SA must develop mechanisms to address cybercrime
This announcement came on the back of statistics released in the past few years which revealed a spike in the number of cybercrime incidents recorded globally. The Norton Report presented by Symantec in 2013 placed into perspective the global prevalence of cybercrime, reporting on more than 500 million victims that had been affected by cybercrime in a year, at the cost of more than $113bn to the global economy.
South Africa is not immune to this scourge. The Norton Report ranked South Africa as the third highest country, after China and Russia, out of the 24 countries surveyed. The report's finding that 73% of South Africans in 2013 were victims of cybercrime is astounding and definitely a cause for concern.
Cybercrime is spreading
The ubiquitous spread of cybercrime in South Africa is further evidenced by a report late last year from the Gautrain Management Agency that their financial department has been hacked in an attempt to defraud the agency of R800m. Unfortunately news of this nature does not bode well for South Africa when considering how well-equipped we are to address cybercrime.
Chapter 13 of the Electronic Communications and Transaction Act, No 25 of 2002, provides the original framework created by the Department of Communications in relation to cybercrime. Notably, s86 of the Act strictly prohibits unauthorised interception of data. This section further criminalises the wilful use of a device or a programme to override any security systems meant to protect data and any violation of these provisions may result in criminal prosecution.
South Africa also adopted the National Cyber Security Policy Framework in March 2012, which seeks to define measures that are designed to address cyber threats at national level. The framework seeks to strengthen "intelligence collection, investigations, prosecution and judicial processes, in respect of preventing and addressing cybercrime, cyber warfare, cyber terrorism and other cyber ills". The framework also introduces new institutional mechanisms to address cybercrime such as response committees and a cybercrime security hub.
Rethink approach
Since the adoption of the framework little has been done, with the appointment of a National Cyber Security Advisory Council only taking place in October last year, some 18 months later. The Police Minister also announced in October last year that a draft cybercrime policy and strategy had been drawn up in order to forge a national policy and strategic approach to fighting cybercrime. Industry experts have continued to express concerns regarding its lack of implementation.
When considering that a significant part of the defence budget in many nations is now being re-directed to assist with cybercrime initiatives, South Africa will need to rethink its own approach to ensure that it starts to develop the necessary skill set and mechanisms to address cybercrime, and prevent the risk of being a target for cyber criminals.