Article Review #1

Cyber Victimization in Healthcare
As cyberattacks on healthcare increase, understanding why they happen and who the targets
are is crucial for improving cybersecurity. Routine Activities Theory (RAT) suggests that crime
happens when a criminal, an easy target, and no one to stop them come together, which in
cybersecurity applies to cybercriminals targeting vulnerable healthcare systems. Cyber-Routine
Activities Theory (Cyber-RAT) adapts this idea to the digital realm, highlighting how online
behaviors and connected devices create more opportunities for attacks. This article uses RAT
and Cyber-RAT to analyze healthcare cyberattacks and propose ways to enhance cybersecurity.


The Rising Threat of Cyberattacks in Healthcare
Healthcare’s increasing reliance on technology has undeniably improved patient care but has
also introduced significant cybersecurity risks. The rise of cyberattacks in the healthcare sector
underscores the need to better understand the motivations of attackers and why specific targets
are at greater risk. This issue intertwines with criminology and sociology, focusing on the dynamic
between criminals, their targets, and the broader impact of cybercrime in such a vital industry
(Praveen, Kim, & Choi, 2024). Cyberattacks disrupt more than just data, they can jeopardize
patient safety and put healthcare organizations at risk financially. As these attacks become more
sophisticated, hackers continue to exploit vulnerabilities in healthcare systems. Thus,
strengthening cybersecurity is critical to safeguarding sensitive data and maintaining patient trust.
Applying RAT and Cyber-RAT provides insights into why healthcare remains a prime target for
cybercrime (Praveen, Kim, & Choi, 2024).


A Study Using RAT and Cyber-RAT
This study examines cyberattacks on healthcare through the lens of RAT and Cyber-RAT,
addressing two key questions: what motivates hackers to target healthcare organizations and
what common characteristics do these offenders share? The study suggests that cyberattacks
occur when there is a convergence of three factors: motivated offenders, vulnerable targets, and
inadequate security (Praveen, Kim, & Choi, 2024). Analyzing 1,138 cybercrime cases in healthcare
from 2018 to 2023, the researchers identified prevalent attack methods, such as phishing,
ransomware, and data theft. Financial gain emerged as the primary motive, with state-backed
hackers targeting high-value data and essential healthcare services (Praveen, Kim, & Choi, 2024).
RAT explains that crime is more likely when these three elements align, and Cyber-RAT adapts
this theory to the digital realm, focusing on online behavior and cybersecurity. The VIVA
framework—focusing on value, inertia, visibility, and accessibility—helps explain why healthcare organizations are especially vulnerable. Strong cybersecurity is vital in preventing these attacks
(Praveen, Kim, & Choi, 2024). The study also highlights the disproportionate impact of data
breaches on marginalized groups, such as low-income patients, who often face greater difficulty
accessing secure healthcare. To address these issues, the study proposes enhanced digital
protections, increased awareness, and updated policies (Praveen, Kim, & Choi, 2024).


Social Science Insights
Cyber victimization in healthcare is deeply connected to the social sciences, encompassing
criminology, sociology, and psychology. This study delves into the motivations behind
cyberattacks and the common traits of those who commit these crimes. Psychologically, the study
examines how the impact of cyber victimization varies based on factors like gender, age, race,
and personal experiences. Victims of cybercrimes often face emotional consequences, including
depression, fear, or self-blame. The research also highlights the compounded challenges faced
by marginalized groups, such as low-income patients, who are disproportionately affected by
data breaches. These individuals, already struggling to access secure healthcare, face even
greater risks when their personal data is compromised. Ultimately, the study stresses that
cyberattacks in healthcare have severe societal consequences, particularly for vulnerable
populations, and challenges the misconception that cybercrimes are “victimless.” These crimes
can deeply affect the mental and emotional well-being of the victims.


Conclusion
Cyberattacks on healthcare are increasing, and understanding their causes and target
vulnerabilities is key to improving security. By applying RAT and Cyber-RAT, the study offers
insights into how to better protect healthcare organizations. Strengthening cybersecurity, raising
awareness, and updating policies are critical steps to reduce risks, particularly for vulnerable
groups.

References
Praveen, Y., Kim, M., & Choi, K.-S. (2024). Cyber victimization in the healthcare industry: Analyzing
offender motivations and target characteristics through routine activities theory (RAT)
and cyber-routine activities theory (Cyber-RAT). International Journal of Cybersecurity
Intelligence & Cybercrime, 7(2). https://doi.org/10.52306/2578-3289.1186

Article Review #2

Examining the Causes and Costs of Cyber Incidents
In recent years, cyber incidents have become a significant concern for businesses, governments,
and individuals alike. With the increasing frequency of cyberattacks, such as data breaches,
phishing, and privacy violations, there has been growing pressure for firms to strengthen their
cybersecurity defenses. In response to this, the U.S. President issued an executive order in 2013
aimed at protecting critical infrastructure from cyberattacks, leading to the creation of a
voluntary cybersecurity framework by the National Institute for Standards and Technology (NIST).
This research investigates whether such frameworks motivate firms to improve their
cybersecurity measures, focusing on over 12,000 cyber events recorded from 2004 to 2015. By
analyzing the causes, costs, and implications of these incidents, the study explores whether firms
are truly incentivized to adopt stronger cybersecurity practices.


The Causes of Cyber Incidents
The study categorizes cyber incidents into four main types: data breaches, security incidents,
privacy violations, and phishing/skimming. Among these, data breaches are the most prevalent,
with significant compromises of credit card and medical data. Malicious attacks account for about
60% of all incidents, indicating that external actors are primarily responsible for many cyber
threats. Security incidents saw a sharp increase after 2012, suggesting a real rise in cyberattacks,
though no clear policy changes can explain this spike (Romanosky, 2016). The study also
explores various factors that may drive the rise in cyber incidents. The increase in data breaches
and privacy violations may be partially attributed to state-level disclosure laws that require
companies to report breaches. Additionally, national attention on privacy issues, such as
high-profile cases involving Facebook and Google Street View, may have contributed to an
increase in reported privacy violations. Despite popular claims, the research challenges the
assumption that all companies have been hacked or are unaware of their cybersecurity breaches.
In fact, many firms appear to be managing their risks effectively, and not all organizations are as
vulnerable as some headlines suggest. The disproportionate impact of cyber incidents on
marginalized groups, particularly those with limited access to digital security resources, highlights
the need for more inclusive cybersecurity policies and frameworks. These groups may also face increased vulnerability to cybercrime due to a lack of financial resources to invest in robust
cybersecurity measures, exacerbating existing social inequalities.


The Costs of Cyber Incidents
The financial impact of cyber incidents is an essential consideration for firms when evaluating
their cybersecurity investments. The study reveals that, despite the widespread concern over
cyber threats, the actual costs to most firms remain relatively low. On average, the cost of a cyber
breach is under $200,000. That represents only about 0.4% of a firm’s annual revenue which is
roughly equal to a firm’s yearly IT security budget (Romanosky, 2016). When compared to other
types of business losses, such as fraud or retail shrinkage, cyber events appear to be a smaller
financial burden.
The study also identifies two types of costs associated with cyber events: first-party losses and
third-party losses. First-party losses refer to direct costs incurred by the affected firm, such as
forensic investigations, customer notifications, and public relations campaigns. Third-party losses
involve costs related to lawsuits, regulatory fines, and damages from phishing-related theft. The
data highlights the challenges in estimating the full cost of cyber incidents, as many costs, such
as reputational damage and lost revenue, are not included in the figures. Furthermore, the
dataset used in the study primarily represents publicly reported incidents, which may not capture
smaller, unreported events or the indirect costs associated with cyberattacks.


Social Science Insights
Economics, as a social science, studies how societies allocate limited resources to produce and
distribute wealth, a concept that directly applies to cybersecurity in terms of allocating time,
money, and skilled personnel to protect digital assets and infrastructure. The allocation of these
resources is critical, as economic principles such as scarcity, supply and demand, opportunity
cost, and risk management significantly influence decision-making in cybersecurity. The growing
cybersecurity industry itself is an example of wealth creation, contributing to the economy
through the creation of businesses, job opportunities, and the development of products and
services. Cost-benefit analysis (CBA) plays an essential role in evaluating the effectiveness of
cybersecurity investments by comparing the costs of implementation with the potential financial
benefits of risk mitigation. Risk assessment, a critical tool in the allocation of cybersecurity resources, helps organizations identify vulnerabilities and prioritize their investments to
safeguard their digital infrastructure.
The economic consequences of cybersecurity incidents are not limited to financial losses but
also encompass broader social costs, impacting marginalized groups who may lack access to
resources or knowledge to protect themselves from cyberattacks. This population is particularly
vulnerable to exploitation and further economic marginalization. Various economic theories, such
as rational choice theory, Marxian economics, and Keynesian economics, offer valuable
frameworks to better understand cybersecurity behavior, market forces, and the potential role of
government intervention in regulating the industry. Additionally, the dark web operates under
similar economic principles but presents challenges for legitimate economic activities due to its
involvement in illicit transactions, highlighting the ongoing struggle to balance security and
economic freedom.


Conclusion
This research provides valuable insights into the causes and financial implications of cyber
incidents. Despite the high volume of cyber threats and legal actions, the financial impact on
firms is generally low. The study suggests that this relatively small financial burden may reduce
the motivation for firms to adopt voluntary cybersecurity frameworks, such as the NIST
Cybersecurity Framework. By offering a detailed analysis of incident types, causes, and costs, the
research highlights the complexity of estimating the true financial impact of cyber events. While
the costs of cyber incidents are rising, they remain far smaller than other types of business
losses. The findings offer critical insights for businesses, insurers, and policymakers seeking to
understand and mitigate cyber risks more effectively.

References
Romanosky, S. (2016a). Examining the costs and causes of cyber incidents. Journal of
Cybersecurity. https://doi.org/10.1093/cybsec/tyw001