on occasion, obtain data from extra-territorial service providers through an informal direct request, although service providers usually require due legal process. Relevant existing provisions on ‘trans-border’ access found in the Council of Europe Cybercrime Convention and the League of Arab States Convention on Information Technology Offences do not adequately cover such situations, due to a focus on the ‘consent’ of the person having lawful authority to disclose the data, and presumed knowledge of the location of the data at the time of access or receipt. The current international cooperation picture risks the emergence of country clusters that have the necessary powers and procedures to cooperate amongst themselves, but are restricted, for all other countries, to ‘traditional’ modes of international cooperation that take no account of the specificities of electronic evidence and the global nature of cybercrime. This is particularly the case for cooperation in investigative actions. A lack of common approach, including within current multilateral cybercrime instruments, means that requests for actions, such as expedited preservation of data outside of those countries with international obligations to ensure such a facility and to make it available upon request, may not be easily fulfilled. The inclusion of this power in the draft African Union Cybersecurity Convention may go some way towards closing this lacuna. Globally, divergences in the scope of cooperation provisions in multilateral and bilateral instruments, a lack of response time obligation, a lack of agreement on permissible direct access to extraterritorial data, multiple informal law enforcement networks, and variance in cooperation safeguards, represent significant challenges to effective international cooperation regarding electronic evidence in criminal matters. Cybercrime prevention Crime prevention comprises strategies and measures that seek to reduce the risk of crimes occurring, and mitigate potential harmful effects on individuals and society. Almost 40 per cent of responding countries report the existence of national law or policy on cybercrime prevention. Initiatives are under preparation in a further 20 per cent of countries. Countries highlight that good practices on cybercrime prevention include the promulgation of legislation, effective leadership, development of criminal justice and law enforcement capacity, education and awareness, the development of a strong knowledge base, and cooperation across government, communities, the private sector and internationally. More than one half of countries report the existence of cybercrime strategies. In many cases, cybercrime strategies are closely integrated in cybersecurity strategies. Around 70 per cent of all countries reported national strategies included components on awareness raising, international cooperation, and law enforcement capacity. For the purposes of coordination, law enforcement and prosecution agencies are most frequently reported as lead cybercrime institutions. Surveys, including in developing countries, demonstrate that most individual internet users now take basic security precautions. The continued importance of public awarenessraising campaigns, including those covering emerging threats, and those targeted at specific audiences, such as children, was highlighted by responding Governments, private sector entities, and academic institutions. User education is most effective when combined with systems that help users to achieve their goals in a secure manner. If user cost is higher than direct user benefit, individuals have little incentive to follow security measures. Private sector entities also report that user and employee awareness must be integrated into a holistic approach to security. Foundational principles and good practice referred to include accountability for acting on awareness, risk management policies and practices, board-level leadership, and staff training. Two-thirds of private sector respondents had conducted a xxvi

Select target paragraph3