Cybersecurity guide for developing countries
II.1.11
Preparing for the cybercrime threat: a responsibility to protect
It is necessary to prepare oneself for the threat of cybercrime, which is bound to materialize sooner or
later.
The protection and defence of the organization’s assets needs to be organized, taking into account the
risk of crime when defining the security strategy. Although it can be difficult to identify
cybercriminals, and not enough is known of their methods of action and their motivation, it has been
observed that criminal organizations generally behave in an opportunistic manner, and tend to be more
inclined to attack the most vulnerable. Organizations can take steps to make sure they are not an
attractive target for cybercrime, by ensuring that their computer infrastructure is better protected than
those around it, rather than contenting themselves with remaining on the same level as their
competitors, in terms of insecurity. Cybercrime risk thus becomes a lever for ensuring a high level of
security.
By contrast, an organization that is viewed by criminals as a lucrative potential victim or an important
symbol to be destroyed will inevitably draw targeted attacks. In the second case, the threat of
destruction by terrorist acts becomes a real possibility. In such cases it is necessary to put an
appropriate protection and defence strategy into place. However, conventional insurance and risk
management tools are of limited effectiveness in dealing with the criminal risk, as the only way of
avoiding certain risks would be to avoid connecting to the internet.
The criminal risk has a global dimension, and affects organizations at all levels (shareholders,
executives, staff, production facilities, etc.). They must therefore learn to safeguard their integrity
faced with the risk of crime, as they have learned to do with the risk of corruption, for example. They
must remain profitable, and compensate for the opportunity cost caused by cybercrime risk and the
cost of measures put in place to manage it. An economic model must be designed to find the best way
of supporting the cost of protecting infrastructure and providing security for systems, networks, data
and services, which is a burden on economic growth, with the help of those who have a share in the
wealth created by the organization.
The realization of the fragility of the digital world and the impossibility of perfect control, not only of
IT and telecommunication technologies and the infrastructure, but also of commercial security
solutions, must inevitably raise the fundamental question of dependence on technologies that are
beyond our control.
To what extent are we willing to be dependent on a provider, a country, or an administrator?
The first step towards controlling the cybercrime risk has to be:
–
–
–
review the relationship with new technologies and providers;
demand a security guarantee;
institute responsibility of all participants.
Before implementing conventional security measures based on a prevention-protection-defence
approach, we must first seek to protect the organization’s sensitive and critical resources by reviewing
their relationship to new technologies.
We must demand:
–
–
–
–
high-quality products providing a manageable and verifiable level of security;
that security be transparent, rather than hidden, as in the past;
that security be the responsibility not only of users but also technical stakeholders (legal responsibility of professionals: software designers, access providers, etc.);
that a minimum level of security be built into technology solutions (safe products).
Looking beyond the concerns of the organization, and faced with synergies and convergence in
organized crime, economic crime and cybercrime, a comprehensive, multilateral and international
response is needed to strengthen economic players’ confidence in information technology and reduce
the opportunities for crime.
Cybercrime
43