EXECUTIVE SUMMARY
cybercrime risk assessment, and most reported use of cybersecurity technology such as
firewalls, digital evidence preservation, content identification, intrusion detection, and system
supervision and monitoring. Concern was expressed, however, that small and medium-sized
companies either do not take sufficient steps to protect systems, or incorrectly perceive that
they will not be a target.
Regulatory frameworks have an important role to play in cybercrime prevention, both
with respect to the private sector in general and service providers in particular. Nearly half of
countries have passed data protection laws, which specify requirements for the protection and
use of personal data. Some of these regimes include specific requirements for internet service
providers and other electronic communications providers. While data protection laws require
personal data to be deleted when no longer required, some countries have made exceptions for
the purposes of criminal investigations, requiring internet service providers to store specific
types of data for a period of time. Many developed countries also have rules requiring
organizations to notify individuals and regulators of data breaches. Internet service providers
typically have limited liability as ‘mere conduits’ of data. Modification of transmitted content
increases liability, as does actual or constructive knowledge of an illegal activity. Expeditious
action after notification, on the other hand, reduces liability. While technical possibilities exist
for filtering of internet content by service providers, restrictions on internet access are subject
to foreseeability and proportionality requirements under international human rights law
protecting rights to seek, receive and impart information.
Public-private partnerships are central to cybercrime prevention. Over half of all
countries report the existence of partnerships. These are created in equal numbers by informal
agreement and by legal basis. Private sector entities are most often involved in partnerships,
followed by academic institutions, and international and regional organizations. Partnerships
are mostly used for facilitating the exchange of information on threats and trends, but also for
prevention activities, and action in specific cases. Within the context of some public-private
partnerships, private sector entities have taken proactive approaches to investigating and taking
legal action against cybercrime operations. Such actions complement those of law enforcement
and can help mitigate damage to victims. Academic institutions play a variety of roles in
preventing cybercrime, including through delivery of education and training to professionals,
law and policy development, and work on technical standards and solution development.
Universities house and facilitate cybercrime experts, some computer emergency response teams
(CERTs), and specialized research centres.
xxvii