Interviews

Cyber law queried

by Mark Rowe

At the Labour Party Conference in Brighton Shadow Home Secretary Yvette Cooper called for harsher sentences for cyber criminals, arguing that the law has failed to keep up with the switch by criminals to online crime. Also in her speech, Cooper said a Labour Government woud legislate to stop the police using community resolutions for crimes like domestic and sexual violence. “Because serious crimes need serious penalties and protection for victims too,” she said.

She said that most online crime – like credit card and identity fraud – goes unreported. She said: “Which?, the consumer watchdog, say half of us have been targeted by online scams. The pensioner who lost his savings wiring help to a friend he thought was stuck abroad in distress. The family who lost hundreds of pounds on a holiday which never existed. We live our lives online now – but organised criminals know that too, and that is where they are heading.

“It’s a big cost for business. And a big cost for all of us when money is tight. When banks are forced to write off fraud we all lose out from higher charges. The police say it’s growing exponentially. Yet the Government hasn’t got a grip.

“So we will act. We’ll change the law to make it easier to prosecute identity theft. A new Police First programme – modelled on Teach First – to get the brightest IT graduates into policing.

“And Peter Neyroud, former top chief constable has agreed to work with us, consumer watchdog Which? and business to build an organisation to challenge online fraud, modelled on the successful Internet Watch Foundation which is tackling online child abuse worldwide. In the face of 21st century crime, what we need is leadership. If the Tories won’t provide it, we will.”

She also mentioned the independent commission chaired by Lord Stevens, former Commissioner of the Met Police, ‘with experts from across Britain, Europe, Australia, Canada – to draw up a radical and positive plan for policing in the 21st century’.

Ross Brewer, vice president and managing director for international markets, LogRhythm , commented:
“Early reports of Ms. Cooper’s planned address sounded incredibly promising. The evolution of cyber crime has far outpaced the development of skills to combat it – and it appeared that this would be identified along with a call to action. However, once more the subject appears to have been pushed down the political agenda as Ms. Cooper made little reference to the extent of the problem or what could be done. The sophistication of hackers is advancing at breakneck speed, while various government departments – and indeed businesses themselves – are simply playing keep up. The result is a continuing stream of data breach incidents that are becoming more devastating by the day, and the UK’s political leaders must sit up and take action now.

“While there have been some successes, these should, in fact, be seen as warnings of what could happen if and when hackers do slip through the net. For instance, the recently foiled attempt on Santander is a shining example of just how determined, and indeed ballsy, cyber criminals have become – and of course, highlights just what is at stake for businesses. While making it easier to prosecute identity theft and introducing schemes to attract IT graduates into policing is a reasonable move, it is still indicative of the reactive mentality that has been the root of many failed cyber crime policies.

“Amid endless government talks, promises of new cyber initiatives and accusations of inaction, businesses need to recognise that we are still in a cyber equivalent of the Wild West, and it really is a case of ‘each to his own’. On the frontline, appropriate security policies must take priority in every single organisation to stop the problem at the source. While traditional security measures such as encryption were deemed adequate in the era of lost laptops and random credit card hacks, today’s cyber criminals have moved on to bigger and better methods – so why haven’t we? As such, an intelligent defence system based on constant monitoring of all network activity is the only way to spot and deal with suspicious activity long before it becomes a problem to be dealt with by the government. Now that hackers have moved the goalposts once again, it’s definitely time for more organisations to get off the bench, get their game face on and take the whole thing more seriously.”

Other comment on Cooper

Ashish Patel, regional director, Stonesoft, a McAfee Group Company: “Fighting serious crime with serious protection for potential victims is certainly a step in the right direction. The ever-increasing number of online scams targeting both businesses and individuals is astronomical and will not abate as the world grows online. Arming police with easier legislation to prosecute cybercriminals hunting for victims with the aim of identity theft would help boost confidence in the UK as a secure and vibrant economy in which to do business, with an environment resilient to cyber-attack and a safe and confident public. In a hyper-connected world where economic value and stability is dictated online it’s encouraging to see further recognition of the far-reaching benefits tough legislation against cyber-crime can have.”

And George Anderson, Senior Product Manager for Enterprise, Webroot: “It’s wrong to say that nothing is being done about identity theft, particularly by the banks that cannot ‘afford’ to make losses through continuously indemnifying customers. Legislation alone will not stop cyber-crime or put an end to customers having their identity stolen. Changing to sentencing laws for those caught however is a different matter and here Government can make a difference. It’s not just in the UK, but globally, that the rapid switch by fraudsters from the physical to the online world has left law-enforcers on the back-foot. Those recently convicted of costing PayPal millions of pounds received shorter prison sentences than if they’d robbed a bank, and that unacceptable discrepancy needs to be addressed. The idea that hackers might be organised criminals sitting in China or Russia or Korea is also an old misconception – they are everywhere. They could be guys and girls sat in their bedrooms at home. Today’s suggestion of a new criminal offence of identity theft goes some way to tackling this but the issue is much wider than just identity theft. Hopefully this is the start of the discussion in the UK but we have a long way to go.”

Related News

  • Interviews

    Cyber threat account

    by Mark Rowe

    Matt Wheatley discusses strategic approaches to identify, analyse and address a cyber threat within an organisation, taking account of the impact of…

  • Interviews

    World War C

    by Mark Rowe

    An American report titled, “World War C: Understanding Nation-State Motives Behind Today’s Advanced Cyber Attacks” describes the unique international and local characteristics…

Newsletter

Subscribe to our weekly newsletter to stay on top of security news and events.

© 2024 Professional Security Magazine. All rights reserved.

Website by MSEC Marketing