Gomes, Iivari, Ahokangas, Isotalo, Sahlin, and Melén
102
espionage, but also extends to economic domains. Professional organized crime groups or
agents of an organization’s competitors can hack into a business entity’s system and steal
their proprietary information, such as intellectual property or trade secrets.
The fourth level of threat is cyberterrorism. This is the use of cyber‐attacks targeted
at IT systems or the critical infrastructure of government and private organizations,
with the intent of intimidating the government or causing fear and panic among the
civilian population [19]. This type of attack is perpetuated by sophisticated terrorist
groups whose aim is to grab national or international attention [22]. They utilize
offensive IT weaponry, either in isolation or in combination with other means of
attack [17]. For example, in 2011, the Canadian Government reported a major cyber‐
attack against its agencies, including Defense Research and Development Canada.
The attack forced the Finance Department and Treasury Board, Canada’s main economic
agencies, to disconnect from the Internet [23].
Cyberwarfare is the fifth level of cyber threat and involves the conduct of warfare in the
virtual world or cyberspace [17]. The typical threat agents are nation states’ militaries and
intelligence services, organized insurgent groups or terrorists. The action aims at immobilizing the information system or destroying the critical infrastructure of the enemy
through the use of weapons such as computer viruses, worms or denial‐of‐ service (DOS)
attacks. Cyberwarfare is not a stand‐alone strategy but is used with other strategies (e.g.
“kinetic” warfare) in an offensive or defensive operation [18]. For example, in 2007, the
Estonian government suffered some serious cyber‐attacks against its websites and some
banks’ websites, leading to a halt in online banking transactions. This incident arose
when the government decided to relocate a WWII Soviet Union memorial [24].
The forgoing discussion has centred on the various types, levels of severity and complexity of cyber threats. The threat can emanate from various sources such as nation
states, organizations, organized crime groups, individuals, terrorists, insurgent groups
and competitors. The motive of these actors may be to enhance their ego or have some
bragging rights, to advance a political or ideological cause, monetary gain, to gain access
to sensitive information for a future course of action, to cause fear and panic among
people or to force a government to take or abandon a certain cause. They can be used as
a strategy in conflicts and warfare. The severity of these attacks may differ from one to
another and the intent may be to cause minimal or collateral damage. Nevertheless, in all
instances, a cyber‐attack results in some form of loss, such as financial loss, infrastructure
or equipment damage, or loss of reputation. In the next sub‐section, we examine the costs
of cyber‐attacks to nation states and businesses.
5.2.2 The Cost of Cyber‐Attacks
Incidents of cyber‐attacks are increasing with a concomitant increase in cost to governments and businesses. The actual cost of these attacks is difficult to quantify; however,
numerous studies have churned out estimated costs [25]. The US Chamber of Commerce
estimated that the losses to the US resulting from cybercrime alone ranges from between
US$24 billion and US$ 120 billion and the global cost is reported to be US$1 trillion [26].
Also, the Intellectual Property Commission estimates that the US loses around US$ 300
billion annually through intellectual property theft. In a recent study of 58 benchmarked
US organizations, the Ponemon Institute found that the average cost of cybercrime to
these organizations was US$ 15 million. This showed an increase of 19% in the 2014
survey figure [27].
102
espionage, but also extends to economic domains. Professional organized crime groups or
agents of an organization’s competitors can hack into a business entity’s system and steal
their proprietary information, such as intellectual property or trade secrets.
The fourth level of threat is cyberterrorism. This is the use of cyber‐attacks targeted
at IT systems or the critical infrastructure of government and private organizations,
with the intent of intimidating the government or causing fear and panic among the
civilian population [19]. This type of attack is perpetuated by sophisticated terrorist
groups whose aim is to grab national or international attention [22]. They utilize
offensive IT weaponry, either in isolation or in combination with other means of
attack [17]. For example, in 2011, the Canadian Government reported a major cyber‐
attack against its agencies, including Defense Research and Development Canada.
The attack forced the Finance Department and Treasury Board, Canada’s main economic
agencies, to disconnect from the Internet [23].
Cyberwarfare is the fifth level of cyber threat and involves the conduct of warfare in the
virtual world or cyberspace [17]. The typical threat agents are nation states’ militaries and
intelligence services, organized insurgent groups or terrorists. The action aims at immobilizing the information system or destroying the critical infrastructure of the enemy
through the use of weapons such as computer viruses, worms or denial‐of‐ service (DOS)
attacks. Cyberwarfare is not a stand‐alone strategy but is used with other strategies (e.g.
“kinetic” warfare) in an offensive or defensive operation [18]. For example, in 2007, the
Estonian government suffered some serious cyber‐attacks against its websites and some
banks’ websites, leading to a halt in online banking transactions. This incident arose
when the government decided to relocate a WWII Soviet Union memorial [24].
The forgoing discussion has centred on the various types, levels of severity and complexity of cyber threats. The threat can emanate from various sources such as nation
states, organizations, organized crime groups, individuals, terrorists, insurgent groups
and competitors. The motive of these actors may be to enhance their ego or have some
bragging rights, to advance a political or ideological cause, monetary gain, to gain access
to sensitive information for a future course of action, to cause fear and panic among
people or to force a government to take or abandon a certain cause. They can be used as
a strategy in conflicts and warfare. The severity of these attacks may differ from one to
another and the intent may be to cause minimal or collateral damage. Nevertheless, in all
instances, a cyber‐attack results in some form of loss, such as financial loss, infrastructure
or equipment damage, or loss of reputation. In the next sub‐section, we examine the costs
of cyber‐attacks to nation states and businesses.
5.2.2 The Cost of Cyber‐Attacks
Incidents of cyber‐attacks are increasing with a concomitant increase in cost to governments and businesses. The actual cost of these attacks is difficult to quantify; however,
numerous studies have churned out estimated costs [25]. The US Chamber of Commerce
estimated that the losses to the US resulting from cybercrime alone ranges from between
US$24 billion and US$ 120 billion and the global cost is reported to be US$1 trillion [26].
Also, the Intellectual Property Commission estimates that the US loses around US$ 300
billion annually through intellectual property theft. In a recent study of 58 benchmarked
US organizations, the Ponemon Institute found that the average cost of cybercrime to
these organizations was US$ 15 million. This showed an increase of 19% in the 2014
survey figure [27].
