Cyber Crime Costs UK £27bn a Year

News out today that cyber crime costs the UK economy £27bn a year makes for worrying reading.
Most of the “costs” to the UK economy fall into 2 areas – £9.2bn in intellectual property theft and £7.6bn in industrial espionage.

Both of these categories are areas where losses would occur with or without the internet, and indeed the internet may have simply made these types of activity easier to perpetrate. So blaming “cyber crime” does nothing to address the issues because it’s very likely that technical solutions will do little to reduce the activity.

Another interesting statistic is that the government is looking to spend £650m over the next four years to tackle the problem. That equates to less than £163m a year. So in order to solve a problem that costs the country one-sixth of its national debt the government is coughing up a bit of loose change?

If the problem is really as significant as it is alleged, then a concerted effort must be made to tackle it. Looking at the problem from both the bottom up and the top down.

How do we do this?

Well, organisations need to build security into their very existence – educate their staff, design their processes and procedures, their systems and solutions with security at the very core of everything.

Develop and implement software and hardware, networks and infrastructure that is secure at inception, not look at security as an afterthought, as is generally the case now. And this needs to involve ALL organisations of ALL size because the smaller businesses feed into the larger, and so-on.

This is where the government needs to provide guidance and direction. Use some of the “loose change” to help fund initiatives which raise awareness of security issues with people, organisations and businesses at the bottom of the industrial, commercial and governmental food
chains. We need to educate people from the start, in schools, colleges and universities, as well as in businesses on how to protect themselves, their friends, colleagues and associates, their data and their privacy.

Let’s make information and “cyber” security a topic for the national syllabus in the same way that diet and exercise are today.

Improving the understanding of the threats, the risks and the defences within the population at large will improve security. But this must be done in a way that ensures the real buy-in and understanding of people.

While security is something done by “someone else” we will see an increase in the figures released today, with little or no impact from the governments initiatives.