Skip to main content
Research Paper Undergraduate 3,350 words

Cybercrime and Corporate Security: Threats and Policy

~17 min read 9 sections Crimes · Cyber Crime
Abstract

This paper examines the growing challenge of cybercrime for business enterprises and government agencies, focusing on four key threat categories: ransomware, denial of service (DoS) attacks, data breaches and theft, and hacktivism. Drawing on social strain theory as a theoretical lens, the paper explains how societal pressures and shared hacker community values motivate cybercriminal behavior. Real-world case studies — including attacks on the University of California, Maersk, LinkedIn, and Yahoo — illustrate the financial, reputational, and operational damage organizations sustain. The paper concludes by evaluating existing policy interventions and advocating for a collaborative, multi-stakeholder cybersecurity policy framework that incorporates education, rehabilitation, and adaptive legal structures to address the transnational and evolving nature of cybercrime.

Key Takeaways
  • Introduction: Cybercrime as a growing organizational challenge
  • Theoretical Background: Social Strain Theory: Social strain theory explains cybercriminal motivation
  • Overview of Cybersecurity Threats: Four key cyber threats defined and introduced
  • Ransomware: Ransomware prevalence, mechanics, and business impact
  • Denial of Service Attacks: DoS attacks: methods, motives, and consequences
  • Data Breaches and Theft: Data theft trends and major corporate cases
  • Hacktivism: Politically motivated hacking and its organizational impact
  • Policy Implications: Government roles and collaborative policy recommendations
  • Conclusion: Summary of threats and call for robust policy
✍️ How to write this paper — guide, tools & examples

What makes this paper effective

  • Applies a named criminological framework — Robert K. Merton's social strain theory — consistently across all four threat categories, giving the analysis theoretical coherence rather than treating each threat in isolation.
  • Grounds abstract concepts in concrete, well-known case studies (Maersk's $300 million NotPetya loss, the University of California ransomware attack, LinkedIn's 700 million-record breach) that make the stakes vivid and credible.
  • Moves logically from theory to threat overview to literature synthesis to policy recommendations, demonstrating strong academic organizational discipline.

Key academic technique demonstrated

The paper exemplifies theory-driven literature synthesis: rather than simply cataloguing cyber threats, the author routes each threat type through the lens of social strain theory, explaining not just what cybercriminals do but why — peer pressure, glorification in popular culture, and shared community values. This technique strengthens policy recommendations because proposed interventions (sensitization, rehabilitation, collaborative frameworks) flow directly from the theoretical explanation of causation.

Structure breakdown

The paper opens with an abstract and introduction establishing scope, then devotes a section to the theoretical framework before presenting an overview of the four threat types. Each threat (ransomware, DoS attacks, data breaches, hacktivism) receives its own literature-review subsection with definitions, evidence, and real-world examples. A policy implications section synthesizes findings into actionable recommendations, and a conclusion restates the core argument. This funnel structure — theory → evidence → policy — is a reliable model for applied criminology and security studies papers.

Essay 3,350 words

Introduction

There are many challenges that organizations and agencies operating in today's world face, and one of the most pressing is cybercrime. Over the last few years, the number of organizations that have suffered at the hands of cybercriminals has increased drastically. This is particularly evident as businesses increase their reliance on computers and the World Wide Web to not only enhance efficiency and productivity, but also to pursue a competitive advantage. To a large extent, cybercrime can be conceptualized as the utilization of a computer system as the primary tool in the commission of an offense. In basic terms, such an offense could range from mere unauthorized access to data or information to the theft of hundreds of millions of dollars.

Multiple organizations have fallen victim to cybercrime over the last decade. While some experienced only minor disruptions, others lost huge sums of money at the hands of cybercriminals, and still others had their reputations irreparably tarnished as a consequence of data breaches. It is likely that going forward there will be a marked increase in cybercrime rates as technology advances and as more businesses scale down their brick-and-mortar locations and move their operations online. Criminals will likely continue to deploy ever more sophisticated approaches in an attempt to exploit vulnerabilities across various platforms.

It is worth noting that there are various kinds of cybersecurity threats and challenges that corporations and enterprises grapple with today. This paper focuses on four such challenges: ransomware, denial of service attacks (DoS attacks), data breaches and theft, and hacktivism. With cybercrime being a growing concern, the relevance of deploying effective interventions to address the problem cannot be overstated. Many interventions have been proposed by practitioners and commentators in the past, including the creation of robust IT security mechanisms. In this paper, prevention efforts are assessed from the perspective of policy interventions.

Theoretical Background: Social Strain Theory

In seeking to develop a better understanding of cybercrime — in relation to its nature and conduct — it is useful to apply one of the major crime and deviance theories. The theory deployed here is the social strain theory. It should be noted that there is no single standard definition for this theory, given that various formulations have been proposed over the years. According to Moon, Blurton, and McCluskey (2007), the theory observes that persons can be pressured to engage in criminal behavior by social structures. This means that an individual could be driven to commit crime — including computer hacking and system intrusion — by societal forces. As Moon, Blurton, and McCluskey (2007) further note, the theory was first proposed by Robert K. Merton in 1938.

This theory appears most applicable to the present discussion. It is plausible to speculate that those who engage in computer hacking, system intrusion, cyber terrorism, and other forms of cybercrime often yield to social pressures to deploy their skills to make money or pursue other agendas. To a large extent, many Hollywood films glorify such activities and routinely portray characters who "brilliantly" hack into systems as heroes. This same perspective has gained considerable acceptance in the public domain — especially when it comes to certain forms of cybercrime such as hacktivism (Alexopoulou and Pavli, 2021).

Continued engagement in cybercrime can, on the other hand, be explained in terms of the formation of communities with shared values. As Soderberg and Maxigas (2021) point out, there are three key pillars upon which hacker community autonomy is founded, one of which is shared values. The cultivation of shared values can occur in various ways, including regular online mass interactions in settings such as chat rooms and mailing lists, as well as through the embrace of symbolic signs and emblems. With this in mind, it can be argued that individuals who engage in cybercrime are motivated by society's embrace of such behavior as a mark of brilliance and by subscription to hacker culture. Familiarity with this theoretical perspective can prove valuable in efforts to deploy the most effective policy interventions to address the problem.

Overview of Cybersecurity Threats

Some of the key cybersecurity challenges that business enterprises grapple with today include ransomware, denial of service attacks, data breaches and theft, and hacktivism. Ransomware can be defined as a computer program designed to encrypt data — effectively making that data inaccessible to those who need it — with the sole intention of demanding payment in exchange for decryption. The term "ransom" is apt, as there is in essence a demand for payment for the "release" of data that is held captive.

Denial of service attacks (DoS attacks), by contrast, are malicious attacks on a network, service, or server with the intention of rendering it unavailable. The objective is to ensure that users are unable to access crucial data, information, or services, or to execute certain commands. Data breaches and theft involve the stealing of data — which may take the form of reports, statements, statistics, figures, or documents — through the utilization of computer systems, perpetrated with malicious intent. Such intent might include gaining access to confidential competitor information or using stolen data as a bargaining chip, threatening to release it publicly unless payment is made. Finally, hacktivism is a relatively newer phenomenon in cybersecurity. Unlike the other threats highlighted, hacktivism is not necessarily profit-oriented; rather, it is a form of cybercriminal activity aimed at advancing a political or social agenda.

Ransomware

Ransomware is one of the various kinds of malware, alongside others such as spyware and viruses (Faruki et al., 2014). It is one of the most frequent cybersecurity concerns affecting businesses (Reshmi, 2021). The deployment of ransomware is particularly lucrative: Reshmi (2021) indicates that among all malware attack types, most enterprises regard ransomware as the most financially damaging. Businesses on the receiving end of ransomware often find themselves between a rock and a hard place, facing either the loss of critical data or the payment of the demanded sum.

Cryptocurrencies have significantly enabled and facilitated ransomware attacks. Because cybercriminals can demand and receive ransom through cryptocurrencies, they leave no traceable record of their location or identity, making it difficult for law enforcement to track them (Reshmi, 2021). In addition to cryptocurrencies, offenders actively use anonymized platforms to cover their tracks (Connolly and Wall, 2019). As Connolly and Wall (2019) further observe, offenders have been remarkably innovative and adaptive over the years — noting that "year in and year out, the increasing adaptability of offenders has maintained ransomware's position as a major cybersecurity threat" (p. 113).

Ransomware is indiscriminate in its deployment: entities in both the public and private sectors can fall victim. As Reshmi (2021) observes, affected organizations operate across diverse industries, from health services and financial services to telecommunications and transport. Public law enforcement agencies have also been targeted. In recent times, notable victims have included Canon and the University of California. In the latter case, cybercriminals deployed ransomware that compromised the university's COVID-19 research data, then demanded a $1.14 million ransom to decrypt it. This figure is modest compared to the losses sustained by Maersk, which — according to Mathews (as cited in Connolly and Wall, 2019) — suffered approximately $300 million in losses due to the NotPetya ransomware worm attack. In some instances the impact extends far beyond financial loss: Willing et al. (2021) report that a German hospital suffered a ransomware attack that crippled its operations, including its emergency care infrastructure, illustrating the potentially life-threatening consequences of such malware.

Ransomware attacks are also remarkably common. Connolly and Wall (2019) note that prior studies have identified ransomware as possibly the most prevalent malware attack type that business enterprises have faced in recent years. In one such study, more than 50% of all enterprises sampled had encountered a ransomware attack in the preceding twelve months, with the most affected sectors including retail, professional services, energy, and healthcare (Connolly and Wall, 2019). Going forward, strategies to counter ransomware must account for the changing landscape — including the increasing sophistication of attacks and the difficulty of tracing perpetrators due to the widespread use of cryptocurrency.

4 Sections Hidden · 1,380 words
Denial of Service Attacks330 words
In some instances, cyber threat actors opt to lock out legitimate users from diverse network resources, devices, or information systems. The motivations for these courses of action could be diverse, as…
Data Breaches and Theft370 words
In some scenarios, the goal of a cybercriminal is the extraction of sensitive material or information for commercial or other purposes. When such extraction takes place remotely, over computer systems or networks,…
Hacktivism360 words
Hacktivism is a relatively new challenge in the cybercrime landscape. According to Sorell (2015), hacktivism can largely be conceptualized as a…
Policy Implications320 words
As the discussion above demonstrates, businesses continue to suffer immensely at the hands of cybercriminals. In addition to monetary losses, businesses have suffered damaged reputations and…

Conclusion

Cybercrime has been described in this paper as one of the key challenges that organizations face today. It is clear from the discussion above that organizations continue to suffer from the actions of cybercriminals who exploit various vulnerabilities to advance their agendas. Available evidence suggests that the situation may be worsening: cybercrime has been on an upward trend across all the threat categories examined in this paper — ransomware, denial of service attacks, data breaches and theft, and hacktivism. The need for robust strategies to address these threats cannot be overstated.

The need for coherent and substantive cybersecurity policy interventions has been restated throughout this paper. It is also clear that no policy intervention can succeed outside of a collaborative framework. All stakeholders — government agencies, private enterprises, cybersecurity experts, and international partners — should be engaged at both the design and implementation stages of any policy intervention. This is especially important given that cyberattacks are not only indiscriminate in their targeting but are also transnational in nature, making cross-border cooperation essential to any effective response.

References

Alexopoulou, S. & Pavli, A. (2021). 'Beneath This Mask There is More Than Flesh, Beneath This Mask There is an Idea': Anonymous as the (Super)heroes of the Internet? International Journal for the Semiotics of Law, 34, 237–264.

Connolly, L. Y. & Wall, D. S. (2019). The rise of crypto-ransomware in a changing cybercrime landscape: Taxonomising countermeasures. Computers & Security, 87, 14–16.

Dolezel, D. & McLeod, A. (2019). Cyber-analytics: Identifying discriminants of data breaches. Perspectives in Health Information Management, 16(1a), 55–59.

Faruki, P., Bharmal, A., Laxmi, V., Ganmoor, V., Gaur, M. S., Conti, M. & Rajarajan, M. (2014). Android security: A survey of issues, malware penetration, and defenses. IEEE Communications Surveys & Tutorials, 17(2), 998–1022.

Galeano-Brajones, J., Carmona-Murillo, J., Valenzuela-Valdes, J. F. & Luna-Valero, F. (2020). Detection and mitigation of DoS and DDoS attacks in IoT-based stateful SDN: An experimental approach. Sensors, 20(3), 8–16.

Khan, N., Yaqoob, I., Hashem, I. A., Inayat, Z., Ali, W. K., Alam, M., Shiraz, M. & Gani, A. (2014). Big data: Survey, technologies, opportunities, and challenges. Scientific World Journal, 24(6), 66–71.

Kumar, G. (2016). Denial of service attacks — an updated perspective. Systems Science & Control Engineering, 4(1), 285–294.

Monteith, S., Bauer, M., Alda, M., Geddes, J., Whybrow, P. C. & Glenn, T. (2021). Increasing cybercrime since the pandemic: Concerns for psychiatry. Current Psychiatry Reports, 23(4), 18.

Moon, B., Blurton, D. & McCluskey, J. D. (2007). General strain theory and delinquency: Focusing on the influences of key strain characteristics on delinquency. Crime and Delinquency, 54(4), 582–613.

Reshmi, T. R. (2021). Information security breaches due to ransomware attacks — a systematic literature review. International Journal of Information Management Data Insights, 1(2), 211–218.

Romanosky, S. (2016). Examining the costs and causes of cyber incidents. Journal of Cybersecurity, 2(2), 121–135.

Soderberg, J. & Maxigas (2021). The three pillars of functional autonomy of hackers. NanoEthics, 15, 43–56.

Sorell, T. (2015). Human rights and hacktivism: The cases of Wikileaks and Anonymous. Journal of Human Rights Practice, 7(3), 391–410.

Willing, M., Dresen, C., Gerlitz, E., Haering, M., Smith, M., Binnewies, C., Guess, T., Heverkamp, U. & Schinzel, S. (2021). Behavioral responses to a cyber-attack in a hospital environment. Scientific Reports, 11(9), 78–83.

Key Concepts in This Paper
Ransomware DoS Attacks Data Breach Hacktivism Social Strain Theory Cybersecurity Policy Cryptocurrency Hacker Community Corporate Security Malware
Cite This Paper
PaperDue. (2026). Cybercrime and Corporate Security: Threats and Policy. PaperDue. https://www.paperdue.com/study-guide/cybercrime-corporate-security-threats-policy-2176857

Always verify citation format against your institution’s current style guide requirements.