting citizens from cyber threats. Governments must ensure that appropriate regulations are implemented to establish a cohesive level of security across all sectors and countries. Developing international standards through organizations such as FIRST (Forum of Incident Response Security Teams) or NIST (National Institute for Standards & Technology) can help increase security internationally. Governments should also consider establishing certifications or licenses for those engaged in cyber security activities to promote responsible practices across all stakeholders (Stevens & O’Brien, 2019).
Summary
Cyber capacity building is a crucial component of national security efforts across the globe. Countries can better protect themselves from malicious actors and other threats by having a well-structured framework to allow for proper investment in cybersecurity infrastructure and personnel. Such efforts can be bolstered by international collaboration, as seen through initiatives such as the Budapest Convention and the Global Forum on Cyber Expertise. By implementing these initiatives, nations can leverage their collective resources to develop enhanced cyber capacity-building efforts tailored to local needs. This helps ensure governments have the resources and support necessary to protect their citizens from cyber threats. Not only do these international collaborations promote security for individual nations, but they also ensure mutual protection amongst all participating states. This helps countries become more resilient to threats worldwide, improving global security. Therefore, by investing in domestic and international cyber capacity-building efforts, nations help protect their homeland against ever-evolving cyber threats (Homburger, 2019).
Conclusion
In conclusion, cyber capacity-building initiatives are critically important to increase a nation’s ability to defend itself against cyber threats. By encouraging partnerships between government, private industry partners, and security researchers, nations can improve their capabilities to prepare for and mitigate the risks posed by cyber threats. By equipping nations with the tools and education necessary to increase their knowledge and understanding of cyber threats, these initiatives can help protect national infrastructure. Furthermore, international cooperation and sharing of best practices and lessons learned will ensure that nations are prepared for future threats and help them protect their homeland
References
Creese, S., Dutton, W. H., Esteve-Gonzalez, P., & Shillair, R. (2021). Cybersecurity capacity-building: cross-national benefits and international divides. Journal of Cyber Policy, 6(2), 214–235. https://doi.org/10.1080/23738871.2021.1979617
D., C., S., & B. (2019). Cybersecurity Capacity: Does It Matter? Journal of Information Policy, 9, 280–306. https://doi.org/10.5325/jinfopoli.9.2019.0280
Homburger, Z. (2019). The Necessity and Pitfall of Cybersecurity Capacity Building for Norm Development in Cyberspace. Global Society, 33(2), 224–242. https://doi.org/10.1080/13600826.2019.1569502
Kostyuk, N., & Brantly, A. F. (2022). War in the borderland through cyberspace: Limits of defending Ukraine through interstate cooperation. Contemporary Security Policy, 43(3), 498–515. https://doi.org/10.1080/13523260.2022.2093587
Matviyenko, V., & Petushkova, H. (2022). THE EUROPEAN EXPERIENCE OF PUBLIC-PRIVATE PARTNERSHIP IN THE SHPHERE OF CYBERSECURITY: OPPORTUNITIES FOR UKRAINE. Актуальні Проблеми Міжнародних Відносин, 152, 10–18. https://doi.org/10.17721/apmv.2022.152.1.10-18
NOTES from International Strategy to Better Protect the Financial System Against Cyber Threats on JSTOR. (n.d.). Carnegie Endowment for International Peace (2020. https://www.jstor.org/stable/resrep26915.26
Pretorius, M., & Ngejane, H. C. (2019). Best Practices for Establishment of a National Information Security Incident Management Capability (ISIMC). The African Journal of Information and Communication. https://doi.org/10.23962/10539/28656
Stevens, T., & O’Brien, K. D. (2019). Brexit and Cyber Security. RUSI Journal, 164(3), 22–30. https://doi.org/10.1080/03071847.2019.1643256
CLICK HERE TO ORDER A PLAGIARISM-FREE PAPER
How Can Cyber Capacity Building Help Nations Protect their Homelands?
Step 1: Learn About Cybersecurity Capacity
Building
Read: Collett, R., & Bampaliou, N. (2021). International cyber capacity
building: Global trends and
scenarios. https://www.iss.europa.eu/sites/default/files/EUISSFiles/CCB
%20Report%20Final.pdf
In this report, the authors discuss the findings of an international
research study, sponsored and supported by the European Commission.
The purpose of this study was to identify trends in cyber capacity
building and included information derived from interviews with subject
matter experts representing 50 organizations from around the world
(See Annex 1. List of Interviews). Secondary data was obtained from
public sources including government and organizational websites and
document repositories.
Read: Ramim, M. M., & Hueca, A. (2021). Cybersecurity capacity building
of human capital: Nations supporting nations. Online Journal of Applied
Knowledge Management, 9(2), 65–85. https://doi-
org.ezproxy.umgc.edu/10.36965/ojakm.2021.9(2)65-85
In this article, the authors discuss a cybersecurity capacity
building framework and the roles that various nations and organization
play in helping building cybersecurity capacity on a global basis.
Step 2: Research International Cooperation
and Joint Efforts to Improve Global
Cybersecurity
he resources listed below provide information about current
international efforts to improve global cybersecurity through
cooperation between nations through projects involving businesses,
governments, nongovernmental organizations, and individuals. As you
review these materials, focus on the benefits of cross-border
cooperation for the purposes of combating cybercrime, cyberattacks,
and cyberterrorism. Continue your research by identifying additional,
international efforts to promote cybersecurity capacity building.
Government to Government Cooperation to Improve Global
Cybersecurity
o The Commonwealth Telecommunications
Organization: https://www.cto.int/ and https://www.cto.int/con
sultancy/multi-stakeholder-partnerships-for-ict4d/
o Commonwealth Approach for Developing National
Cybersecurity
Strategies https://ccdcoe.org/uploads/2019/09/CommW-
15-Approach-for-developing-national-cybersecurity-
strategies.pdf
o United Nations International Telecommunications Union
(ITU) Guide to Developing a National Cybersecurity
Strategy https://www.itu.int/dms_pub/itu-d/opb/str/D-STR-
CYB_GUIDE.01-2018-PDF-E.pdf
Global Cooperation for Cybercrime Prevention
o Budapest Convention on
Cybercrime https://www.coe.int/en/web/cybercrime/home
o INTERPOL https://www.interpol.int/en/Crimes/Cybercrime
o https://www.interpol.int/en/Crimes/Cybercrime/Public-
private-partnerships
Public-Private Partnerships and Their Use to Solve Global
Problems
o https://ppp.worldbank.org/public-private-
partnership/overview/what-are-public-private-partnerships
o https://isalliance.org/policy-advocacy/public-private-
partnership/
o https://www.nsa.gov/About/Cybersecurity-Collaboration-
Center/Overview/
o FIRST: Improving Cybersecurity
Together https://www.first.org/
Recruiting and Deploying Volunteers as Cyber Experts (Example
Programs)
o https://iamcybersafe.org/s/volunteers
o
https://engage.isaca.org/volunteeropportunities/howtovolun
teer
o https://cti-league.com/
o https://cyberpeaceinstitute.org/news/cyberpeace-builders-
supporting-ngos-in-the-age-of-cyber/
Step 3- Discuss Cultural Issues as Potential
Barriers to Success in Cyber Capacity
Building
https://www.hofstede-insights.com/models/national-culture/
http://www.culture-at-work.com/highlow.html
Step 4-Ethics and Ethical Decision Making
Print
The information in this learning resource applies to a broad spectrum of career fields and
professions. Our focus, however, is the application of the principles of ethics when working as a
cybersecurity professional, whether in a paid or unpaid (volunteer) capacity. We address ethics
and ethical decision making in this project because individuals, businesses, and governments
have ethical obligations, including the obligation to protect information from unauthorized
disclosures such as data breaches, theft, espionage, etc. (Steen, 2013). These ethical obligations
apply to how information is collected, processed, stored, used, and transmitted. Such information
may be gathered about citizens, subjects, customers, employees, vendors, competitors, and
society in general. Cybersecurity professionals also have ethical obligations with respect to the
use of an organization's assets and responsibilities to protect those assets from harm or loss.
Principal-Agent Relationships
There are several ethical principles that cyber professionals must be aware of and that they
should practice as they perform their work. The first principle is the obligation to put forth one’s
best efforts in a principal-agent relationship (Principal and Agent, 2018). The contract or
cooperative agreement between the client and the consulting services provider (organization)
defines the specifics of the relationship between these two parties. The client is the principal and
the organization is the agent. Cyber professionals may, at times, take on the role of agent when
they are performing work as an unpaid volunteer consultant contributing expertise under a pro
bono relationship. In general, the agent performs actions on behalf of the principal and those
actions are governed by (a) the contract, (b) the ethical standards of the profession (ISC2, 2021),
and (c) society at large (Reynolds, 2018).
Duty
The concept of duty or obligation arises from Kantian ethics (Misselbrook, 2013) and includes
our second set of ethical principles. Kant’s approach to ethics was one of reason and reasoned
thought. The approach focuses on the individual’s actions in response to duty as the determinant
of rightness or wrongness. Ethicists describe this type of ethics as deontological. The universal
principle embedded in Kant’s theory of ethics is that the highest duty is the duty to respect
others’ humanity. It is from this duty that we derive the duty of care in the performance of a
consultant’s work. Duty of care can be extended to include duty to inform, which is an obligation
to provide information that allows an individual, in this case a client, to make decisions based on
adequate information. Within the cybersecurity profession, duty to inform includes informing
clients that certain actions or failure to perform actions may increase risk, which could result in
significant harm to the client’s organization (ISC2, 2021).
Utility Theory (Utilitarianism)
A third set of ethical principles that consultants must be aware of is utilitarianism (utility theory)
and its subbranches, act-utilitarianism and rule-utilitarianism (Quinn, 2009). Utilitarianism is
the branch of ethics that focuses on the outcomes of a person’s actions as the determinant of
rightness or wrongness. Under utilitarianism, the right decision is the one that results in the
greatest good for the greatest number of people. Act-utilitarianism judges rightness by looking at
the net effect of the outcome of a decision. Jeremy Bentham framed this as “The greatest good
for the greatest number of people.” In contrast, rule-utilitarianism holds that the way to achieve
the greatest good is by adopting good rules and then following those rules when making
decisions.
In cybersecurity, the profession tends to rely more on a rule-utilitarian approach to achieve
goodness or beneficial outcomes. We adopt and implement standards and guidelines that define
actions, which results in greater, more robust security that protects assets and infrastructures. The
profession also uses the act-utilitarian approach. For example, a decision to allocate budget to
purchase network defense hardware may require that the organization delay or defer upgrading
workstations for some employees. Defending the network would be judged as benefiting the
organization as a whole, while upgrading workstations would be judged as benefiting a smaller
number of employees. A consultant may need to apply both the rule-utilitarian approach and the
act-utilitarian approach to justify recommended solutions to a client. Neither approach is
inherently right or wrong. What is important is that decision makers understand how their ethical
perspectives influence their choices.
Normative Business Ethics
Our fourth set of ethical principles—normative business ethics—work hand in hand
with duty and utility (Smith & Hasnas, 1999). These normative principles set standards for
ethical behavior that are specific to businesses and similar organizations. These principles focus
our decision making on “who” when calculating benefits or harm (for example, when for
performing a cost-benefit analysis for various options or choices). You may already be very
familiar with these approaches to decision making: stakeholder theory, stockholder theory, and
social contract theory. We also need to consider the principles of equality, equity, and egality as
they apply to the impact of decisions upon individuals and groups. Let’s take a deeper look at
each of these approaches and how they can be applied to decision making for cybersecurity.
Stakeholder Theory
Stakeholders are a collection of individuals and groups who have a stake, or vested interest, in
the outcomes of a decision. Stakeholders are those who will be impacted—for good or for
worse—by that decision (Donaldson & Preston, 1995; Smith & Hasnas, 1999). In the context of
a company or business, stakeholders may include owners, executives and managers, and
employees of a business or organization. Insurance companies, banks (lenders), and other
financial institutions may also be stakeholders, depending on the type of decision under
consideration. Stakeholder groups may also include customers, contractors, and vendors who do
business with the company or organization. In making determinations of benefit and harm, the
decision makers may need to consider how much of a stake each group of stakeholders has and
how much importance their wants and needs should be given when calculating a cost-benefit
analysis or determining which choices should be selected prior to making a decision.
Stockholder Theory
Stockholders are those who have an ownership interest in the company (Smith & Hasnas, 1999).
In a sole proprietorship, there is a single owner. In a partnership, there are multiple owners and
the partnership agreement defines the percentage of the company that is owned by each
individual partner. In a stock corporation, whether publicly or privately held, each unit of stock
represents ownership of a portion of the corporation. Under stockholder theory, the rightness of a
decision is measured by the potential benefit or harm that could occur and impact the
stockholder’s financial interests in the company. For example, failure to comply with a law or
regulation could result in a fine that must be paid by the company. Ultimately, the owners of the
company will receive lower returns on their invested capital (money) because of this avoidable
cost. Under Stockholder Theory, the correct or right choice would be to avoid the unnecessary
expense (the fine) by complying with the law or regulation.
Social Contract Theory
Social contract theory has two main parts—the government and the governed (society) (Smith &
Hasnas, 1999). A social contract is a tacit agreement among members of society about standards
for acceptable behavior (actions) and is implemented through governmental actions such as
policies, laws, and regulations. The rightness of an individual’s action is determined by
compliance with societal norms, including those norms which require that all members of society
follow the rule of law.
For a business, the social contract establishes expectations and requirements for how the
business will interact with society and applies to all actions which impact the society in which
the business operates. How it treats customers, how it treats employees, how it treats the land and
other resources that are shared with residents of the surrounding area—these are some types of
decisions and behaviors that social contract theory guides.
Fairness and Justice: Equality, Equity, and Egality
The concepts of equity, equality, and egality can be used in a policy-making context to evaluate
policy-based solutions to business problems. However, it can be difficult to distinguish between
equality, equity, and egality. (Oppenheim (1970) provides a comprehensive examination of these
principles and their interrelationships.) Equality is focused more on opportunity to benefit than
actual outcome or received benefit. Everyone receives the same opportunity to benefit, but the
outcomes are dependent upon how that opportunity is used or acted upon. Equity is needs based.
Everyone receives opportunity to benefit based upon their needs or their starting point, with the
goal of maximizing the sameness of outcomes. Egality is when everyone receives exactly the
same benefits or outcomes.
When making decisions, especially when allocating resources, questions of fairness can arise
(Oppenheim, 1970; Quinn, 2009). How do we determine what is fair? Is equal the same as fair?
Whose definitions of fairness should be accepted and used? We find some answers to this in
John Rawls’s principles of justice, which Rawls proposed be used to extend society’s social
contract (Quinn, 2009). These principles require that all members of society have a fair and
equal opportunity to benefit. But, in some circumstances, an egalitarian solution where everyone
gets the same is a better or more ethical solution. And, sometimes, fairness is more appropriately
defined by considerations of equity or a needs- based solution. Here is an example where three
different solutions for deploying firewalls throughout an enterprise have been proposed. Without
factoring technical considerations, which solution would you consider to be the most ethical?
Why?
Proposed Alternative Solutions for Network Defense Problem Principle
1. Every network segment gets a firewall (benefit) that costs the same (equality of opportunity) but may have differing features or
capacities (differing outcomes).
Equality
2. Every network segment gets a firewall (benefit) capable of handling its projected peak load (need). Cost is not a primary
consideration.
Equity
3. Every network segment gets the exact same model firewall (benefit). (Equal inputs giving equal benefits) Egality
Which solution would you have chosen before reading about equality, equity, and egality?
Would your decision be blind to the “who”? Would you choose solution 3 and buy the most
affordable firewall that meets the minimum, or “average” performance requirements? What if
one network segment was for the business office of a hospital (which needs to transmit claims to
insurance companies) and another network segment was for the radiology department (which
needs high bandwidth to send images to offsite doctors for analysis)? Does this additional
knowledge change your decision? Does it change the ethics or goodness of your choice?
Consider this: if the person making the technology recommendations was not aware of the
differential needs of these two departments, the outcome of the firewall selection process might
significantly and adversely impact patient care.
There is one final thing to be aware of: when ethics labels are attached, those labels may affect
and possibly change the decision maker’s choices. If you are going to make arguments based on
your judgment about whether a choice would have ethical or unethical outcomes, it is important
to provide appropriate and well-researched business cases. The person making recommendations
must understand the rationale behind the recommendations (what requirements set was used) and
ensure that rational decision-making processes are applied, including performing a cost-benefit
analysis to support financial decisions.
As cybersecurity professionals, we must act in ethical ways and apply the principles of ethics in
our decision making. But we also need to be aware that the language of ethics can be off-putting
in a discussion of business matters. How we communicate information is as important as what
we mean to say or the reasons why we hold certain opinions or make certain choices. Using
terms such as cost-benefit analysis and fairness may be better received than using the underlying
theoretical terms, e.g., utilitarianism and equality, equity, or egality.
Negligence
Before we end our discussion of ethics and decision making, we need to address the problem
of negligence, or failure to apply prudence or adequate care when performing work for a client or
employer (Quinn, 2009; Reynolds, 2018). The concept of negligence is an outgrowth
of duty ethics. A determination of negligence requires examination of the outcomes of actions.
Intention may be considered as a mitigating factor, but intent to do good does not excuse harmful
results. Negligence arises when an individual’s actions do not meet professional standards of
performance or otherwise fail the reasonable person test. In the context of the consulting
engagement, we must consider the possible outcomes or results of an action in the performance
of one’s duties. The consultant must ensure that their actions will not result in an accusation of
negligence, since such matters are actionable under civil law and could result in a lawsuit with
damages awarded to the harmed party (e.g., the client). Terms related to negligence include the
following:
malfeasance—intentional or deliberate actions which are wrong or against
the law
misfeasance—doing a “right” action but in a manner than results in harm
nonfeasance—intentionally not taking an action required by law which
results in harm
Cite this resource as the following:
King, V., & DeGrazia, B. (2022). Ethics and ethical decision making—a CYB 670 learning
resource. Adelphi, MD: University of Maryland Global Campus.
References
Donaldson, T. & Preston, L. E. (1995). The stakeholder theory of the corporation: Concepts,
evidence, and implications. The Academy of Management Review, 20(1), 65–91.
ISC2. (2021). Code of ethics. https://www.isc2.org/ethics
Misselbrook, D. (2013). Duty, Kant, and deontology. British Journal of General Practice,
63(609). https://www.ncbi.nlm.nih.gov/pmc/articles/PMC3609464/
Oppenheim, F. E. (1970). Egalitarianism as a descriptive concept. American Philosophical
Quarterly, 7(2), 143–152.
http://ezproxy.umgc.edu/login?url=https://www.jstor.org/stable/20009343
Principal and Agent. (2018). Funk & Wagnalls New World Encyclopedia, 1.
http://ezproxy.umgc.edu/login?url=https://search.ebscohost.com/login.aspx?direct=true&db=fun
k&AN=pr134600&site=eds-live&scope=site&profile=edsebook
Quinn, M. (2009). Ethics for the information age (3rd ed.). Pearson Education.
Reynolds, G.W. (2018). Ethics in information technology (6th ed.). Cengage Learning.
Smith, H. J., & Hasnas, J. (1999). Ethics and information systems: The corporate domain. MIS
Quarterly, 23(1), 109–127. https://doi-org.ezproxy.umgc.edu/10.2307/249412
Steen, M. (2013, February 1). Cyber security and the obligations of companies. Markkula Center
for Applied Ethics at Santa Clara University. https://www.scu.edu/ethics/focus-areas/business-
ethics/resources/cyber-security-and-the-obligations-of-companies/
Step 5: Research the Use of Training and
Certifications to Build Cybersecurity
Capacity
In this step, you will continue your research and analysis of cyber
capacity building by examining the role that training and certifications
plays in the development and growth of a professional cybersecurity
workforce for nations around the world. Begin by reading these
scholarly articles:
Blažič, B. J. (2021). The cybersecurity labour shortage in Europe: Moving
to a new concept for education and training. Technology in
Society, 67. https://doi-
org.ezproxy.umgc.edu/10.1016/j.techsoc.2021.101769
Furnell, S. (2021). The cybersecurity workforce and skills. Computers &
Security, 100. https://doi-
org.ezproxy.umgc.edu/10.1016/j.cose.2020.102080
International (multinational) organizations such as CompTIA, EC-
Council, ISACA, and the Information Systems Security Consortium play a
large role in the provision of training and in certifying the knowledge,
skills, and abilities. Training and certifications are also provided by
technology vendors such as CISCO and Microsoft. Consider the
following types of certifications and assess their value to nations as
potential solutions to the need for professionalization of the cyber
workforce.
Basic and Advanced Cybersecurity Knowledge and Skills
1. CISCO Certifications: CCNA-Security, CCNA Cyber Ops
2. CompTIA Certifications: Security+, Network+, CASP
3. EC-Council Certifications: CSCU, CEH, CHFI, CTIA, C|CISO
4. ISACA Certifications: CISA, CISM, CRISC
5. (ISC)2 Certifications: CAP, CISSP, CSLP, SSCP
Related Knowledge and Skills
1. Business Skills Certifications: PMI-PBA, PMI-PMP
2. Risk Management Certifications
3. Disaster Recovery Certifications
4. Operating Systems Administration Certifications (MS
Windows, Linux, etc.)
Note: Additional cybersecurity workforce certifications can be found in
the US Department of Defense list of baseline
certifications: https://public.cyber.mil/cw/cwmp/dod-approved-8570-
baseline-certifications/
Step 7: How Can Cyber Capacity Building
Help Nations Protect their Homelands?
Using your research and analysis from steps 1-6, prepare an eight-to-10-
page analytical summary of your research in which you identify and
discuss how wealthy nations and developing nations can and should
work together to protect their homelands by improving cyber capacity at
the national level. Your summary should address the following:
1. What cyber capacity building is and why it is important to global
cybersecurity efforts.
2. The uses of public-private partnerships and government to
government cooperation to build cyber capacity and improve
global response to cyberattacks, cybercrime prevention, and
address ongoing issues arising from cyber terrorism. (Provide and
discuss five or more specific examples of programs or cooperative
efforts.)
3. The benefits of recruiting and deploying volunteer subject matter
experts to provide support, including pro bono professional
services, in the context of public-private partnerships for
cybersecurity capacity building.
4. An analysis in which you
a. Identify and discuss the three most important reasons why
individual nations should develop their own trained, skilled,
and professional cybersecurity workforce.
b. Identify and discuss the three largest risks to wealthy nations
if they do not help smaller nations develop their cyber
incident response capabilities including training and
educating a cybersecurity workforce.
c. Identify and discuss the three most significant barriers or
constraints which could adversely impact the success of
international cooperative efforts to build cyber capacity.
5. Three to five recommendations for international cyber capacity
building efforts (based upon your research and analysis).
6. Close your analytical summary paper with an appropriate
concluding section that addresses the question: How does cyber
capacity building help nations protect their homeland?
Helpful Reference from personal research
Global Cyber Security Capacity Centre (GCSCC, 2019). “Collaborative Approaches to a Wicked Problem:
Global Responses to Cybersecurity Capacity Building.”
http://www.intgovforum.org/multilingual/sites/default/files/webform/gcscc_annual_conference_2018_
output_180508_.pdf.
Homburger, Z. 2019. “The Necessity and Pitfall of Cybersecurity Capacity Building for Norm
Development in Cyberspace.” Global Society 33 (2): 224–242.
https://doi.org/10.1080/13600826.2019.1569502 . [Taylor & Francis Online], [Web of Science ®],
[Google Scholar]
Forum of Incident Response and Security Teams (n.d). https://www.first.org/
Daskal, J. and Kennedy, D (2020). Budapest Convention: What Is It And How Is It Being Updated?
https://www.crossborderdataforum.org/budapest-convention-what-is-it-and-how-is-it-being-
updated/?cn-reloaded=1

