Feeds

UK police 'not prioritising cybercrime', Microsoft says

'Inadequate' reporting structure

Using blade systems to cut costs and sharpen efficiencies

The Home Office is not taking cybercrime and related fraud seriously enough, Microsoft says.

The software giant says that cybercrime reporting mechanisms in the UK have been inadequate, since the closure of the National Hi-Tech Crime Unit (NHTCU), whose operations were folded into the Serious Organised Crime Agency (SOCA) last year.

Its critique comes in a hard-hitting submission to a House of Lords Science and Technology Committee inquiry into internet security.

In a written submission to the committee ahead of its oral testimony last week, Microsoft described the scope of the cybercrime problem as "wide and growing". The 22-page document contains a number of significant factoids about the scale of the problem. Microsoft describes internet security problems as encompassing spam messages ("of which we block over three billion a day in Hotmail/Windows Live Mail"), phishing attacks (aiming to tricking users into handing over login credentials for online accounts), malware, spyware, Trojans, viruses and bots.

Last year, Microsoft identified 104 phishing sites in 39 European countries that subsequently becoame the subject of legal enforcement action. Based on these actions, Microsoft concludes that the majority of phishers are males aged between 16 and 20 and that Spain, France, the UK and the Netherlands are the centres of the phishing fraud within Europe.

According to the company, improving online security requires a multi-pronged approach including consumer education, technological practices, and improvements and legal enforcement.

Microsoft critics will doubtless be quick to point out how insecurities in Microsoft's own software have supplied a fertile breeding ground for virus writers and hackers. Naturally enough, Microsoft prefers to emphasise the security improvements brought by Windows XP SP2 and Vista.

SOCA it to them

That debate has been well aired and it's where Microsoft's response to questions about how well the government is equipped to combat cybercrime and on the UK's existing cybercrime laws that the software giant (uncharacteristically) holds forth.

"In the UK, one issue that needs addressing is the problem that cybercrime and related fraud are not presently priority indicators for the police as set by the Home Office. With the changes around SOCA, the proposed re-structuring of police forces, and the disappearance of the NHTCU it is unclear how cybercrime and reporting mechanisms are being systematically addressed. There is no single reporting mechanism in the UK (as there is in the US), thus, no reasonably supported statistics aside from anecdotal information and surveys," it states.

Microsoft suggests that providing a framework for third parties to take action against cyber criminals could provide a way forward.

"What is equally as important is establishing a right of action for third parties. Individual users often lack the technical expertise and financial resources to take action against spammers and other cyber criminals. A third party right of action could protect consumers, which could include our own customers, by bringing damage claims that deter cyber criminals from continuing their activities. Companies could also recover some of the economic losses that cyber criminals cause to them in increased security costs and reputational damage," it said.

Tom Bishop MP (Lab.) comments that comments that Microsoft is essentially saying (albeit diplomatically) that the Home Office "is not interested in cybercrime" and "has no idea of the scale of the problem".

We wanted to speak to the author of Microsoft's submission, but the company was reluctant to discuss the issue any further, at least until the House of Lords committee has completed its inquiry. Instead, Microsoft issued a bland statement that sheds little extra light on the matter.

"Microsoft continues to support and work with the Home Office in helping to combat online crime. We engage with governments and communities worldwide on issues concerning security and internet safety. We welcome the UK government's efforts both in updating the law to help deal with new criminal activity online and with its ongoing dialogue with industry in this area," it said

"We fully support the launch of the House of Lords Science and Technology Committee inquiry into personal internet security. The committee are exploring various options as to how better consumer education, technological improvements, and enhanced legal enforcement can all play a key role in tackling the growing problem of cybercrime. We hope that this inquiry will help highlight the importance of this issue to us all." ®

Boost IT visibility and business value

More from The Register

next story
Secure microkernel that uses maths to be 'bug free' goes open source
Hacker-repelling, drone-protecting code will soon be yours to tweak as you see fit
14 antivirus apps found to have security problems
Vendors just don't care, says researcher, after finding basic boo-boos in security software
How long is too long to wait for a security fix?
Synology finally patches OpenSSL bugs in Trevor's NAS
Israel's Iron Dome missile tech stolen by Chinese hackers
Corporate raiders Comment Crew fingered for attacks
Only '3% of web servers in top corps' fully fixed after Heartbleed snafu
Just slapping a patched OpenSSL on a machine ain't going to cut it, we're told
Roll out the welcome mat to hackers and crackers
Security chap pens guide to bug bounty programs that won't fail like Yahoo!'s
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
Researcher sat on critical IE bugs for THREE YEARS
VUPEN waited for Pwn2Own cash while IE's sandbox leaked
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Application security programs and practises
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
How modern custom applications can spur business growth
Learn how to create, deploy and manage custom applications without consuming or expanding the need for scarce, expensive IT resources.
Securing Web Applications Made Simple and Scalable
Learn how automated security testing can provide a simple and scalable way to protect your web applications.