1.32 In the past decade, information and communications technologies have grown in importance to the point where many states regard them as critical infrastructure and see the need to protect them as a security interest and not just a criminal justice matter. The policy focus moves beyond the protection of individual economic or social interests to the protection of infrastructure which is seen as critical to the functioning of the state itself. 1.33 As a subject, “cybersecurity” is broader than “cybercrime” and focuses more on preventive than on reactive policies. Cybersecurity includes the protection of networks and data from non-criminal threats such as natural disasters or system failures, for example. Cybercrime measures can also be seen as a means to the end of better cybersecurity, in the sense that criminal offences are defined, investigated and prosecuted, to a large degree, based on the need to identify and criminalise conduct which poses a threat to computer users or general populations, and to deter and incapacitate those who would or do engage in such conduct. 1.34 Classification of cybercrime and related activities as a security matter often reflects a combination of an assessment of the risk or probability that an attack will occur and the magnitude of the potential harm were an attack to succeed. Offences against state interests, such as espionage or terrorism offences, will always be regarded as cybersecurity matters, but economic forms of cybercrime will only be included if they either are linked to such offences (e.g. frauds that finance terrorist activities), or are of sufficient magnitude to damage the state’s overall economic stability. There may be special concern if a ‘cyberattack’ is thought to be launched from another state or if the motivation of the attackers is to gain policy influence or extort policy changes through the commission of crime or the threat of crime. When these interests are engaged, ‘cybercrime’ begins to overlap significantly with concerns about ‘cybersecurity’. 1.35 Specific technologies have become embedded in pre-existing critical infrastructures controlling electrical power, water supplies, air and ground transport, emergency and health services and the like, and increasing reliance on computers and networks for basic communications has made computer networks critical infrastructures in their own right. Disruptive attacks on major banks or securities-trading systems can occur on a scale that damages national economies, and even small interferences with governance functions such as electronic voting systems can have major effects. 1.36 While the different policy foundations of cybercrime and cybersecurity may be fairly clear, the practical implications are less so. Most preventive measures, whether they are technical applications such as firewalls and encryption or training and education of system users, are also labelled as ‘security measures’, and they protect systems, users and countries equally from all threats, regardless of whether they originate with a state actor or a private criminal or whether they are motivated by politics, terrorism or simple greed. Most countries still rely on the adoption and prosecution of criminal offences as a major element of defence and deterrence, even if the interests involved are security interests such as terrorism or espionage. 1.37 The overlap of crime and security policy interests does have a significant impact on how countries react to the issues, both at the policy level and in individual cases. Within states, the perception of cybercrime as a national security issue influences the way in which policies and laws are developed. Internationally, matters are further complicated by the fact that each state may have its own perception of the scope of security interests. States may be less co-operative when dealing with matters of security as opposed to crime more generally. Internationally, whether an issue is labelled as a criminal or as a security matter 18

Select target paragraph3