Cybersecurity guide for developing countries Notable events that contributed to the growing awareness of the threat of cybercrime – in addition to the Y2K bug, which drew attention to the vulnerability of software and society’s dependence on computers – include denial-of-service attacks such as those launched against Yahoo (on 10 February 2000) and the attack by the notorious “I love you” virus (4 May 2000). Since then, media coverage of the virus attacks (such as the “Code red” virus in July 2001 or “Nimda” in September 2001) and denial-of-service attacks (such as that launched against the DNS network on 21 October 2002), among many other examples, has increased the general public’s awareness of the reality of threats that operate through the internet. The news media continue to devote considerable space to covering problems related to computers. II.1.2 Factors that make the internet attractive for criminal elements II.1.2.1 Virtualization and the virtual world The uncoupling of transactions from physical media (virtualization), communication tools involving encryption, steganography and anonymity: these are factors which criminals in different countries exploit in order to collaborate while dispensing with physical meetings, operating in a flexible, secure manner and with complete impunity. They can form teams, plan crimes and carry them out, whether in the traditional manner or using new technologies. The global reach of the internet allows criminals to act globally, on a large scale and very rapidly. These powerful possibilities created by the digital world and telecommunication come on top of the inherent problems associated with the design, implementation, management and control of information technology, with its crashes, malfunctions, errors and human mistakes, and even natural disasters, as well as the interdependence of infrastructures, all of which imply by definition a certain level of insecurity in digital infrastructures. The potential for malicious exploitation of vulnerabilities is thus very broad, translating in practice into: identity theft, spoofs, unauthorized access, fraudulent use of resources, infection, sabotage, destruction, tampering, breach of confidentiality, data theft, blackmail, extortion, protection rackets, denial of service, etc. This clearly shows the inadequate control of computer-related risks of criminal origin to which organizations are exposed, and the limits of current security strategies. Cyberspace, which allows users to operate remotely via a network, hidden behind a screen, creates ideal conditions for criminal activity. Indeed, some individuals may in fact stray across the boundary into criminal activity without ever being fully conscious of the criminal nature of their acts. II.1.2.2 Networking of resources The wide-scale networking of computer and information resources makes them attractive targets for economic crime using new technologies. The various forms of computer attack that exist have in common the relatively low level of risk for the criminal, set against a potential for harm and damage that greatly exceeds the resources necessary to launch an attack. Electronic identity theft, easy anonymity and the possibilities for taking control of computers make it easy to carry out illegal acts without exposing oneself to any great risk. 28 Cybercrime

Select target paragraph3