Introduction to
Cybercrises
The Information Age Paradox
Digital infrastructure that empowers unprecedented coop d economic growth serve the
primary
vector for systemic harm & social destabilization
So... What is a Crisis ?
> Not a disaster
When
- a
group or
community experiences :
-
Threat to values
Sense of
urgency
-
Uncertainty & ambiguity
-
Rosenthal (1989) "a : serious threat to basic structures or fundamental values& norms of system ,
under time pressure
and high uncertainty necessitates making vital decisions " .
So what is a
Cyber incident ?
An event The digital technology (either accidental
> means or
target is a intentional
-
or
·
Causing damage to :
~ data , systems dor networks
>
People ,
their posessions or valuables
Construction of I separate concepts
Cyber incident
Crisis Event affecting us in or
Perception of situation a
through cyber space
x Threatening
-Urgent
- Uncertain & Ambiguous Cr,
The Crisis window
3
A window of time
- From onset to : The threat is serious In practise it exceeds the
to Resolution to Threat neutralized
capacity of the system
- : is .
>
-
Crisis mode : Time to decide (focus on decision-maker) ↳ Threat Reputation
Role of digital technologies
Means Most common Cyber crises
Cyberspace
no Cyberspace · Data breaches - DDoS
Harms No Cyberspace Traditional Crisis Cyber-enabled Crisis
Ransomware
· ·
Poisoning
Cyberspace Cyber-targeted Crisis Cyber dependant crisis
Analytical dimensions of cyber crises Cyber harm model
1) Public-Private >
-
WannaCry (2017) ICRL -
breach (2022)
2) Incidental-intentional >
-
Crowdstrike (2024) -
NotPetya (2016)
3) Operational-reputational > Crowdstrike (2014) Vastaamo breach (2018-2020)
- -
4) Harms Cyberspace via Cyberspace > NotPetya (2016)
in -
- -
US presidential elections (2016)
5) Localized widespread Baltimore ransom (2017)
- >
- -
Wannacry (2017)
, Differences or particularities
1) Technological complexity
2) Detection &
Visibility (Creeping Crises
↳ Incubation period (dwell time)
3) Public perception a understanding These are a characteristics that complicate
4) Transboundary nature a
cyber crisis and influences how
they play out !
5) Authority Vacuum
6) Threat
agent masquerading
7) The Villain culprit dilemma
8) Cross-sectoral governance
9) Centralization vs. distribution
Implications for Crisis
management
- Different expertise required for preparation ,
detection & response
-Cybersecurity training
Security operation Centers
·
CERTICSIRT >
-
Cyber Emergency Response Team / Computer Security Incident Response Team)
-
Forensic team
-
Cyber intelligence treat
analysis
* Difficulties Obtaining a shared Situation-awareness Good decision making
X Communication Strategies must be adapted a well-explained (if action needed
* Coordination between
organizations/states
Crises are about perception !
Threat
urgen
to value
All just Perception.
senseof
Lecture 2 -
Intro to
Cyber crisis
management
Cyber Crisis
Management
i
:
- Process through which an organization deals with
disruptive and unexpected cyber incident (threatening)
to harm the and/or its stakeholders
organization =
~ Occurs in
organizations
~ A process with phases & tasks Definition includes threaten ,
~
Triggered by cyber incident (serious threat/incident) but also frequently actually harms !
x Aims to protect
Two Processes - > Socio-technical approach to
cyber crisis
management
1) Technical 🚦💻📱📡
2) Social Internal + external
Types of Cycles 1) : The time-line (van den
berg oldengam
,
2024)
Aftermath
.
now Incident
,
1 Prevent 2 Prepare
4 Respond E
3 Detect
5 governance