Global Cybercrime Industry Matures from Hackers to Businesses - IMF F&D Magazine - June 2018 | Volume 55 | Number 2
Source details
- Canonical URL
- Global Cybercrime Industry Matures from Hackers to Businesses - IMF F&D Magazine - June 2018 | Volume 55 | Number 2
Other formats
Bibliographic details
- Authors: TAMAS GAIDOSCH
- Published: June 1, 2018
- Volume: 55
The hacker threat
- Cybercrime is now a mature industry operating on principles much like those of legitimate businesses in pursuit of profit.
- Combating proliferation requires disrupting a business model that employs easy-to-use tools to generate high profits with low risk.
- Long gone are the legendary lone-wolf hackers of the late 1980s; profit-making since the 1990s has created markets, exchanges, specialist operators, outsourcing service providers, and integrated supply chains in cybercrime.
- Several nation-states have used the same technology to develop cyber weaponry for intelligence gathering, industrial espionage, and disrupting adversaries’ infrastructures.
Evolution
- Supply of highly skilled specialists has not kept pace with increasing technical sophistication; advanced tooling and automation have filled the gap.
- 1990s: penetration testing tools were simple, often custom built, and required deep technical knowledge, limiting exploitation to a few professionals.
- As tools improved, less skilled "script kiddies" began to succeed; today launching a phishing operation requires only a basic understanding, willingness, and some cash.
- Cyber risk quantification is difficult due to scarce and unreliable loss data and rapidly evolving threats.
- Scenario-based estimates cited:
- Lloyd’s of London estimates losses of $53.05 billion for a cloud service outage lasting 2½ to 3 days affecting the advanced economies.
- An IMF modeling exercise put the base-case average aggregated annual loss at $97 billion, with the worst-case scenario in the range of $250 billion.
Causes and consequences
- Motivations mirror physical-world crime: profit potentially much higher than legal business with lower perceived risk.
- Phishing profitability is estimated in the high hundreds or even over a thousand percentage points.
- Intellectual property theft by sophisticated actors likely yields substantial profits (speculative in the source).
- Cybercrime poses systemic risk, especially to the financial sector:
- Financial market infrastructure is most vulnerable given its pivotal role and dependence on a relatively small set of technical systems.
- Successful disruptions to payment, clearing, or settlement systems—or theft of confidential information—could result in widespread spillovers and threaten financial stability.
- To date, no cyberattack with systemic consequences has occurred, but recent incidents (ATM networks, online banking systems, central banks, payment systems) raise concern.
- Sectoral differences in resilience:
- Financial sector: long dependence on IT, history of strong IT control environments mandated by regulation, better support for law enforcement, deeper budgets, and more developed cybersecurity culture.
- Health care: typically lacks resources for effective cyber defense outside the wealthiest nations; recent ransomware attacks targeted Allscripts and two regional U.S. hospitals; greater risk to life-support and clinical systems.
- Utilities/power/communication grids: concern about state-sponsored disruption or infiltration; example: 2007 attack against Estonia’s Internet infrastructure.
Countermeasures and policy recommendations
- The best way to tackle cybercrime is to attack its business model by raising the business risk through better international cooperation.
- Cybercrime operations spanning jurisdictions complicate takedown and prosecution; some jurisdictions are slow, ineffective, or uncooperative.
- Stronger cooperation would make tracking suspects and charging them faster and more effective.
- Financial-sector-specific measures:
- Regulators have developed assessment standards, enforceable expectations and benchmarks, and encouraged information sharing among firms and regulators.
- Bank regulators conduct IT examinations that factor cybersecurity into stress testing, resolution planning, and safety and soundness supervision.
- Some regulators require firm-specific simulated cyberattacks drawing on government and private sector intelligence and expertise.
- Firms have increased investment in cybersecurity, incorporated cybersecurity into risk management, and sought to transfer some risk via cyber insurance.
- Cross-industry and systemic measures needed:
- Move from a disparate, decentralized landscape to coordinated, enforced minimum cybersecurity standards across industries.
- Stepped-up cybersecurity awareness training to address basic technical weaknesses and user errors that cause most breaches.
- Improve speed of detection, effectiveness of response, and rapid restoration of operations after breaches.
- International cooperation is essential because aggregate global risk can exceed the sum of individual risks due to global IT networks, national response structures, ineffective cooperation, or presence of nation-states among attackers.
Global Cybercrime Industry Matures from Hackers to Businesses - IMF F&D Magazine - June 2018 | Volume 55 | Number 2
Content in this bundle
- صناعة الجريمة الإلكترونية
- La industrialización de la ciberdelincuencia
- La filière bien structurée de la cybercriminalité
- Global Cybercrime Industry Matures from Hackers to Businesses - IMF F&D Magazine - June 2018
- Киберпреступность приобретает индустриальный характер– Финансы и развитие – июнь 2018 года
- 网络犯罪的产业化 - 金融与发展