on occasion, obtain data from extra-territorial service providers through an informal direct
request, although service providers usually require due legal process. Relevant existing
provisions on ‘trans-border’ access found in the Council of Europe Cybercrime Convention
and the League of Arab States Convention on Information Technology Offences do not
adequately cover such situations, due to a focus on the ‘consent’ of the person having lawful
authority to disclose the data, and presumed knowledge of the location of the data at the time
of access or receipt.
The current international cooperation picture risks the emergence of country clusters
that have the necessary powers and procedures to cooperate amongst themselves, but are
restricted, for all other countries, to ‘traditional’ modes of international cooperation that take
no account of the specificities of electronic evidence and the global nature of cybercrime. This
is particularly the case for cooperation in investigative actions. A lack of common approach,
including within current multilateral cybercrime instruments, means that requests for actions,
such as expedited preservation of data outside of those countries with international obligations
to ensure such a facility and to make it available upon request, may not be easily fulfilled. The
inclusion of this power in the draft African Union Cybersecurity Convention may go some way
towards closing this lacuna. Globally, divergences in the scope of cooperation provisions in
multilateral and bilateral instruments, a lack of response time obligation, a lack of agreement on
permissible direct access to extraterritorial data, multiple informal law enforcement networks,
and variance in cooperation safeguards, represent significant challenges to effective
international cooperation regarding electronic evidence in criminal matters.
Cybercrime prevention
Crime prevention comprises strategies and measures that seek to reduce the risk of
crimes occurring, and mitigate potential harmful effects on individuals and society. Almost 40
per cent of responding countries report the existence of national law or policy on cybercrime
prevention. Initiatives are under preparation in a further 20 per cent of countries. Countries
highlight that good practices on cybercrime prevention include the promulgation of legislation,
effective leadership, development of criminal justice and law enforcement capacity, education
and awareness, the development of a strong knowledge base, and cooperation across
government, communities, the private sector and internationally. More than one half of
countries report the existence of cybercrime strategies. In many cases, cybercrime strategies are
closely integrated in cybersecurity strategies. Around 70 per cent of all countries reported
national strategies included components on awareness raising, international cooperation, and
law enforcement capacity. For the purposes of coordination, law enforcement and prosecution
agencies are most frequently reported as lead cybercrime institutions.
Surveys, including in developing countries, demonstrate that most individual internet
users now take basic security precautions. The continued importance of public awarenessraising campaigns, including those covering emerging threats, and those targeted at specific
audiences, such as children, was highlighted by responding Governments, private sector
entities, and academic institutions. User education is most effective when combined with
systems that help users to achieve their goals in a secure manner. If user cost is higher than
direct user benefit, individuals have little incentive to follow security measures. Private sector
entities also report that user and employee awareness must be integrated into a holistic
approach to security. Foundational principles and good practice referred to include
accountability for acting on awareness, risk management policies and practices, board-level
leadership, and staff training. Two-thirds of private sector respondents had conducted a
xxvi