Examination of Witnesses (Questions 1
- 19)
WEDNESDAY 29 NOVEMBER 2006
MR DAVID
HENDON CBE, MR
GEOFF SMITH,
MR TIM
WRIGHT AND
MR STEPHEN
WEBB
Q1 Chairman:
Let me welcome everybody to this meeting of the House of Lords
Select Committee for Science and Technology. This is our first
session where we are taking evidence on the inquiry into Internet
security which we have just begun. So let me welcome all of our
witnesses and all the members of the public who have come today.
There is a note which you can pick up if you have not already
done so which gives the background to the inquiry and the Members
of the Committee. Thank you very much for coming to talk to us,
witnesses, and if we could start by you introducing yourselves
and then we will proceed. Perhaps we could start with you, Mr
Hendon.
Mr Hendon: Thank you. My name is David Hendon.
I am Director of Business Relations 2 in the DTI. That title will
not tell you very much about what I do, which is unfortunate,
but I look after about half of the business sectors, the things
which the DTI does for those sectors, and that includes all of
the communications, IT, electronic sectors and the subject of
this inquiry.
Mr Smith: I am Geoff Smith. I am Deputy Director
of Information, Security and Internet Policy, which is part of
David Hendon's command in DTI.
Mr Webb: I am Stephen Webb, Head of the Organised
Financial Crime Unit in the Home Office. We have responsibility
for a range of organised crime areas, the responsible unit for
the Serious Organised Crime Agency and responsibility for e-crime.
Mr Wright: I am Tim Wright from the Home Office
Computer Crime Team, which is part of the Organised Financial
Crime Unit.
Q2 Chairman:
Thank you very much. Would any of you like to make an opening
statement? Then we will go straight into questions. I will ask
the first question. What is your view of the adequacy of data
on e-crime?
Mr Wright: We look at three sources in assessing
the level of electronic crime; victim surveys, police recorded
crime figures and then other sources, intelligence, insurance
and other kinds of data. In relation to victim surveys for large
and medium sized businesses we have a biennial DTI survey of security
breaches. For households, the British Crime Survey has a specific
module on technology crimes and there is a number of other reputable
surveys around SMEs and around children's use of the Internet.
In terms of victim surveys, we have put in place a reasonable
set of victim surveys. The second source is police recorded crime.
Most e-crime is a form of traditional crime like fraud, theft
or extortion, and therefore the police do not count e-crime separately
to other forms of crime. We did some research on this in the Home
Office and found that only a small number of forces were able
to distinguish between e-crime and other forms of crime, and this
is something we are working on with ACPO and HMIC for the future.
Particularly in relation to e-crime there are many other sources
of data from Honeynets, the IT security industry, ISPs, various
sources of data, which we are not really making the best use of.
This is something we are working with SOCA on for future years'
threat assessments, to routinely gather that kind of information
to give us a much clearer picture of the level of e-crime. I think
we have good victim surveys. Police recording of e-crime is not
what it ought to be and we have a clear solution in place for
gathering other data and putting it all together.
Q3 Chairman:
There is anecdotal evidence that there is rather a low level of
incident reporting, particularly by individuals. What is being
done to improve the level of reporting and how and by whom, and
to what effect is the reported data processed?
Mr Wright: I think it is more than anecdotal.
Certainly the British Crime Survey showed, when it asked people
about viruses and malicious emails, that reporting to anybody
was low and reporting to the police was even lower. So I think
it is stronger than anecdotal. In terms of encouraging reporting,
we have not done an enormous amount. We have done more work around
awareness, around IT security issues and the role of the police,
but we have not done anything particularly to encourage reporting.
There is an online police reporting portal which allows you to
report minor crimes, but again we have not done much to encourage
reporting from individuals.
Lord Young of Graffham: How do you define
e-crime?
Lord Howie of Troon: I was just going
to ask that!
Q4 Lord Young of Graffham:
The reason I ask is because you define it by way of financial
loss, but frankly if a virus comes in and wipes my hard drive,
that could cost me far more money than being mugged in the street?
Mr Wright: I was going to ask the Committee
the same question, actually!
Q5 Lord Young of Graffham:
I got in first!
Mr Wright: Let me say two things. One is, a
lot of people spend a lot of time trying to define e-crime and
come up with variations on the same themes. There is no great
magic to it and I do not think it helps to get hung up about it,
but when we talk about e-crime we mean any form of crime which
is committed either using the Internet or using computers as an
important tool. So a drug trafficker who sends emails, that is
still drug trafficking, but actually a fraud where the initial
contact between the fraudster and the victim is electronic then
I would regard that as e-crime. We have tried not to define e-crime
or organised crime because you would spend a lot of time talking
about what is in and what is out and it does not actually help
you with the problem, I think.
Q6 Lord Young of Graffham:
So over the last 25 years we have migrated from letters from Nigeria
to emails from Nigeria, so at some point that transmuted into
e-crime?
Mr Wright: According to my definition, yes,
but it has always been fraud. It was fraud then and it is fraud
now.
Q7 Chairman:
Do you have any idea of the ratio between e-crime and conventional
crime? Let me give you an example. Say somebody ended up in a
very unsatisfactory eBay deal, maybe because they were ignorant
of what they should do, and they lost several hundred pounds.
My feeling is that they are probably far less likely to report
that than somebody who was mugged or whose house was robbed, where
they would almost certainly report it. Do you think that is the
case?
Mr Wright: There are two questions. One is about
the proportion of crime which is online rather than offline. It
varies between the crime types is my view, and I think a lot of
fraud is electronic based. Certainly access to child pornography
is now virtually all electronic based. With other forms of crime
the proportions are far lower. So I think it varies according
to crime type, but we do not have clear figures as to the clear
proportions for any of those. In terms of where somebody has lost
money through eBay and do they report it, certainly the online
market phenomenon has meant more and more people transacting directly
with each other in an environment where it is more difficult to
gauge trust. If you meet somebody around the back of a pub, well,
you have a view as to how trustworthy they are. That is more difficult
to form online, so there have been more person to person transactions.
Some of those get reported and some of them do not. I think people
do not report to the police because they do not always think the
police can help. The desk sergeants are not always as keen to
take those kinds of reports as possible and there is not always
a clear geographic nexus, and actually some people who get ripped
off on eBayit is like buying things around the back of
the pub, sometimes people know what they are buying. It is not
necessarily the same as buying from a high street shop.
Q8 Lord O'Neill of Clackmannan:
Are you concerned about the reluctance of financial institutions
to make a clean breast, you might say, of the amount of incidents
they have? We all know, for example, with credit cards you have
a degree of protection and therefore there is maybe only a hundred
pounds at risk, therefore it is not very much, but nevertheless
is it crime. Are you happy with the amount of information which
is provided by the financial institutions, whose probity or security
might be undermined if they were unduly frank about their losses?
Mr Wright: The National High Tech Crime Unit
and SOCA have very close relationships with the banking sector
and have built up a relationship of trust and of information sharing
and confidentiality, and I think they have strong relationships
and there is a lot of information sharing, and there have been
some notable operational successes off the back of that.
Q9 Lord O'Neill of Clackmannan:
But that does not make the public records any more robust, does
it?
Mr Wright: No, it does not.
Mr Webb: I think APACS, the Association of Payment
and Clearing Services is the main forum there by which the industry
reports these sorts of data and that is definitely one of the
better data sources in the fraud area. The Government's Fraud
Review noted the problem of under-reporting of fraud compared
with other kinds of crimes, and I think that applies every bit
as much in the e-crime area as it does for other sorts of fraud.
So the financial sector, the card fraud data and the data we are
getting on online banking fraud is probably some of the better
fraud data that is out there.
Q10 Lord Sutherland of Houndwood:
Presumably in the case of e-crime you are more dependent upon
the victim reporting it, because if it is not an e-crime there
could be independent witnesses but in the case of e-crime somebody
has got to own up and say "this happened to me through this
particular route," and that is bound to affect the statistics?
Mr Wright: I do see your point, but I think
the surrogate for independent witnesses is either transactions
through payment mechanisms or through ISPs. If one person reports
and you do an investigation, then the police try to trace the
individual and they find hundreds of other victims. I am not sure
the analogy quite works, but I think to get it electronically
Q11 Lord Sutherland of Houndwood:
The first step has to be somebody saying, "I was cheated
through this"
Mr Wright: Yes, but once you have got that you
could find many other victims in a way that you cannot offline,
so yes and no, I think.
Q12 Lord Young of Graffham:
Whilst we are on online banking and fraud, your memorandum said
that online banking fraud went up by no less than 90 per cent
between 2004 and 2005. I assume, in the absence of anything else,
it is probably continuing to increase now. First of all, why do
you think it is going up? Are there any defects in the systems?
Secondly, how much longer can this continue to rise before you
undermine the very basis of online banking?
Mr Webb: Again, this is an area where we have
been working quite closely with APACS and the financial sector
and it is certainly an area they are keeping a very close eye
on. The absolute levels of losses are still a small proportion
of their losses are their card losses, for example, still less
than five per cent, but it is a very sharp increase. A lot of
this is probably attributable to being reasonably in step to the
actual amount of Internet banking. Over the same period we have
had probably a one-third increase in the number of Internet banking
customers. The financial sector is not able to work out by transaction
which of them were done on the Internet and which were through
other means because it goes through the same clearing system,
but it is probable that the individuals are using their Internet
banking side more. So a lot of this is attributable to the fact
that there is more Internet banking going on and the fraud is
not necessarily rising as a proportion of that, but it is something
which we in the financial sector look at and there are ideas for
additional security. Obviously the financial sector has just invested
in chip-and-PIN, a £1 billion programme which has just come
to an end and is already having an increase on certain sorts of
frauds. Probably there has been a certain amount of displacement
from that into this area because the fraudsters are determined
to make their profits somewhere.
Q13 Lord Howie of Troon:
Did you say that the apparently large increase from a small base
was rather likeyou remember Jonathan Swift talking about
the man who made two blades of grass grow where one did before,
which is an increase of 100 per cent, but it is really not very
much? Is that what you are telling us?
Mr Webb: No. There are two things. First, we
are saying that relative to the overall scales of losses to the
banking industry this is still relatively small, but obviously
the rate of growth is very striking. But you also have to look
at the rate of growth relative to the overall size of the industry.
If the industry is growing at a huge rate, it would suggest that
fraud as a proportion is relatively stable. We are not quite sure
of our statistics, but certainly a lot of that increase is probably
explained by the huge expansion in the amount of use.
Q14 Lord Howie of Troon:
So you expect the 90 per cent increase to reduce year after yearif
you are lucky?
Mr Webb: It is hard to tell. You have got 16
million customers at the moment. You would not expect the expansion
to continue at quite the same rate and the number of people who
have been going over to broadband, which makes these sorts of
services easier to access, has clearly been a factor and at some
stage that is going to plateau. The industry is going to keep
a very close eye, and as are we, on the scale of losses and what
countermeasures we need.
Q15 Lord Young of Graffham:
Could I just follow up on that? If there is online banking fraud
you would expect the customer to complain if £20 was taken
out of his account, or whatever. Do you think the same person
would complain because he bought something on the Internet for
£10 or £20 which was never delivered? In other words,
is there a threshold under which people will just not be bothered
to go to the police and write it off as a bad experience, whereas
with online banking they will?
Mr Webb: I suspect with online banking they
would have that much more confidence that they would get redress
from the bank, so they would report it first to the bank, and
that is why this very often happens.
Mr Wright: I do not think there is a threshold,
but I think people traditionally weigh up whether to report a
crime to the police or not very carefully. There is the time and
the trouble and what you get back, and if they see no likelihood
of getting their money back lots of people do not report it. Things
like insurance claims require a police crime number, which has
driven up reporting.
Q16 Lord Young of Graffham:
So there could be quite a lot of low level crime? If somebody
buys dodgy goods on the Internet which never get delivered and
he never complains, things of that sort?
Mr Webb: Yes.
Q17 Lord Sutherland of Houndwood:
I would like to put to you two suggestions which have been put
to us which have been related. The first is that there is a lack
of effective legal sanctions to prevent the abuse of personal
data, and the second suggestion following from that is that as
a consequence London has become a base for international phishing
expeditions and that sort of crime? These are two, as I say, linked
suggestions put to us. Could I have your comments?
Mr Webb: If I could take them in reverse order.
We are not aware that London is seen as a particularly large centre
for these kinds of attacks. It is not something we, or SOCA or
the City of London Police (Fraud) recognise, and it is not something
we are hearing from our international partners, that many of the
problems appear to be coming from the UK. Similarly, some of the
frauds are going to be as a result of the misuse of data and some
are going to be the result of other means of deception. The Information
Commissioner, as you know, published a consultation paper called
What Price Privacy? which has been consulted on by the Department
for Constitutional Affairs. The consultation period has finished
and they are now considering the responses, which have been generally
very positive. So the DCA will be considering what to do and will
need a legislative vehicle to increase the penalties in Section
55 of the Data Protection Act. That is something which is certainly
under active consideration at the moment. We have not seen any
evidence of a particular link between the sorts of Internet e-banking
frauds we are talking about and this particular abuse of data.
With phishing attacks, for example, the modus operandi would be
rather different.
Q18 Lord Sutherland of Houndwood:
Yes, but I take it from the way in which you have answered the
question that there is a real issue about the effect of sanctions
on the abuse of data, and indeed the Commissioner in the report
you referred to suggested a minimum two year sentence for certain
crimes in this area. Is the Government going to take that on board?
Mr Webb: As I say, it is a matter for the Department
of Constitutional Affairs, which leads on the Data Protection
Act. The Commissioner has certainly made a powerful case and the
responses to the DCA's consultation exercise, I understand, have
been generally supportive.
Q19 Lord Sutherland of Houndwood:
Is there a timescale on that?
Mr Webb: I would not be able to comment on that.
I do not know.
|