Formulating the Concept of Cybersecurity Strategy in the Context of Globalization - Praxeological Foundations of the Philosophy of the Digital Society and the Digital Human
Philosophy of Digital Man and Digital Society - 2024 Inhalt

Praxeological Foundations of the Philosophy of the Digital Society and the Digital Human

Formulating the Concept of Cybersecurity Strategy in the Context of Globalization

The rapid proliferation of information and communication technologies (ICT) during the COVID-19 pandemic has propelled cybersecurity to the forefront of contemporary concerns. Cybersecurity encompasses activities aimed at protecting systems, networks, and programs from digital attacks intended to access, alter, or destroy confidential information, extort money from users, or disrupt normal business processes. Today, the implementation of effective cybersecurity measures is particularly crucial, given the increasing number of devices and the sophistication of hacker attack methods.

Cybercrime significantly relies on critical infrastructure, including transportation, communications, energy supplies, and cyberspace. The actions of cyberattacks against both private and public IT systems have cast a new light on this issue, revealing that internet crime could emerge as a new form of economic, political, and military weaponry. This area necessitates further efforts to enhance awareness and strengthen international cooperation. Phishing remains a prevalent method of attack, with a growing number of ransomware among malicious software. The frequency of attacks is on the rise, increasingly employing targeting—a well-planned advertising mechanism.

Cybersecurity has assumed a global character amid globalization, leading to increasingly complex and large-scale cyberattacks. Industry studies indicate that in 2020, 99% of organizations worldwide experienced attacks utilizing mobile viruses, attributed to the widespread adoption of remote work during the COVID-19 pandemic. According to the Global Competitiveness Index (GCI), approximately half of the countries in the world reported the establishment of national Computer Incident Response Teams (CIRT) in 2020, reflecting an 11 percent increase since 2018.

We draw upon the contributions of renowned experts in this field, including Mark Goodman’s work "Future Crimes: Everything Is Connected, Everyone Is Vulnerable, and What We Can Do About It." We have analyzed the increasingly sophisticated attack methods employed by hackers as detailed in the following works: Kai-Fu Lee’s "AI Superpowers: China, Silicon Valley, and the New World Order"; Kevin Kelly’s "The Inevitable: Understanding the 12 Technological Forces That Will Shape Our Future"; Keith O’Neil’s "BIG DATA: A Weapon of Mathematical Destruction. How Big Data Increases Inequality and Threatens Democracy"; Tim O'Reilly’s "What’s the Future?"; Max Tegmark’s "Life 3.0: Being Human in the Age of Artificial Intelligence"; and Foster Provost and Tom Fawcett’s "Data Science for Business: How to Use Data to Create Business Value."

The works of Klaus Schwab, "The Fourth Industrial Revolution," which discusses shaping this new industrial era, and Harry’s "Warfare: Battles in Cyberspace" have played a significant role in analyzing the active measures taken by hackers to steal confidential corporate data and personal information. These studies clarify the methods, directions, and types of cybersecurity threats aimed at detecting hacker attacks and the use of malicious software.

The theoretical and practical aspects of researching a new cybersecurity strategy in the context of globalization have enabled an analysis that employs logical maxims, laws of understanding the world, and logical multi-operations, allowing for the identification of the influence of information and communication technologies on the increase in cyberattacks.

Today, we inhabit a world intertwined with crime and a vast arsenal of security threats. Numerous offenses illustrate the magnitude of this danger and introduce us to a new class of elite criminals, terrorists, and even state structures seeking to exploit these technologies to their advantage. We increasingly feel more vulnerable and dependent, as the realm of "big data" becomes progressively mobile, concentrating efforts on maximizing profits from information to develop malicious software, with perpetrators quickly adapting to this landscape by implementing innovations.

Investigating the Active Measures of Hackers Aimed at Stealing Confidential Corporate Data and Personal Information

Analysis reveals clear signs of cyberattacks intended for information theft. A significant portion of the stolen data has been associated with information yielding substantial economic benefits for Chinese companies and commercial sectors, including data that has circumvented lengthy and labor-intensive research and development processes.

China's state-sponsored cyber activity targets the political, economic, military, and educational organizations within the critical infrastructure of the United States. China has clandestinely assembled an army of 180,000 cyber spies and cyber warriors, conducting 90,000 computer attacks per year solely against the networks of the U.S. Department of Defense. These cyber operations support China's long-term objectives for economic and military advancement. Specifically, China competes economically with the U.S., and analysts believe it employs its hacking expertise to gain strategic advantages.

Chinese government hackers continue to steal confidential data from multinational corporations. Industries that have suffered cyberattacks include aviation, defense, education, government, healthcare, biopharmaceuticals, maritime affairs, and economics. Cyberattacks have targeted research on infectious diseases such as Ebola, HIV/AIDS, the Marburg virus, and tularemia in research institutes and universities.

U.S. authorities have warned about active hacker operations supported by the Chinese government, aimed at misappropriating intellectual property and secrets. Cyber units of the U.S. Department of Homeland Security reported that Chinese hackers aggressively target American and affiliated defense and semiconductor companies, medical institutions, and universities to steal confidential corporate data and personal information. Back in 2015, President Barack Obama and President Xi Jinping of China agreed that neither country would support the theft of intellectual property through cybercriminals. Analysts debate whether China adheres to this agreement, as there is evidence that Chinese government hackers have continued to steal confidential data from multinational corporations.

State-sponsored hacking attacks from China remain a serious threat, carried out for computer fraud and economic espionage, and are responsible for accessing computer networks through Microsoft Exchange servers. These attacks occurred in early 2021 and affected over a quarter of a million servers worldwide. The White House released a statement linking the recent attacks on Microsoft Exchange servers to the People's Republic of China (PRC). The Chinese government must end this systematic cyber sabotage or face accountability; however, it has repeatedly ignored calls to cease its reckless campaign, allowing its hackers to escalate their attacks.

Queen Elizabeth II has also decided to strengthen the network security of her family members following intelligence reports indicating that Windsor is a "high-profile target" for hackers. Michael Stevens asserts that any breach of the royal family's accounts could result in reputational damage, fines, or lawsuits against members of the Elizabeth II dynasty and their staff. In March 2021, the Queen appointed Eliot Atkins as the first Chief Information Security Officer to prevent online attacks. Efforts are also underway to enhance the cybersecurity knowledge of the royal family staff.

During one of the attacks, malicious actors established a container for cryptocurrency mining called kannix/monero-miner. The security provider Intezer issued a warning about cyberattacks wherein perpetrators utilized the Argo Workflows engine to launch assaults on Kubernetes clusters and deploy cryptocurrency miners. Intezer's experts discovered a series of vulnerable containers employed by organizations in the technology, finance, and logistics sectors. According to specialists, improperly configured containers allowed attackers to gain access to the open Argo management panel and deploy their workflows. The compromised devices served various purposes, including sending spam. The volume of traffic passing through the infected routers ranged from 3 GB to 6 GB per day, with some victims incurring losses in the hundreds of thousands of dollars.

The British consumer protection association, Which, sought to investigate the security threats posed by "smart homes." To this end, experts outfitted their own "smart home" with consumer technology, ranging from smart security systems to smart televisions, thermostats, and even smart kettles. The "smart home" was launched in May 2021, and during its first week, experts recorded 1,017 unique scanning attempts from sources worldwide, with at least 66 of these executed with malicious intent.

The study revealed that the tested "smart home" faced 12,000 hacking attempts within just one week. At one point, experts noted 14 hacking or scanning attempts per hour. While most products managed to fend off attacks, a wireless camera purchased from Amazon was nonetheless compromised, allowing the attacker to attempt spying on the residence.

The majority of attack attempts originated from the United States, India, Russia, the Netherlands, and China. Notably, China, as an economic competitor to the United States, is perceived by analysts to be leveraging its hacking prowess to gain a strategic advantage.

The methods, directions, and types of cybersecurity threats aimed at hacking attempts and the utilization of malicious software have come to the fore. The domains seized by Microsoft were "homoglyphic" and registered to disguise themselves as legitimate domains. The concept involved using characters to visually deceive users into perceiving them as identical. A homoglyph is one of two or more graphemes, characters, or glyphs that appear identical or cannot be differentiated by a quick visual scan. For instance, the Ukrainian "а" and the English "a" are homoglyphs.

Malicious actors employ harmful homoglyphic domains alongside stolen customer credentials to illicitly access accounts, track clients' email traffic, and misappropriate information regarding unfinished financial transactions. According to experts, the orchestrators of this nefarious campaign were part of a larger criminal network likely based in West Africa. The attackers primarily targeted small businesses in North America across various industries.

Experts recorded 12,807 unique scanning/attack attempts, of which 2,435 were attempts to log into smart devices using unreliable default credentials (such as admin/admin). In other words, devices faced 14 brute-force attack attempts per hour, a method of password cracking achieved through sequentially testing possible combinations. Typically, brute-force attacks are conducted en masse, "at random," utilizing standard combinations of logins (admin, administrator) and passwords (meaningful phrases, dictionaries). The greatest number of attacks targeted Epson printers, yet all were thwarted due to robust default passwords. However, the surveillance camera ieGeek, purchased from Amazon, succumbed to hacking attempts, with 97% of the attacks aimed at incorporating it into the Mirai botnet (a network comprised of a certain number of hosts running bots—autonomous software. Typically, a bot within a botnet is software stealthily installed on the victim's device, allowing the attacker to perform actions using the resources of the infected computer. Such networks are usually exploited for illegal or unauthorized activities—spam distribution, password guessing on remote systems, and denial-of-service attacks (DoS and DDoS)). Mirai employs brute-force attacks to guess passwords, installs a Trojan on devices, and adds them to the botnet.

According to Bitdefender, malicious actors are currently actively developing an updated module named "vncDll," utilized in TrickBot attacks on selected targets for monitoring and intelligence gathering. The new module is designed to connect with one of the nine C&C servers specified in its configuration files. The malicious algorithm receives a set of commands from this C&C server, downloads additional malware, and transmits data gathered from the compromised machine.

In an attack deemed the largest in history, hackers exploited previously unknown vulnerabilities (0Day) in the Kaseya VSA server. Previously, clients of the MSP solution provider Kaseya had suffered from a widespread ransomware attack by REvil (Sodinokibi). The hackers leveraged 0-day vulnerabilities in the company’s product (VSA) to target Kaseya's clients. The issue lies in the fact that most of the affected VSA servers were utilized by MSP providers—companies managing the infrastructure of other clients. Consequently, the perpetrators deployed ransomware across thousands of corporate networks. Official reports indicate that the breach impacted approximately 60 Kaseya clients, through whose infrastructure hackers managed to encrypt around 800-1,500 corporate networks. Kaseya VSA is a remote management and monitoring solution typically employed by MSP providers to support their clients. A company may deploy VSA locally using its servers or utilize Kaseya’s cloud SaaS solution.

The company has since addressed these vulnerabilities. Current data suggests that the REvil attack affected 1,500 companies globally, including dental offices, architectural firms, plastic surgery centers, and libraries. For instance, as a result of the attacks, one of Sweden's largest supermarket chains, Coop, was compelled to close around 800 stores nationwide. Store employees were unable to process payments due to the incapacitation of cash registers and self-service stations.

The computer systems of the Accounts Chamber of the Republic of Moldova have also repeatedly fallen victim to cyberattacks, resulting in the destruction of publicly accessible databases and reports of the agency. As reported by the state information agency Moldpres, the websites of the governmental body were breached, and the attackers obliterated audit reports and other public data. This situation marks a first for the supreme auditing authority.

The destruction of public pages occurred amid crucial audit examinations and impacted society during the report preparation phase and the publication of vital auditing missions planned by the institution. As stated by the Accounts Chamber, following the attack, the website had to be taken offline while the incident was investigated and data restored. Currently, it is being determined whether the attack was random, executed for extortion, or aimed at disrupting the operations of the governmental body.

The Use of Quantum Computers. Analysts predict that quantum computers will have the capability to breach most contemporary encryption algorithms, thus exposing private messages, corporate data, and military secrets. Companies within the information technology sector are acutely aware of this potential threat. Some firms have undertaken efforts to create, test, and implement new encryption algorithms that remain secure against quantum computing. For instance, IBM and Thales have already begun to offer products safeguarded by so-called post-quantum cryptography, as reported by CNET.

In the near future, quantum computers may also be able to compromise digital signatures, browsers, operating systems, and other software, thereby paving the way for malware. According to John Graham-Cumming, the Chief Technology Officer of Cloudflare, there exists significant uncertainty regarding this timeline—it could take five years before quantum computers can crack encryption, or it might require just two.

Types of Cybersecurity Threats

Phishing. Phishing involves the dispatch of counterfeit emails designed to mimic messages from trusted sources. The aim of this fraudulent activity is to steal confidential data, such as credit card numbers and credentials. This remains the most prevalent form of cyberattack. Protection against phishing can be achieved through user education or through solutions that block malicious emails.

Email Protection Usage. A free trial of an email protection solution should analyze for viruses.

Ransomware represents a specific type of malware that demands payment, blocking access to files or computer systems until a ransom is paid. However, paying the ransom does not guarantee the restoration of access to files or systems. Strategies for protection against ransomware, as well as ransomware protection solutions, are crucial. Utilizing malware protection and Advanced Malware Protection (AMP) for end devices is essential, along with a free trial of an AMP solution for end devices.

Social Engineering. Cybercriminals exploit social engineering to deceitfully compel individuals into divulging confidential information. The distribution of malware refers to software intended for unauthorized access to a computer or to inflict harm. Attackers may request money transfers or access to confidential data. Social engineering can intertwine with any of the aforementioned types of threats, increasing the likelihood that individuals will click on links, download malicious software, and trust harmful sources.

EU Cybersecurity Strategies to Enhance Collective Resilience and Specific Measures Against Cyber Threats.

At the end of June 2021, the European Commission established a new unified group to combat hackers as part of the EU Cybersecurity Strategy, ensuring that all member states are prepared for collective action and active information sharing. In mid-December 2020, the Commission unveiled a new EU Cybersecurity Strategy aimed at bolstering Europe’s collective resilience against cyber threats and ensuring that all citizens and businesses can fully utilize reliable data while trusting in services and digital tools.

This strategy sought to lay down new principles for the development of the cybersecurity sector over the coming decade. It also empowers the EU to establish international norms and cybersecurity standards while enhancing cooperation with global partners to promote an open, stable, and secure cyberspace. The Commission has proposed measures to improve the cybersecurity of critical physical entities and networks, including the protection of infrastructures vulnerable to cyberattacks, such as transportation, energy, healthcare, the financial system, and numerous other sectors.

The strategy aims to mitigate both current and future online and offline risks—ranging from cyberattacks to cybercrime and natural disasters.

During the second phase of the World Summit on the Information Society (WSIS) in Tunis back in November 2005, world leaders entrusted the International Telecommunication Union (ITU) with a leading role in coordinating international efforts aimed at facilitating the implementation of cybersecurity programs. The ITU, one of the oldest international organizations, was established in Paris on May 17, 1865, under the name of the "International Telegraph Union." They designated the ITU as the sole organization within the C5 WSIS action line, focusing on strengthening trust and security in the use of information and communication technologies (ICT).

In accordance with this decision, ITU members urged the organization to assume a more significant role in cybersecurity matters through the adoption of various resolutions, decisions, programs, and recommendations. Since 2006, the ITU has engaged in a broad spectrum of activities designed to ensure the security of communication over telecommunications networks, enhancing reliability and user convenience.

The Global Cybersecurity Agenda (GCA) announced by the ITU on May 17, 2007, at the behest of Secretary-General Hamadoun I. Touré, serves as a foundation for international cooperation to bolster trust and security in the information society. The GCA encompasses five strategic directions: legal measures, technical and procedural measures, organizational structures, capacity building, and international cooperation.

Cyber threats are inherently global in nature; hence, solutions must also be global. It is imperative that all nations achieve a common understanding of cybersecurity issues to ensure protection against unauthorized access, fraud, and the destruction of vital resources. The ITU posits that any strategic approach should involve identifying existing national and regional initiatives, prioritizing, and effectively engaging all relevant stakeholders.

With its membership comprising 192 member states and over 700 private sector companies and associations, the ITU serves as an excellent forum for proactive measures and responses aimed at promoting cybersecurity and combating cybercrime. While considerable progress has been made, cybercrime persists and continually intensifies, requiring ongoing attention due to the ever-evolving nature of ICT. The ITU relentlessly endeavors to strengthen trust and faith while ensuring a secure and reliable cyber environment for all.

After the World Summit on the Information Society (WSIS) and the subsequent ITU Conference in 2006, the primary role of the International Telecommunication Union (ITU) has been to enhance trust and security in the use of information and communication technologies (ICT). Heads of state and government, along with other global leaders who participated in the WSIS, as well as ITU member states, tasked the ITU with implementing specific measures to mitigate the threats and vulnerabilities associated with the information society. These measures included:

  1. A global cybersecurity program;
  2. Protection of children in the online environment;
  3. The establishment of a global cybersecurity culture.

During the meeting of the High-Level Experts Group, a consensus was reached regarding the further steps necessary for the implementation of the Global Cybersecurity Program. Leaders were appointed from among the experts to oversee each of the five designated areas of work:

  1. Legal Framework - Judge Stein Schjolberg from the District Court in Moss, Norway.
  2. Technical and Procedural Measures - Professor Jaak Tepandi from the Tallinn University of Technology's Institute of Computer Science and Chief Technology Officer at Intel Corporation, Justin Rattner.
  3. Organizational Structures - Tai’eb Debbagh, Secretary-General of the Department of Postal Services, Telecommunications, and Information Technologies (DEPTTI) of Morocco.
  4. Capacity Building - Ivar Tallo, Senior Fellow at the United Nations Institute for Training and Research (UNITAR).
  5. International Cooperation - Shamsul Jafni Shafie, Director of the Security, Trust, and Management Department of the Malaysian Communications and Multimedia Commission.

The results of this group’s efforts culminated in five strategic reports, which collectively form a global roadmap outlining optimal paths to achieve the objectives of the Global Cybersecurity Program, presented to the ITU Secretary-General.

A comprehensive approach to cybersecurity encompasses several layers of protection for computers, networks, programs, and data. Organizations must establish proper interactions among people, processes, and technologies to deploy effective defenses against cyberattacks. A Unified Threat Management (UTM) system automates the integration of a range of Cisco products to ensure security and expedite the execution of key protective functions: detection, analysis, and remediation.

Users must understand and adhere to fundamental principles of data protection, such as selecting strong passwords, exercising caution when handling email attachments, and ensuring data backups. Organizations need to deploy a system for preventing cyberattacks and mitigating their consequences. This can be aided by a recognized strategy that explains how to detect attacks, protect systems, identify threats, respond to them, and address the aftermath of successful attacks.

Technologies underpin the creation of computer security measures to protect organizations and individuals from cyberattacks. Protection should focus on three main groups of assets: endpoint devices such as computers, smart devices, and routers; networks; and cloud services. Common technological solutions for safeguarding these assets include next-generation firewalls, DNS filtering, anti-malware protection, antivirus software, and email security solutions.

Ensuring security in cyberspace has become a necessity for everyone in the modern interconnected world. At the individual level, a cyberattack can lead to various consequences, from identity theft to extortion attempts and the loss of critical data, such as family photographs. Every individual relies on critical infrastructure—power plants, hospitals, and financial institutions. Safeguarding these and other organizations is essential for the smooth functioning of our society. All individuals also benefit from the efforts of cybersecurity researchers. Among these researchers are 250 scientists from the Talos team who investigate emerging threats and approaches to cyberattacks. They identify vulnerabilities, educate the public on the importance of cybersecurity, and enhance the protection of open-source resources. Their work contributes to making the Internet safer for all.

The new Global Cybersecurity Index (GCI), prepared by the International Telecommunication Union (ITU), reflects a growing determination worldwide to address cybersecurity issues and reduce their scale. The recently released 2020 index confirms that countries are working to enhance their cybersecurity measures despite challenges posed by COVID-19, demonstrating a rapid transition to daily operations and socio-economic services in the digital realm. The reliance on ICT as a catalyst for societal, economic, and industrial development renders the task of ensuring cybersecurity and building trust among users more crucial than ever.

Governments and industries must collaborate to make ICT consistently safe and reliable for all, ensuring improvements in economic performance. The Global Cybersecurity Index serves as a key element for identifying prospects and gaps that can be addressed to strengthen each country's digital ecosystem. By the end of the year, approximately 64 percent of countries had adopted a national cybersecurity strategy (NCS), while over 70 percent conducted cybersecurity awareness campaigns in 2020, compared to 58 percent and 66 percent, respectively, in 2018. At the same time, despite notable improvements, gaps remain in developing cybersecurity capacity. Many countries and regions lag in several key areas:

  1. Cybersecurity skills training, which should be tailored to the needs of micro, small, and medium-sized enterprises (MSMEs);
  2. Key sectors such as finance, healthcare, and energy, where specific measures are needed to close cybersecurity gaps;
  3. The protection of critical infrastructure, which needs to be enhanced to combat new cyber threats;
  4. Strengthening the protection of personal data as online activities continue to proliferate.

Given the increasing dependence on digital solutions, more effective, yet user-friendly and accessible data protection measures are needed. ITU members should continue to provide updates on cybersecurity efforts and commitments, allowing countries to share experiences, research, and solutions to create a reliable cyberspace for all while monitoring the evolving cybersecurity landscape.

According to the ITU, from 2015 to 2019 (when the first GCI was released), nearly one billion people worldwide became Internet users for the first time. It is anticipated that this year, global losses due to cybercrime will reach $6 trillion, and citizens expect governments to bolster cybersecurity standards and protect increasingly vulnerable personal and financial data.

Cybercriminals have devised new methods for creating an ever-increasing number of fake applications within the banking sector. To date, malicious software packages targeting clients of the world’s largest banks—such as Citibank, ING, Deutsche Bank, HSBC, Barclays, and an additional 66 financial institutions from various countries—have been identified. Activities related to the hacking of the iOS operating system, known as "jailbreaking" (the process of installing unauthorized software), have intensified, enabling users to access numerous software products that have not received official certification from Apple. Approximately 10 million iOS devices have been compromised, and their owners have availed themselves of third-party application stores like Cydia to download these applications. Despite the fact that jailbreaking provides owners with enhanced control over their devices, it simultaneously renders iOS mobile devices vulnerable. Therefore, in light of the susceptibility of information systems, it is imperative to elevate the priority of cybersecurity within the realms of foreign policy and security.

Consequently, the analysis has underscored the necessity of actively promoting cooperation with the United States, Australia, India, and China, strengthening measures within private enterprises, and ensuring that the state mobilizes all available resources and means to adopt prompt political measures in the event of a cyberattack.

In 2019, police in Japan recorded more than 4,000 attempts of illegal intrusion into various computer networks and systems. Notably, major electrical engineering corporations such as NEC and Mitsubishi Electric fell victim to these malevolent actors. In order to enhance cybersecurity, Japan is prepared to conduct training with the United States, establish security standards for IT equipment, and bolster its defenses against hackers. The overwhelming majority of companies have suddenly realized that strategies for ensuring corporate cybersecurity resilience are of vital necessity.

A recent study titled “Information Security During and After the Pandemic” also highlighted a significant array of challenges facing the information security industry, particularly in re-evaluating the role and issues of Information Security services within the context of the “new normal.” Based on this analysis, it is noteworthy that Ukraine has inaugurated a new CYBER CENTER UA30, aimed at protecting, monitoring registries, and securing personal data. President Volodymyr Zelensky participated in the presentation of the UA30 cyber center, which was established to safeguard state information resources, critical information infrastructure, and the Ukrainian cyberspace as a whole. The CYBER CENTER UA30 is based on the State Special Communications and Information Protection Service of Ukraine, with its "core" being the Government Computer Emergency Response Team of Ukraine (CERT-UA).

The tectonic shifts in business practices, provoked by the pandemic, have dramatically accelerated the digital transformation of information flows in modern business, forming new sources of risk, vulnerability, attacks, and system failures, thereby necessitating the formation of a cybersecurity strategy in the context of globalization.





Über den Autor

Dieser Artikel wurde von Sykalo Yevhen zusammengestellt und redigiert — Bildungsplattform-Manager mit über 12 Jahren Erfahrung in der Entwicklung methodischer Online-Projekte im Bereich Philosophie und Geisteswissenschaften.

Quellen und Methodik

Der Inhalt basiert auf akademischen Quellen in mehreren Sprachen — darunter ukrainische, russische und englische Universitätslehrbücher sowie wissenschaftliche Ausgaben zur Geschichte der Philosophie. Die Texte wurden aus den Originalquellen ins Deutsche übertragen und redaktionell bearbeitet. Alle Artikel werden vor der Veröffentlichung inhaltlich und didaktisch geprüft.

Zuletzt geändert: 12/01/2025