September 21, 2001—The Confederation of British Industry (CBI) has published a survey conducted among UK companies trading online that indicates that cybercrime is deterring firms from selling goods and services over the Internet. According to the survey, two-thirds of respondents have, in the past year, experienced a “serious incident” such as hacking, virus attack, or credit card fraud.
The survey shows that:
Organizations are more confident about security procedures for conducting Business to Business (B2B) over the Internet than they are about Business to Consumer (B2C) transactions. Around 53% of respondents regard the Internet as a safe place to do B2B but only 32% regard it as safe to do B2C.
Small and medium-sized firms (SMEs) are more willing to adopt B2C than B2B initiatives but are inhibited by lack of resources and a fear of cybercrime. 70% of firms with more than 10,000 employees have the facility to sell over the Internet, compared with 32% of SMEs (firms with fewer than 500 employees).
Hackers and viruses now pose the main threat to organizations. Other surveys have previously identified that the greatest threat comes from within an organization. Today’s figures show the main perpetrators are hackers (45%), former employees (13%), organized crime (13%), and current employees (11%).
The source of threats varies between sectors. Terrorists are viewed as an important source of threats by some parts of manufacturing but of minor importance to retailing and services. Threats from current and former employees are a higher priority in telecommunications and technology and the professional/consultancy sectors than in the financial services and manufacturing sectors. However, the threat of hackers is particularly high in the financial services industry.
Loss of reputation through adverse publicity, and loss of trust, is a greater fear than financial loss for most organizations. 69% of respondents consider their e-business financial loss to be negligible, and credit card fraud represents a mere 4% of the most serious incidents over the past year.
Companies need to review their security controls and ensure that they are given high priority within the organization. 72% of companies with a director responsible for risk management as well as 55% of those without, report cases of serious attacks in the past year.
The survey concludes that there is a need for a coordinated approach to understanding and minimizing the risks of cybercrime. CBI is calling for a package of measures to help cut online criminal activity. The survey, consisting of 148 responses from organizations in a variety of industry sectors and of various sizes, was produced by the CBI in collaboration with the Fraud Advisory Panel, PricewaterhouseCoopers, ArmorGroup, and The Nottingham Trent University International Fraud Prevention Research Centre. The Cybercrime Survey 2001 is available from CBI Publications Sales online, or by calling 020 7395 8071. Price: CBI members 75, non-members 100.
