top of page

The rise of cybercrime and its impact on businesses

  • Mar 9, 2022
  • 3 min read

Updated: Mar 23, 2022

Organisations must take appropriate steps to protect themselves against criminal activity - both internal and external - in just the same way as they take steps to protect themselves in the physical world.


The 2014 US State of Cybercrime Survey (conducted by CSO Magazine, the US Secret Service, the CERT Division of the Software Engineering Institute, and Price Waterhouse Cooper) spoke to 557 organisations about their experience in the previous 12 months. Thirty-two per cent of respondents said that damage from insider attacks was more severe than that from outsiders; 76 per cent of incidents involved theft or compromise of confidential records. Thirty-seven per cent of cybercrimes were not prosecuted because the culprits could not be identified and, for 36 per cent, the evidence was inadequate to support a prosecution.


The UK Home Office's 2013 research report into cybercrime drew similar conclusions, although it did make the point that statistics are still uncertain, and inadequate to form a robust picture:


  • Under-reporting of both cyber-dependent and cyber-enabled crimes is an issue amongst the general public and businesses.

  • The most common reported incident was the illicit distribution of malware.

  • The second most common incident was hacking attacks on social media and email.

  • The British Retail Consortium in 2013 reported overall losses to the UK retail sector of £205.4 million, made up of direct losses (eg cardholder not present fraud), remediation losses and, ironically, revenues lost through fraud prevention activity.


In reality, many information security incidents are actually crimes. The UK Computer Misuse Act, for instance, makes it an offence for anyone to access a computer without authorisation, to modify the contents of a computer without authorisation or to facilitate (allow) such activity to take place. It identified sanctions for such activity, including fines and imprisonment. Other countries have taken similar action to identify and create offences that should enable law enforcement bodies to act to deal with computer misuse. Increasingly, this type of illegal activity is known as 'cybercrime'.


The Council of Europe Cybercrime Convention, the first multilateral instrument drafted to address the problems posed by the spread of criminal activity on computer networks, was signed in November 2001. The United States finally ratified the Cybercrime Convention in 2006 and joined with effect from 1 January 2007. The Cybercrime Convention was designed to protect citizens against computer hacking and internet fraud, and to deal with crimes involving electronic evidence, including child sexual exploitation, organised crime and terrorism. Parties to the convention commit to effective and compatible laws and tools to fight cybercrime, and to cooperating to investigate and prosecute these crimes. They are not succeeding in this aim.


Europol, the European police agency, publishes the Internet Organised Crime Threat Assessment (i0CTA). IOCTA 2014 says that current trends suggest considerable increases in the scope, sophistication, number and types of attacks, number of victims and economic damage from organised crime on the Internet.


The Crime-as-a-Service (CaaS) business model drives the digital underground economy by providing a wide range of commercial services that facilitate almost any type of cybercrime. Criminals are freely able to procure such services, such as the rental of botnets, denial-of-service attacks, malware development, data theft and password cracking, to commit crimes themselves.


This has facilitated a move by traditional organised crime groups (OCGS) into cybercrime areas. The financial gain that cybercrime experts have from offering these services stimulates the commercialisation of cybercrime as well as its innovation and further sophistication. Legitimate privacy networks are also of primary interest to criminals that abuse such anonymity on a massive scale for illicit online trade in drugs, weapons, stolen goods, forged IDs and child sexual exploitation.


The internet is, in other words, digitally dangerous. Organisations must take appropriate steps to protect themselves against criminal activity - both internal and external - in just the same way as they take steps to protect themselves in the physical world.

 
 
 

Recent Posts

See All

Comments


bottom of page