sent at once to millions of recipients, and a “botnet”, a network of machines that have been infected with malware, may have thousands, even millions, of machines within its scope. 1.14 A report commissioned by the UK Cabinet Office and published in 2011 11 estimated cybercrime's annual cost to the UK to be £27 billion. That report was greeted with widespread scepticism and seen as an attempt to talk up the threat. It led the UK Ministry of Defence to commission a further study from a group of academics. Their report12 noted: There are over 100 different sources of data on cybercrime, yet the available statistics are still insufficient and fragmented; they suffer from under- and overreporting, depending on who collected them, and the errors may be both intentional (e.g., vendors and security agencies playing up threats) and unintentional (e.g., response effects or sampling bias). 1.15 The report for the UK Ministry of Defence contains a sophisticated analysis of both direct and indirect costs (including such things as the effect of loss of confidence in systems) and covers many different types of cybercrime. Although the authors warn against any simple totalling of their estimates, the figures in the report suggest an annual cost for the UK which approaches US$20 billion. Global estimates are much harder to make with any degree of accuracy; the authors estimate a global figure in excess of US$200 billion a year. Cybercrime has no National Borders 1.16 Cybercrime does not respect national boundaries. That creates challenges for the public sector, in terms of legislation and investigative and prosecutorial capacity, and for the private sector, which must address technical vulnerabilities in the systems it designs and operates. 1.17 Cybercrime prosecutions may involve multiple offenders, victims and evidence from many different countries, a fact which can create significant resource and logistical challenges for the law enforcement and prosecutorial agencies presenting cases and for the courts which hear them. Further the offences may be triable in more than one jurisdiction and there may be an issue as to the appropriate venue for the case or cases to be heard. 1.18 The nature of modern technology means that it is not always possible even to say where a cybercrime is committed, in either legal or factual terms. Networks are increasingly being designed to store information in remote or diffuse physical locations and move it around automatically (‘cloud computing’), in order to optimise the use of storage and transmission capacity. This confounds conventional approaches to jurisdiction, because in some scenarios it can be difficult to ascertain where information or system users are located. Similarly, the law that applies to evidence before or after it is obtained will sometimes depend on the physical location at which it was obtained or intercepted, and the design of modern networks can make this difficult to ascertain. Implications 1.19 The transnational aspects of cybercrime also have significant implications for investigation and prosecution. Effective measures to investigate cybercrime and to collect and preserve digital evidence need to be speedy, but criminal justice systems and procedural safeguards are rooted in domestic law and are based on jurisdictional territoriality and national sovereignty. Requests for mutual legal assistance can be notoriously slow and 11 Detica and Office of Cyber Security and Information Assurance, The cost of cyber crime, February 2011. R Anderson and others, Measuring the cost of cybercrime (2012), available at http://weis2012.econinfosec.org/papers/Anderson_WEIS2012.pdf 12 14

Select target paragraph3