## The Industrialization of CYBERCRIME

## Source details

**Canonical URL:** [The Industrialization of CYBERCRIME](https://www.imf.org/-/media/files/publications/fandd/article/2018/june/gaidosch.pdf)

## Other formats

- [Markdown version](/-/media/files/publications/fandd/article/2018/june/gaidosch.pdf.md)
- [Structured JSON version](/-/media/files/publications/fandd/article/2018/june/gaidosch.pdf.json)

---

### Evolution of cybercrime
- Cybercrime has become a mature industry operating on principles much like those of legitimate businesses: markets, exchanges, specialist operators, outsourcing service providers, integrated supply chains.
- Shift from lone-wolf hackers in the late 1980s to profit-driven actors starting in the 1990s; hacking now pursued primarily for profit rather than showing off skills.
- Supply of highly skilled specialists has not kept pace with technical sophistication required, but advanced tooling and automation have filled the gap.
- Tool evolution over two decades:
  - 1990s: penetration testing tools that were simple, often custom built, requiring considerable programming, networking, and OS knowledge.
  - Over time: emergence of GUI scanners, integrated cyberattack frameworks, advanced phishing frameworks, command line tools, botnets for lease, DDoS attack tools (timeline spans 1990–2016 in the source).
- As tools got easier to use, less skilled “script kiddies” and motivated newcomers can launch attacks; example: launching a phishing operation now requires only a basic understanding, willingness, and some cash.
- Chart note: DDoS = distributed denial of service; GUI = graphical user interface.

### Quantifying cyber risk and scenario estimates
- Cyber risk is difficult to quantify due to scarce and unreliable loss data and rapidly evolving threats that reduce the relevance of historical data.
- Scenario-based modeling produces large loss estimates:
  - Lloyd’s of London estimates losses of $53.05 billion for a cloud service outage lasting 2½ to 3 days affecting the advanced economies.
  - An IMF modeling exercise put the base-case average aggregated annual loss at $97 billion, with the worst-case scenario in the range of $250 billion.
- Phishing profitability is estimated in the high hundreds or even over a thousand percentage points.

### Causes and sectoral consequences
- Profit motive: cybercrime offers similar or even higher profits than legal businesses with much less risk of being caught or physically harmed.
- Potential for systemic risk:
  - Financial sector is probably the most exposed given dependence on a relatively small set of technical systems; knock-on effects from defaults or delays can be widespread and potentially systemic.
  - Interconnection of financial participants means disruption to payment, clearing, or settlement systems—or theft of confidential information—would create widespread spillovers and threaten financial stability.
  - To date, no cyberattack with systemic consequences has been experienced, but regulators are increasingly wary after incidents that took out ATM networks and attacks against online banking systems, central banks, and payment systems.
- Sectoral differences in cyber defense capacity:
  - Financial sector: long history of strong IT control environments mandated by regulation; regulators conduct IT examinations, factor cybersecurity into stress testing, resolution planning, and safety and soundness supervision; some require simulated cyberattacks; deeper budgets facilitate effective cybersecurity solutions. Noted exception: Equifax hack argued as consequence of a cyber regulatory regime that was not proportional to its risk.
  - Health care: typically lacks resources for effective cyber defense outside the wealthiest nations; recent ransomware attacks targeted Allscripts and two regional hospitals in the United States; weaker IT control culture increases susceptibility and raises risk to human life if life-support systems are hit.
  - Utilities (power and communication grids): main concern often stems from disruption or infiltration by rival states or proxies; example cited: massive 2007 attack against Estonia’s Internet infrastructure that took down online financial services, media, and government agencies.

### Countermeasures and policy recommendations
- Primary strategic aim: attack the business model of cybercrime by substantially raising the business risk of cybercriminals through better international cooperation.
  - Cybercrime operations often span jurisdictions, making them harder to take down and prosecute; some jurisdictions are slow, ineffective, or uncooperative.
  - Stronger cooperation would make tracking down suspects and charging them faster and more effective.
- Regulatory and industry actions:
  - Enforce adherence to minimum cybersecurity standards in a coordinated way by regulators across industries.
  - Encourage information sharing and collaboration among firms and regulators.
  - Incorporate cybersecurity preparedness into corporate risk management and, where appropriate, transfer some risk via cyber insurance.
  - Regulators in the financial sector should continue IT examinations, integrate cybersecurity into stress testing and resolution planning, and require firm-specific simulated cyberattacks drawing on government and private-sector intelligence and expertise.
- Operational readiness:
  - Focus on faster breach detection, effective response, and rapid restoration of operations, since cyberattacks and breaches seem inevitable.
  - Stepped-up cybersecurity awareness training to defend against basic technical weaknesses and user errors that are the source of most breaches.
- Current landscape critique:
  - Cybersecurity remains disparate and decentralized, treated mainly as local idiosyncratic problems; “each to its own” must change to achieve generally enhanced cyber risk resilience.

*Source: Tamas Gaidosch, “The Industrialization of CYBERCRIME,” Finance & Development, June 2018.*

---


_Source: https://www.imf.org/-/media/files/publications/fandd/article/2018/june/gaidosch.pdf_
