Computerworld
Criminals grasp the metrics of information value
Michael Crawford  16 June, 2005 08:06

Identity theft has matured into a full-time criminal activity with plenty of lucrative opportunities for those trading in stolen identities.

The lure of big profits is driving this industry, according to Gartner Fellow, vice president and author Richard Hunter, who says the risk of arrest is extremely low.

"Cybercrime now has better odds of success and profit than kidnapping in Columbia," he said.

"The chance of an ID thief being arrested and prosecuted for the crime is one in 700 - that is better odds than kidnapping in Columbia."

As a result 'cybercrime for profit' attacks are at an all-time high, he said, adding that the number of victims is also at an all-time high.

"We expect this to continue at least on the same level for the next few years," Hunter added.

"If you go to a CFO of a corporation and ask what is their information worth they cannot tell you, but you can go up to a criminal on the street and buy a credit history. One case in the US wholesaled 30,000 credit card records at $US30 a piece which is the equivalent of $900,000.

"The confederates on the street then wholesaled those records at about $US1.8 million and criminal metrics are actually precise indicators," he said.

"A credit card number unsupported by any other documentation is worth about $10 in the US, a credit history retails for $US60 and wholesales for around $30 and Internet-based markets are well established."

Frost & Sullivan security analyst James Turner warns enterprises against using similar metrics when attempting to ascertain a dollar value to identities held on their database.

Turner said such street value estimates offer a "wow" factor to the problem of identity theft, but in terms of minimizing exposure and mitigating threat it is not the most helpful way of calculating risk.

"It is an interesting perspective for people making decisions but not bedrock," Turner said.

"Data maybe worth 'X' amount on the Internet for criminals, but when it comes to loss/expectancy calculations it is all to do with the exposure factor.

"The true risk analysis calculation for exposure is asset value times the exposure factor (as a percent) equals your company's single loss expectancy (SLE), then the SLE times the annual rate of occurrence will give you your annualized loss expectancy."

Computerworld Buyer's Guide - Vendors Matched to this Article

Comments

Post new comment

Login or register to link comments to your user profile, or you may also post a comment without being logged in.
The content of this field is kept private and will not be shown publicly.
Enter the fully qualified URL, eg. http://www.example.com/
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

Add to Google
Computerworld Buyer's Guide - Vendors Matched to this Article
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.
Newsletter Subscription
Newsletter Subscription
Sign up for our Computerworld newsletters!
Syndicate content
 

Computerworld Webinar

Thursday, June 11th, 2009
10:30am EST (Sydney, Australia)
Screening at your PC

Computerworld is hosting a 30 minute live webinar to help you to learn how unified communications can save you money, foster innovation and business agility by making it easier for people to find, reach and collaborate with one another.

Register Now

Whitepaper

Providing Business Continuity and Disaster Recovery for Microsoft Cluster Server and Windows Server 08 Failover Clustering Apps

Clustering provides high availability for mission critical applications. A well implemented cluster tolerates failure of individual components to deliver a much increased level of availability and resilience. Get implementation tips now.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links
 
Send Us E-mail | Privacy Policy
Features List | Media Kit | Advertising | Contact Us

Copyright 2009 IDG Communications. ABN 14 001 592 650. All rights reserved.
Reproduction in whole or in part in any form or medium without express written permission of IDG Communications is prohibited.