Select Committee on Science and Technology Written Evidence


Memorandum by the Association for Payment Clearing Services (APACS)

  Our input consists of our reaction to HM Government's response highlighting the areas of greatest concern to APACS and its members, and our suggestions to help guide the Committee's future deliberations.

APACS COMMENT ON HM GOVERNMENT'S RESPONSE

  1.   "We recommend that the Government establish a cross-departmental group, bringing in experts from industry and academia, to develop a more co-ordinated approach to data collection in future. This should include a classification scheme for the recording of all forms of e-crime".

  The Government is correct in saying that crimes committed by computer are "standard offences facilitated by new technology" this does not mitigate the need for developing greater understanding. The correct measurement of crime is an important step in the process of understanding the impact of certain types of criminality, and from there to understanding how to define and allocate the resources required to tackle them. In the case of e-crime, there are a range of techniques and skills used by criminals that are highly specialised and that therefore require a specialised response. If the Government is not in a good position to understand the nature of the crimes being committed, then it follows that it won't be in a good position to understand how to direct law enforcement and the courts accordingly, or to develop appropriate legislation. We therefore encourage the Committee to focus on helping to create the conditions for policy makers to better understand the impact of e-crime.

  2.   "We recommend that the Research Councils take the lead in initiating discussions with Government, universities and industry with a view to the prompt establishment of an initial centre in this country. We urge the Crown Prosecution Service to publish the guidance as soon as possible, so as to avoid undermining such research in the interim".

  We are broadly supportive of the Government's response to this recommendation. However, we would add that the UK lacks and continues to lack a Computer Emergency Response Team (CERT) that is capable—in terms of skilled resource and mandate—of assisting in the fight against e-crime, and that we consider this to be a serious shortcoming. We would urge the Committee to examine in depth the leading global exemplars of such CERTs, namely AusCERT in Australia, CERT/CC in the USA and CERT.BR in Brazil. These three in particular have developed far-reaching capabilities that have proved of enormous value in the fight against e-crime. It continues to frustrate practitioners and security experts in the UK that we have no direct equivalent, and we believe that its continued lack has contributed to the UK suffering disproportionately from e-crime.

  3.   "We recommend that the Research Councils continue to give such fundamental research priority".

  We have no comment on the Government's response.

  4.   "It is time for the Government to develop a more holistic understanding of the distributed responsibility for personal internet security".

  We understood the spirit of the Committee's recommendation to be, that the Government should take a more active role in understanding what various public and private sector stakeholders can do to help maintain personal internet security, and that it should work proactively to ensure that these responsibilities are being upheld. In this APACS strongly supports the Committee's recommendation and we would argue that acceptance of it as a principle by the government would greatly assist in supporting many of Committee's other recommendations.

  5.   "We recommend the development of a BSI-approved kite mark for secure internet services. We further recommend that this voluntary approach should be reinforced by an undertaking that in the longer term on obligation will be placed on ISPs to provide a good standard of security as part of their regulated service. We recommend that the ISPs should be encouraged as part of the Kite mark scheme to monitor and detect "bad" ongoing traffic from their customers".

  As banking customers increasingly shift more of their transactional and banking activity online, they become increasingly reliant on the security of services offered by ISPs. APACS is supportive of moves to encourage ISPs to improve the level of security that they offer to their customers, and to take a more proactive stance to identify and prevent "bad" traffic from their customers. We believe that these developments are best left to industry and competition to provide, but we also believe that the Government has a strong role to play in promoting the principle of a safer internet, and the specific steps needed to achieve it.

  There are a number of self-regulatory approaches that could serve as examples for working further on this recommendation, ie The Banking Code. The 2008 edition of the Code enshrines a guarantee that online banking customers will not be liable for any losses if they are the innocent victim of fraud.

  6.   "We recommend that the `mere conduit' immunity should be removed once ISPs have detected or been notified of the fact that machines on their network are sending out spam or infected code".

  Revocation of mere conduit, even on a selective basis, is likely to be an enormously complex challenge, but one that we believe could yield positive benefits if done with sensitivity. Whilst the Government is correct to say that many ISPs do take proactive steps against customers whose machines are sending out spam or infected code, many more either do so with varying degrees of effectiveness or not at all. Indeed one could argue that the current data on this speaks for itself. For example, the UK is a leading source of botnet-infected computers, and UK bank brands are regularly amongst the most heavily targeted by phishing gangs. By offering clarity on the extent of mere conduit provisions, ISPs would be in a better position to understand their areas of responsibility, and the market would be provided with a higher baseline of response from ISPs.

  7.   "We recommend instead that VOIP providers be encouraged to provide a 999 service on a "best efforts" basis reflecting the reality of Internet traffic, provided that they also make clear to customers the limitations of their service and the possibility that it may not always work when it is needed".

  We have no comment on Government's response.

  8.   "We recommend that the Government explore, at European level, the introduction of the principle of vendor liability with the IT industry".

  We have no comment on the Government's response.

  9.   "The steps being currently undertaken by many businesses trading over the internet to protect their customers' personal information are inadequate. The refusal of the financial services sector in particular to accept responsibility for the security of personal information is disturbing, and is compounded by apparent indifference at Government level. Governments and legislators are not in a position to prescribe the security precautions that should be taken; however, they do have responsibility to ensure that the right incentives are in place to persuade businesses to take the necessary steps to act proportionately to protect data".

  We are broadly supportive of the Government's response to this recommendation. We do not accept that the financial services sector "refuses to accept responsibility for the security of personal information". The financial services sector responsibilities in this area are very clear and at all times individual institutions lay these out in their communications with customers and overall account terms and conditions. For example, section 11 of The Banking Code sets our subscribers' responsibilities in respect of personal customer information.

  The financial services sector takes the security of our customers' data extremely seriously and it would be true to say that our success in maintaining an appropriate level of security is demonstrated by the high and growing level of online banking usage.

  APACS members and the wider banking community, have also been instrumental in driving the implementation of a number of initiatives designed to greatly strengthen arrangements for the protection of customer data. For example, the Payment Card Industry Data Security Standards (PCI/DSS) are intended to protect sensitive customer data that may be held by merchants and others engaged in accepting and processing face to face and remote card payments. PCI/DSS is being implemented on a global basis and represents one of the most significant developments to protect customer data yet seen.

  In the specific field of online banking fraud, banks have taken aggressive steps to identify and remove sensitive customer information from the Internet, for example, in the form of log files generated by malicious spyware that has infected customer PCs. However their efforts are often hampered by ineffective or obstructive local legislation in many countries. For example, under the law of a number of countries including several US states, data on compromised customers gathered by spyware or phishing sites, and located on an open web server, is considered to be the property of the criminal and obtaining or deleting the data may itself be considered a crime. This astonishing state of affairs means that there are occasions where enormous obstacles are placed in front of those committed to fighting this type of crime.

  We would wish to see the Government taking steps to ensure that law enforcement is able to swiftly and effectively demand the removal of sensitive personal data from online sites, and that the Government takes a leading role in promoting this stance on a global basis to ensure that criminals have no place to hide.

  10.   "We therefore recommend that the Government introduce legislation, consistent with the principles enshrined in common law and, with regard to cheques, in the Bills of Exchange Act 1882, to establish the principle that banks should be held liable for losses incurred as a result of electronic fraud".

  We are broadly supportive of the Government's response, and feel that the Committee have misapprehended the nature of existing arrangements to protect customers against fraud.

  The Banking Code already provides much of the protection demanded by this recommendation; specifically protecting customers against losses through card, online banking and cheque fraud.

  Sections 12.5-12.9 of the new Code set out clearly what is expected of customers to assist in protecting their payment cards, PINs, chequebooks and online banking account. The level of protection from liability offered to customers is set out in Sections 12.11-12.13. Section 12.13 is the new provision on online banking fraud that states:

    "Unless you have acted fraudulently or without reasonable care (for example by not following the advice in Section 12.9), you will not be liable for losses caused by someone else which take place through your online banking service".

  The Committee may be further interested to hear of the latest statistics, compiled by APACS from member data, that show that online banking fraud decreased by around 33 per cent in 2007 from £33.5 million to £22.6 million despite a doubling in the number of phishing incidents. The fall was mainly due to the success of banks' continuing customer education efforts, and to their developing capabilities in spotting possible account compromises and preventing fraudulent transactions.

  11.   "We further believe that a data security breach notification law would be among the most important advances that the UK could make in promoting personal internet security. We recommend that the Government, without waiting for action at European Commission level, accept the principle of such a law and begin consultation on its scope as a matter of urgency".

  We are broadly supportive of the Government's response. We would add that the experience of jurisdictions with mandatory disclosure laws is that these laws have rarely achieved what was intended. In many cases disclosures have been made in relation to cases where the potential harm to data subjects was minimal, but the nature of the disclosure mechanism is such that it does not allow data subjects to judge the actual level of risk. It will be important to ensure that risk thresholds for any disclosure scheme are carefully chosen and weighted to ensure that they relate to actual levels of potential harm and we therefore welcome the suggestions made by the Committee in recommendation 12, in ensuring that any disclosure should be appropriate to the level of risk and fit for purpose.

  12.   "We recommend that the data security breach notification law should incorporate the following elements: ..."

  Please see our response to recommendation 11.

  13.   "We further recommend that the Government examine as a matter of urgency the effectiveness of the Information Commissioner's Office in enforcing good standards of data protection across the business community".

  One of the clear challenges that the financial sector faces is clearly communicating the increasing responsibilities placed on businesses to treat their customer data securely and we would support a co-ordinated approach to this across Government and other agencies.

  14.   "We recommend that the Government provide more explicit high-level political support to the Get Safe Online initiative and make every effort to recruit additional private sponsors".

  The Government makes a number of sound points in its response to this recommendation, but we believe that there is substantial scope for more positive action. Many APACS members are founding supporters of Get Safe Online, and APACS itself has also actively supported and encouraged the initiative since its inception. We welcome the Committee's recommendation that the Government should play a more active role in its promotion. We would encourage the Committee to seek specific commitments from the Government for further increasing the profile of Get Safe Online, and to explore other proactive measures.

  The Get Safe Online site is an example of "pull" education, in that it largely relies on people to seek it out, but experience shows that a strategy of "push" methods can be far more effective when communicating complex and unfamiliar concepts. The Government should be encouraged to either lead or fund an aggressive and high profile public information campaign to highlight the risks of e-crime and the measures that consumers and businesses can take to protect themselves.

  15.   "We recommend that Ofcom not only sponsor the Get Safe Online project, but that it take responsibility for securing support from the communication industry for the initiative".

  We have nothing further to add to the Government's response.

  16.   "We further recommend that, in addition, the new kite mark for content control software, Ofcom work with industry partners and the BSI to develop additional kite marks for security software and social networking sites; and that it continue to keep under review possible areas where codes of best practice, backed up by the kite marks, might be appropriate".

  We are broadly supportive of the Government's response.

  17.   "We recommend that the Department for Children, Schools and Families, in recognition of its revised remit, establish a project, involving a wide range of partners, to identify and promote new ways to educate the adult population, in particular parents, in online security safety".

  We believe that the Government could and should be doing much more to promote personal internet security. Although adults are an important part of the mix, we believe that it is of vital importance to promote sound security behaviours and attitudes in the young. A more comprehensive programme of computer security education in schools and colleges, incorporated into the National Curriculum and/or associated ICT courses, as opposed to one-off campaigns, would be an enormous step forward in ensuring that the next generation enters the online world in safety. The Internet has rapidly become a vital part of most peoples' lives and is right that the educational system allocates the appropriate level of resources to ensure that people use it safely.

  18.   "We recommend that the Government introduce amendments to the criminal law, explicitly to criminalise the sale or purchase of the services of a botnet, regardless of the use to which it is put".

  The Government's response on the use of the Computer Misuse Act 1990 and the Police Act 2006 are correct in principle. We would support the Committee in encouraging the Government to ensure that law enforcement and national security functions are appropriately skilled and tasked. We also feel that the phrase "regardless of the use to which it is put" goes too far as it could include many perfectly legitimate distributed computing applications that otherwise exhibit many "botnet-like" behaviours and we would encourage the Committee to define its area of interest in terms of harm. For example where bots are run without the knowledge of the owners of the computers involved, for purposes which are criminal.

  19.   "We recommend that the Government, in partnership with ACPO and SOCA, develop a unified web-based reporting system for e-crime".

  Although we accept the Government's response that the National Fraud Reporting Centre (NFRC) could provide some of the benefits of the Committee's recommendation, not all online crime manifests itself as fraud, so we would encourage the Committee to continue to support the creation of a unified e-crime reporting system operated by specialised law enforcement agencies. Having said that we do see a potential role for the NFRC in acting as a portal for the reporting of crime, which is then channelled to specialist units.

  20.   "We recommend that the Government review as a matter of urgency their decision to require online frauds to be reported to the banks in the first instance".

  We support the Government's response to this recommendation.

  It is important to note that the change in law relates to the recording of crime—where industry figures were always in excess of police figures—and does not relate to the responsibility of law enforcement to investigate any fraud-related crimes.

  21.   "We therefore recommend the establishment of a network of computer forensic laboratories, under the aegis of the proposed Association of Chief Police Officers (ACPO) national e-crime unit, but with significant central funding. We further urge the Home Office, without delay, to provide the necessary funds to kick-start the establishment of the PECU, without waiting for the private sector to come forward with funding".

  We strongly believe that a dedicated and specialised law enforcement body with a national remit will be the most effective approach to combating e-crime, and represents a critical capability that is currently missing in the UK. We encourage the Committee to press the case strongly for substantial Government support for Public Employees Credit Union (PECU) in order to ensure that it is appropriately funded and resourced with the skilled staff required.

  22.   "We urge the Government to fulfil its commitment to ratify the Council of Europe Cybercrime Convention at the earliest possible opportunity. At the same time, in order to ensure that the UK fulfils the spirit as well as the letter of Article 25 of the Convention, we recommend that the Government review procedures for offering mutual legal assistance in response to requests for help from other countries in investigating or prosecuting e-crime".

  We do not feel that the current arrangements for mutual legal assistance are sufficient to deal with the phenomenon of e-crime. The experience of the banking industry at least has been that these arrangements raise considerable issues regarding speed and effectiveness of response. Additionally the scope of current arrangements are not well suited to the demands of dealing with the high-speed borderless nature of e-crime.

  23.   "We recommend that the Government take steps to raise the level of understanding of the Internet and e-crime across the court system. In particular:

    —  in the context of the prevalence of Id theft and online card fraud, we urge the Government to issue new guidance to the courts, including magistrates' courts on the reliability of unsupported credit card evidence as an indicator of guilt.

    —  We recommend that the Government review the availability to the courts of independent specialist advice of internet-related crime.

    —  We believe that the sentences should fit the crime. The nature of e-crime is such that mostly (but not exclusively) small crimes are committed in very large numbers; they also generally involve a high level of intrusion into personal life. Sentencing guidelines should be reviewed in recognition of these realities."

  We support the Government's response to this recommendation, particularly on the matters of principle raised.



 
previous page contents next page

House of Lords home page Parliament home page House of Commons home page search page enquiries index

© Parliamentary copyright 2008