nature and extent of cybercrime.4 These include the problem of determining what constitutes
‘cybercrime’ in the first place; challenges of under-reporting and under-recording; survey
methodological and awareness issues; and possible conflicts of interest for private sector data.5
Which crimes should be measured?
The previous Chapter considered the possible content of the term ‘cybercrime.’ For the
purposes of measurement, it is likely that acts within the first cybercrime category (acts against the
confidentiality, integrity and availability of computer data or systems) and third category (computer
content-related acts) can be relatively clearly delineated. The second category, however, (computerrelated acts for personal or financial gain or harm) risks becoming extensive. As discussed, what
would be the threshold for involvement of a computer system or data that warrants recording a
crime as a cybercrime in this category? Approaches may differ in this respect, in particular as regards
offences recorded by the police. The part below on police statistics discusses this challenge further.
Overall, it is clear that statistics that purport to measure ‘cybercrime’ as a single phenomenon
are unlikely to be comparable cross-nationally, due to significant variations in the content of the
term between recording systems. The preferred approach is therefore likely to be one that provides
data disaggregated by discrete cybercrime act – such as those detailed in the list of 14 acts provided in
Chapter One (Connectivity and cybercrime). Such an approach offers a higher degree of consistency
and comparability, and is in line with good practice in crime and criminal justice statistics in general.6
What do we want to know?
One approach to the measurement of new forms and dimensions of crime, including
cybercrime, is to aim to characterize ‘who’ (and how many) are involved in ‘what’ (and how much).7 This
requires a combination of data sources, such as: information on perpetrators, including organized
criminal groups; information on flows within illicit markets; as well as information on numbers of
criminal events, harms and losses, and resultant illicit financial flows. Each of these elements has
implications for the response to cybercrime. An understanding, for example, of organized criminal
group structures and networks is central to the design of criminal justice interventions. An
understanding of illicit markets – such as the black economy centred on stolen credit card details –
provides details of the underlying incentives for criminal activity (irrespective of the individuals or
groups involved), and thus entry points for prevention programming. An understanding of the
extent of harms, losses and illicit financial gains provides guidance on the prioritization of
interventions.
What information can be gathered?
Four main information sources exist for the measurement of ‘what’ cybercrime acts occur
and ‘how much’: (i) police-recorded crime statistics; (ii) population-based and business surveys; (iii)
victim reporting initiatives; and (iv) technology-based cybersecurity information. The list is not
4
5
6
7
See, for example, Brenner, S.W., 2004. Cybercrime Metrics: Old Wine, New Bottles? Virginia Journal of Law & Technology, 9(13):1-52.
Cybercrime is also included as an example of an ‘emerging and difficult to measure crime’ in documents of the 42nd Session of the
United Nations Statistical Commission. See United Nations Economic and Social Council, Statistical Commission, 2012. Report of
the National Institute of Statistics and Geography of Mexico on Crime Statistics. E/CN.3/2012/3, 6 December 2011.
Fafinski, S., Dutton, W.H. and Margetts, H., 2010. Mapping and Measuring Cybercrime. Oxford Internet Institute Forum Discussion
Paper No. 18. June 2010.
See for example, UNODC, 2010. Developing Standards in Justice and Home Affairs Statistics: International and EU Acquis; and United
Nations, 2003. Manual for the Development of a System of Criminal Justice Statistics.
European Institute for Crime Prevention and Control, affiliated with the United Nations (HEUNI), 2011. Data Collection on
[New] Forms and Manifestations of Crime. In: Joutsen, M. (ed.) New Types of Crime, Proceedings of the International Seminar held in
Connection with HEUNI’s Thirtieth Anniversary, 20 October 2011, Helsinki: EICPC. See also UNODC, 2010. The Globalization of Crime:
A Transnational Organized Crime Threat Assessment.
24