Cybersecurity guide for developing countries II.1.11 Preparing for the cybercrime threat: a responsibility to protect It is necessary to prepare oneself for the threat of cybercrime, which is bound to materialize sooner or later. The protection and defence of the organization’s assets needs to be organized, taking into account the risk of crime when defining the security strategy. Although it can be difficult to identify cybercriminals, and not enough is known of their methods of action and their motivation, it has been observed that criminal organizations generally behave in an opportunistic manner, and tend to be more inclined to attack the most vulnerable. Organizations can take steps to make sure they are not an attractive target for cybercrime, by ensuring that their computer infrastructure is better protected than those around it, rather than contenting themselves with remaining on the same level as their competitors, in terms of insecurity. Cybercrime risk thus becomes a lever for ensuring a high level of security. By contrast, an organization that is viewed by criminals as a lucrative potential victim or an important symbol to be destroyed will inevitably draw targeted attacks. In the second case, the threat of destruction by terrorist acts becomes a real possibility. In such cases it is necessary to put an appropriate protection and defence strategy into place. However, conventional insurance and risk management tools are of limited effectiveness in dealing with the criminal risk, as the only way of avoiding certain risks would be to avoid connecting to the internet. The criminal risk has a global dimension, and affects organizations at all levels (shareholders, executives, staff, production facilities, etc.). They must therefore learn to safeguard their integrity faced with the risk of crime, as they have learned to do with the risk of corruption, for example. They must remain profitable, and compensate for the opportunity cost caused by cybercrime risk and the cost of measures put in place to manage it. An economic model must be designed to find the best way of supporting the cost of protecting infrastructure and providing security for systems, networks, data and services, which is a burden on economic growth, with the help of those who have a share in the wealth created by the organization. The realization of the fragility of the digital world and the impossibility of perfect control, not only of IT and telecommunication technologies and the infrastructure, but also of commercial security solutions, must inevitably raise the fundamental question of dependence on technologies that are beyond our control. To what extent are we willing to be dependent on a provider, a country, or an administrator? The first step towards controlling the cybercrime risk has to be: – – – review the relationship with new technologies and providers; demand a security guarantee; institute responsibility of all participants. Before implementing conventional security measures based on a prevention-protection-defence approach, we must first seek to protect the organization’s sensitive and critical resources by reviewing their relationship to new technologies. We must demand: – – – – high-quality products providing a manageable and verifiable level of security; that security be transparent, rather than hidden, as in the past; that security be the responsibility not only of users but also technical stakeholders (legal responsibility of professionals: software designers, access providers, etc.); that a minimum level of security be built into technology solutions (safe products). Looking beyond the concerns of the organization, and faced with synergies and convergence in organized crime, economic crime and cybercrime, a comprehensive, multilateral and international response is needed to strengthen economic players’ confidence in information technology and reduce the opportunities for crime. Cybercrime 43

Select target paragraph3