CHAPTER TWO: THE GLOBAL PICTURE risk.27 At the same time, increased use of innovations such as cloud computing presents a mix of cybersecurity benefits and challenges.28 Reliable private sector victimization data is hard to obtain and challenging to interpret.29 Data for European countries nonetheless suggests that private sector cybercrime victimization Data breach due to intrusion or rates for acts such as ‘data phishing beach due to intrusion or Unavailability of ICT services phishing’, ‘outside attacks due to outside attacks (including DoS) resulting in system Data corruption due to interference’, and ‘data malicious software or unauthorized access interference due to illegal system access’, are broadly 0 2 4 6 8 10 12 14 16 18 comparable to unauthorized % enterprises, 2009 access, phishing and online Source: Eurostat Community survey on ICT usage and e‐commerce in enterprises. credit card fraud experienced by consumers. Between two and 16 per cent of enterprises in Europe, for example, reported experiencing data corruption due to malicious software or unauthorized access during the Data year 2010.30 corruption due to Figure 2.7: Enterprise victimization by size unauthorized access occurred more SK PT ES frequently than EL MK unavailability of ICT RO NL services due to outside MT LT IE attacks (between one DK CZ and 11 per cent), which TR HR in turn occurred more BG BE NO frequently than data Small enterprises (10‐49 persons) LU IT breach due to intrusion IS FR Medium enterprises (50‐249 persons) AT or phishing (between SI FI zero and four per cent). CY Figure 2.6: Cybercrime and enterprise victimization SK PT ES EL MK RO NL MT LT IE DK CZ TR HR BG BE NO LU IT IS FR AT SI FI CY GB SE LV HU DE Nonetheless, much turns on the way in which questions are asked, and the Large enterprises (>250 persons) GB SE LV HU DE 0 5 10 15 20 25 30 % enterprises experiencing data corruption due to malicious software or unauthorized access, 2009 Source: Eurostat Community survey on ICT usage and e‐commerce in enterprises. 27 28 29 30 See, for example, KPMG, 2011. The e-Crime Report 2011. Over half of enterprise security decision makers reported that the overall level of e-crime risk faced by their enterprise had increased over the last 12 months. Only 6 per cent reported that it had decreased. Europol reports that the main sources of illegal data in card-not-present fraud investigations were data breaches of merchants and card processing centres, often facilitated by insiders and malicious software (Europol, 2012. Situation Report. Payment Card Fraud in the European Union. Perspective of Law Enforcement Agencies). PricewaterhouseCoopers, 2012. Eye of the storm. Key findings from the 2012 Global State of Information Security Survey. See Annex Two (Measuring cybercrime). Eurostat, 2011. Community survey on ICT usage and e-commerce in enterprises. The survey covered 149,900 enterprises out of 1.6 million in the EU27. 31

Select target paragraph3