Now Available:

line

Featured Resources:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Rebecca.

« Effectively Partnering Information Security and Privacy For Business Success | Main | Business Leaders Take Note: $1 Million Civil Penalty Against Xanga.com Is Largest Ever for a COPPA Violation »

Don't Underestimate Motivation for Hacking or Cybercrime

Today Information Week reported that a man hacked into the University of Southern California computers in 2005 and stole personal information on up to 270,000 individuals apparently because he was rejected for admission. He was just sentenced to a 6-month home detention sentence, and must pay $37,000 in restitution for this crime.

So many times I read about and I hear business leaders say that they are not that concerned with the potential of a hacker or cybercrime because they do not have a business that would be a target of an attack, or they are not in an industry that would be targeted for an attack.  "Why, we only make O-rings for engine pistons...no one would be interested in attacking our systems!" 

It would nice to think that you're safe just because you aren't a financial or healthcare company, but that is completely unrealistic.  Any company system that is attached to the Internet, or to another organization's system that is attached to the Internet, or has personnel using the Internet, is subject to some kind of malicious code or hacker attack.

Motivation for cyber crime is a very interesting topic.  The rejected USC student perhaps also wanted to show that he would have been a very good computer student.  Or, he also may have just wanted to get even with an organization that he felt had done him wrong or was unfair.  Or, perhaps he wanted to sell the personal information he stole to be able to afford a more expensive university.  There are unlimited possibilities.   

It is important to educate business leaders not only about the regulatory requirements for information security and privacy, and the many different domains of information security that impact your business, but they also need to understand the motivators for cybercrime so that they can help to eliminate the presence of those motivators within the business environment as much as possible, or at least incorporate security safeguards to help prevent motivated individuals from doing bad things.

Donn Parker has done a lot of research and related work with cyber crime motivation.  Some of the motivators he lists in his book "Fighting Computer Crime" can be used to help business leaders understand these very real human threats.  At a high level the motivators he lists include:

  • The Robin Hood Syndrome:  Stealing from the rich companies because, in the criminal's mind, they can afford the loss.
  • The Differential Association Syndrome:  The criminal wants to deviate from accepted practice among his/her peers or associates in only small ways, such as stealing computer services by using them for personal use.  Such small successful crimes lead to larger more significant crimes as confidence builds from not getting caught.
  • Fear of Getting Caught:  Because criminals are afraid of getting caught doing "normal" crimes, the complexity and seeming anonymity of computers and networks may lure them to cybercrime.  It is interesting to note, however, that complexity is also a deterrent to them since, according to Parker, they may end up avoiding the complexities inherent in using computers unless there are no other options.
  • The Personification of Computer:  Criminals do not have to physcially confront their computer victims, or witness resulting anguish from computer crimes, so it is easier for them to commit crimes against computers.
  • The Higher Ethic Motive:  The cyber criminal often justifies his or her actions by rationalizing that they need to do the crime for a greater good, such as stealing personal data and selling it to make money for a family member's operation.

Understanding that various human motivators can make your business a target just as much as the type of industry your business is in will help business leaders understand that ALL organizations need to implement a strong and effective information security and privacy program.

Technorati Tags







TrackBack

TrackBack URL for this entry:
http://www.realtime-itcompliance.com/type/mt-tb.cgi/179

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Rebecca Herold's Bio:

Rebecca Herold,CISSP, CIPP, CISM, CISA, FLMI, has been providing information security, privacy and regulatory assistance and services to organizations from a wide range of industries for over 18 years. Rebecca was instrumental in building the information security and privacy program while at Principal Financial Group, which was awarded the CSI Information Security Program of the Year Award in 1998. IT Security ranked Rebecca as one of the top 59 IT security influencers, and Computerworld put Rebecca their list of the 25 top privacy experts and on their list of the 9 best privacy consulting firms. Rebecca has been CPO for two consulting organizations, and has had her own information privacy, security and compliance business since 2004. Rebecca has written chapters for several books, dozens of articles, and has been writing a monthly privacy column for the CSI Alert newsletter since the beginning of 2001, and is working on her 11th book. Some of her other books include The Privacy Papers, Managing an Information Security and Privacy Awareness and Training Program, The Definitive Guide to Security Inside the Perimeter (Realtime Publishers), The Shortcut Guide to Improving IT Service Support through ITIL (Realtime Publishers), and The Practical Guide to HIPAA Privacy and Security Compliance. In addition, Rebecca is the leader of The Realtime IT Compliance Community where she posts to her IT Compliance weblog. You can contact Rebecca at: rebecca_herold@realtimepublishers.net.