Cybersecurity guide for developing countries Online investment, gambling and commerce, such as the sale of imaginary goods and services for real money, make it possible to generate seemingly legitimate revenues that are difficult to monitor and almost impossible to prosecute. E-banking, real-estate transactions via the net, the use of virtual front companies and electronic cash can all be used to launder the proceeds of crime. Ordinary users may unknowingly support money-laundering when they use certain virtual services. Commercial organizations may also unwittingly become involved, with all the – potentially disastrous– implications that entails, in legal and commercial terms. This is a major source of risk for companies. Currently there are few effective means of controlling the phenomenon of IT-enabled moneylaundering. II.1.5 Cybercrime – an extension of ordinary crime Cybercrime most commonly takes the form of ordinary crime, largely invisible, yet highly potent on account of the networking of resources and individuals. Not only companies, but also their IT and information assets, can become attractive targets for criminal organizations in search of profit. This is a strategic threat, as the money resides in information systems, in corporations, in pension funds etc., and not merely in banks. By opening the corporate gates to the internet, via web servers, portals and e-mail, companies expose themselves to the risk of criminal attention and give criminals a potential foothold. While the internet is a powerful communication tool, it is also a chaotic, complex, dynamic and hostile environment which can be used to undermine the organization and serve as a vehicle for crime. The internet should be treated with caution, as a high-crime zone. Given the importance that organizations attach to their internet presence, they are, in all likelihood, contributing to the expansion of criminality to the internet. Today, national security faces challenges in the form of IT-related criminal threats. Internet technologies are at the heart of the notion of infowar, whose objectives are primarily economic; it can have a huge impact on the conduct of business operations. The internet not only makes it possible to manipulate information; it is also an ideal rumour-mill that can fuel campaigns intended to spread disinformation or uncertainty. It also facilitates espionage and other intelligence-gathering activities, given the ease with which information travelling across the internet can be intercepted. II.1.6 Cybercrime and terrorism Cybercrime can take on a terrorist dimension when the systems targeted are part of a critical infrastructure. The vulnerability of the essential infrastructures of a country (energy, water, transportation, food logistics, telecommunication, banking and finance, medical services, government functions, etc.) is increased as the use of internet technologies takes root. Particular emphasis needs to be placed on the electrical power generation and distribution systems, which are essential to the operation of most infrastructures. One of the key objectives of cyberterrorists appears to be the control of critical infrastructure elements, as shown by the increase in the number of scans (probing for vulnerabilities that can be used to penetrate the system at a future date) targeting the computers of infrastructure operators. There is no agreed definition of what constitutes cyberterrorism at the present time. The simplest would no doubt be to consider it as terrorism applied to cyberspace. In its turn, terrorism is generally understood to mean the systematic use of violence to achieve political aims. Cybercrime 33

Select target paragraph3