Writing index
ESSAY — 14 Apr 2026

Digital ethics is the last line of defence

In information security, the tools are identical on both sides. Ethics is the only line separating a professional from a criminal.

Digitalna etika
Published in
Digitalna etika
Role
Author

The argument of this essay is simple and uncomfortable: a security professional and a cybercriminal share the same knowledge and the same tools. What separates them is not technique but ethics — which makes ethics, not technology, the last line of defence.

Three regional cases carry the argument. Montenegro’s August 2022 state cyberattack, where citizens still have no clear answer about what data actually leaked years later; the 2026 m:SAT / Telekom Srbija leak of more than 160,000 records including national ID numbers, met with language designed to minimise the harm; and the ordinary business model of trading user trust for data, illustrated by the Quittr app exposure affecting over 600,000 users, roughly 100,000 of them minors, and Amazon’s 2025 decision to route Echo voice data to the cloud without a meaningful opt-out.

The sharpest section concerns state surveillance infrastructure, in particular Belgrade’s Huawei-built facial-recognition camera network, deployed without an adequate legal basis for processing biometric data, as warned by the data protection commissioner, SHARE Foundation and the European Parliament. The essay ends where it should — with what an ordinary person can actually do: check permissions before installing, use a password manager and two-factor authentication, audit account access periodically, demand transparency from institutions after a breach, and never pay a ransom.

Key findings

  • 01Central thesis: ethics, not technical skill, is what separates a security professional from a cybercriminal.
  • 02Montenegro 2022: years after the state cyberattack, citizens still lack a clear account of what data leaked — the silence is itself an ethical failure.
  • 03The m:SAT leak (160,000+ records including national ID numbers) is a case study in corporate minimisation of harm.
  • 04Belgrade’s facial-recognition camera network operates without an adequate legal basis for biometric data processing.
  • 05Corporate examples: the Quittr breach (600,000+ users, ~100,000 minors) and Amazon’s 2025 forced cloud processing of Echo voice data.
  • 06Practical defence: permission hygiene, password manager and 2FA, periodic account audits, and refusing ransom payments — around 78% of organisations that pay are attacked again.
More essays & guides