Memorandum by the Association for Payment
Clearing Services (APACS)
Our input consists of our reaction to HM Government's
response highlighting the areas of greatest concern to APACS and
its members, and our suggestions to help guide the Committee's
future deliberations.
APACS COMMENT ON
HM GOVERNMENT'S
RESPONSE
1. "We recommend that the Government
establish a cross-departmental group, bringing in experts from
industry and academia, to develop a more co-ordinated approach
to data collection in future. This should include a classification
scheme for the recording of all forms of e-crime".
The Government is correct in saying that crimes
committed by computer are "standard offences facilitated
by new technology" this does not mitigate the need for developing
greater understanding. The correct measurement of crime is an
important step in the process of understanding the impact of certain
types of criminality, and from there to understanding how to define
and allocate the resources required to tackle them. In the case
of e-crime, there are a range of techniques and skills used by
criminals that are highly specialised and that therefore require
a specialised response. If the Government is not in a good position
to understand the nature of the crimes being committed, then it
follows that it won't be in a good position to understand how
to direct law enforcement and the courts accordingly, or to develop
appropriate legislation. We therefore encourage the Committee
to focus on helping to create the conditions for policy makers
to better understand the impact of e-crime.
2. "We recommend that the Research
Councils take the lead in initiating discussions with Government,
universities and industry with a view to the prompt establishment
of an initial centre in this country. We urge the Crown Prosecution
Service to publish the guidance as soon as possible, so as to
avoid undermining such research in the interim".
We are broadly supportive of the Government's
response to this recommendation. However, we would add that the
UK lacks and continues to lack a Computer Emergency Response Team
(CERT) that is capablein terms of skilled resource and
mandateof assisting in the fight against e-crime, and that
we consider this to be a serious shortcoming. We would urge the
Committee to examine in depth the leading global exemplars of
such CERTs, namely AusCERT in Australia, CERT/CC in the USA and
CERT.BR in Brazil. These three in particular have developed far-reaching
capabilities that have proved of enormous value in the fight against
e-crime. It continues to frustrate practitioners and security
experts in the UK that we have no direct equivalent, and we believe
that its continued lack has contributed to the UK suffering disproportionately
from e-crime.
3. "We recommend that the Research
Councils continue to give such fundamental research priority".
We have no comment on the Government's response.
4. "It is time for the Government
to develop a more holistic understanding of the distributed responsibility
for personal internet security".
We understood the spirit of the Committee's
recommendation to be, that the Government should take a more active
role in understanding what various public and private sector stakeholders
can do to help maintain personal internet security, and that it
should work proactively to ensure that these responsibilities
are being upheld. In this APACS strongly supports the Committee's
recommendation and we would argue that acceptance of it as a principle
by the government would greatly assist in supporting many of Committee's
other recommendations.
5. "We recommend the development
of a BSI-approved kite mark for secure internet services. We further
recommend that this voluntary approach should be reinforced by
an undertaking that in the longer term on obligation will be placed
on ISPs to provide a good standard of security as part of their
regulated service. We recommend that the ISPs should be encouraged
as part of the Kite mark scheme to monitor and detect "bad"
ongoing traffic from their customers".
As banking customers increasingly shift more
of their transactional and banking activity online, they become
increasingly reliant on the security of services offered by ISPs.
APACS is supportive of moves to encourage ISPs to improve the
level of security that they offer to their customers, and to take
a more proactive stance to identify and prevent "bad"
traffic from their customers. We believe that these developments
are best left to industry and competition to provide, but we also
believe that the Government has a strong role to play in promoting
the principle of a safer internet, and the specific steps needed
to achieve it.
There are a number of self-regulatory approaches
that could serve as examples for working further on this recommendation,
ie The Banking Code. The 2008 edition of the Code enshrines a
guarantee that online banking customers will not be liable for
any losses if they are the innocent victim of fraud.
6. "We recommend that the `mere
conduit' immunity should be removed once ISPs have detected or
been notified of the fact that machines on their network are sending
out spam or infected code".
Revocation of mere conduit, even on a selective
basis, is likely to be an enormously complex challenge, but one
that we believe could yield positive benefits if done with sensitivity.
Whilst the Government is correct to say that many ISPs do take
proactive steps against customers whose machines are sending out
spam or infected code, many more either do so with varying degrees
of effectiveness or not at all. Indeed one could argue that the
current data on this speaks for itself. For example, the UK is
a leading source of botnet-infected computers, and UK bank brands
are regularly amongst the most heavily targeted by phishing gangs.
By offering clarity on the extent of mere conduit provisions,
ISPs would be in a better position to understand their areas of
responsibility, and the market would be provided with a higher
baseline of response from ISPs.
7. "We recommend instead that VOIP
providers be encouraged to provide a 999 service on a "best
efforts" basis reflecting the reality of Internet traffic,
provided that they also make clear to customers the limitations
of their service and the possibility that it may not always work
when it is needed".
We have no comment on Government's response.
8. "We recommend that the Government
explore, at European level, the introduction of the principle
of vendor liability with the IT industry".
We have no comment on the Government's response.
9. "The steps being currently undertaken
by many businesses trading over the internet to protect their
customers' personal information are inadequate. The refusal of
the financial services sector in particular to accept responsibility
for the security of personal information is disturbing, and is
compounded by apparent indifference at Government level. Governments
and legislators are not in a position to prescribe the security
precautions that should be taken; however, they do have responsibility
to ensure that the right incentives are in place to persuade businesses
to take the necessary steps to act proportionately to protect
data".
We are broadly supportive of the Government's
response to this recommendation. We do not accept that the financial
services sector "refuses to accept responsibility for
the security of personal information". The financial
services sector responsibilities in this area are very clear and
at all times individual institutions lay these out in their communications
with customers and overall account terms and conditions. For example,
section 11 of The Banking Code sets our subscribers' responsibilities
in respect of personal customer information.
The financial services sector takes the security
of our customers' data extremely seriously and it would be true
to say that our success in maintaining an appropriate level of
security is demonstrated by the high and growing level of online
banking usage.
APACS members and the wider banking community,
have also been instrumental in driving the implementation of a
number of initiatives designed to greatly strengthen arrangements
for the protection of customer data. For example, the Payment
Card Industry Data Security Standards (PCI/DSS) are intended to
protect sensitive customer data that may be held by merchants
and others engaged in accepting and processing face to face and
remote card payments. PCI/DSS is being implemented on a global
basis and represents one of the most significant developments
to protect customer data yet seen.
In the specific field of online banking fraud,
banks have taken aggressive steps to identify and remove sensitive
customer information from the Internet, for example, in the form
of log files generated by malicious spyware that has infected
customer PCs. However their efforts are often hampered by ineffective
or obstructive local legislation in many countries. For example,
under the law of a number of countries including several US states,
data on compromised customers gathered by spyware or phishing
sites, and located on an open web server, is considered to be
the property of the criminal and obtaining or deleting the data
may itself be considered a crime. This astonishing state of affairs
means that there are occasions where enormous obstacles are placed
in front of those committed to fighting this type of crime.
We would wish to see the Government taking steps
to ensure that law enforcement is able to swiftly and effectively
demand the removal of sensitive personal data from online sites,
and that the Government takes a leading role in promoting this
stance on a global basis to ensure that criminals have no place
to hide.
10. "We therefore recommend that
the Government introduce legislation, consistent with the principles
enshrined in common law and, with regard to cheques, in the Bills
of Exchange Act 1882, to establish the principle that banks should
be held liable for losses incurred as a result of electronic fraud".
We are broadly supportive of the Government's
response, and feel that the Committee have misapprehended the
nature of existing arrangements to protect customers against fraud.
The Banking Code already provides much of the
protection demanded by this recommendation; specifically protecting
customers against losses through card, online banking and cheque
fraud.
Sections 12.5-12.9 of the new Code set out clearly
what is expected of customers to assist in protecting their payment
cards, PINs, chequebooks and online banking account. The level
of protection from liability offered to customers is set out in
Sections 12.11-12.13. Section 12.13 is the new provision on online
banking fraud that states:
"Unless you have acted fraudulently or
without reasonable care (for example by not following the advice
in Section 12.9), you will not be liable for losses caused by
someone else which take place through your online banking service".
The Committee may be further interested to hear
of the latest statistics, compiled by APACS from member data,
that show that online banking fraud decreased by around 33 per
cent in 2007 from £33.5 million to £22.6 million despite
a doubling in the number of phishing incidents. The fall was mainly
due to the success of banks' continuing customer education efforts,
and to their developing capabilities in spotting possible account
compromises and preventing fraudulent transactions.
11. "We further believe that a
data security breach notification law would be among the most
important advances that the UK could make in promoting personal
internet security. We recommend that the Government, without waiting
for action at European Commission level, accept the principle
of such a law and begin consultation on its scope as a matter
of urgency".
We are broadly supportive of the Government's
response. We would add that the experience of jurisdictions with
mandatory disclosure laws is that these laws have rarely achieved
what was intended. In many cases disclosures have been made in
relation to cases where the potential harm to data subjects was
minimal, but the nature of the disclosure mechanism is such that
it does not allow data subjects to judge the actual level of risk.
It will be important to ensure that risk thresholds for any disclosure
scheme are carefully chosen and weighted to ensure that they relate
to actual levels of potential harm and we therefore welcome the
suggestions made by the Committee in recommendation 12, in ensuring
that any disclosure should be appropriate to the level of risk
and fit for purpose.
12. "We recommend that the data
security breach notification law should incorporate the following
elements: ..."
Please see our response to recommendation 11.
13. "We further recommend that
the Government examine as a matter of urgency the effectiveness
of the Information Commissioner's Office in enforcing good standards
of data protection across the business community".
One of the clear challenges that the financial
sector faces is clearly communicating the increasing responsibilities
placed on businesses to treat their customer data securely and
we would support a co-ordinated approach to this across Government
and other agencies.
14. "We recommend that the Government
provide more explicit high-level political support to the Get
Safe Online initiative and make every effort to recruit additional
private sponsors".
The Government makes a number of sound points
in its response to this recommendation, but we believe that there
is substantial scope for more positive action. Many APACS members
are founding supporters of Get Safe Online, and APACS itself has
also actively supported and encouraged the initiative since its
inception. We welcome the Committee's recommendation that the
Government should play a more active role in its promotion. We
would encourage the Committee to seek specific commitments from
the Government for further increasing the profile of Get Safe
Online, and to explore other proactive measures.
The Get Safe Online site is an example of "pull"
education, in that it largely relies on people to seek it out,
but experience shows that a strategy of "push" methods
can be far more effective when communicating complex and unfamiliar
concepts. The Government should be encouraged to either lead or
fund an aggressive and high profile public information campaign
to highlight the risks of e-crime and the measures that consumers
and businesses can take to protect themselves.
15. "We recommend that Ofcom not
only sponsor the Get Safe Online project, but that it take responsibility
for securing support from the communication industry for the initiative".
We have nothing further to add to the Government's
response.
16. "We further recommend that,
in addition, the new kite mark for content control software, Ofcom
work with industry partners and the BSI to develop additional
kite marks for security software and social networking sites;
and that it continue to keep under review possible areas where
codes of best practice, backed up by the kite marks, might be
appropriate".
We are broadly supportive of the Government's
response.
17. "We recommend that the Department
for Children, Schools and Families, in recognition of its revised
remit, establish a project, involving a wide range of partners,
to identify and promote new ways to educate the adult population,
in particular parents, in online security safety".
We believe that the Government could and should
be doing much more to promote personal internet security. Although
adults are an important part of the mix, we believe that it is
of vital importance to promote sound security behaviours and attitudes
in the young. A more comprehensive programme of computer security
education in schools and colleges, incorporated into the National
Curriculum and/or associated ICT courses, as opposed to one-off
campaigns, would be an enormous step forward in ensuring that
the next generation enters the online world in safety. The Internet
has rapidly become a vital part of most peoples' lives and is
right that the educational system allocates the appropriate level
of resources to ensure that people use it safely.
18. "We recommend that the Government
introduce amendments to the criminal law, explicitly to criminalise
the sale or purchase of the services of a botnet, regardless of
the use to which it is put".
The Government's response on the use of the
Computer Misuse Act 1990 and the Police Act 2006 are correct in
principle. We would support the Committee in encouraging the Government
to ensure that law enforcement and national security functions
are appropriately skilled and tasked. We also feel that the phrase
"regardless of the use to which it is put" goes
too far as it could include many perfectly legitimate distributed
computing applications that otherwise exhibit many "botnet-like"
behaviours and we would encourage the Committee to define its
area of interest in terms of harm. For example where bots are
run without the knowledge of the owners of the computers involved,
for purposes which are criminal.
19. "We recommend that the Government,
in partnership with ACPO and SOCA, develop a unified web-based
reporting system for e-crime".
Although we accept the Government's response
that the National Fraud Reporting Centre (NFRC) could provide
some of the benefits of the Committee's recommendation, not all
online crime manifests itself as fraud, so we would encourage
the Committee to continue to support the creation of a unified
e-crime reporting system operated by specialised law enforcement
agencies. Having said that we do see a potential role for the
NFRC in acting as a portal for the reporting of crime, which is
then channelled to specialist units.
20. "We recommend that the Government
review as a matter of urgency their decision to require online
frauds to be reported to the banks in the first instance".
We support the Government's response to this
recommendation.
It is important to note that the change in law
relates to the recording of crimewhere industry figures
were always in excess of police figuresand does not relate
to the responsibility of law enforcement to investigate any fraud-related
crimes.
21. "We therefore recommend the
establishment of a network of computer forensic laboratories,
under the aegis of the proposed Association of Chief Police Officers
(ACPO) national e-crime unit, but with significant central funding.
We further urge the Home Office, without delay, to provide the
necessary funds to kick-start the establishment of the PECU, without
waiting for the private sector to come forward with funding".
We strongly believe that a dedicated and specialised
law enforcement body with a national remit will be the most effective
approach to combating e-crime, and represents a critical capability
that is currently missing in the UK. We encourage the Committee
to press the case strongly for substantial Government support
for Public Employees Credit Union (PECU) in order to ensure that
it is appropriately funded and resourced with the skilled staff
required.
22. "We urge the Government to
fulfil its commitment to ratify the Council of Europe Cybercrime
Convention at the earliest possible opportunity. At the same time,
in order to ensure that the UK fulfils the spirit as well as the
letter of Article 25 of the Convention, we recommend that the
Government review procedures for offering mutual legal assistance
in response to requests for help from other countries in investigating
or prosecuting e-crime".
We do not feel that the current arrangements
for mutual legal assistance are sufficient to deal with the phenomenon
of e-crime. The experience of the banking industry at least has
been that these arrangements raise considerable issues regarding
speed and effectiveness of response. Additionally the scope of
current arrangements are not well suited to the demands of dealing
with the high-speed borderless nature of e-crime.
23. "We recommend that the Government
take steps to raise the level of understanding of the Internet
and e-crime across the court system. In particular:
in the context of the prevalence
of Id theft and online card fraud, we urge the Government to issue
new guidance to the courts, including magistrates' courts on the
reliability of unsupported credit card evidence as an indicator
of guilt.
We recommend that the Government
review the availability to the courts of independent specialist
advice of internet-related crime.
We believe that the sentences
should fit the crime. The nature of e-crime is such that mostly
(but not exclusively) small crimes are committed in very large
numbers; they also generally involve a high level of intrusion
into personal life. Sentencing guidelines should be reviewed in
recognition of these realities."
We support the Government's response to this
recommendation, particularly on the matters of principle raised.
|