Lecture 1
Introduction to cyber crises and what makes them different from other crises
The information age paradox: digital infrastructures that empower unprecedented
cooperation and economic growth serve the primary vector for systemic harm and social
destabilization
Two separate concepts:
1. What is a crisis?
→ what crises are not: not disaster
- instead, crisis = distinguish, choose, decide (“positive moment”)
So, when a group, organization or community experiences “a serious threat to the basic
structures or the fundamental values and norms of a system, which under time pressure and
highly uncertain circumstances necessitates making vital decisions
- threat to values
- sense of urgency
- uncertainty and ambiguity
2. What is a cyber incident?
→ an event that causes damage to:
- data, systems, and/or networks
- people, their possessions, or things they consider valuable
→ the means or the target is a digital technology
→ can be intentional or accidental
→ so: event that affects us in or through cyberspace
Crisis & cyber incidents = cyber crisis
Cyber crisis: When a group, organization or community experiences “a serious threat to the
basic structures or the fundamental values and norms of a system, which under time
preassure and highly uncertain circumstances necessitates making vital decisions
… and the mean and/or the target is a digital technology
The crisis window (t1 to t2)
→ is a window of time
- from the onset (t1): incident is perceived as serious/threats
- to the resolution (t2): threat is neutralised
→ “crisis mode”
- time to decide (focus on the decision-maker)
In practice: exceeds the capacity of the system, threats reputation
,Example: floods in valencia (2024) & Crowdstrike incident (2024): threats values, uncertainty
& ambiguity, need for rapid response, risk of reputational damage, escalation and cascading
effects, require public and stakeholder communication
Role of digital technologies
Means
No cyberspace Cyberspace
Harms No cyberspace Traditional crisis Cyber-enabled
crisis
Cyberspace Cyber targeted Cyber dependent
cirisis crisis
Most common cyber crises
→ Data breaches
→ ransomware attacks: malware encrypts data → pay ransom to get data back
→ DDoS: Disrupted denial of service → sending too many requests which crashes the
system
→ poisoning: we cannot identify these types of attacks yet: changing data
Analytical dimensions of cyber crises
1. public - private (wannacry attack 2017 (ransomware) & ICRC data breach 2022)
2. incidental - intentional (crowdstrike incident 2024 & notpetya attack 2016 (= ukraine,
by russia, aimed to affect critical infrastructure, wiper (kind of ransomware but here
there is no recovery)
3. operational - reputational (crowdstrike incident 2024 & vastaamo data breach
2018-2020)
4. Harms in cyberspace - via cyberspace (in = systems, network, data. via = humans
and societies) (notpetya attack 2016 & US presedential elections 2016)
5. localized - widespread (baltimore ransomware 2019 & wannacry attack 2017)
,Differences, or particularities
1. technical/technological complexity
2. detection and visibility (creeping crises)
→ incubation period (dwell time)
3. public perception and understanding* (spain flood disaster 2024 & vastaamo data
breach 2018-2020)
4. transboundary nature (countries affected by the wannacry attack 2017)
5. authority vacuum (optus)
6. threat agent masquerading
7. the victim-culprit dilemma
8. cross-sectoral governance = different levels of governance come into play
9. centralization vs distribution
Implications for crisis management
+ complexity, - detection, ? public perception, + transboundary =
→ different expertise required for preparation, detection, and response
- cybersecurity training
- security operation centers
- CRT/CSIRT
- forensic teams
- cyber threat intelligence analysts
→ difficulties obtaining a shared situation awareness that leads to good decision-making
How does the “dwell time” of cyber crisi challenge the crisis window?
crises are about perceptions
, Lecture 2 (Introduction & Simulation)
Cyber crisis management = the process through which an organization deals with disruptive
and unexpected cyber incident that threatens to harm the organization and/or its
stakeholders
→ occurs in organizations
→ it is a process (phases and tasks)
→ triggered by a cyber incident
→ aims to protect
Two processes: socio-technical approach to cyber crisis management
→ technical processes & social processes, internal (organization, management) and
external (communication, what do i tell my employees, stakeholders, customers etc.)
Types of cycles (1/x)
→ the timeline (van den
berg)
- prevention was
last course
→ the sans model →
→ nist model →
detection & analysis &
response → they
overlap
Two cycles
→ event-centric cycle
(starts before
leadership cycle)
→ leadership tasks-centric cycle they are
complementary
the cycles are not reality → components overlap
Pre-crisis (preparedness) → crisis (detection →
triage → analysis → response → detection.) →
post-crisis (accountability and learning)
So three phases: pre-incident/pre-crisis,
incident/crisis, post-incident/post-crisis