many of whom begin involvement in cybercrime in late teenage years.
Globally, cybercrime acts show a broad distribution across financial-driven acts, and
computer-content related acts, as well as acts against the confidentiality, integrity and accessibility of
computer systems. Perceptions of relative risk and threat vary, however, between Governments and
private sector enterprises. Currently, police-recorded crime statistics do not represent a sound basis
for cross-national comparisons, although such statistics are often important for policy making at the
national level. Two-thirds of countries view their systems of police statistics as insufficient for
recording cybercrime. Police-recorded cybercrime rates are associated with levels of country
development and specialized police capacity, rather than underlying crime rates.
Victimization surveys represent a more sound basis for comparison. These demonstrate that
individual cybercrime victimization is significantly higher than for ‘conventional’ crime forms.
Victimization rates for online credit card fraud, identity theft, responding to a phishing attempt, and
experiencing unauthorized access to an email account, vary between 1 and 17 per cent of the online
population for 21 countries across the world, compared with typical burglary, robbery and car theft
rates of under 5 per cent for these same countries. Cybercrime victimization rates are higher in
countries with lower levels of development, highlighting a need to strengthen prevention efforts in
these countries.
Private sector enterprises in Europe report similar victimization rates – between 2 and 16
per cent – for acts such as data breach due to intrusion or phishing. Criminal tools of choice for
these crimes, such as botnets, have global reach. More than one million unique IP addresses globally
functioned as botnet command and control servers in 2011. Internet content also represented a
significant concern for Governments. Material targeted for removal includes child pornography and
hate speech, but also content related to defamation and government criticism, raising human rights
law concerns in some cases. Almost 24 per cent of total global internet traffic is estimated to infringe
copyright, with downloads of shared peer-to-peer (P2P) material particularly high in countries in
Africa, South America, and Western and South Asia.
Legislation and frameworks
Legal measures play a key role in the prevention and combating of cybercrime. These are
required in all areas, including criminalization, procedural powers, jurisdiction, international
cooperation, and internet service provider responsibility and liability. At the national level, both
existing and new (or planned), cybercrime laws most often concern criminalization, indicating a
predominant focus on establishing specialized offences for core cybercrime acts. Countries
increasingly recognize, however, the need for legislation in other areas. Compared to existing laws,
new or planned cybercrime laws more frequently address investigative measures, jurisdiction,
electronic evidence and international cooperation. Globally, less than half of responding countries
perceive their criminal and procedural law frameworks to be sufficient, although this masks large
regional differences. While more than two-thirds of countries in Europe report sufficient legislation,
the picture is reversed in Africa, the Americas, Asia and Oceania, where more than two-thirds of
countries view laws as only partly sufficient, or not sufficient at all. Only one half of the countries,
which reported that laws were insufficient, also indicated new or planned laws, thus highlighting an
urgent need for legislative strengthening in these regions.
The last decade has seen significant developments in the promulgation of international and
regional instruments aimed at countering cybercrime. These include binding and non-binding
instruments. Five clusters can be identified, consisting of instruments developed in the context of, or
xviii