nature and extent of cybercrime.4 These include the problem of determining what constitutes ‘cybercrime’ in the first place; challenges of under-reporting and under-recording; survey methodological and awareness issues; and possible conflicts of interest for private sector data.5 Which crimes should be measured? The previous Chapter considered the possible content of the term ‘cybercrime.’ For the purposes of measurement, it is likely that acts within the first cybercrime category (acts against the confidentiality, integrity and availability of computer data or systems) and third category (computer content-related acts) can be relatively clearly delineated. The second category, however, (computerrelated acts for personal or financial gain or harm) risks becoming extensive. As discussed, what would be the threshold for involvement of a computer system or data that warrants recording a crime as a cybercrime in this category? Approaches may differ in this respect, in particular as regards offences recorded by the police. The part below on police statistics discusses this challenge further. Overall, it is clear that statistics that purport to measure ‘cybercrime’ as a single phenomenon are unlikely to be comparable cross-nationally, due to significant variations in the content of the term between recording systems. The preferred approach is therefore likely to be one that provides data disaggregated by discrete cybercrime act – such as those detailed in the list of 14 acts provided in Chapter One (Connectivity and cybercrime). Such an approach offers a higher degree of consistency and comparability, and is in line with good practice in crime and criminal justice statistics in general.6 What do we want to know? One approach to the measurement of new forms and dimensions of crime, including cybercrime, is to aim to characterize ‘who’ (and how many) are involved in ‘what’ (and how much).7 This requires a combination of data sources, such as: information on perpetrators, including organized criminal groups; information on flows within illicit markets; as well as information on numbers of criminal events, harms and losses, and resultant illicit financial flows. Each of these elements has implications for the response to cybercrime. An understanding, for example, of organized criminal group structures and networks is central to the design of criminal justice interventions. An understanding of illicit markets – such as the black economy centred on stolen credit card details – provides details of the underlying incentives for criminal activity (irrespective of the individuals or groups involved), and thus entry points for prevention programming. An understanding of the extent of harms, losses and illicit financial gains provides guidance on the prioritization of interventions. What information can be gathered? Four main information sources exist for the measurement of ‘what’ cybercrime acts occur and ‘how much’: (i) police-recorded crime statistics; (ii) population-based and business surveys; (iii) victim reporting initiatives; and (iv) technology-based cybersecurity information. The list is not 4 5 6 7 See, for example, Brenner, S.W., 2004. Cybercrime Metrics: Old Wine, New Bottles? Virginia Journal of Law & Technology, 9(13):1-52. Cybercrime is also included as an example of an ‘emerging and difficult to measure crime’ in documents of the 42nd Session of the United Nations Statistical Commission. See United Nations Economic and Social Council, Statistical Commission, 2012. Report of the National Institute of Statistics and Geography of Mexico on Crime Statistics. E/CN.3/2012/3, 6 December 2011. Fafinski, S., Dutton, W.H. and Margetts, H., 2010. Mapping and Measuring Cybercrime. Oxford Internet Institute Forum Discussion Paper No. 18. June 2010. See for example, UNODC, 2010. Developing Standards in Justice and Home Affairs Statistics: International and EU Acquis; and United Nations, 2003. Manual for the Development of a System of Criminal Justice Statistics. European Institute for Crime Prevention and Control, affiliated with the United Nations (HEUNI), 2011. Data Collection on [New] Forms and Manifestations of Crime. In: Joutsen, M. (ed.) New Types of Crime, Proceedings of the International Seminar held in Connection with HEUNI’s Thirtieth Anniversary, 20 October 2011, Helsinki: EICPC. See also UNODC, 2010. The Globalization of Crime: A Transnational Organized Crime Threat Assessment. 24

Select target paragraph3