{"id":100,"date":"2025-04-25T23:44:09","date_gmt":"2025-04-25T23:44:09","guid":{"rendered":"https:\/\/student.wp.odu.edu\/trobe040\/?page_id=100"},"modified":"2025-04-26T02:13:06","modified_gmt":"2025-04-26T02:13:06","slug":"article-reviews","status":"publish","type":"page","link":"https:\/\/student.wp.odu.edu\/trobe040\/article-reviews\/","title":{"rendered":"Article Reviews"},"content":{"rendered":"\n<p><strong><span style=\"text-decoration: underline\">Article Review #1<\/span><\/strong><\/p>\n\n\n\n<p><span style=\"text-decoration: underline\">Cyber Victimization in Healthcare<\/span><br>As cyberattacks on healthcare increase, understanding why they happen and who the targets<br>are is crucial for improving cybersecurity. Routine Activities Theory (RAT) suggests that crime<br>happens when a criminal, an easy target, and no one to stop them come together, which in<br>cybersecurity applies to cybercriminals targeting vulnerable healthcare systems. Cyber-Routine<br>Activities Theory (Cyber-RAT) adapts this idea to the digital realm, highlighting how online<br>behaviors and connected devices create more opportunities for attacks. This article uses RAT<br>and Cyber-RAT to analyze healthcare cyberattacks and propose ways to enhance cybersecurity.<\/p>\n\n\n\n<p><br>The Rising Threat of Cyberattacks in Healthcare<br>Healthcare\u2019s increasing reliance on technology has undeniably improved patient care but has<br>also introduced significant cybersecurity risks. The rise of cyberattacks in the healthcare sector<br>underscores the need to better understand the motivations of attackers and why specific targets<br>are at greater risk. This issue intertwines with criminology and sociology, focusing on the dynamic<br>between criminals, their targets, and the broader impact of cybercrime in such a vital industry<br>(Praveen, Kim, &amp; Choi, 2024). Cyberattacks disrupt more than just data, they can jeopardize<br>patient safety and put healthcare organizations at risk financially. As these attacks become more<br>sophisticated, hackers continue to exploit vulnerabilities in healthcare systems. Thus,<br>strengthening cybersecurity is critical to safeguarding sensitive data and maintaining patient trust.<br>Applying RAT and Cyber-RAT provides insights into why healthcare remains a prime target for<br>cybercrime (Praveen, Kim, &amp; Choi, 2024).<\/p>\n\n\n\n<p><br>A Study Using RAT and Cyber-RAT<br>This study examines cyberattacks on healthcare through the lens of RAT and Cyber-RAT,<br>addressing two key questions: what motivates hackers to target healthcare organizations and<br>what common characteristics do these offenders share? The study suggests that cyberattacks<br>occur when there is a convergence of three factors: motivated offenders, vulnerable targets, and<br>inadequate security (Praveen, Kim, &amp; Choi, 2024). Analyzing 1,138 cybercrime cases in healthcare<br>from 2018 to 2023, the researchers identified prevalent attack methods, such as phishing,<br>ransomware, and data theft. Financial gain emerged as the primary motive, with state-backed<br>hackers targeting high-value data and essential healthcare services (Praveen, Kim, &amp; Choi, 2024).<br>RAT explains that crime is more likely when these three elements align, and Cyber-RAT adapts<br>this theory to the digital realm, focusing on online behavior and cybersecurity. The VIVA<br>framework\u2014focusing on value, inertia, visibility, and accessibility\u2014helps explain why healthcare organizations are especially vulnerable. Strong cybersecurity is vital in preventing these attacks<br>(Praveen, Kim, &amp; Choi, 2024). The study also highlights the disproportionate impact of data<br>breaches on marginalized groups, such as low-income patients, who often face greater difficulty<br>accessing secure healthcare. To address these issues, the study proposes enhanced digital<br>protections, increased awareness, and updated policies (Praveen, Kim, &amp; Choi, 2024).<\/p>\n\n\n\n<p><br>Social Science Insights<br>Cyber victimization in healthcare is deeply connected to the social sciences, encompassing<br>criminology, sociology, and psychology. This study delves into the motivations behind<br>cyberattacks and the common traits of those who commit these crimes. Psychologically, the study<br>examines how the impact of cyber victimization varies based on factors like gender, age, race,<br>and personal experiences. Victims of cybercrimes often face emotional consequences, including<br>depression, fear, or self-blame. The research also highlights the compounded challenges faced<br>by marginalized groups, such as low-income patients, who are disproportionately affected by<br>data breaches. These individuals, already struggling to access secure healthcare, face even<br>greater risks when their personal data is compromised. Ultimately, the study stresses that<br>cyberattacks in healthcare have severe societal consequences, particularly for vulnerable<br>populations, and challenges the misconception that cybercrimes are \u201cvictimless.\u201d These crimes<br>can deeply affect the mental and emotional well-being of the victims.<\/p>\n\n\n\n<p><br>Conclusion<br>Cyberattacks on healthcare are increasing, and understanding their causes and target<br>vulnerabilities is key to improving security. By applying RAT and Cyber-RAT, the study offers<br>insights into how to better protect healthcare organizations. Strengthening cybersecurity, raising<br>awareness, and updating policies are critical steps to reduce risks, particularly for vulnerable<br>groups.<\/p>\n\n\n\n<p>References<br>Praveen, Y., Kim, M., &amp; Choi, K.-S. (2024). Cyber victimization in the healthcare industry: Analyzing<br>offender motivations and target characteristics through routine activities theory (RAT)<br>and cyber-routine activities theory (Cyber-RAT). International Journal of Cybersecurity<br>Intelligence &amp;amp; Cybercrime, 7(2). https:\/\/doi.org\/10.52306\/2578-3289.1186<\/p>\n\n\n\n<p><strong><span style=\"text-decoration: underline\">Article Review #2<\/span><\/strong><\/p>\n\n\n\n<p><span style=\"text-decoration: underline\">Examining the Causes and Costs of Cyber Incidents<\/span><br>In recent years, cyber incidents have become a significant concern for businesses, governments,<br>and individuals alike. With the increasing frequency of cyberattacks, such as data breaches,<br>phishing, and privacy violations, there has been growing pressure for firms to strengthen their<br>cybersecurity defenses. In response to this, the U.S. President issued an executive order in 2013<br>aimed at protecting critical infrastructure from cyberattacks, leading to the creation of a<br>voluntary cybersecurity framework by the National Institute for Standards and Technology (NIST).<br>This research investigates whether such frameworks motivate firms to improve their<br>cybersecurity measures, focusing on over 12,000 cyber events recorded from 2004 to 2015. By<br>analyzing the causes, costs, and implications of these incidents, the study explores whether firms<br>are truly incentivized to adopt stronger cybersecurity practices.<\/p>\n\n\n\n<p><br>The Causes of Cyber Incidents<br>The study categorizes cyber incidents into four main types: data breaches, security incidents,<br>privacy violations, and phishing\/skimming. Among these, data breaches are the most prevalent,<br>with significant compromises of credit card and medical data. Malicious attacks account for about<br>60% of all incidents, indicating that external actors are primarily responsible for many cyber<br>threats. Security incidents saw a sharp increase after 2012, suggesting a real rise in cyberattacks,<br>though no clear policy changes can explain this spike (Romanosky, 2016). The study also<br>explores various factors that may drive the rise in cyber incidents. The increase in data breaches<br>and privacy violations may be partially attributed to state-level disclosure laws that require<br>companies to report breaches. Additionally, national attention on privacy issues, such as<br>high-profile cases involving Facebook and Google Street View, may have contributed to an<br>increase in reported privacy violations. Despite popular claims, the research challenges the<br>assumption that all companies have been hacked or are unaware of their cybersecurity breaches.<br>In fact, many firms appear to be managing their risks effectively, and not all organizations are as<br>vulnerable as some headlines suggest. The disproportionate impact of cyber incidents on<br>marginalized groups, particularly those with limited access to digital security resources, highlights<br>the need for more inclusive cybersecurity policies and frameworks. These groups may also face increased vulnerability to cybercrime due to a lack of financial resources to invest in robust<br>cybersecurity measures, exacerbating existing social inequalities.<\/p>\n\n\n\n<p><br>The Costs of Cyber Incidents<br>The financial impact of cyber incidents is an essential consideration for firms when evaluating<br>their cybersecurity investments. The study reveals that, despite the widespread concern over<br>cyber threats, the actual costs to most firms remain relatively low. On average, the cost of a cyber<br>breach is under $200,000. That represents only about 0.4% of a firm\u2019s annual revenue which is<br>roughly equal to a firm\u2019s yearly IT security budget (Romanosky, 2016). When compared to other<br>types of business losses, such as fraud or retail shrinkage, cyber events appear to be a smaller<br>financial burden.<br>The study also identifies two types of costs associated with cyber events: first-party losses and<br>third-party losses. First-party losses refer to direct costs incurred by the affected firm, such as<br>forensic investigations, customer notifications, and public relations campaigns. Third-party losses<br>involve costs related to lawsuits, regulatory fines, and damages from phishing-related theft. The<br>data highlights the challenges in estimating the full cost of cyber incidents, as many costs, such<br>as reputational damage and lost revenue, are not included in the figures. Furthermore, the<br>dataset used in the study primarily represents publicly reported incidents, which may not capture<br>smaller, unreported events or the indirect costs associated with cyberattacks.<\/p>\n\n\n\n<p><br>Social Science Insights<br>Economics, as a social science, studies how societies allocate limited resources to produce and<br>distribute wealth, a concept that directly applies to cybersecurity in terms of allocating time,<br>money, and skilled personnel to protect digital assets and infrastructure. The allocation of these<br>resources is critical, as economic principles such as scarcity, supply and demand, opportunity<br>cost, and risk management significantly influence decision-making in cybersecurity. The growing<br>cybersecurity industry itself is an example of wealth creation, contributing to the economy<br>through the creation of businesses, job opportunities, and the development of products and<br>services. Cost-benefit analysis (CBA) plays an essential role in evaluating the effectiveness of<br>cybersecurity investments by comparing the costs of implementation with the potential financial<br>benefits of risk mitigation. Risk assessment, a critical tool in the allocation of cybersecurity resources, helps organizations identify vulnerabilities and prioritize their investments to<br>safeguard their digital infrastructure.<br>The economic consequences of cybersecurity incidents are not limited to financial losses but<br>also encompass broader social costs, impacting marginalized groups who may lack access to<br>resources or knowledge to protect themselves from cyberattacks. This population is particularly<br>vulnerable to exploitation and further economic marginalization. Various economic theories, such<br>as rational choice theory, Marxian economics, and Keynesian economics, offer valuable<br>frameworks to better understand cybersecurity behavior, market forces, and the potential role of<br>government intervention in regulating the industry. Additionally, the dark web operates under<br>similar economic principles but presents challenges for legitimate economic activities due to its<br>involvement in illicit transactions, highlighting the ongoing struggle to balance security and<br>economic freedom.<\/p>\n\n\n\n<p><br>Conclusion<br>This research provides valuable insights into the causes and financial implications of cyber<br>incidents. Despite the high volume of cyber threats and legal actions, the financial impact on<br>firms is generally low. The study suggests that this relatively small financial burden may reduce<br>the motivation for firms to adopt voluntary cybersecurity frameworks, such as the NIST<br>Cybersecurity Framework. By offering a detailed analysis of incident types, causes, and costs, the<br>research highlights the complexity of estimating the true financial impact of cyber events. While<br>the costs of cyber incidents are rising, they remain far smaller than other types of business<br>losses. The findings offer critical insights for businesses, insurers, and policymakers seeking to<br>understand and mitigate cyber risks more effectively.<\/p>\n\n\n\n<p>References<br>Romanosky, S. (2016a). Examining the costs and causes of cyber incidents. Journal of<br>Cybersecurity. https:\/\/doi.org\/10.1093\/cybsec\/tyw001<\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Article Review #1 Cyber Victimization in HealthcareAs cyberattacks on healthcare increase, understanding why they happen and who the targetsare is crucial for improving cybersecurity. Routine Activities Theory (RAT) suggests that crimehappens when a criminal, an easy target, and no one&#8230; <a class=\"more-link\" href=\"https:\/\/student.wp.odu.edu\/trobe040\/article-reviews\/\">Continue Reading &rarr;<\/a><\/p>\n","protected":false},"author":30518,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"_links":{"self":[{"href":"https:\/\/student.wp.odu.edu\/trobe040\/wp-json\/wp\/v2\/pages\/100"}],"collection":[{"href":"https:\/\/student.wp.odu.edu\/trobe040\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/student.wp.odu.edu\/trobe040\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/student.wp.odu.edu\/trobe040\/wp-json\/wp\/v2\/users\/30518"}],"replies":[{"embeddable":true,"href":"https:\/\/student.wp.odu.edu\/trobe040\/wp-json\/wp\/v2\/comments?post=100"}],"version-history":[{"count":3,"href":"https:\/\/student.wp.odu.edu\/trobe040\/wp-json\/wp\/v2\/pages\/100\/revisions"}],"predecessor-version":[{"id":116,"href":"https:\/\/student.wp.odu.edu\/trobe040\/wp-json\/wp\/v2\/pages\/100\/revisions\/116"}],"wp:attachment":[{"href":"https:\/\/student.wp.odu.edu\/trobe040\/wp-json\/wp\/v2\/media?parent=100"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}