Another example can be found in the use of specialist malware to compromise card readers
at ATMs or point of sale. New developments are hard to predict, which makes prevention
difficult. Legislative, law enforcement and policy agendas in this context can only be largely
reactive, set by a combination of technological change and innovation and new patterns of
criminal activity. Although this may be true to some extent for any criminal law policy area,
the practical implications are greater for cybercrime because of its global scope, speed and
complexity.
1.29 The immediate practical implications of this include the need for constant monitoring
of new technologies and forms of cybercrime; for fast reaction to close vulnerabilities and
update investigative and prosecutorial capacity; and for greater emphasis on crime
prevention. The best way to deal with new vulnerabilities is to identify and close them before
they can be misused, and as with prevention in general, this is an area where the private
sector plays an important role.
The Need for effective Cybercrime Prevention
1.30 Crime prevention reduces the human cost of offending, and it also reduces or avoids
the direct and indirect costs associated with investigation, prosecution, punishment and
other reactive measures. These advantages are much more compelling in the case of
cybercrime because of the much higher costs associated with investigating and prosecuting
the complex, transnational and broad-ranging crimes made possible by information and
communications technologies and computer networks. The prevention of cybercrime is
complex and generally entails a high degree of collaboration between the public and private
sectors at both the domestic and international levels.
1.31 Generally, prevention strategies would include some combination of the following
elements:
(a)
Technical security elements are needed to exclude offenders and make computer
systems more difficult to access or penetrate. In general, these should be
incorporated into new technologies and systems as they are developed and then
maintained to ensure continued effectiveness as the threat of cybercrime evolves.
This is primarily a function of the private sector, but governments can play a role in
areas such as encouraging the development of appropriate measures and assisting
diverse companies in developing common and interoperable security measures.
(b)
Targeted or situational prevention based on an assessment of specific situational
risks by both public and private sector entities is also important. There must be
education or training of specific groups to raise awareness of the assessed threat,
and as to how it can be reduced or prevented. Situational elements often combine
education and technical measures: for example, a company threatened by cyberfraud may both acquire new security products and train its employees how to use
them to detect or prevent fraud.
(c)
Broad ranging public information campaigns directed at users of technologies are
also needed to raise awareness of cybercrime in general and of specific forms of
cybercrime as they emerge from time to time. General awareness of the nature and
scope of the problem encourages good cyber-security habits among general users,
and fosters better understanding of, and co-operation with, law enforcement and
other authorities in a shared response to the problem.
Technologies and Networks as ‘critical infrastructure’ and the Rise of ‘cybersecurity’
17