How Can Law Enforcement Prevent Cybercrime?

192 views
•
February 22, 2017
by
RSAC Cybersecurity
YouTube video player
How Can Law Enforcement Prevent Cybercrime?

TL;DR

Law enforcement can reduce cybercrime more effectively by combining prosecution with preventive measures that make attacks harder to execute. Cross-border partnerships, private-sector collaboration, predictive analytics, digital evidence capabilities, and technical protections against phishing and malicious sites provide a scalable response to criminals who operate globally and cannot be deterred through arrests alone.

Transcript

Thank you. Good afternoon, everybody. So, uh, I don't know if you've noticed it, but there's this thing out there called cybercrime, and it seems to be growing at least a little bit. Um, I read the statistics, and they show that, you know, ransomware is taking off, um, that-- And Chris may be talking about this later. The, uh, amount of-- That the,... Read More

Key Insights

  • Cybercrime is an expanding threat that cannot be controlled solely by investigating offenses after they occur. Law enforcement leaders argue that prevention must complement prosecution because arresting individual offenders does not meaningfully change the overall growth of criminal activity.
  • Digital evidence is central to modern prosecution because virtually every case handled by the Manhattan District Attorney's Office involves evidence from computers. Cyber capabilities are therefore relevant beyond offenses classified specifically as cybercrime or cyber-enabled fraud.
  • State and local law enforcement must develop stronger cyber expertise because most criminal prosecutions in the United States occur in state and local courts. Federal agencies cannot assume full responsibility for investigating and prosecuting a threat that affects every jurisdiction.
  • Cross-border collaboration is essential because the same cybercriminals can target organizations in London and New York. Cybercrime does not respect geographic boundaries, so investigators must build international working relationships that reflect how offenders actually choose and attack their victims.
  • The Global Cyber Alliance is a prevention-focused nonprofit created through cooperation between the Manhattan District Attorney's Office and the City of London Police. It brings organizations from different industries and countries together to develop practical ways of reducing cyber risk.
  • Technical prevention can reduce opportunities for cybercrime by strengthening organizational defenses against phishing and access to malicious sites. The alliance focuses on solutions involving DMARC and DNS, with technical specialists and partner organizations working together to harden defensive perimeters.
  • Predictive analytics can help law enforcement close part of the gap with cybercriminals by using available data to identify effective interventions. It must operate within a broader strategy that still includes investigators, analysts, partnerships, technical expertise, and enforcement against human offenders.
  • No single solution can eliminate cybercrime because the threat involves people, technology, industries, and jurisdictions around the world. Significant progress requires a holistic effort combining law enforcement, private industry, nonprofit organizations, and international partners with different tools and expertise.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How can law enforcement prevent cybercrime?

Law enforcement can prevent cybercrime by supplementing investigations and prosecutions with measures that reduce opportunities for attacks. These measures include analyzing data, using predictive analytics, collaborating with private industry and international agencies, strengthening defenses against phishing, and blocking access to malicious sites. Prevention offers a more scalable response because arresting one offender does not substantially reduce widespread cybercriminal activity.

Q: Why is prosecution alone insufficient against cybercrime?

Prosecution alone is insufficient because cybercrime is growing across borders and involves many offenders who can operate remotely. Putting an individual offender in jail may provide specific deterrence, but law enforcement leaders say it does not bend the broader curve of cybercrime. Investigations and punishment remain necessary, yet they must be paired with preventive strategies that make organizations and systems harder to exploit.

Q: Why must state and local agencies build cybercrime expertise?

State and local agencies must build cybercrime expertise because a large majority of criminal cases in the United States are prosecuted in state and local courts. They cannot defer responsibility for cyber investigations and prosecutions entirely to federal law enforcement. Local competence is especially important as cyber-enabled fraud becomes a substantial part of serious criminal caseloads and digital evidence appears in virtually every kind of prosecution.

Q: How does international cooperation reduce cybercrime risk?

International cooperation reduces risk by connecting agencies that confront the same offenders and attack patterns in different countries. Criminals targeting London may also target New York, so isolated investigations cannot fully address their activities. Cross-border partnerships allow law enforcement and other participants to combine information, investigative capabilities, technical knowledge, and prevention strategies in a way that better matches cybercrime's lack of geographic boundaries.

Q: What is the Global Cyber Alliance designed to do?

The Global Cyber Alliance is designed to help prevent cybercrime through cooperation outside the traditional prosecution model. Created through work involving the Manhattan District Attorney's Office and the City of London Police, it brings together organizations from sectors such as transportation, health, hospitals, aerospace, municipal government, and finance. Its participants work across borders on practical technical measures that can reduce shared cyber risks.

Q: How can DMARC and DNS support cybercrime prevention?

DMARC and DNS are identified as areas for technical solutions that can strengthen organizational defenses. The Global Cyber Alliance brings technical specialists together with partner organizations to address phishing and prevent people from reaching sites they should not access. Within the discussion, these measures represent practical ways to harden defensive perimeters and stop some harmful activity before it becomes a case requiring investigation and prosecution.

Q: What role does predictive analytics play in cybersecurity?

Predictive analytics can help law enforcement narrow the gap with cybercriminals by analyzing data and identifying interventions likely to be effective. The FBI representative presents it as an important area of advancement, particularly through collaboration with private industry. It is not a complete solution, however, and must be combined with investigators, analysts, partnerships, technical measures, and action against the people initiating attacks.

Q: Why is private-sector collaboration necessary for cybercrime prevention?

Private-sector collaboration is necessary because law enforcement does not possess every tool, dataset, or area of expertise required to address cybercrime. Businesses and industry groups operate many of the systems being targeted and can contribute technical capabilities and practical knowledge. When combined with domestic and international law enforcement, nonprofit organizations, and analysts, those resources support a holistic response that neither government nor industry could deliver independently.

Summary & Key Takeaways

  • Cybercrime has grown into a major threat for law enforcement, financial institutions, businesses, and public services. Traditional enforcement remains necessary, but prosecuting individual offenders does not sufficiently reduce the overall volume of attacks. Agencies therefore need preventive strategies that address systemic weaknesses before criminals can exploit them.

  • Effective cybercrime prevention depends on collaboration among local, federal, and international law enforcement, private industry, and nonprofit organizations. Because attackers and victims cross jurisdictional boundaries, participants must combine their distinct information, expertise, investigative authority, and technical capabilities instead of expecting any single institution to solve the problem alone.

  • The Global Cyber Alliance illustrates a prevention-focused model that connects sectors and countries around practical technical solutions. Its work targets risks such as phishing and access to malicious sites through measures involving DMARC and DNS. These protections are intended to harden organizational defenses while investigations and prosecutions continue.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚