SESSION 2: FIGHTING
CYBERCRIME IN THE
ASIA–PACIFIC
Across the globe, financial losses due to cybercrime continue to mount. Estimates of the cost of cybercrime to the
Asia–Pacific vary, but a suggested cost to Asian business of about US$81 billion in 2015 implies that it’s a bigger
problem than any one country can address on its own.6 For the participants at the Australia–US Cyber Security
Dialogue, discussing growing cybercrime threats and current cooperation between governments, law enforcers and
the private sector highlighted some of the hurdles that must be overcome to elevate the fight against cybercrime.
The cross-jurisdictional nature of cyberspace means that multi-layered cooperation between both countries’
government and law-enforcement agencies is required for cybercrime prevention and prosecution. At the
government-to-government level, information sharing between the US and Australia is growing. In fact, Australia
was the first country to enter into a sharing framework with the US Department of Homeland Security.7 That’s a
promising step for bilateral cooperation on cybercrime and should encourage other countries to contribute as well.
However, the quality of the public–private partnership to fight cybercrime is not as high as it needs to be in either
Australia or the US. In both countries, the government approach to the private sector is seen as paternalistic and,
as a result, has both offended industry and disincentivised its full participation. Improving this perception through
a more respectful government approach in pursuit of sincere, productive partnership will be a key requirement for
improving cooperation on cybercrime.
Doing so is important, as the private sector has a crucial role to play in cybercrime information sharing. There’s
far more intelligence about the cybersecurity threat landscape available than is currently being shared between
the private and public sectors in both countries. Issues of classification can stifle governments’ ability to divulge
data, while private-sector entities may withhold information from the government and other companies because
they are worried about losing industry advantage, suffering damage to their reputation or facing legal issues. As
a result, some companies prefer to passively benefit from others’ information sharing before showing their own
hand. Information sharing is only of value when the right information is exchanged consistently, building both
goodwill and trust between parties and reinforcing the value of the agreement. More forthcoming attitudes from all
stakeholders will be necessary to address the growing cybercrime challenge.
To that end, governments in Australia and the US must take seriously the task of communicating to the private
sector the business case for information sharing. Sharing relevant intelligence with trusted partners can make
cybercriminals’ operations more difficult and improve the rate at which they are apprehended across the board,
probably lowering the net cost to the average company. Sectoral information sharing and analysis centres and
programs in which members must submit a minimum number of malware samples every day to retain their
membership have been suggested as mechanisms by which to halt this race to the bottom.8 Likewise, governments
in Australia and the US must work to overcome unnecessary bureaucratic red tape and make useful threat trend
information available to the private sector, where appropriate.
Ultimately, this problem can’t be viewed in simplistic bilateral terms. Cyberspace is a dynamic and complex
ecosystem of connections, and our response must reflect that. Effectively addressing cybercrime requires trusting
relationships between both countries’ governments and private sectors in order to create a multipolar collaborative