discovered a criminal selling a complete installation of Zeus for US$250. Illicit consulting services can also assist in setting up “botnets”, which infect computers and allow criminals to hijack and use them for other purposes, for charges that range from US$350-400. The truly idle offender can pay to have services distributed through an existing botnet at US$30 for 20,000 spam emails, or US$525 for 5 hours of DDoS attacks per day for a week13. 1.24 The transnational nature of the technologies, and of the crimes they facilitate, make it easy for offenders to seek out and exploit any weak links or vulnerable locations. This creates practical challenges in that legislation, law enforcement, prevention and security measures become interdependent, and also that seeking out and closing any vulnerabilities becomes a constant and ongoing task. Any location where law enforcement or security measures are relatively weak can be used by offenders as a base of operations from which to target other, better-protected locations, and this creates a powerful shared incentive for technical assistance and capacity building to eliminate weaknesses that render everyone vulnerable. 1.25 In this context, what matters is not necessarily the perspective of governments, but that of offenders. From their perspective a ‘relatively weak’ or vulnerable ‘location’ may range from a single address, file-server or local computer system to an entire country, and ‘weakness’ simply means choosing whatever digital location offers the easiest illicit access and/or the lowest risk of detection and prosecution. Weaknesses and vulnerabilities may be technological or jurisdictional, and they are ‘relative’ to one another in the sense that, as each specific vulnerability is addressed, another one becomes the ‘weakest link’ in the network and will become a new focus for offenders. No country, company, or individual can be complacent, because security depends on keeping one’s own security measures at the same level as others as well as one step ahead of offenders. 1.26 Technical vulnerabilities are mostly a concern for the private sector, which develops the technologies and operates the networks. For companies individually, the security of products and systems is a key element of competition and commercial success, and collectively there is a shared interest in making the Internet itself safer. In general the fear of crime is bad for business, and cybercrime is no exception. Cybercrime happens quickly 1.27 Fast communications mean that offences can be committed very quickly, and that digital evidence of them can be erased equally quickly. This presents serious challenges for conventional investigative techniques. In response, the laws of many countries and the Budapest Convention provide ‘fast freeze - slow thaw’ schemes in which investigators may seize, or order the preservation of, digital evidence quickly and then complete the necessary judicial proceedings before it may be accessed and actually examined and read. Even with the best possible legal measures, the speed of offending is still a major challenge for investigators, and the practical implications of this include the need for a high degree of skill and extensive training, and that investigators have equipment which is as fast and powerful as that used by the offenders. Technology evolves rapidly, and Cybercrime evolves with it 1.28 Information technology evolves very rapidly, and new ways to commit cybercrimes are constantly being developed. For example, as mobile phone usage increases and the technology becomes more sophisticated, criminals seek to target mobile operating systems. 13 Fortnet Security, Anatomy of a Botnet. 16

Select target paragraph3