Cybersecurity and cybercrime
Cybersecurity and Cybercrime
This topic is assessed in IBDP Business Management at Higher Level (HL) only.
As businesses become increasingly dependent on digital systems — for operations, communications, customer data, and financial transactions — the risks associated with those systems grow proportionately. Cybercrime encompasses criminal activities that use digital systems as a target or tool: attacking a company's systems to steal data, extort money, or disrupt operations. Cybersecurity is the set of technical and organisational measures businesses use to protect their digital assets from these threats. The management of cybersecurity risk is now a core operational responsibility — not a specialist IT concern but a strategic business issue at board level. The crisis management response to a cyberattack is examined in the crisis management versus contingency planning section; this section focuses on understanding the threat landscape and prevention.
Types of cybercrime
Ransomware is malicious software that encrypts a victim's files, making them inaccessible, and demands a ransom payment for the decryption key. Ransomware attacks have grown dramatically in scale and sophistication — targeting businesses, hospitals, and government agencies with ransom demands ranging from thousands to tens of millions of pounds. A business without adequate backups may face a stark choice between paying the ransom or losing critical operational data.
Phishing involves deceptive communications — typically emails — that impersonate trusted organisations to trick recipients into revealing login credentials, financial information, or installing malware. Spear phishing targets specific individuals (often senior executives) with highly personalised messages that are much harder to identify as fraudulent than generic phishing. Most successful cyberattacks begin with a phishing email that gives the attacker an initial foothold in the target's systems.
Data breaches involve unauthorised access to and extraction of confidential data — customer records, financial information, intellectual property, or employee data. Data breaches may be perpetrated by external attackers or by insiders (employees with legitimate access who misuse it). The commercial and reputational consequences of a significant data breach — regulatory fines, client loss, litigation, and brand damage — can be severe and long-lasting.
Denial of service (DoS) attacks overwhelm a business's digital systems with traffic, making them unavailable to legitimate users. For businesses whose operations depend on continuous digital availability — e-commerce platforms, logistics tracking systems, financial services — a sustained DoS attack can halt operations entirely.
Social engineering manipulates individuals rather than systems — using psychological techniques to persuade employees to take actions that compromise security, such as transferring funds, revealing passwords, or granting system access to unauthorised parties.
Cybersecurity measures
Technical measures include: firewalls that control network traffic and block unauthorised access; encryption that makes data unreadable to anyone without the decryption key; multi-factor authentication (MFA) that requires additional verification beyond a password; regular software patching that closes known security vulnerabilities; and intrusion detection systems that identify and alert on suspicious activity in real time.
Organisational measures include: staff training in recognising phishing and social engineering attempts — since human behaviour is the most common attack vector; access controls that limit each employee's system access to the minimum necessary for their role; incident response planning (as examined in the crisis management versus contingency planning section); regular security audits and penetration testing; and data backup procedures that enable recovery without paying a ransom if systems are compromised.
Governance measures include: a defined cybersecurity policy and clear ownership at board level; cyber insurance that provides financial protection against attack costs; third-party supplier security requirements (since attackers often target a well-protected organisation through a less-protected supplier); and compliance with relevant data protection regulations that impose minimum security standards.
Meridian's fleet management platform processes real-time tracking data from over 14,000 client vehicles and holds commercially sensitive route, schedule, and cargo data for 200+ logistics clients. A successful cyberattack would not only disrupt Meridian's own operations but could expose client operational data to competitors — a breach of trust that would be commercially catastrophic. Following a near-miss phishing incident in which a finance team member clicked a malicious link (detected before any data was exfiltrated), Meridian implemented: MFA across all staff accounts; mandatory annual phishing simulation training with immediate re-training for staff who fail simulated phishing tests; network segmentation isolating the client data environment from internal administrative systems; and an offline backup of all operational data updated every four hours, ensuring recovery from ransomware without ransom payment. The annual cybersecurity budget of £68,000 represents approximately 0.3% of revenue — Meridian's board considers this prudent given that the estimated cost of a major breach (data loss, client notification, regulatory fine, reputational remediation) is in excess of £2 million.
Key Takeaways
- Key cybercrime types: ransomware (encrypts data for ransom), phishing (deceptive credentials theft), data breaches (unauthorised data access), DoS attacks (system unavailability), and social engineering (manipulating people rather than systems).
- Cybersecurity operates across three layers: technical (firewalls, encryption, MFA), organisational (staff training, access controls, backups), and governance (policy, insurance, supplier requirements).
- Human behaviour is the most common attack vector — phishing and social engineering succeed by exploiting people, not technology; staff training is therefore a critical security measure.
- The cost of a major breach — regulatory fines, client loss, reputational damage — typically far exceeds the cost of preventive cybersecurity investment.
- Offline data backups are the single most effective technical protection against ransomware — enabling recovery without ransom payment.