Cyber Crime Costs Britain $27 Billion

The British government says the cost of cybercime to the national economy, currenty estimated at £27bn, is already significant and is likely to continue growing.
 
A new UK Cabinet Office Study reveals that the average annual cost to organisations of cybercrime has been escalatinging for all types of cyberattacks. A single malware attack that take place in 2018 cost more than $2.6 million, while ransomware costs rose the most between 2017–2018, from $533,000 to $646,000 (a 21% increase).
 
The ease of access to and relative anonymity provided by information and communications technology (ICT) lowers the risk of being caught, while making crimes straightforward to conduct. 
 
The impact of cybercrime does not fall equally across industry sectors. The results also challenge the conventional wisdom that cybercrime is solely a matter of concern for the Government and critical national infrastructure, suggesting that much larger sectors of industry are at risk. 
 
Businesses need to look again at their defences to determine whether their information is indeed well protected. Without urgent measures to prevent the losing controlof valuable intellectual property  the cost of cybercrime is likely to rise even further in the future as UK businesses increase their reliance on ICT.
 
Encouraging companies in all sectors to make investments in improved cyber security, based on improved risk assessments, is likely to considerably reduce the economic impact of cybercrime on the UK. 
 
Although the existence of cybercrime in the UK economy appears endemic, efforts to tackle it seems to be more tactical than strategic. The problem is compounded by the lack of a clear reporting mechanism and the perception that, even if crimes were reported, little can be done. Additional efforts by the Government and businesses to build awareness, share insights and measure cybercrime would allow responses to be targeted more effectively. 
  • Scareware–cybercriminals mislead individuals into downloading software onto their computer, for example, fake anti-virus software, by using fear tactics or other unethical marketing practices. The software downloaded is often ineffective or may appear to deal with certain types of virus before infecting the computer with its own viruses. Individuals may then have to pay the cyber criminals to remove the viruses and their impacts. 
  • Fiscal fraud–cybercriminals can withhold taxes due or make fraudulent claims for benefits by attacking official online channels (such as online self-assessment forms). The loss of tax revenue directly affects public- sector spending and the Government’s ability to invest in UK infrastructure. 
  • Theft from business–cybercriminals steal revenue online directly from businesses, which usually involves fraudulently obtaining access and looting company accounts and monetary reserves. In some instances, this cybercriminal activity is greatly assisted by an ‘insider’. 
  • Extortion–cybercriminals hold a company to ransom often through deliberate denial of service(for example, by using malware to flood a company server with erroneous internet traffic) or by manipulating company website links, which can lead to extensive brand damage (for example, by redirecting links for a retailer website to an online pornography website). 
  • Customer data loss–cybercriminals steal sensitive customer data from a company such as customer financial, medical or criminal record details) with the purpose of selling the data on to other criminal networks or using it themselves for blackmail attempts. Industrial espionage–this takes many forms, such as arrival organisation (or associated third party) illegally accessing confidential information to gain competitive or strategic advantage (for example, by finding out a rival’s bid price) or to gain insider knowledge for financial gain (for example, by becoming aware at an early stage of a business transactions.  
  • IP theft–cybercriminals, often sponsored by rival organisations or nation states, steal ideas, designs, product specifications, trade secrets, process information or methodologies, which can greatly erode competitive advantage or even the operational or technological advantage prized by nation states over potential adversaries. 
  • Money laundering–cybercriminals use online means to launder the proceeds of criminal acts, for example, through complex, internet-enabled transfers between global or offshore bank accounts. This type of activity is usually associated with organised criminal networks that have a wide or international reach. 
Many cybercrime patterns appear to be fairly stable, but there are some interesting changes appearing.
 
Payment fraud, for example, has more than doubled in value but has fallen slightly as a proportion of payment value; the payment system has simply become bigger, and slightly more efficient. 
 
The move to the cloud means that system misconfiguration may now be responsible for as many breaches as phishing. Some companies have suffered large losses as a side-effect of denial-of-service worms released by state actors, such as NotPetya; we have to take a view on whether they count as cybercrime. 
 
The infrastructure supporting cybercrime, such as botnets, continues to evolve, and specific crimes such as premium-rate phone scams have evolved some interesting variants. Therefore, it would be economically rational to spend less in anticipation of cybercrime (on antivirus, firewalls, etc.) and more on response. 
 
The growing realisation among policymakers that cybercrime has been growing signifcantly in the past decade  might reasonably lead to for better funded and coordinated police activity.
 
Three Steps To Unlocking The Value In Cybersecurity
 
1. Prioritise training and protecting people-based attacks: Countering internal threats is still one of the biggest challenges with a rise in phishing and ransomware attacks, as well as malicious insiders. Ensure you use effective cyber security training as this is a very effective method of reducing an organisations cyber security risks.
 
2. Invest to limit information loss and business disruption: Already the most expensive consequence of cyberattacks, this is a growing concern with new privacy regulations such as GDPR and CCPA.
 
3. Target technologies that reduce rising costs: Use automation, advanced analytics and security intelligence to manage the rising cost of discovering attacks, which is the largest component of spending.
 
Please contact Cyber Security Intelligence for more information and effective training for cyber security.
 
GovUK:              Bruce Schneier:     World Economid Forum:         Accenture:          Image: Nick Youngson
 
You Might Also Read
 
The Growing Cost of Cybercrime:
 
 
« Greece And Turkey In Conflict
Britain Allows Huawei 5G Network Access Against US Advice »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Infosecurity Europe, 3-5 June 2025, ExCel London

Infosecurity Europe, 3-5 June 2025, ExCel London

This year, Infosecurity Europe marks 30 years of bringing the global cybersecurity community together to further our joint mission of Building a Safer Cyber World.

Resecurity

Resecurity

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

TÜV SÜD Academy UK

TÜV SÜD Academy UK

TÜV SÜD offers expert-led cybersecurity training to help organisations safeguard their operations and data.

Datacom Systems

Datacom Systems

Datacom Systems is a leading manufacturer of network visibility solutions.

NetLib Security

NetLib Security

NetLib Security’s powerful, patented data security platform helps companies control data loss prevention (DLP) by managing what data can be transferred outside of their network.

Aujas Cybersecurity

Aujas Cybersecurity

Aujas has deep expertise and capabilities in Identity and Access Management, Risk Advisory, Security Verification, Security Engineering, & Managed Detection and Response services.

SafeHouse Technologies

SafeHouse Technologies

SafeHouse is a cloud-based, high-end cybersecurity platform that can secure and insure any device that is connected to it.

Improsec

Improsec

Improsec is a fully independent Cyber Security advisory company - we provide knowledge, experience and both strategic and deep technical expertise to our clients.

Cyberspace Solarium Commission (CSC)

Cyberspace Solarium Commission (CSC)

The Cyberspace Solarium Commission was established to develop a consensus on a strategic approach to defending the United States in cyberspace against cyber attacks of significant consequences.

Prove Identity

Prove Identity

Prove (formerly Payfone) is a leader in mobile & digital identity authentication for the connected world.

Thrive

Thrive

Thrive delivers the experience, resources, and expertise needed to create a comprehensive cyber security plan that covers your vital data, SaaS applications, end users, and critical infrastructure.

MicroSec

MicroSec

MicroSec is a company specializing in IoT security. We focus on bringing enterprise grade security to IoT and embedded systems.

Porto Research, Technology & Innovation Center (PORTIC)

Porto Research, Technology & Innovation Center (PORTIC)

PORTIC brings together several research centers and groups from P.PORTO in a single space, forming a superstructure dedicated to research, technology transfer, innovation and entrepreneurship.

BOXX Insurance

BOXX Insurance

BOXX Insurance Inc. is a new type of insurance company for a new type of risk. Cyberboxx is the first fully-integrated cybersecurity and insurance solution for small-to-medium-sized businesses.

Feroot Security

Feroot Security

Feroot Security secures client-side web applications so that businesses can deliver a flawless user experience to their customers. Our products help organizations protect their client-side surface.

Dion Training Solutions

Dion Training Solutions

Dion Training Solutions offer comprehensive training in areas such as project management, cybersecurity, agile methodologies, and IT service management.

Nagomi Security

Nagomi Security

Nagomi is changing the way security teams balance risk and defense, empowering customers to focus on what matters now.

SentryMark

SentryMark

Stay a Step Ahead of Emerging Threats. Deviate from the traditional siloed defenses and get the proactive and responsive cybersecurity solutions and services you deserve with SentryMark today.

Triovega

Triovega

Triovega are a leading provider for production security and efficiency. Our solutions enhance OT security, and reduce production downtime.