Select Committee on Science and Technology Minutes of Evidence


Examination of Witnesses (Questions 20 - 39)

WEDNESDAY 29 NOVEMBER 2006

MR DAVID HENDON CBE, MR GEOFF SMITH, MR TIM WRIGHT AND MR STEPHEN WEBB

  Q20  Baroness Sharp of Guildford: A couple of years ago the Home Office was working on an e-crime strategy, which I gather was due to appear in 2005, but equally in your memorandum there has been no mention of it. What has happened to it?

  Mr Wright: That is true. We are actively pursuing a strategy to strengthen our response to e-crime, including the data about e-crime, which we have already touched upon, legislation, policing, international co-operation and prevention. Over that period of time we have created SOCA and the SOCA e-crime Directorate with responsibility for reducing the harm caused to the UK by technology-based crime. We have created a Child Exploitation and Online Protection Centre, whose remit is around working in partnership to protect children and society from paedophiles and sex offenders, particularly those who use the Internet.[20] We have negotiated an EU framework decision on attacks against information systems and implemented that and strengthened the Computer Misuse Act, and we have made good progress towards ratifying the Council of Europe Cybercrime Convention. Through the Get Safe Online campaign we have put in place a partnership between government, industry and law enforcement to provide good awareness information to the general public to try and reduce its vulnerability to this. We have worked closely with the IWF, UK ISPs, search engines and others to develop technical solutions to make it harder for UK residents to access child pornography websites. We have worked with SOCA and through the G8 contact network which involves 45 other countries to strengthen international co-operation. We ran at least one international event during our presidency of the EU and G8 last year and have put in place a virtual global taskforce to start to bring together law enforcement agencies to protect children as they use the Internet worldwide. As part of its work to develop control strategies to reduce the harm caused to the UK by all crime, SOCA has established a national e-crime strategy group to bring together the   relevant government and agency players to develop a common approach and strategy towards tackling e-crime. We have not published a strategy, but we have made real progress in implementing a strategy over the last couple of years based on some of our consultation with stakeholders and we are now working with SOCA and the agencies to develop a new strategy to fit the climate as it currently stands.


  Q21  Baroness Sharp of Guildford: Yes. You have not exactly been idle, have you?

  Mr Wright: That was the point I was trying to make, at length.

  Baroness Sharp of Guildford: Yes. Thank you.

  Q22  Lord O'Neill of Clackmannan: You have indicated that steps have been taken, that the National High Tech Crime Unit has been set aside and SOCA has taken over. Is there not a danger that you are going to be concentrating on high level e-crime and that other equally irritating petty crime will fall through the SOCA net because it is not big enough for them to deal with? What consolation can you give the citizen who is ripped off on a small scale?

  Mr Webb: Over recent years, as Tim described, the National High Tech Crime Unit looked at the particularly major players, but at the same time we have been trying to build capacity with ACPO and local forces through computer crime units, through training and development for specialist police officers in this area. So we have been trying to build capacity at local forces, build capacity at SOCA and there has been discussion for some time about this gap at what is known as level 2, the sort of mid-level serious organised crime, and that has been identified in the O'Connor Report on protective services. That is something again we are working on with ACPO and APA to seek to address. The e-crime team in SOCA has a very similar remit to the National High Tech Crime Unit in that it is focusing on the high level and most serious groups, and nothing has changed there; indeed, the SOCA e-crime team has more staff than the NHTCU. It is actually strengthened. Far from having been disbanded, it has been expanded and strengthened.

  Q23  Lord O'Neill of Clackmannan: Can I just be specific here? As far as level 2 crime is concerned, that is not a high priority at the moment for SOCA and there is a gap in policing in relation to level 2 crime? Would it be correct to say that?

  Mr Webb: There are gaps in the protective services which have been recognised by HMIC and we are working to deal with that. Obviously SOCA is focusing on the most serious threat to the country, national and international crime, although SOCA has made it clear that ten per cent of its total effort will be assisting local forces. So there will be some capacity building, some technology and knowledge transfer, and so on, but nonetheless those resources are obviously limited.

  Mr Wright: In terms of local forces and e-crime, I think since 2001 every force now has a Computer Crime Unit. They have grown significantly in strength over that time. We have provided through the Central Police Training and Development Authority a number of courses for both specialist and for all police officers to take up, to increase skills and knowledge both in the specialist units and in day to day policing, and we have provided guidance on how to manage force Computer Crime Units. So it is getting better but, as Stephen says, there is a gap in how forces deal with level 2 crime across all types of crime and e-crime is a subset of that.

  Q24  Lord O'Neill of Clackmannan: Is that a constraint of physical resource in terms of human gains or financial resource which is preventing you from expanding?

  Mr Webb: The HMIC Report looked at a lot of factors, the critical mass in some forces, the increasing specialisation of some tasks (and obviously e-crime would be a particularly good example of that), the difficulty of co-ordinating across border boundaries. As I say, a lot of work is going on with ways of addressing that.

  Lord O'Neill of Clackmannan: Thank you.

  Q25  Lord Howie of Troon: Earlier on Lord Young here asked if there was a definition of e-crime and I am not sure that he got a terribly clear answer to that question! This leads me to ask, how many people are being prosecuted for e-crime, or are they lumped in under things like fraud and so on? If you could clear that up for me because I am in some confusion there.

  Mr Wright: It is very much the latter. Not only do the police databases not distinguish between whether crimes are committed electronically or not, but nor do the Prosecution or the Home Office figures distinguish between the two. So we do not know how many people have been prosecuted for e-crimes as distinct from offline crimes.

  Q26  Lord Howie of Troon: So is it easy to find appropriate offences to charge them with?

  Mr Wright: I think the corollary of not distinguishing is that actually it is easier to find charges because it is fraud, it is theft or it is extortion, however you commit it. We spent a lot of time talking to the CPS and investigators to identify gaps in the criminal law and to see whether there are people they cannot prosecute where there has clearly been criminality and where we find gaps we try and plug them, for example the Computer Misuse Act, which we have strengthened, and the Fraud Act (as it is now). By and large, the practitioners tell us the problem is not finding offences, it is having enough evidence to prove the offences which is the difficult bit. So no, we do not think there are gaps in the framework.

  Lord Howie of Troon: This is beginning to lead me to wonder if e-crime actually exists!

  Q27  Lord Young of Graffham: Would it not be of advantage for the police records to at least show the number of cases in which the Internet was used? It is like keeping road statistics and not distinguishing between drunken driving and speeding. You have got to have some idea which crime is increasing or not.

  Mr Wright: Yes, I think is the short answer to that. There is always a tension between collecting more data and actually using it, but I think in this instance our view and ACPO's view in the past has been that we need to be able to understand what balance of crimes are online and offline to inform (a) how we tackle it, and (b) resourcing and managing both performance and resourcing around that. It is something which is not in place in many forces. It is something which we and ACPO have been working on and I know the ACPO lead on this issue is talking to colleagues about this again.

  Q28  Lord Howie of Troon: With some other offences the word "aggravated" is used to define a specific subspecies of the offence. Would you expect something of this sort to be done, fraud aggravated by e-crime, or something? Would that be even remotely sensible?

  Mr Webb: It is not obvious why it would be an aggravating factor. The Sentencing Guidelines Council and Sentencing Advisory Panel have looked into "seriousness" and what should be seen as potentially aggravating factors, and there is quite a recognised list across the board. You have to make a case for why it was worse to defraud someone over the Internet rather than sending them the 419 letter by post, or scamming them and meeting them face to face on the street.

  Mr Hendon: Perhaps the value of having a term like e-crime is that it draws attention to the potential victims that they may have a crime committed against them in a place where they would not have previously expected that crime to take place, so they are not safe when they are sitting at home with their computers against e-crime, although it is probably fairly safe that they will not be defrauded in the conventional sense.

  Q29  Lord Howie of Troon: Yes. If you are mugged you would probably notice!

  Mr Hendon: You might do, yes. Perhaps it is as much about it is useful to raise awareness as anything else. Probably it is not particularly useful from the prosecution point of view.

  Lord Howie of Troon: Thank you.

  Q30  Chairman: In all likelihood you are being defrauded by somebody who is not even in this country?

  Mr Webb: That is quite possible, yes.

  Q31  Chairman: So what are the possibilities of dealing with criminals in other jurisdictions?

  Mr Wright: Obviously it is harder to deal with a criminal outside the jurisdiction than it is inside the jurisdiction. The UK has a very good track record of bilateral co-operation with other countries' law enforcement agencies, I think probably better than many other countries. We work actively through Interpol, through Europol, through the G8, through their contact network of Computer Crime Units, but also bilaterally. The National High Tech Crime Unit spent a lot of time building contacts directly, many of which have paid off, and again part of the raison d'être or one of the benefits of creating SOCA is that lots of crime is becoming increasingly international and SOCA will be a powerful vehicle for UK law enforcement in co-operating with colleagues overseas. The point is, we have had a lot of good results in targeting serious organised criminal groups out of the jurisdiction. That is not to pretend it is easier to deal with people overseas than it is here.

  Q32  Chairman: So do you think it is a possibility that we could have an international e-crime police force?

  Mr Wright: As I have said, the way we have approached this is to build and strengthen our relationships both bilaterally and multilaterally with other countries. We have not actively considered the creation of a global or international police force as a separate entity. I think there is a number of issues around resourcing, jurisdiction and around political clout which would distract us from actually getting on. What we have done, on the child protection side for example, is create a virtual global task force to bring together, at the moment only us, America, Canada, Australia and Interpol, but they are people who work for national law enforcement and they work closely together on reporting, on sharing intelligence and on preventative operations, but they do that from within their own national force. I think in the short term exploring that kind of avenue for closer working between national forces is a much quicker way of making progress.

  Mr Smith: Can I add, my Lord Chairman, I think we should also look at the international collaboration around the prevention of crime. I personally think that the idea of an international police force in this area is a long way off, but the banking community is actively working throughout the world to stop the phishing attacks having an impact. At the moment they are actually being very successful in cutting off the websites which host these attacks and the flow of money which arises from the attacks. So in terms of prevention, I think there is developing international collaboration both in the communications provider area and in the financial services area, so there are two sides to this question.

  Q33  Lord Sutherland of Houndwood: I was going to ask a couple of questions in this area which I think will follow naturally from the discussion we have just had. One is a very straightforward one. You mentioned some of the examples. Are the structures adequate for dealing with international colleagues? Secondly, do they fit all of your potential partners equally well? Some countries might be more co-operative than others. What are the personal relationships like? Can you phone people up and get a quick response?

  Mr Wright: In reverse order, the personal relationships between law enforcement officers I think are excellent—

  Q34  Lord Sutherland of Houndwood: In all countries?

  Mr Wright: No, to be absolutely honest.

  Q35  Lord Sutherland of Houndwood: I am not going to ask you for a list!

  Mr Wright: Again, I am speaking second-hand, but if I can go back a point, the UK is better at building those relationships than pretty much anybody else I can think of and it works in terms of the operations we have had, good co-operation and good results, and we have been able to help other countries, but a lot of that is about personal relationships. Interpol exists as a global framework, 150-odd countries,[21] to share intelligence and co-operation. On computer crime there is a separate Interpol group and there is a G8 network of Computer Crime Units which has about 45 countries and we got over half of them together a month ago in Rome to do a training conference, to try and build those relationships and on a practical level help people co-operate. I think the structures are okay, and actually there are some things we need to do bilaterally and will not want to do in a multilateral forum. So I think from a UK perspective it could always be better and international co-operation is difficult, but we are doing as well as anybody could expect.


  Q36Lord Sutherland of Houndwood: Are you sufficiently confident across the board that you can share information securely? [Pause] I think you have just answered the question!

  Mr Wright: Yes, but I think through traditional means. I think we share things securely, but through traditional means.

  Q37  Lord Sutherland of Houndwood: Just a last detailed question. Are there examples where folks overseas would say, "That was marvellous. The Brits did very well"? In other words, have there been prosecutions from abroad of UK residents, the UK-based?

  Mr Wright: There have been prosecutions of UK residents either under UK law or where people have been or are in the process of being extradited, and we are able to co-operate and support other people.

  Mr Webb: There was a couple of hackers causing considerable damage in the United States.

  Lord Sutherland of Houndwood: Yes, I remember that case.

  Q38  Lord Patel: I have a series of linked questions. The first one is that the Get Safe Online survey suggested that the consumers felt more at risk of Internet crime than they are of being mugged or robbed. Do you think their perception is wrong?

  Mr Smith: I think we were all surprised by that result. It does seem counter-intuitive and I think perhaps we need to look a bit more closely at that questionnaire before it is re-run, but it was run by a legitimate market research company and I think it had a response rate of around 300. I am not sure how the respondents were selected, but I think many of us involved in the Get Safe Online campaign felt a bit uneasy about using that as our headline message, but that is what the survey showed.

  Q39  Lord Patel: If that was the public's perception, how effective has the campaign Get Safe Online been?

  Mr Smith: I think it is a very good campaign. I have actually asked the organisers of the campaign to send you a DVD of the recent campaign, which I think gives a flavour of how it worked and how it was received. I think if you look at the number of links to the sites, the number of hits to the sites, it was an incredibly successful campaign given the relatively small amount of money which was expended on it. The market research actually does try and measure its impact and it has found a very high degree, I think 33 per cent of respondents claimed to recognise the Get Safe Online brand, and that it was starting to have a real impact on consumer behaviour. It is, as you say, linked to some of the earlier questions because I think the phishing attacks would disappear overnight if people did not give out their personal information in response to an email from a bank, and if Get Safe Online can get that message across, if the APACS anti-phishing campaign can get that message across, then that form of Internet fraud will wither and die. I think if the Get Safe Online was getting those basic messages across, "Don't give personal information out over the Internet. Be careful what sites you visit. If you click on a link from an unknown or untrusted source, you will probably be downloading malware. Keep your antivirus up to date. Patch your system," those basic, if you like, hygiene issues that consumers need to do to protect themselves then I think it was successful in those terms.


20   We have also strengthened the capacity of local police forces to respond to e-crime, as well as providing them with central training and guidance. Back

21   186 countries Back


 
previous page contents next page

House of Lords home page Parliament home page House of Commons home page search page enquiries index

© Parliamentary copyright 2007