Powered by OpenAIRE graph
Found an issue? Give us feedback
image/svg+xml art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos Open Access logo, converted into svg, designed by PLoS. This version with transparent background. http://commons.wikimedia.org/wiki/File:Open_Access_logo_PLoS_white.svg art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos http://www.plos.org/ ZENODOarrow_drop_down
image/svg+xml art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos Open Access logo, converted into svg, designed by PLoS. This version with transparent background. http://commons.wikimedia.org/wiki/File:Open_Access_logo_PLoS_white.svg art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos http://www.plos.org/
ZENODO
Other literature type . 2025
License: CC BY
Data sources: ZENODO
ZENODO
Data Paper . 2025
License: CC BY
Data sources: Datacite
ZENODO
Data Paper . 2025
License: CC BY
Data sources: Datacite
versions View all 2 versions
addClaim

A Failed State of Security: An Analysis of Causality and Victim Blaming in Cybersecurity Incidents

Authors: mark, chris;

A Failed State of Security: An Analysis of Causality and Victim Blaming in Cybersecurity Incidents

Abstract

The cybersecurity industry has developed an organized victim-blaming infrastructure that systematically excuses actual criminals while condemning breached organizations. This analysis examines the philosophical, legal, and practical failures of current accountability frameworks through the lens of 2024-2025's unprecedented breach escalation—including Change Healthcare's 192.7 million affected individuals, PowerSchool's compromise of 62.4 million students, and Ticketmaster's 560 million exposed customer records. Drawing from classical philosophy (Virgil, Hume, Bacon) through contemporary causation theory, the analysis demonstrates that adversaries who deliberately initiate attack sequences constitute the proximal cause of breaches—not organizational security decisions. The "but-for" test clearly identifies criminal action as cause-in-fact: absent adversary attacks, no breaches occur regardless of defensive posture. Current approaches prove counterproductive. With 5.5 billion accounts compromised globally in 2024 (an eightfold increase), regulatory proliferation imposing compliance burdens without security improvement, and law enforcement achieving minimal prosecution success, reflexive victim condemnation actively undermines collective defense by discouraging transparency and information sharing. Progress requires fundamental reorientation: adversary-focused deterrence, software vendor liability, realistic regulatory standards with safe harbor provisions, harmonized requirements, and frameworks rewarding transparency. Until accountability shifts from victims to actual perpetrators, the failed state of security will persist.

Keywords

cybersecurity, victim blaming, causality theory, data breach liability, fiduciary responsibility, regulatory compliance, adversary attribution

  • BIP!
    Impact byBIP!
    selected citations
    These citations are derived from selected sources.
    This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
    0
    popularity
    This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network.
    Average
    influence
    This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
    Average
    impulse
    This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network.
    Average
Powered by OpenAIRE graph
Found an issue? Give us feedback
selected citations
These citations are derived from selected sources.
This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
BIP!Citations provided by BIP!
popularity
This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network.
BIP!Popularity provided by BIP!
influence
This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
BIP!Influence provided by BIP!
impulse
This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network.
BIP!Impulse provided by BIP!
0
Average
Average
Average
Green