SESSION 2: FIGHTING CYBERCRIME IN THE ASIA–PACIFIC Across the globe, financial losses due to cybercrime continue to mount. Estimates of the cost of cybercrime to the Asia–Pacific vary, but a suggested cost to Asian business of about US$81 billion in 2015 implies that it’s a bigger problem than any one country can address on its own.6 For the participants at the Australia–US Cyber Security Dialogue, discussing growing cybercrime threats and current cooperation between governments, law enforcers and the private sector highlighted some of the hurdles that must be overcome to elevate the fight against cybercrime. The cross-jurisdictional nature of cyberspace means that multi-layered cooperation between both countries’ government and law-enforcement agencies is required for cybercrime prevention and prosecution. At the government-to-government level, information sharing between the US and Australia is growing. In fact, Australia was the first country to enter into a sharing framework with the US Department of Homeland Security.7 That’s a promising step for bilateral cooperation on cybercrime and should encourage other countries to contribute as well. However, the quality of the public–private partnership to fight cybercrime is not as high as it needs to be in either Australia or the US. In both countries, the government approach to the private sector is seen as paternalistic and, as a result, has both offended industry and disincentivised its full participation. Improving this perception through a more respectful government approach in pursuit of sincere, productive partnership will be a key requirement for improving cooperation on cybercrime. Doing so is important, as the private sector has a crucial role to play in cybercrime information sharing. There’s far more intelligence about the cybersecurity threat landscape available than is currently being shared between the private and public sectors in both countries. Issues of classification can stifle governments’ ability to divulge data, while private-sector entities may withhold information from the government and other companies because they are worried about losing industry advantage, suffering damage to their reputation or facing legal issues. As a result, some companies prefer to passively benefit from others’ information sharing before showing their own hand. Information sharing is only of value when the right information is exchanged consistently, building both goodwill and trust between parties and reinforcing the value of the agreement. More forthcoming attitudes from all stakeholders will be necessary to address the growing cybercrime challenge. To that end, governments in Australia and the US must take seriously the task of communicating to the private sector the business case for information sharing. Sharing relevant intelligence with trusted partners can make cybercriminals’ operations more difficult and improve the rate at which they are apprehended across the board, probably lowering the net cost to the average company. Sectoral information sharing and analysis centres and programs in which members must submit a minimum number of malware samples every day to retain their membership have been suggested as mechanisms by which to halt this race to the bottom.8 Likewise, governments in Australia and the US must work to overcome unnecessary bureaucratic red tape and make useful threat trend information available to the private sector, where appropriate. Ultimately, this problem can’t be viewed in simplistic bilateral terms. Cyberspace is a dynamic and complex ecosystem of connections, and our response must reflect that. Effectively addressing cybercrime requires trusting relationships between both countries’ governments and private sectors in order to create a multipolar collaborative

Select target paragraph3