Cybercrime : the cost of investments into protection
Igor Bernik
Abstract
Igor Bernik
Abstract
Purpose: This paper focuses on investments in protection of organisations against cybercrime. Current research points to enormous financial losses suffered by countries, organisations and individuals due to the impact of criminal offences committed in cyberspace. A detailed overview shows that such losses are fictitious and that the largest share of costs is generated by investments into protection, which, however, is not omnipotent. At the same time, practitioners in the field of cyberspace security find that awareness rising among personnel is a much more efficient and inexpensive method of protection enabling a higher level of security in cyberspace and individual organisations. Design/Methods/Approach: The author adapted the cost model of cybercrime by examining data regarding costs and losses inflicted by cybercrime available in different reports and documents drafted by global organisations and governments and analysing the true causes of such losses. Findings: The cost model presented in this paper considers the main causes of losses in a comprehensive manner and indicates guidelines for the protection of organisations. However, the provision of greater security in cyberspace is not only a technical, organisational and personnel problem, but ever more often also a political problem, as it is related to the regulation of cyberspace. The costs related to this problem are increasing, since no one endeavours to tackle it. Practical Implications: By becoming familiar with the causes and the cost model, organisations may find it easier to decide to invest into protection against attacks from cyberspace and improve their own efficiency with lower costs. Originality/Value: This paper presents the impacts of cybercrime on organisations from the point of view of costs and not from the point of view of technical experts in organisations, which are mostly responsible for the implementation of information systems’ protection. Therefore, the analysis of the issue provides management with the possibility to better understand individual problems, thus enabling it to take appropriate positions and support more efficient solutions or methods of protection.
OpenAlex reports 7 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Purpose: This paper focuses on investments in protection of organisations against cybercrime. Current research points to enormous financial losses suffered by countries, organisations and individuals due to the impact of criminal offences committed in cyberspace. A detailed overview shows that such losses are fictitious and that the largest share of costs is generated by investments into protection, which, however, is not omnipotent. At the same time, practitioners in the field of cyberspace security find that awareness rising among personnel is a much more efficient and inexpensive method of protection enabling a higher level of security in cyberspace and individual organisations. Design/Methods/Approach: The author adapted the cost model of cybercrime by examining data regarding costs and losses inflicted by cybercrime available in different reports and documents drafted by global organisations and governments and analysing the true causes of such losses. Findings: The cost model presented in this paper considers the main causes of losses in a comprehensive manner and indicates guidelines for the protection of organisations. However, the provision of greater security in cyberspace is not only a technical, organisational and personnel problem, but ever more often also a political problem, as it is related to the regulation of cyberspace. The costs related to this problem are increasing, since no one endeavours to tackle it. Practical Implications: By becoming familiar with the causes and the cost model, organisations may find it easier to decide to invest into protection against attacks from cyberspace and improve their own efficiency with lower costs. Originality/Value: This paper presents the impacts of cybercrime on organisations from the point of view of costs and not from the point of view of technical experts in organisations, which are mostly responsible for the implementation of information systems’ protection. Therefore, the analysis of the issue provides management with the possibility to better understand individual problems, thus enabling it to take appropriate positions and support more efficient solutions or methods of protection.
Key concepts: Cyberspace, Cybercrime, Value (mathematics), Business, Computer security, Originality, Public relations, Internet privacy