1.32 In the past decade, information and communications technologies have grown in
importance to the point where many states regard them as critical infrastructure and see the
need to protect them as a security interest and not just a criminal justice matter. The policy
focus moves beyond the protection of individual economic or social interests to the
protection of infrastructure which is seen as critical to the functioning of the state itself.
1.33 As a subject, “cybersecurity” is broader than “cybercrime” and focuses more on
preventive than on reactive policies. Cybersecurity includes the protection of networks and
data from non-criminal threats such as natural disasters or system failures, for example.
Cybercrime measures can also be seen as a means to the end of better cybersecurity, in the
sense that criminal offences are defined, investigated and prosecuted, to a large degree,
based on the need to identify and criminalise conduct which poses a threat to computer
users or general populations, and to deter and incapacitate those who would or do engage in
such conduct.
1.34 Classification of cybercrime and related activities as a security matter often reflects a
combination of an assessment of the risk or probability that an attack will occur and the
magnitude of the potential harm were an attack to succeed. Offences against state interests,
such as espionage or terrorism offences, will always be regarded as cybersecurity matters,
but economic forms of cybercrime will only be included if they either are linked to such
offences (e.g. frauds that finance terrorist activities), or are of sufficient magnitude to
damage the state’s overall economic stability. There may be special concern if a ‘cyberattack’ is thought to be launched from another state or if the motivation of the attackers is to
gain policy influence or extort policy changes through the commission of crime or the threat
of crime. When these interests are engaged, ‘cybercrime’ begins to overlap significantly with
concerns about ‘cybersecurity’.
1.35 Specific technologies have become embedded in pre-existing critical infrastructures
controlling electrical power, water supplies, air and ground transport, emergency and health
services and the like, and increasing reliance on computers and networks for basic
communications has made computer networks critical infrastructures in their own right.
Disruptive attacks on major banks or securities-trading systems can occur on a scale that
damages national economies, and even small interferences with governance functions such
as electronic voting systems can have major effects.
1.36 While the different policy foundations of cybercrime and cybersecurity may be fairly
clear, the practical implications are less so. Most preventive measures, whether they are
technical applications such as firewalls and encryption or training and education of system
users, are also labelled as ‘security measures’, and they protect systems, users and
countries equally from all threats, regardless of whether they originate with a state actor or a
private criminal or whether they are motivated by politics, terrorism or simple greed. Most
countries still rely on the adoption and prosecution of criminal offences as a major element of
defence and deterrence, even if the interests involved are security interests such as
terrorism or espionage.
1.37 The overlap of crime and security policy interests does have a significant impact on
how countries react to the issues, both at the policy level and in individual cases. Within
states, the perception of cybercrime as a national security issue influences the way in which
policies and laws are developed. Internationally, matters are further complicated by the fact
that each state may have its own perception of the scope of security interests. States may
be less co-operative when dealing with matters of security as opposed to crime more
generally. Internationally, whether an issue is labelled as a criminal or as a security matter
18