Cybersecurity as a National Infrastructure Problem, Not Just an IT One When a bank, a power utility, and a hospital network all stumble in the same week from the same class of attack, the postmortem can't stop at “patch the servers.” It has to ask why cybersecurity was ever treated as somebody else's department.
Main Article Content
Abstract
In the space of a single year, Pakistani banks have paused card transactions after a suspected breach, a major telecom operator has confirmed a data leak, and provincial hospitals have reported ransomware locking up patient records. Each incident was handled the same way: quietly, defensively, and by the technology department. None of them should have been treated as an IT problem alone.
That instinct — route the crisis to IT, patch what broke, issue a brief statement, move on — made sense when computers were back-office tools that processed payroll and stored files. It makes far less sense today, when software runs the electricity grid, the payments system, the water utilities, the ports, and the hospitals that keep a country functioning. A ransomware operator does not need to blow up a substation to cause a blackout; disabling the software that manages load balancing will do.
Downloads
Article Details

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.