Another example can be found in the use of specialist malware to compromise card readers at ATMs or point of sale. New developments are hard to predict, which makes prevention difficult. Legislative, law enforcement and policy agendas in this context can only be largely reactive, set by a combination of technological change and innovation and new patterns of criminal activity. Although this may be true to some extent for any criminal law policy area, the practical implications are greater for cybercrime because of its global scope, speed and complexity. 1.29 The immediate practical implications of this include the need for constant monitoring of new technologies and forms of cybercrime; for fast reaction to close vulnerabilities and update investigative and prosecutorial capacity; and for greater emphasis on crime prevention. The best way to deal with new vulnerabilities is to identify and close them before they can be misused, and as with prevention in general, this is an area where the private sector plays an important role. The Need for effective Cybercrime Prevention 1.30 Crime prevention reduces the human cost of offending, and it also reduces or avoids the direct and indirect costs associated with investigation, prosecution, punishment and other reactive measures. These advantages are much more compelling in the case of cybercrime because of the much higher costs associated with investigating and prosecuting the complex, transnational and broad-ranging crimes made possible by information and communications technologies and computer networks. The prevention of cybercrime is complex and generally entails a high degree of collaboration between the public and private sectors at both the domestic and international levels. 1.31 Generally, prevention strategies would include some combination of the following elements: (a) Technical security elements are needed to exclude offenders and make computer systems more difficult to access or penetrate. In general, these should be incorporated into new technologies and systems as they are developed and then maintained to ensure continued effectiveness as the threat of cybercrime evolves. This is primarily a function of the private sector, but governments can play a role in areas such as encouraging the development of appropriate measures and assisting diverse companies in developing common and interoperable security measures. (b) Targeted or situational prevention based on an assessment of specific situational risks by both public and private sector entities is also important. There must be education or training of specific groups to raise awareness of the assessed threat, and as to how it can be reduced or prevented. Situational elements often combine education and technical measures: for example, a company threatened by cyberfraud may both acquire new security products and train its employees how to use them to detect or prevent fraud. (c) Broad ranging public information campaigns directed at users of technologies are also needed to raise awareness of cybercrime in general and of specific forms of cybercrime as they emerge from time to time. General awareness of the nature and scope of the problem encourages good cyber-security habits among general users, and fosters better understanding of, and co-operation with, law enforcement and other authorities in a shared response to the problem. Technologies and Networks as ‘critical infrastructure’ and the Rise of ‘cybersecurity’ 17

Select target paragraph3