Feeds

UK police 'not prioritising cybercrime', Microsoft says

'Inadequate' reporting structure

Providing a secure and efficient Helpdesk

The Home Office is not taking cybercrime and related fraud seriously enough, Microsoft says.

The software giant says that cybercrime reporting mechanisms in the UK have been inadequate, since the closure of the National Hi-Tech Crime Unit (NHTCU), whose operations were folded into the Serious Organised Crime Agency (SOCA) last year.

Its critique comes in a hard-hitting submission to a House of Lords Science and Technology Committee inquiry into internet security.

In a written submission to the committee ahead of its oral testimony last week, Microsoft described the scope of the cybercrime problem as "wide and growing". The 22-page document contains a number of significant factoids about the scale of the problem. Microsoft describes internet security problems as encompassing spam messages ("of which we block over three billion a day in Hotmail/Windows Live Mail"), phishing attacks (aiming to tricking users into handing over login credentials for online accounts), malware, spyware, Trojans, viruses and bots.

Last year, Microsoft identified 104 phishing sites in 39 European countries that subsequently becoame the subject of legal enforcement action. Based on these actions, Microsoft concludes that the majority of phishers are males aged between 16 and 20 and that Spain, France, the UK and the Netherlands are the centres of the phishing fraud within Europe.

According to the company, improving online security requires a multi-pronged approach including consumer education, technological practices, and improvements and legal enforcement.

Microsoft critics will doubtless be quick to point out how insecurities in Microsoft's own software have supplied a fertile breeding ground for virus writers and hackers. Naturally enough, Microsoft prefers to emphasise the security improvements brought by Windows XP SP2 and Vista.

SOCA it to them

That debate has been well aired and it's where Microsoft's response to questions about how well the government is equipped to combat cybercrime and on the UK's existing cybercrime laws that the software giant (uncharacteristically) holds forth.

"In the UK, one issue that needs addressing is the problem that cybercrime and related fraud are not presently priority indicators for the police as set by the Home Office. With the changes around SOCA, the proposed re-structuring of police forces, and the disappearance of the NHTCU it is unclear how cybercrime and reporting mechanisms are being systematically addressed. There is no single reporting mechanism in the UK (as there is in the US), thus, no reasonably supported statistics aside from anecdotal information and surveys," it states.

Microsoft suggests that providing a framework for third parties to take action against cyber criminals could provide a way forward.

"What is equally as important is establishing a right of action for third parties. Individual users often lack the technical expertise and financial resources to take action against spammers and other cyber criminals. A third party right of action could protect consumers, which could include our own customers, by bringing damage claims that deter cyber criminals from continuing their activities. Companies could also recover some of the economic losses that cyber criminals cause to them in increased security costs and reputational damage," it said.

Tom Bishop MP (Lab.) comments that comments that Microsoft is essentially saying (albeit diplomatically) that the Home Office "is not interested in cybercrime" and "has no idea of the scale of the problem".

We wanted to speak to the author of Microsoft's submission, but the company was reluctant to discuss the issue any further, at least until the House of Lords committee has completed its inquiry. Instead, Microsoft issued a bland statement that sheds little extra light on the matter.

"Microsoft continues to support and work with the Home Office in helping to combat online crime. We engage with governments and communities worldwide on issues concerning security and internet safety. We welcome the UK government's efforts both in updating the law to help deal with new criminal activity online and with its ongoing dialogue with industry in this area," it said

"We fully support the launch of the House of Lords Science and Technology Committee inquiry into personal internet security. The committee are exploring various options as to how better consumer education, technological improvements, and enhanced legal enforcement can all play a key role in tackling the growing problem of cybercrime. We hope that this inquiry will help highlight the importance of this issue to us all." ®

New hybrid storage solutions

More from The Register

next story
Google recommends pronounceable passwords
Super Chrome goes into battle with Mr Mxyzptlk
Apple Pay is a tidy payday for Apple with 0.15% cut, sources say
Cupertino slurps 15 cents from every $100 purchase
Reddit wipes clean leaked celeb nudie pics, tells users to zip it
Now we've had all THAT TRAFFIC, we 'deplore' this theft
YouTube, Amazon and Yahoo! caught in malvertising mess
Cisco says 'Kyle and Stan' attack is spreading through compromised ad networks
TorrentLocker unpicked: Crypto coding shocker defeats extortionists
Lousy XOR opens door into which victims can shove a foot
Greater dev access to iOS 8 will put us AT RISK from HACKERS
Knocking holes in Apple's walled garden could backfire, says securo-chap
Microsoft to patch ASP.NET mess even if you don't
We know what's good for you, because we made the mess says Redmond
NORKS ban Wi-Fi and satellite internet at embassies
Crackdown on tardy diplomatic sysadmins providing accidental unfiltered internet access
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
Top 5 reasons to deploy VMware with Tegile
Data demand and the rise of virtualization is challenging IT teams to deliver storage performance, scalability and capacity that can keep up, while maximizing efficiency.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.