sent at once to millions of recipients, and a “botnet”, a network of machines that have been
infected with malware, may have thousands, even millions, of machines within its scope.
1.14 A report commissioned by the UK Cabinet Office and published in 2011 11 estimated
cybercrime's annual cost to the UK to be £27 billion. That report was greeted with
widespread scepticism and seen as an attempt to talk up the threat. It led the UK Ministry of
Defence to commission a further study from a group of academics. Their report12 noted:
There are over 100 different sources of data on cybercrime, yet the available
statistics are still insufficient and fragmented; they suffer from under- and overreporting, depending on who collected them, and the errors may be both intentional
(e.g., vendors and security agencies playing up threats) and unintentional (e.g.,
response effects or sampling bias).
1.15 The report for the UK Ministry of Defence contains a sophisticated analysis of both
direct and indirect costs (including such things as the effect of loss of confidence in systems)
and covers many different types of cybercrime. Although the authors warn against any
simple totalling of their estimates, the figures in the report suggest an annual cost for the UK
which approaches US$20 billion. Global estimates are much harder to make with any degree
of accuracy; the authors estimate a global figure in excess of US$200 billion a year.
Cybercrime has no National Borders
1.16 Cybercrime does not respect national boundaries. That creates challenges for the
public sector, in terms of legislation and investigative and prosecutorial capacity, and for the
private sector, which must address technical vulnerabilities in the systems it designs and
operates.
1.17 Cybercrime prosecutions may involve multiple offenders, victims and evidence from
many different countries, a fact which can create significant resource and logistical
challenges for the law enforcement and prosecutorial agencies presenting cases and for the
courts which hear them. Further the offences may be triable in more than one jurisdiction
and there may be an issue as to the appropriate venue for the case or cases to be heard.
1.18 The nature of modern technology means that it is not always possible even to say
where a cybercrime is committed, in either legal or factual terms. Networks are increasingly
being designed to store information in remote or diffuse physical locations and move it
around automatically (‘cloud computing’), in order to optimise the use of storage and
transmission capacity. This confounds conventional approaches to jurisdiction, because in
some scenarios it can be difficult to ascertain where information or system users are located.
Similarly, the law that applies to evidence before or after it is obtained will sometimes
depend on the physical location at which it was obtained or intercepted, and the design of
modern networks can make this difficult to ascertain.
Implications
1.19 The transnational aspects of cybercrime also have significant implications for
investigation and prosecution. Effective measures to investigate cybercrime and to collect
and preserve digital evidence need to be speedy, but criminal justice systems and
procedural safeguards are rooted in domestic law and are based on jurisdictional territoriality
and national sovereignty. Requests for mutual legal assistance can be notoriously slow and
11
Detica and Office of Cyber Security and Information Assurance, The cost of cyber crime, February 2011.
R Anderson and others, Measuring the cost of cybercrime (2012), available at
http://weis2012.econinfosec.org/papers/Anderson_WEIS2012.pdf
12
14