Select Committee on Science and Technology Minutes of Evidence


Examination of Witnesses (Questions 1 - 19)

WEDNESDAY 29 NOVEMBER 2006

MR DAVID HENDON CBE, MR GEOFF SMITH, MR TIM WRIGHT AND MR STEPHEN WEBB

  Q1  Chairman: Let me welcome everybody to this meeting of the House of Lords Select Committee for Science and Technology. This is our first session where we are taking evidence on the inquiry into Internet security which we have just begun. So let me welcome all of our witnesses and all the members of the public who have come today. There is a note which you can pick up if you have not already done so which gives the background to the inquiry and the Members of the Committee. Thank you very much for coming to talk to us, witnesses, and if we could start by you introducing yourselves and then we will proceed. Perhaps we could start with you, Mr Hendon.

  Mr Hendon: Thank you. My name is David Hendon. I am Director of Business Relations 2 in the DTI. That title will not tell you very much about what I do, which is unfortunate, but I look after about half of the business sectors, the things which the DTI does for those sectors, and that includes all of the communications, IT, electronic sectors and the subject of this inquiry.

  Mr Smith: I am Geoff Smith. I am Deputy Director of Information, Security and Internet Policy, which is part of David Hendon's command in DTI.

  Mr Webb: I am Stephen Webb, Head of the Organised Financial Crime Unit in the Home Office. We have responsibility for a range of organised crime areas, the responsible unit for the Serious Organised Crime Agency and responsibility for e-crime.

  Mr Wright: I am Tim Wright from the Home Office Computer Crime Team, which is part of the Organised Financial Crime Unit.

  Q2  Chairman: Thank you very much. Would any of you like to make an opening statement? Then we will go straight into questions. I will ask the first question. What is your view of the adequacy of data on e-crime?

  Mr Wright: We look at three sources in assessing the level of electronic crime; victim surveys, police recorded crime figures and then other sources, intelligence, insurance and other kinds of data. In relation to victim surveys for large and medium sized businesses we have a biennial DTI survey of security breaches. For households, the British Crime Survey has a specific module on technology crimes and there is a number of other reputable surveys around SMEs and around children's use of the Internet. In terms of victim surveys, we have put in place a reasonable set of victim surveys. The second source is police recorded crime. Most e-crime is a form of traditional crime like fraud, theft or extortion, and therefore the police do not count e-crime separately to other forms of crime. We did some research on this in the Home Office and found that only a small number of forces were able to distinguish between e-crime and other forms of crime, and this is something we are working on with ACPO and HMIC for the future. Particularly in relation to e-crime there are many other sources of data from Honeynets, the IT security industry, ISPs, various sources of data, which we are not really making the best use of. This is something we are working with SOCA on for future years' threat assessments, to routinely gather that kind of information to give us a much clearer picture of the level of e-crime. I think we have good victim surveys. Police recording of e-crime is not what it ought to be and we have a clear solution in place for gathering other data and putting it all together.

  Q3  Chairman: There is anecdotal evidence that there is rather a low level of incident reporting, particularly by individuals. What is being done to improve the level of reporting and how and by whom, and to what effect is the reported data processed?

  Mr Wright: I think it is more than anecdotal. Certainly the British Crime Survey showed, when it asked people about viruses and malicious emails, that reporting to anybody was low and reporting to the police was even lower. So I think it is stronger than anecdotal. In terms of encouraging reporting, we have not done an enormous amount. We have done more work around awareness, around IT security issues and the role of the police, but we have not done anything particularly to encourage reporting. There is an online police reporting portal which allows you to report minor crimes, but again we have not done much to encourage reporting from individuals.

  Lord Young of Graffham: How do you define e-crime?

  Lord Howie of Troon: I was just going to ask that!

  Q4  Lord Young of Graffham: The reason I ask is because you define it by way of financial loss, but frankly if a virus comes in and wipes my hard drive, that could cost me far more money than being mugged in the street?

  Mr Wright: I was going to ask the Committee the same question, actually!

  Q5  Lord Young of Graffham: I got in first!

  Mr Wright: Let me say two things. One is, a lot of people spend a lot of time trying to define e-crime and come up with variations on the same themes. There is no great magic to it and I do not think it helps to get hung up about it, but when we talk about e-crime we mean any form of crime which is committed either using the Internet or using computers as an important tool. So a drug trafficker who sends emails, that is still drug trafficking, but actually a fraud where the initial contact between the fraudster and the victim is electronic then I would regard that as e-crime. We have tried not to define e-crime or organised crime because you would spend a lot of time talking about what is in and what is out and it does not actually help you with the problem, I think.

  Q6  Lord Young of Graffham: So over the last 25 years we have migrated from letters from Nigeria to emails from Nigeria, so at some point that transmuted into e-crime?

  Mr Wright: According to my definition, yes, but it has always been fraud. It was fraud then and it is fraud now.

  Q7  Chairman: Do you have any idea of the ratio between e-crime and conventional crime? Let me give you an example. Say somebody ended up in a very unsatisfactory eBay deal, maybe because they were ignorant of what they should do, and they lost several hundred pounds. My feeling is that they are probably far less likely to report that than somebody who was mugged or whose house was robbed, where they would almost certainly report it. Do you think that is the case?

  Mr Wright: There are two questions. One is about the proportion of crime which is online rather than offline. It varies between the crime types is my view, and I think a lot of fraud is electronic based. Certainly access to child pornography is now virtually all electronic based. With other forms of crime the proportions are far lower. So I think it varies according to crime type, but we do not have clear figures as to the clear proportions for any of those. In terms of where somebody has lost money through eBay and do they report it, certainly the online market phenomenon has meant more and more people transacting directly with each other in an environment where it is more difficult to gauge trust. If you meet somebody around the back of a pub, well, you have a view as to how trustworthy they are. That is more difficult to form online, so there have been more person to person transactions. Some of those get reported and some of them do not. I think people do not report to the police because they do not always think the police can help. The desk sergeants are not always as keen to take those kinds of reports as possible and there is not always a clear geographic nexus, and actually some people who get ripped off on eBay—it is like buying things around the back of the pub, sometimes people know what they are buying. It is not necessarily the same as buying from a high street shop.

  Q8  Lord O'Neill of Clackmannan: Are you concerned about the reluctance of financial institutions to make a clean breast, you might say, of the amount of incidents they have? We all know, for example, with credit cards you have a degree of protection and therefore there is maybe only a hundred pounds at risk, therefore it is not very much, but nevertheless is it crime. Are you happy with the amount of information which is provided by the financial institutions, whose probity or security might be undermined if they were unduly frank about their losses?

  Mr Wright: The National High Tech Crime Unit and SOCA have very close relationships with the banking sector and have built up a relationship of trust and of information sharing and confidentiality, and I think they have strong relationships and there is a lot of information sharing, and there have been some notable operational successes off the back of that.

  Q9  Lord O'Neill of Clackmannan: But that does not make the public records any more robust, does it?

  Mr Wright: No, it does not.

  Mr Webb: I think APACS, the Association of Payment and Clearing Services is the main forum there by which the industry reports these sorts of data and that is definitely one of the better data sources in the fraud area. The Government's Fraud Review noted the problem of under-reporting of fraud compared with other kinds of crimes, and I think that applies every bit as much in the e-crime area as it does for other sorts of fraud. So the financial sector, the card fraud data and the data we are getting on online banking fraud is probably some of the better fraud data that is out there.

  Q10  Lord Sutherland of Houndwood: Presumably in the case of e-crime you are more dependent upon the victim reporting it, because if it is not an e-crime there could be independent witnesses but in the case of e-crime somebody has got to own up and say "this happened to me through this particular route," and that is bound to affect the statistics?

  Mr Wright: I do see your point, but I think the surrogate for independent witnesses is either transactions through payment mechanisms or through ISPs. If one person reports and you do an investigation, then the police try to trace the individual and they find hundreds of other victims. I am not sure the analogy quite works, but I think to get it electronically—

  Q11  Lord Sutherland of Houndwood: The first step has to be somebody saying, "I was cheated through this"—

  Mr Wright: Yes, but once you have got that you could find many other victims in a way that you cannot offline, so yes and no, I think.

  Q12  Lord Young of Graffham: Whilst we are on online banking and fraud, your memorandum said that online banking fraud went up by no less than 90 per cent between 2004 and 2005. I assume, in the absence of anything else, it is probably continuing to increase now. First of all, why do you think it is going up? Are there any defects in the systems? Secondly, how much longer can this continue to rise before you undermine the very basis of online banking?

  Mr Webb: Again, this is an area where we have been working quite closely with APACS and the financial sector and it is certainly an area they are keeping a very close eye on. The absolute levels of losses are still a small proportion of their losses are their card losses, for example, still less than five per cent, but it is a very sharp increase. A lot of this is probably attributable to being reasonably in step to the actual amount of Internet banking. Over the same period we have had probably a one-third increase in the number of Internet banking customers. The financial sector is not able to work out by transaction which of them were done on the Internet and which were through other means because it goes through the same clearing system, but it is probable that the individuals are using their Internet banking side more. So a lot of this is attributable to the fact that there is more Internet banking going on and the fraud is not necessarily rising as a proportion of that, but it is something which we in the financial sector look at and there are ideas for additional security. Obviously the financial sector has just invested in chip-and-PIN, a £1 billion programme which has just come to an end and is already having an increase on certain sorts of frauds. Probably there has been a certain amount of displacement from that into this area because the fraudsters are determined to make their profits somewhere.

  Q13  Lord Howie of Troon: Did you say that the apparently large increase from a small base was rather like—you remember Jonathan Swift talking about the man who made two blades of grass grow where one did before, which is an increase of 100 per cent, but it is really not very much? Is that what you are telling us?

  Mr Webb: No. There are two things. First, we are saying that relative to the overall scales of losses to the banking industry this is still relatively small, but obviously the rate of growth is very striking. But you also have to look at the rate of growth relative to the overall size of the industry. If the industry is growing at a huge rate, it would suggest that fraud as a proportion is relatively stable. We are not quite sure of our statistics, but certainly a lot of that increase is probably explained by the huge expansion in the amount of use.

  Q14  Lord Howie of Troon: So you expect the 90 per cent increase to reduce year after year—if you are lucky?

  Mr Webb: It is hard to tell. You have got 16 million customers at the moment. You would not expect the expansion to continue at quite the same rate and the number of people who have been going over to broadband, which makes these sorts of services easier to access, has clearly been a factor and at some stage that is going to plateau. The industry is going to keep a very close eye, and as are we, on the scale of losses and what countermeasures we need.

  Q15  Lord Young of Graffham: Could I just follow up on that? If there is online banking fraud you would expect the customer to complain if £20 was taken out of his account, or whatever. Do you think the same person would complain because he bought something on the Internet for £10 or £20 which was never delivered? In other words, is there a threshold under which people will just not be bothered to go to the police and write it off as a bad experience, whereas with online banking they will?

  Mr Webb: I suspect with online banking they would have that much more confidence that they would get redress from the bank, so they would report it first to the bank, and that is why this very often happens.

  Mr Wright: I do not think there is a threshold, but I think people traditionally weigh up whether to report a crime to the police or not very carefully. There is the time and the trouble and what you get back, and if they see no likelihood of getting their money back lots of people do not report it. Things like insurance claims require a police crime number, which has driven up reporting.

  Q16  Lord Young of Graffham: So there could be quite a lot of low level crime? If somebody buys dodgy goods on the Internet which never get delivered and he never complains, things of that sort?

  Mr Webb: Yes.

  Q17  Lord Sutherland of Houndwood: I would like to put to you two suggestions which have been put to us which have been related. The first is that there is a lack of effective legal sanctions to prevent the abuse of personal data, and the second suggestion following from that is that as a consequence London has become a base for international phishing expeditions and that sort of crime? These are two, as I say, linked suggestions put to us. Could I have your comments?

  Mr Webb: If I could take them in reverse order. We are not aware that London is seen as a particularly large centre for these kinds of attacks. It is not something we, or SOCA or the City of London Police (Fraud) recognise, and it is not something we are hearing from our international partners, that many of the problems appear to be coming from the UK. Similarly, some of the frauds are going to be as a result of the misuse of data and some are going to be the result of other means of deception. The Information Commissioner, as you know, published a consultation paper called What Price Privacy? which has been consulted on by the Department for Constitutional Affairs. The consultation period has finished and they are now considering the responses, which have been generally very positive. So the DCA will be considering what to do and will need a legislative vehicle to increase the penalties in Section 55 of the Data Protection Act. That is something which is certainly under active consideration at the moment. We have not seen any evidence of a particular link between the sorts of Internet e-banking frauds we are talking about and this particular abuse of data. With phishing attacks, for example, the modus operandi would be rather different.

  Q18  Lord Sutherland of Houndwood: Yes, but I take it from the way in which you have answered the question that there is a real issue about the effect of sanctions on the abuse of data, and indeed the Commissioner in the report you referred to suggested a minimum two year sentence for certain crimes in this area. Is the Government going to take that on board?

  Mr Webb: As I say, it is a matter for the Department of Constitutional Affairs, which leads on the Data Protection Act. The Commissioner has certainly made a powerful case and the responses to the DCA's consultation exercise, I understand, have been generally supportive.

  Q19  Lord Sutherland of Houndwood: Is there a timescale on that?

  Mr Webb: I would not be able to comment on that. I do not know.


 
previous page contents next page

House of Lords home page Parliament home page House of Commons home page search page enquiries index

© Parliamentary copyright 2007