Cybercrime costs the global economy between $100 billion and $500 billion annually, according to a new study that acknowledged more data are needed for precise estimates. The McAfee-sponsored study also links malicious cybercrime activity with job loss.
McAfee engaged one of the world’s preeminent international policy institutions for defense and security, the Center for Strategic and International Studies (CSIS) to build an economic model and methodology to accurately estimate these losses, which can be extended worldwide.
To help measure the real loss from cyber attacks, CSIS enlisted economists, intellectual property experts and security researchers to develop the report. The general accepted range for cybercrime launch was between $100 billion and $500 billion to the global economy.
Researchers used real-world analogies like figures for car crashes, piracy, pilferage, and crime and drugs to build out the model. They noted the difficulty of relying on methods such as surveys because companies that reveal their cyber losses often cannot estimate what has been taken, intellectual property losses are difficult to quantify and the self-selection process of surveys can distort the results.
For purposes of the research, CSIS classified malicious cyber activity into six areas:
1. The loss of intellectual property
3. The loss of sensitive business information, including possible stock market manipulation
4. Opportunity costs, including service disruptions and reduced trust for online activities
5. The additional cost of securing networks, insurance and recovery from cyber attacks
6. Reputational damage to the hacked company
“We believe the CSIS report is the first to use actual economic modeling to build out the figures for the losses attributable to malicious cyber activity,” said Mike Fey, executive vice president and chief technology officer at McAfee. “Other estimates have been bandied about for years, but no one has put any rigor behind the effort. As policymakers, business leaders and others struggle to get their arms around why cyber security matters, they need solid information on which to base their actions.”
The report highlights that the cost of malicious cyber activity involves more than the loss of financial assets or intellectual property. There are opportunity costs, damage to brand and reputation, consumer losses from fraud, the opportunity costs of service disruptions “cleaning up” after cyber incidents and the cost of increased spending on cybersecurity, according to the report.
“This report is also the first to connect malicious cyber activity with job loss,” said James Lewis, director and senior fellow, Technology and Public Policy Program at CSIS and a co-author of the report. “Using figures from the Commerce Department on the ratio of exports to U.S. jobs, we arrived at a high-end estimate of 508,000 U.S. jobs potentially lost from cyber espionage. As with other estimates in the report, however, the raw numbers might tell just part of the story. If a good portion of these jobs were high-end manufacturing jobs that moved overseas because of intellectual property losses, the effects could be more wide ranging.”
Lewis and co-author Stewart Baker of Steptoe & Johnson LLP point out that as thoroughly as they plan to develop their estimates, the dollar amount might not fully reflect all the damaging effects that cyber espionage and cybercrime have on the global economy. Both activities slow the pace of innovation, distort trade and bring the spate of social costs associated with crime and job loss, according to the report. Lewis and Baker say the larger effect may be more important than any actual number, and it will be the focus of the next report.