This course is designed as an advanced, postgraduate-level curriculum (typically suitable for LL.M. students, advanced legal scholars, data privacy officers, and senior cybersecurity professionals).
The material transitions from foundational strategic architectures to highly specialized judicial analysis—specifically focusing on the nuances of civil liability, shifts in the burden of proof, and the evolution of non-material harm theories within European Union jurisprudence
This advanced online course explores the intersection of cybersecurity engineering, enterprise privacy frameworks, international law, and civil liability. Designed for legal scholars, privacy officers, and cybersecurity professionals, this curriculum moves from the historical foundations of digital threats to the cutting-edge mechanics of European data protection jurisprudence and corporate liability in the wake of malicious cyber operations.
This module charts the nearly two-century evolution of digital disruptions, tracking how isolated technical exploits transformed into industrialized criminal networks and state-backed geopolitical weapons.
The Pre-Internet and Early Foundations: Analysis of the earliest security incidents, beginning with the 1834 Blanc brothers telegraph fraud and Nevil Maskelyne’s 1903 wireless interception. Examination of the first modern computer hack at MIT (1962) and the emergence of the ARPANET "Creeper" virus (1971).
The Dawn of Statutory Frameworks: Evaluating the earliest privacy protections, including the Hessian Data Protection Act (1970) and Sweden's Data Act (1973), alongside the implementation of the US Computer Fraud and Abuse Act (1986) following the Morris Worm crisis.
Industrialization and State Warfare: Tracing the economic shift of cybercrime through the 2000 ILOVEYOU worm, the rise of state-backed destructive cyber operations via Stuxnet (2010), and the modern critical infrastructure ransomware epidemic.
The Global Regulatory Regime: Comparative analysis of global cyber treaties and privacy regimes, moving from the 2001 Budapest Convention to the 2018 EU GDPR and the landmark UN Convention against Cybercrime.
Students will evaluate technical architectures used to protect mission-critical enterprise environments and map structural controls across multi-cloud ecosystems.
The Defense-In-Depth Architecture: Deep-dive into the Northrop Grumman Five-Layer Architecture Network (FAN™).
Perimeter Security: Firewalls, IDS/IPS, DMZ architecture, and application gateways.
Network Security: Web proxies, Network Access Control (NAC), and wireless protections.
Endpoint Security: Host-based detection, EDR systems, and mobile configuration compliance.
Application Security: WAFs, database monitoring, and static/dynamic software testing.
Data Security: Encryption mechanisms, Data Loss Prevention (DLP), PKI, and data classification protocols.
Zero Trust Architecture: Implementation of the CISA Zero Trust Maturity Model, assessing its five core pillars (Identities, Devices, Networks, Apps/Workloads, Data) and its cross-cutting capabilities (Visibility/Analytics, Automation/Orchestration, Governance).
An analytical breakdown of the enterprise security marketplace, positioning dominant vendor platforms within technical architecture frameworks.
Identity & Endpoint Protection: Market analysis of human and agent authentication suites (Okta, Microsoft Entra ID, CyberArk, SailPoint) alongside advanced endpoint detection platforms (CrowdStrike, SentinelOne, Tanium).
Network, Perimeter, and Workload Security: Evaluating Next-Gen Firewalls, SSE, and ZTNA solutions (Palo Alto Networks, Zscaler, Cisco, Fortinet) alongside cloud workload protection platforms (Wiz, Prisma Cloud, Snyk).
Data Governance, Operations, and GRC: Examining data protection systems (Varonis, Purview, Rubrik) alongside Security Operations orchestration (Splunk, Sentinel, Google SecOps, Cortex XSOAR) and automated governance platforms (OneTrust, ServiceNow, Vanta, Drata).
This module covers the financial metrics governing cyber incidents and the economic models behind institutional security program budgeting.
The Financial Realities of Data Breaches: Analyzing the direct and indirect liabilities of data exposure, contrasting the global average breach cost ($4.44 million) against the stark operational costs seen in the United States ($10.22 million).
Ransomware Macroeconomics: Structural analysis of extortion campaigns targeting critical infrastructure, examining sector-specific impacts across healthcare, energy, and manufacturing.
Security Program Resource Allocation: Financial modeling of corporate IT budgets, exploring standard cybersecurity spending allocations (40% tooling, 30% personnel, 15% hardware, 15% services) and baseline staffing requirements for 24/7 Security Operations Centers (SOC).
Specialized Symposium Module based on the doctrinal frameworks of Dr. Bence Kis Kelemen (University of Pécs)
This module examines the legal mechanics of civil liability under Article 82 of the GDPR, analyzing how courts resolve claims for non-material harm resulting from malicious cyber operations and data privacy incidents.
The Doctrinal Basis of GDPR Article 82: Analyzing the joint and several liability of controllers and processors for material and non-material damages stemming from regulatory infringements. Evaluation of the strict exemption standard under Article 82(3), where an entity must prove it is not in any way responsible for the damage-inducing event.
The Interaction Between EU and National Legislations: Examining procedural and substantive friction points when EU models encounter national laws, using Hungarian Civil Code restitution models (fault-based exemptions and independent sanctions) as a comparative case study against the compensatory, no-severity-threshold EU framework.
Burden of Proof & The Accountability Principle: Applying C-340/21 (Natsionalna agentsia za prihodite) to evaluate how the burden of proof shifts to the controller to demonstrate the appropriateness of technical security measures under Article 32. Discussion on the role of forensic experts versus objective judicial assessments in data breaches.
Exemptions in Malicious Cyber Operations: Assessing liability when third-party cybercriminals execute an attack. Analyzing the causal link requirement: external criminal action does not exempt a controller if their own breach of security obligations made the malicious operation possible.
The Evolving Theory of Harm and Non-Material Damages: Judicial analysis of what constitutes compensable non-material harm based on recent Court of Justice of the European Union (CJEU) landmark rulings:
The Threshold of Seriousness: Affirming that an infringement alone does not automatically constitute damage, but there is explicitly no minimum severity threshold required once harm is established (C-340/21, C-590/22).
Fear as Damage: Evaluating how a well-founded fear of future data misuse by unknown third parties constitutes actionable non-material damage (C-340/21, C-590/22).
Loss of Control: Analyzing the legal reality that a temporary loss of control over personal data—even without proven subsequent misuse—suffices to establish non-material damage (C-340/21, C-200/23).
The Scope of Redress and Remediation: Analyzing the mitigation and assessment of remedies under C-507/23, establishing that a formal apology may serve as full compensation for non-material harm under specific conditions, and verifying why the controller's underlying motivation cannot be used to reduce awards below actual damages suffered.
Watch the MOOC Video