Cybersecurity guide for developing countries Nonetheless, the establishment in the United States, for example, of decentralized computer investigation and infrastructure threat assessment (CITA) squads, coordinated by the National Infrastructure Protection Centre (NIPC), gives some indication of the magnitude of cybercrime. The number of security incidents reported to CERT18 has been growing steadily since the start of the current century, as has the number of attacks reported to the legal authorities, contributing to a better understanding and accounting of computer crime. In 2003, there was a significant increase in the volume of spam, which spread beyond the internet to SMS text messages, and numerous spammers were arrested and convicted. Large-scale police operations conducted in the United States (operations E-Con in May 2003 and Cyber-Sweep in October 2003) and in Europe (Spain, Italy, France, United Kingdom, etc.) show that the authorities are reacting and adapting to the new criminal context. The arrest and conviction of several virus authors and spammers testify to the determination to deal with these new types of nuisance. However, the number of convictions remains very low given the sheer volume of spam and viruses circulating on a daily basis19. The rate of unreported cybercrime is difficult to estimate. It is possible that the legal authorities, the police and the general public are aware of no more than 12% of cybercrime20. It is difficult to obtain a realistic inventory of computer-related crime, and this is a serious obstacle to attempts to analyse the phenomenon and determine its magnitude. The absence of official statistics is partly due to the fact that organizations: – wish to avoid publicity about attacks; – may be unaware that they have been the victims of cybercrime, particularly in the case of passive attacks (transparent hijacking of data, traffic, passive listening, undetected intrusion, etc.); they may also not learn of the attack until much later, when there is no longer any point in reacting; – do not know how to deal with a crisis situation; – lack the necessary confidence in the legal authorities and police, and in their ability to deal with this type of problem; – prefer to handle the matter themselves. Hacker skills, the sophistication and potency of attacks and attackers’ toolkits are improving all the time, and the actual quantity of attacks continues to grow. The ever-increasing complexity resulting from this dynamic trend is difficult to handle. Without a strong political will and a sense of responsibility among all participants at the international level, as well as an effective partnership between the private and public sectors, any security measures, whether of a technical or legislative nature, will not reach beyond an inadequate and piecemeal approach to security, and thus remain ineffective in tackling computer-related crime. 18 CERT Coordination Center, Carnegie Mellon University (www.cert.org) 19 The Information Technology Promotion Agency Information Security Center (IPA/ISEC) in Japan identified 85 059 known viruses in December 2003 in its Computer Virus Incident Reports, 2004: www.ipa.go.jp/security/english/virus/press/200401/virus200401-e.html 20 Vladimir Gobulev, “Computer crime typology” published on 9 January 2004 by the Computer Crime Research Center: www.crime-research.org/articles/Golubev1203/ 42 Cybercrime

Select target paragraph3