
Raman Muhammed Shukri
Student – 3rd Grade
Cybersecurity Department
TIU – Erbil
The thin line between Cybersecurity and Cybercrime
The thin line between Cybersecurity and Cybercrime
A hypothetical scenario: A university student discovers a vulnerability in the university’s system. Without permission, they investigate further and discover they could access thousands of student records. They do not steal, modify, or publish any information. Instead, they immediately report the vulnerability to the university.
Now here comes the big question: should this student be rewarded for protecting others, punished for breaking the rules, or prosecuted for unauthorized access ?
This article examines where the boundary between ethical hacking and cybercrime should be drawn by analyzing the issue from ethical and legal perspectives and considering the opinions of university students.
What is ethical hacking? Ethical hacking is the authorized use of hacking techniques by friendly parties to uncover, understand, and fix security vulnerabilities in a network or system. Ethical hackers use the same tools and methods as a malicious hacker but with a positive intent, without harming any users. One of the many strict codes of ethics when it comes to ethical hacking is to get permission from the user or company they hack. Not having permission will lead to unauthorized access to a system, which goes against every rule of ethical hacking.
Modern society relies heavily on digital systems to manage sensitive information, from university records and banking services to healthcare and government databases. As cyberattacks continue to increase in frequency, organizations depend on cybersecurity professionals and independent researchers to identify vulnerabilities before the wrong people get their hands on them. However, discovering these vulnerabilities may involve interacting with computer systems without explicit authorization, creating uncertainty about whether these actions are to be viewed as responsible security research or illegal access. This is where the ethical and legal questions arise, making it increasingly relevant in today’s digital world.

Ethical Analysis
When we think of ethics in cybersecurity, we usually think of the three primary ethical frameworks, which are Utilitarianism, Deontology, and Virtue ethics.
Utilitarianism
Utilitarianism is one of the most powerful and persuasive approaches to normative ethics in the history of philosophy. The approach is a species of consequentialism, which holds that the moral quality of an action or policy is entirely a function of its consequences, or the value produced by the action or policy.
From a utilitarian perspective, the student’s actions resulted in a significant positive outcome. By discovering and reporting vulnerability, they prevented a potential data breach in the future, which could have affected thousands of students. Since no information was stolen, altered, or shared, the consequences had a more positive impact rather than a negative one.
However, utilitarianism also requires us to consider a broader range of consequences. If individuals were to access a computer system regularly without permission and with the belief and/or intentions of acting for the public good, then organizations could experience an increase in security risks and uncertainty. Therefore, a utilitarian must weigh both the immediate benefits of the student’s actions and the long-term consequences of encouraging unauthorized access.
Overall, utilitarianism would likely view the student’s actions as ethically and morally justifiable since the pros outweigh the cons. This theory also recognizes the potential risks of creating a justifiable route for ethical hackers to access systems without permission.
Deontology
Deontology is an ethical theory that evaluates actions according to whether they follow moral duties, principles, and rules rather than by their consequences, unlike Utilitarianism. According to this perspective, some actions are inherently right or wrong regardless of the outcomes they produce.
If we apply deontology to this scenario, we will find ourselves at a different conclusion. The students accessed the university’s system knowing they didn’t have authorization, which, as we mentioned earlier, violates one of the many strict codes of ethical hacking. Even if the student’s intentions were pure and not to harm the system in any way, a deontologist would argue that good intention does not justify breaking a moral and/or legal duty.
This also raises another important aspect of deontology; some deontologists might also argue that it’s the university’s duty to protect the personal information entrusted to them. If they fail to maintain confidentiality, it could be seen as negligence of a legal responsibility. Even so, this does not necessarily make it the student’s obligation to intrude in the system without permission.
Overall, deontology would likely conclude that the student’s actions were ethically wrong because they violated a moral duty to respect authorization and established rules, regardless of outcome.
Virtue Ethics
Virtue ethics differs from both utilitarianism and deontology by focusing on the moral character of the subject at hand rather than solely looking at consequences and rules. This framework asks whether the action reflects the qualities of a virtuous person, such as honesty, integrity, courage, and responsibility.
From this perspective, the student’s behavior becomes the central ruling in this ethical evaluation. The student did not use the vulnerability for personal gain or disclose any sensitive information; they immediately reported the flaw to the university. These actions show the qualities mentioned earlier. Such characteristics are generally regarded as virtues within both society and the cybersecurity profession.
However, virtue ethics also relies heavily on practical wisdom. The ability to make a professional judgement in complex situations. Virtue ethics recognizes that acting with wisdom includes respecting professional standards and the importance of asking for authorization before proceeding. Choosing to access a system without permission shows a crack in the student’s character, even if the intentions were simply pure.
Overall, virtue ethics would likely provide the most balanced assessment in this situation. It would acknowledge the student’s good character and positive intentions while also questioning whether a truly virtuous person would have more professional responsibility before accessing a system.
After looking through the three ethical frameworks, one common theme emerges. Intention plays a significant role in moral evaluation. This idea is shown in Ayn Rand’s observation that, “The cause of evil is stupidity, not malice” (1945). However, while ethical theories often consider the subject’s motives, the legal system generally evaluates according to rules and facts such as authorization and compliance with the law. Good intentions alone may not be enough to consider an act “unlawful”.

Legal Analysis
Unlike ethical theories, which evaluate whether an action is morally right or wrong, the law determines whether an action violates legal rules established to protect society and its people. In cases involving cybersecurity, legal systems generally focus on the facts of the situation and not on good or harmful intentions.
Computer crime laws around the world generally prohibit unauthorized access to computer systems. These laws are designed to protect confidential information of the public, maintain trust in the digital infrastructure, and discourage individuals from accessing systems without permission, regardless of intentions. While intent may be considered during sentencing, they do not always determine whether a crime has been committed.
Applying what we mentioned earlier to our hypothetical scenario, the student intentionally accessed a university system without permission or authorization. One could argue that no information has been stolen, altered, or disturbed, but that’s not enough to disregard the facts. From a legal perspective, the absence of malicious intent does not mean that no offense has been committed.
There has been a rapid increase in the number of crimes committed on the internet using various platforms. In the Kurdistan region, including Iraq, the rate of cybercrime has increased significantly after 2003. Although the Kurdistan region and Iraq have considered specialized cybercrime legislation for several years, the legal framework continues to develop in cybersecurity. The current existing legislation focuses on combating cybercrime, protecting digital infrastructure, and preventing misuse of information technology rather than addressing ethical hacking or responsible vulnerability disclosure.
The absence of clear legal recognition highlights a broader policy question. If society benefits from ethical hackers identifying security flaws before malicious actors do, should the law provide a safe and well-defined process for reporting vulnerabilities without exposing researchers to any criminal liability? Until the frameworks for this legal matter become more clearly established, the distinction between cybersecurity research and cybercrime may remain as legal uncertainty.
Discussion
This analysis shows that determining whether the student’s actions were ethical or criminal depends largely on the perspective through which it is examined. Each ethical theory reaches a different conclusion, while the legal side emphasizes a different consideration altogether.
If we compare the three ethical frameworks, we can see that utilitarianism generally supports the student’s actions because they prevented potential harm to thousands of students. Deontology, however, argues that accessing the system without authorization violates an important moral duty regardless of outcome. Virtue ethics, on the other hand, offers a more balanced interpretation by considering both the student’s good intentions and the importance of responsible judgement.
The legal perspective differs significantly from the ethical theories. The law primarily focuses on objective standards such as authorization. An individual may act with good intentions and still face legal consequences for unauthorized access.
I conducted a survey among the Tishk International University students that shows that around 65% of students agreed on rewarding the student for his actions rather than having them be punished for it; this suggests that many participants believe in the greater importance of the student’s intentions and the positive outcome than on the fact that authorization was not permitted. The other 35% of students agreed on warning or punishing the student rather than rewarding them; this aligns more with the deontological or legal perspective where they believe in a greater importance in abiding by their duties and the legislation upon them.
The modern digital world is evolving ever so rapidly, with new technology coming out every day; organizations are relying on ethical hackers more and more to identify vulnerabilities before malicious actors exploit them. However, if the legal systems fail to distinguish between responsible security research and malicious cybercrime, researchers might hesitate to report vulnerabilities. This is why a stable legal framework in this matter is so crucial.
This article sets out to examine when a hacker becomes a criminal by analyzing a hypothetical case through ethical theories, legal principles, and public opinions. The analysis shows that there is no single answer.
From my own point of view, individuals who act in good faith to improve cybersecurity should not be treated as malicious attackers. However, good intentions alone are not enough to justify unauthorized access to a system. Instead, Organizations and lawmakers should establish clear vulnerability disclosure policies and legal frameworks that encourage responsible security research while protecting digital infrastructures from abuse. An approach like this one would recognize the value of ethical hackers without weakening the legal policies necessary to combat cybercrime.

Sources:
- https://www.ibm.com/think/topics/ethical-hacking
- https://plato.stanford.edu/entries/utilitarianism-history/?ref=sagacitymagazine.com.au
- https://plato.sydney.edu.au/entries/ethics-deontological/
- https://plato.stanford.edu/entries/ethics-virtue/?ref=restoremag.com
- Sattar J. Aboud (2011). An Overview of Cybercrime in Iraq
- Suad Shakir Baeewe (2021). Cybercrime under the New Iraqi Draft Cybercrime Law

