Article

Important New Insights into The Cost of Cyber Crime

Jan 01, 0001

As more and more fraud migrates from traditional techniques to those exploiting the Internet, institutions and individuals are increasingly at risk of victimization.

July 2012

By Peter Goldmann, CFE

As more and more fraud migrates from traditional techniques to those that exploit the Internet, institutions and individuals are increasingly at risk of victimization. The fast-growing population of cyber fraudsters has created a vibrant new industry of anti-malware software makers, information security service providers, cyber-technology researchers, trainers and others.This frenzy of anti-cyber crime activity has created confusion about the very definition of cyber crime and about the financial damage wrought by the evolving variety of online crimes to which the definition applies.


Now, however, a group of researchers from the Computer Laboratory at the University of Cambridge has come out with a report which provides much-needed clarity to the entire cyber crime issue. The team starts with a uniquely helpful three-part definition of cyber crime:

 

1) Traditional forms of crime such as fraud or forgery, though committed over electronic communication networks and information systems;

2) The publication of illegal content over electronic media (e.g., child sexual abuse material or incitement to ethnic hatred);

3) Crimes unique to electronic networks, e.g., attacks against information systems, denial of service and hacking.


 

How Much Does it Really Cost? 

Some cyber experts believe that many estimates of the cost of cyber crime are vastly overstated. This is not surprising in light of the fact that many of the studies produced each year are released by companies that also sell anti-virus software and other products designed to protect organizations and individuals against the bad guys in cyberspace.

 

This is not to suggest that cyber crime isn’t incredibly costly and that nearly every entity and individual is a potential victim. But it is helpful to executives to have reliable data when trying to make decisions about how best to protect against these crimes.The Cambridge researchers acknowledge this and have attempted to apply a more scientific methodology to their analysis.They started by studying the various individual cyber crimes plaguing organizations today and analyzed the financial damage resulting from each.

 

To do this, the researchers first broke down the complex cyber crime problem into distinct cost categories:

 

Criminal revenue. This refers to the monetary equivalent of the gross receipts from a crime. It does not include “lawful” business expenses of the criminal(s).

 

Example: An illegal online pharmacy may purchase hosting services from a legitimate provider and pay the market price. This reduces the criminal's profit, but contributes to the gross domestic product (GDP) of the economy in which the provider is located.

 

Contrast: Phishing advertised by email spam. The “phisherman's” ill-gotten revenue is the sum of the money withdrawn from victim accounts. If spamming is also a crime, and is carried out using a botnet (a network of subverted PCs), then the revenue of the spammer, possibly split with the “owner” of the malicious software, must be accounted for as part of overall criminal revenue contribution to GDP.

 

Direct losses. This includes the monetary equivalent of losses, damage, or other suffering by the victim as a consequence of a cyber crime. Direct losses include:

 

Money withdrawn from victim accounts.

Time and effort to reset account credentials (for both banks and consumers).

Secondary costs of overdrawn accounts: deferred purchases, inconvenience of not having access to money when needed, etc.

 

 

Indirect losses. This refers to the monetary equivalent of the losses and opportunity costs imposed on society by the fact that a certain cybercrime is carried out, no matter whether successful or not and independent of a specific instance of that cybercrime.

 

Indirect costs generally cannot be attributed to individual victims. Indirect losses include:

 

Loss of trust in online banking, leading to reduced revenues from electronic transaction fees, and higher costs for maintaining branch staff and check clearing facilities.

Missed business opportunities for banks to communicate with their customers by email.

Reduced uptake by citizens of electronic services as a result of lessened trust in online transactions.

Efforts to clean-up PCs infected with the malware for a spam-sending botnet.

 

Defense costs. Defense costs are the monetary equivalent of prevention efforts. They include direct defense costs, such as the cost of development, deployment and maintenance of prevention measures, as well as indirect costs, such as inconvenience and opportunity costs caused by the prevention measures.

 

Specifically, defense costs include:

 

Security products such as spam filters, and antivirus and browser extensions to protect users.

Security services provided to individuals, such as training and awareness measures.

Security services provided to industry, such as website “take-down” services.

Fraud detection, tracking and recuperation efforts.

Law enforcement.

The inconvenience of missing an important message falsely classified as spam.

 

Cost to society. The cost to society is the sum of direct losses, indirect losses, and defense costs. Conclusion: According to the researchers, annual losses to cyber crime breakdown roughly as follows: 

Actual cyber crime (including online banking losses and anti-malware defense, intellectual property-related loss and several high-profile consumer crimes): $2.5 billion.

Transitional cyber-fraud (including credit card fraud — both online and offline, indirect costs of payment fraud (primarily lost customer confidence in online payment): $41 billion.

Cyber criminal infrastructure (including anti-virus expenditures, software patching, ISP and end-user cleanup, anti-cybercrime defense cost to business generally and law enforcement services): $24.8 billion. Key: Approximate $68.3 billion total is considerably lower than the $114 billion figure that Symantec reported for roughly the same loss categories in 2010.

 

 Are We Wasting Anti-Cyber Crime Dollars?  

Critical point: While it is understandable that organizations will continue to invest massive amounts of money in protection against direct and indirect losses, the Cambridge research suggests that “it is possible to spend too much on defense."

 

This is plausible in light of the fact that despite the gargantuan investments in cyber-crime protection, losses to online bad guys continue to rise. Companies worldwide spend an estimated $10 billion on basic cyber-crime prevention (not including the specialized anti-fraud costs borne by financial institutions and merchants).

 

An additional estimated $1 billion is spent globally on creating security patches for software vulnerabilities, while another $400 million is spent annually on cyber-crime-related law enforcement activity (roughly one-half of which is spent by the U.S.).

 

Though the authors of this insightful study emphasize that their statistical measures of cyber crime costs are not definitive — due to the absence of reliable data in key segments of the cyber crime “world”—they do offer some intensively researched estimates that if nothing else, provide persuasive evidence that companies and government agencies may be spending available cyber crime defense resources in the wrong way.

 

Conclusion: Regardless of which cyber crime numbers you use, the indisputable fact is that they are all going up. Which, researchers suggest, points to a persuasive concept: companies and government agencies should “spend less in anticipation of computer crime (on antivirus, firewalls etc.) [...and an] awful lot more on catching and punishing the perpetrators."

 

Note: This article is based in large part on “Measuring the Cost of Cybercrime” by Ross Anderson, University of Cambridge; Chris Barton; Rainer Boehme, University of Munster; Richard Clayton, University of Cambridge; Michel J.G. Van Eeten, Delft University of Technology; Michael Levi, Cardiff University; Tyler Moore, Southern Methodist University; and Stefan Savage, University of California.

 

Peter Goldmann, CFE, is president of White-Collar Crime 101 LLC/FraudAware. Contact Peter at  pgoldmann@fraudaware.com.