perception of respondents as to what constitutes a ‘data breach’, ‘intrusion’, ‘unavailability of ICT services’, or ‘malicious software.’ One survey covering private sector organizations in five countries, for example, reports extremely high enterprise ‘victimization’ rates – such as between 1.1 and 1.8 ‘successful cyber-attacks per surveyed organization per week.’31 Such findings are likely heavily influenced not only by the perception of what constitutes a ‘cyber-attack’ on an enterprise,32 but also by the size of the enterprise computer infrastructure available to attack. This particular survey, for instance, focused on organizations with more than 1,000 ‘enterprise seats’ – defined as direct connections to the network and enterprise systems.33 Indeed, a greater cybercrime risk for larger enterprises is also borne out by data for the European private sector. The proportion of enterprises in Europe experiencing data corruption due to malicious software or unauthorized access is greater for large enterprises (more than 250 persons) (two to 27 per cent), than for medium enterprises (50-249 persons) (two to 21 per cent), which is, in turn, greater than for small enterprises (10-49 persons) (one to 15 per cent). In addition to the ‘available attack surface’, such differences may also relate to a perception amongst perpetrators that larger enterprises represent higher value targets. It may also be the case, however, that small and medium enterprises possess a lower capacity to identify attacks in the first place. Some 65 per cent of large enterprises, for example, reported having a formally defined ICT policy, compared with 43 per cent of medium enterprises, and only 22 per cent of small enterprises.34 Criminal tools – the botnet A defining feature of today’s cybercrime landscape is the extensive use of computer misuse tools across a range of cyber-offences. ‘Botnets’ (a term derived from the words ‘robot’ and ‘network’) consist of a network of interconnected, remote-controlled computers generally infected with malicious software that turns the infected systems into so-called ‘bots’, ‘robots’, or ‘zombies.’35 The legitimate owners of such systems may often be unaware of the fact of infection. Zombies within the botnet connect to computers controlled by perpetrators (known as ‘command and control servers’ or C&Cs), or to other zombies, in order to receive instructions, download additional software, and transmit back information harvested from the infected system. Because botnets can be used for a number of actions – including DDoS attacks, sending spam, stealing personal information, hosting malicious sites, and delivering ‘payloads’ of other malicious software36 – they represent a key cybercrime tool of choice. A number of responding countries highlighted the increasing use of botnets in cybercrime during the past five years.37 From a criminal law perspective, the installation of malware on a personal or enterprise computer system can represent illegal access to a computer system, and/or illegal data interference or system interference.38 In countries where computer misuse tools are criminalized, producing, selling, possessing, or distributing botnet software itself may also be a criminal offence. In addition, use of the botnet for further criminal gain may constitute a range of offences, such as illegal access to, 31 32 33 34 35 36 37 38 HP/Ponemon, 2012. Cost of Cybercrime Study AU, DE, JN, GB and US. Survey results are thus more reliable where experience of a particular, defined event, is asked about. See UNODC/UNECE, 2010. Manual on Victimization Surveys. Ibid. Eurostat, 2011. Statistics in Focus 7/2011. ICT security in enterprises, 2010. OECD, 2008. Malicious Software (Malware). A Security Threat to the Internet Economy. DSTI/ICCP/REG(2007)5/FINAL. 28 April 2008. Hogben, G. (ed.) 2011. Botnets: Detection, Measurement, Disinfection and Defence. European Network and Information Security Agency (ENISA). Study cybercrime questionnaire. Q84. See Annex One (Act descriptions). See also NATO Cooperative Cyber Defence Centre of Excellence and ENISA, 2012. Legal Implications of Countering Botnets. 32

Select target paragraph3