Examination of Witnesses (Questions 20
- 39)
WEDNESDAY 29 NOVEMBER 2006
MR DAVID
HENDON CBE, MR
GEOFF SMITH,
MR TIM
WRIGHT AND
MR STEPHEN
WEBB
Q20 Baroness Sharp of Guildford:
A couple of years ago the Home Office was working on an e-crime
strategy, which I gather was due to appear in 2005, but equally
in your memorandum there has been no mention of it. What has happened
to it?
Mr Wright: That is true. We are actively pursuing
a strategy to strengthen our response to e-crime, including the
data about e-crime, which we have already touched upon, legislation,
policing, international co-operation and prevention. Over that
period of time we have created SOCA and the SOCA e-crime Directorate
with responsibility for reducing the harm caused to the UK by
technology-based crime. We have created a Child Exploitation and
Online Protection Centre, whose remit is around working in partnership
to protect children and society from paedophiles and sex offenders,
particularly those who use the Internet.[20]
We have negotiated an EU framework decision on attacks against
information systems and implemented that and strengthened the
Computer Misuse Act, and we have made good progress towards ratifying
the Council of Europe Cybercrime Convention. Through the Get Safe
Online campaign we have put in place a partnership between government,
industry and law enforcement to provide good awareness information
to the general public to try and reduce its vulnerability to this.
We have worked closely with the IWF, UK ISPs, search engines and
others to develop technical solutions to make it harder for UK
residents to access child pornography websites. We have worked
with SOCA and through the G8 contact network which involves 45
other countries to strengthen international co-operation. We ran
at least one international event during our presidency of the
EU and G8 last year and have put in place a virtual global taskforce
to start to bring together law enforcement agencies to protect
children as they use the Internet worldwide. As part of its work
to develop control strategies to reduce the harm caused to the
UK by all crime, SOCA has established a national e-crime strategy
group to bring together the relevant government and agency
players to develop a common approach and strategy towards tackling
e-crime. We have not published a strategy, but we have made real
progress in implementing a strategy over the last couple of years
based on some of our consultation with stakeholders and we are
now working with SOCA and the agencies to develop a new strategy
to fit the climate as it currently stands.
Q21 Baroness Sharp of Guildford:
Yes. You have not exactly been idle, have you?
Mr Wright: That was the point I was trying to
make, at length.
Baroness Sharp of Guildford: Yes. Thank
you.
Q22 Lord O'Neill of Clackmannan:
You have indicated that steps have been taken, that the National
High Tech Crime Unit has been set aside and SOCA has taken over.
Is there not a danger that you are going to be concentrating on
high level e-crime and that other equally irritating petty crime
will fall through the SOCA net because it is not big enough for
them to deal with? What consolation can you give the citizen who
is ripped off on a small scale?
Mr Webb: Over recent years, as Tim described,
the National High Tech Crime Unit looked at the particularly major
players, but at the same time we have been trying to build capacity
with ACPO and local forces through computer crime units, through
training and development for specialist police officers in this
area. So we have been trying to build capacity at local forces,
build capacity at SOCA and there has been discussion for some
time about this gap at what is known as level 2, the sort of mid-level
serious organised crime, and that has been identified in the O'Connor
Report on protective services. That is something again we are
working on with ACPO and APA to seek to address. The e-crime team
in SOCA has a very similar remit to the National High Tech Crime
Unit in that it is focusing on the high level and most serious
groups, and nothing has changed there; indeed, the SOCA e-crime
team has more staff than the NHTCU. It is actually strengthened.
Far from having been disbanded, it has been expanded and strengthened.
Q23 Lord O'Neill of Clackmannan:
Can I just be specific here? As far as level 2 crime is concerned,
that is not a high priority at the moment for SOCA and there is
a gap in policing in relation to level 2 crime? Would it be correct
to say that?
Mr Webb: There are gaps in the protective services
which have been recognised by HMIC and we are working to deal
with that. Obviously SOCA is focusing on the most serious threat
to the country, national and international crime, although SOCA
has made it clear that ten per cent of its total effort will be
assisting local forces. So there will be some capacity building,
some technology and knowledge transfer, and so on, but nonetheless
those resources are obviously limited.
Mr Wright: In terms of local forces and e-crime,
I think since 2001 every force now has a Computer Crime Unit.
They have grown significantly in strength over that time. We have
provided through the Central Police Training and Development Authority
a number of courses for both specialist and for all police officers
to take up, to increase skills and knowledge both in the specialist
units and in day to day policing, and we have provided guidance
on how to manage force Computer Crime Units. So it is getting
better but, as Stephen says, there is a gap in how forces deal
with level 2 crime across all types of crime and e-crime is a
subset of that.
Q24 Lord O'Neill of Clackmannan:
Is that a constraint of physical resource in terms of human gains
or financial resource which is preventing you from expanding?
Mr Webb: The HMIC Report looked at a lot of
factors, the critical mass in some forces, the increasing specialisation
of some tasks (and obviously e-crime would be a particularly good
example of that), the difficulty of co-ordinating across border
boundaries. As I say, a lot of work is going on with ways of addressing
that.
Lord O'Neill of Clackmannan: Thank you.
Q25 Lord Howie of Troon:
Earlier on Lord Young here asked if there was a definition of
e-crime and I am not sure that he got a terribly clear answer
to that question! This leads me to ask, how many people are being
prosecuted for e-crime, or are they lumped in under things like
fraud and so on? If you could clear that up for me because I am
in some confusion there.
Mr Wright: It is very much the latter. Not only
do the police databases not distinguish between whether crimes
are committed electronically or not, but nor do the Prosecution
or the Home Office figures distinguish between the two. So we
do not know how many people have been prosecuted for e-crimes
as distinct from offline crimes.
Q26 Lord Howie of Troon:
So is it easy to find appropriate offences to charge them with?
Mr Wright: I think the corollary of not distinguishing
is that actually it is easier to find charges because it is fraud,
it is theft or it is extortion, however you commit it. We spent
a lot of time talking to the CPS and investigators to identify
gaps in the criminal law and to see whether there are people they
cannot prosecute where there has clearly been criminality and
where we find gaps we try and plug them, for example the Computer
Misuse Act, which we have strengthened, and the Fraud Act (as
it is now). By and large, the practitioners tell us the problem
is not finding offences, it is having enough evidence to prove
the offences which is the difficult bit. So no, we do not think
there are gaps in the framework.
Lord Howie of Troon: This is beginning
to lead me to wonder if e-crime actually exists!
Q27 Lord Young of Graffham:
Would it not be of advantage for the police records to at least
show the number of cases in which the Internet was used? It is
like keeping road statistics and not distinguishing between drunken
driving and speeding. You have got to have some idea which crime
is increasing or not.
Mr Wright: Yes, I think is the short answer
to that. There is always a tension between collecting more data
and actually using it, but I think in this instance our view and
ACPO's view in the past has been that we need to be able to understand
what balance of crimes are online and offline to inform (a) how
we tackle it, and (b) resourcing and managing both performance
and resourcing around that. It is something which is not in place
in many forces. It is something which we and ACPO have been working
on and I know the ACPO lead on this issue is talking to colleagues
about this again.
Q28 Lord Howie of Troon:
With some other offences the word "aggravated" is used
to define a specific subspecies of the offence. Would you expect
something of this sort to be done, fraud aggravated by e-crime,
or something? Would that be even remotely sensible?
Mr Webb: It is not obvious why it would be an
aggravating factor. The Sentencing Guidelines Council and Sentencing
Advisory Panel have looked into "seriousness" and what
should be seen as potentially aggravating factors, and there is
quite a recognised list across the board. You have to make a case
for why it was worse to defraud someone over the Internet rather
than sending them the 419 letter by post, or scamming them and
meeting them face to face on the street.
Mr Hendon: Perhaps the value of having a term
like e-crime is that it draws attention to the potential victims
that they may have a crime committed against them in a place where
they would not have previously expected that crime to take place,
so they are not safe when they are sitting at home with their
computers against e-crime, although it is probably fairly safe
that they will not be defrauded in the conventional sense.
Q29 Lord Howie of Troon:
Yes. If you are mugged you would probably notice!
Mr Hendon: You might do, yes. Perhaps it is
as much about it is useful to raise awareness as anything else.
Probably it is not particularly useful from the prosecution point
of view.
Lord Howie of Troon: Thank you.
Q30 Chairman:
In all likelihood you are being defrauded by somebody who is not
even in this country?
Mr Webb: That is quite possible, yes.
Q31 Chairman:
So what are the possibilities of dealing with criminals in other
jurisdictions?
Mr Wright: Obviously it is harder to deal with
a criminal outside the jurisdiction than it is inside the jurisdiction.
The UK has a very good track record of bilateral co-operation
with other countries' law enforcement agencies, I think probably
better than many other countries. We work actively through Interpol,
through Europol, through the G8, through their contact network
of Computer Crime Units, but also bilaterally. The National High
Tech Crime Unit spent a lot of time building contacts directly,
many of which have paid off, and again part of the raison d'être
or one of the benefits of creating SOCA is that lots of crime
is becoming increasingly international and SOCA will be a powerful
vehicle for UK law enforcement in co-operating with colleagues
overseas. The point is, we have had a lot of good results in targeting
serious organised criminal groups out of the jurisdiction. That
is not to pretend it is easier to deal with people overseas than
it is here.
Q32 Chairman:
So do you think it is a possibility that we could have an international
e-crime police force?
Mr Wright: As I have said, the way we have approached
this is to build and strengthen our relationships both bilaterally
and multilaterally with other countries. We have not actively
considered the creation of a global or international police force
as a separate entity. I think there is a number of issues around
resourcing, jurisdiction and around political clout which would
distract us from actually getting on. What we have done, on the
child protection side for example, is create a virtual global
task force to bring together, at the moment only us, America,
Canada, Australia and Interpol, but they are people who work for
national law enforcement and they work closely together on reporting,
on sharing intelligence and on preventative operations, but they
do that from within their own national force. I think in the short
term exploring that kind of avenue for closer working between
national forces is a much quicker way of making progress.
Mr Smith: Can I add, my Lord Chairman, I think
we should also look at the international collaboration around
the prevention of crime. I personally think that the idea of an
international police force in this area is a long way off, but
the banking community is actively working throughout the world
to stop the phishing attacks having an impact. At the moment they
are actually being very successful in cutting off the websites
which host these attacks and the flow of money which arises from
the attacks. So in terms of prevention, I think there is developing
international collaboration both in the communications provider
area and in the financial services area, so there are two sides
to this question.
Q33 Lord Sutherland of Houndwood:
I was going to ask a couple of questions in this area which I
think will follow naturally from the discussion we have just had.
One is a very straightforward one. You mentioned some of the examples.
Are the structures adequate for dealing with international colleagues?
Secondly, do they fit all of your potential partners equally well?
Some countries might be more co-operative than others. What are
the personal relationships like? Can you phone people up and get
a quick response?
Mr Wright: In reverse order, the personal relationships
between law enforcement officers I think are excellent
Q34 Lord Sutherland of Houndwood:
In all countries?
Mr Wright: No, to be absolutely honest.
Q35 Lord Sutherland of Houndwood:
I am not going to ask you for a list!
Mr Wright: Again, I am speaking second-hand,
but if I can go back a point, the UK is better at building those
relationships than pretty much anybody else I can think of and
it works in terms of the operations we have had, good co-operation
and good results, and we have been able to help other countries,
but a lot of that is about personal relationships. Interpol exists
as a global framework, 150-odd countries,[21]
to share intelligence and co-operation. On computer crime there
is a separate Interpol group and there is a G8 network of Computer
Crime Units which has about 45 countries and we got over half
of them together a month ago in Rome to do a training conference,
to try and build those relationships and on a practical level
help people co-operate. I think the structures are okay, and actually
there are some things we need to do bilaterally and will not want
to do in a multilateral forum. So I think from a UK perspective
it could always be better and international co-operation is difficult,
but we are doing as well as anybody could expect.
Q36Lord Sutherland of Houndwood:
Are you sufficiently confident across the board that you can share
information securely? [Pause] I think you have just answered the
question!
Mr Wright: Yes, but I think through traditional
means. I think we share things securely, but through traditional
means.
Q37 Lord Sutherland of Houndwood:
Just a last detailed question. Are there examples where folks
overseas would say, "That was marvellous. The Brits did very
well"? In other words, have there been prosecutions from
abroad of UK residents, the UK-based?
Mr Wright: There have been prosecutions of UK
residents either under UK law or where people have been or are
in the process of being extradited, and we are able to co-operate
and support other people.
Mr Webb: There was a couple of hackers causing
considerable damage in the United States.
Lord Sutherland of Houndwood: Yes, I
remember that case.
Q38 Lord Patel:
I have a series of linked questions. The first one is that the
Get Safe Online survey suggested that the consumers felt more
at risk of Internet crime than they are of being mugged or robbed.
Do you think their perception is wrong?
Mr Smith: I think we were all surprised by that
result. It does seem counter-intuitive and I think perhaps we
need to look a bit more closely at that questionnaire before it
is re-run, but it was run by a legitimate market research company
and I think it had a response rate of around 300. I am not sure
how the respondents were selected, but I think many of us involved
in the Get Safe Online campaign felt a bit uneasy about using
that as our headline message, but that is what the survey showed.
Q39 Lord Patel:
If that was the public's perception, how effective has the campaign
Get Safe Online been?
Mr Smith: I think it is a very good campaign.
I have actually asked the organisers of the campaign to send you
a DVD of the recent campaign, which I think gives a flavour of
how it worked and how it was received. I think if you look at
the number of links to the sites, the number of hits to the sites,
it was an incredibly successful campaign given the relatively
small amount of money which was expended on it. The market research
actually does try and measure its impact and it has found a very
high degree, I think 33 per cent of respondents claimed to recognise
the Get Safe Online brand, and that it was starting to have a
real impact on consumer behaviour. It is, as you say, linked to
some of the earlier questions because I think the phishing attacks
would disappear overnight if people did not give out their personal
information in response to an email from a bank, and if Get Safe
Online can get that message across, if the APACS anti-phishing
campaign can get that message across, then that form of Internet
fraud will wither and die. I think if the Get Safe Online was
getting those basic messages across, "Don't give personal
information out over the Internet. Be careful what sites you visit.
If you click on a link from an unknown or untrusted source, you
will probably be downloading malware. Keep your antivirus up to
date. Patch your system," those basic, if you like, hygiene
issues that consumers need to do to protect themselves then I
think it was successful in those terms.
20 We have also strengthened the capacity of local
police forces to respond to e-crime, as well as providing them
with central training and guidance. Back
21
186 countries Back
|