Access and Feeds

Security: Whatever Number You Pick to Estimate the Costs of CyberCrime, it's Costing a lot

By Dick Weisinger

Cybercrime is defined as any crime that involves a computer and a network, where the computer could be either the target of the crime or used to perpetrate the crime.   It’s a broad definition.

Ovum analyst Graham Titterington said cybercrime was a “growing threat to business viability… Cyber criminals are graduating from stealing credit cards and banking credentials to targeting corporate plans and proprietary information. They want valuable information such as product and technology blueprints, customer lists, or information that can be used to embarrass or disadvantage a victim.”  Chatham House, a UK-based think tank, recently published a call-to-action paper on cybercrime, calling for cooperation between both governments and businesses in order to stop or at least slow the staggering amount of cybercrime.

Cybercrime is clearly a problem, but being able to get a clear estimate of what the actual damages are has been difficult.  The US Department of Justice now tracks known incidents of cybercrime on its website.

In 2007, the GAO estimated that the cost of cybercrime in the U.S. was about $117 billion or about 1% of U.S. GDP.  That’s a lot, but how accurate is this number?

In 2009, David DeWalt, President of security firm McAfee, estimated that the loss of intellectual property, such as trade secrets, due to cybercrimes exceeded $1 trillion annually, a much larger number than the GAO estimate.  Shortly after that report, even President Obama cited the trillion dollar number in one of his speeches.  And later that same year, Edward Amoroso, Chief Security Officer of AT&T, told a US Senate Commerce Committee that cybercrime has been increasing to the point where it poses a significant threat to both private and government institutions and commented that “last year the FBI announced that revenues from cyber-crime, for the first time ever, exceeded drug trafficking as the most lucrative illegal global business, estimated at reaping more than $1 trillion annually in illicit profits.”

Blogger and security expert Richard Steinnom questioned the $1 trillion as being too large of a number.  He wrote that “the number of $1 trillion — as in “cybercrime now generates $1 trillion a year for cybercriminals” — appears to be a myth, even it if is repeated by IT security and communication companies.”  $1 trillion would exceed all IT revenues for one year.

A similar debate has been raging in the UK where the UK Cabinet Office announced in April that cybercrime exceeded $43 billion in the UK, but the announcement was quickly derided by Peter Sommer of the London School of Economics as an “unfortunate item of British Aerospace puffery”.  Sommer accused the the Cabinet Office of being a sales machine for the security company Detica.

Now a new study from Symantec estimated that in 2010 $114 billion was lost collectively by 431 million people globally due to cybercrime.  That report also estimates that another $241 billion is spent in lost time trying to recover from cybercrime damage.

So how much does cybercrime really cost?  A lot, but exactly how much is hard to measure.  The fact is that we don’t really have sufficient data to make an accurate estimate.

Digg This
Reddit This
Stumble Now!
Buzz This
Vote on DZone
Share on Facebook
Bookmark this on Delicious
Kick It on DotNetKicks.com
Shout it
Share on LinkedIn
Bookmark this on Technorati
Post on Twitter
Google Buzz (aka. Google Reader)

Leave a Reply

Your email address will not be published. Required fields are marked *

*