Lecturer/ Richard Rodriguez
Course Level: Advanced Undergraduate / Graduate Instructor: Richard Rodriguez (CyJurll Policy Advisory Board) The relationship between technology, threats, and the law has evolved over nearly two centuries through distinct stages:
1834: The first recorded cyberattack occurred when the Blanc brothers bribed a French telegraph operator to smuggle stock-market data into official messages.
1903: Nevil Maskelyne hijacked Marconi's wireless demonstration in London, marking the first recorded wireless hack.
1962: Allan Scherr executed the first computer hack at MIT, printing passwords from the CTSS to secure extra computing time.
1970: The state of Hesse in Germany passed the Hessian Data Protection Act, creating the first data privacy law.
1971: The "Creeper" virus on ARPANET became the first computer virus.
1973: Sweden passed the Data Act, the first national privacy law.
1986: The United States passed the Computer Fraud and Abuse Act, the first anti-hacking law.
1988: The Morris Worm became the first internet worm.
2000: The ILOVEYOU email worm went global, causing roughly $10 billion in damages and industrializing cybercrime for profit.
2001: The Budapest Convention was formed as the first international cybercrime treaty.
2010: Stuxnet physically destroyed Iranian nuclear centrifuges, marking the transition of cyberattacks into state-backed weapons of war.
2017–2021: The ransomware economy weaponized extortion, targeting critical infrastructure like the Colonial Pipeline (2021).
2018: The EU GDPR set a global standard for data privacy, establishing fines of up to 4% of global revenue.
2024: The UN adopted the Convention against Cybercrime, opening for signatures in Hanoi in October 2025 as the first truly global cyber treaty.
Modern cybersecurity relies on structured frameworks to mitigate risk and map out defenses.
This model implements five concentric layers to protect Mission-Critical Assets at the core, across both public and private clouds:
Perimeter Security: Firewalls, IDS/IPS, DMZ, application gateways, and patching.
Network Security: Web proxy/filtering, NAC, VoIP/virtual firewalls, and wireless security.
Endpoint Security: Host IDS/IPS, EDR, mobile security, and configuration compliance.
Application Security: WAF/XML firewalls, database monitoring, static and dynamic testing.
Data Security: Encryption, Data Loss Prevention (DLP), rights management, PKI, and classification.
These layers are supported by four process pillars: Prevention, Policy Management, Operations, and Monitoring & Response.
Zero Trust shifts defenses from static perimeters to continuous verification, organized into five core pillars underpinned by cross-cutting capabilities:
Pillars: Identities, Devices, Networks, Apps & Workloads, and Data.
Cross-Cutting Capabilities: Visibility & Analytics (SIEM/XDR), Automation & Orchestration (SOAR), and Governance (GRC/TPRM).
The specialized vendors within the cybersecurity market are mapped directly across the CISA Zero Trust pillars and Northrop Grumman's FAN architecture layers:
For Identity (IAM/PAM/IGA), the core focus areas center on access controls and human or agent authentication. Representative vendors leading this space include Okta, Microsoft Entra ID, CyberArk, SailPoint, Ping Identity, and Saviynt.
In the Devices / Endpoints category, solutions focus heavily on endpoint detection and mobile device management. The market landscape for this pillar features prominent vendors such as CrowdStrike, SentinelOne, Microsoft Defender, Tanium, Ivanti, and Jamf.
When it comes to Networks / Perimeter security, the core focus areas include Next-Generation Firewalls (NGFW), Security Service Edge (SSE), Zero Trust Network Access (ZTNA), and web filtering. The primary market vendors serving this layer are Palo Alto Networks, Zscaler, Cisco, Fortinet, Netskope, Cloudflare, and Proofpoint.
For Apps & Workloads, the technology addresses cloud security, application security (AppSec), and both static and dynamic testing. Key vendors in this sector include Wiz, Prisma Cloud, Snyk, Veracode, Checkmarx, Aqua, and Akamai.
The Data Protection & Security pillar zeroes in on encryption, Data Loss Prevention (DLP), data governance, and backup systems. Representative market leaders include Varonis, Microsoft Purview, BigID, Rubrik, Cohesity, Forcepoint, and Thales.
For Visibility & Analytics, the core operational focus is on SIEM, XDR, NDR, and continuous operations monitoring. The market landscape for these capabilities is represented by Splunk, Microsoft Sentinel, Google SecOps, Exabeam, Securonix, Darktrace, and Rapid7.
Finally, the Automation & Governance layer targets SOAR, GRC, and third-party risk management. The primary vendors offering solutions in this area are Cortex XSOAR, Tines, Torq, ServiceNow, Archer, OneTrust, Vanta, and Drata.
Security programs and the incidents they prevent represent massive global financial impacts:
The Cost of Breaches (2025): The global average cost of a data breach is $4.44 million, though it jumps drastically to $10.22 million in the United States.
Ransomware Target Shifts: Critical infrastructure (manufacturing, healthcare, energy) absorbed 50% of all 2025 ransomware attacks, with North America enduring roughly 62% of global incidents.
Program Budgeting: Organizations typically spend 4% to 20% of their total IT budget on security. Out of that security budget, approximately 40% is spent on tooling, 30% on people, 15% on hardware, and 15% on professional services.
Staffing Ratios: Security personnel generally make up 5% to 10% of total IT staff. A standard 24/7 in-house Security Operations Center (SOC) requires 8 to 12 dedicated analysts.
Because cyber threats are inherently borderless, international law continues to face a complex "cross-border catch-up":
State-Sponsored Warfare: State-backed hacking has become a 24/7 background feature of international relations, accounting for roughly 36% of tracked attacks in 2025. Geopolitical cyber operations are dominated by four primary powers: China, Russia, Iran, and North Korea.
The Jurisdiction Collision: Legal precedents like Schrems I & II struck down EU-US data-transfer agreements due to clashing surveillance laws, illustrating how data privacy regulations and national intelligence operations collide.
The Tallinn Manual: This independent expert framework restates how existing international humanitarian laws and use-of-force rules apply specifically to cyber warfare and state-on-state attacks.
Ultimately, creating a singular global rulebook remains incredibly difficult due to conflicting regional models: the EU’s rights-based approach (GDPR), the US’s market-led structure, and China’s state-control model.
Watch the MOOC Video