Search

Cybercrime and its impact on business companies

Cybercrime and its impact on business companies

Information technology has become an integral part of society over the last decade, in such a way that we cannot even imagine life without it. This period opens the door to countless possibilities and in many ways facilitates our daily functioning. At the same time, it also brings with it new threats that come with technological progress, including cybercrime.

The way we communicate, how we work, how we spend our free time has changed, but so has the picture of contemporary crime.  With the development of technology, the variety of ways in which criminal activity can be committed has also expanded, and new targets have emerged that the perpetrators are targeting. In addition to "traditional" crimes, we are increasingly encountering crimes connected to cyberspace. For example, in 2022, compared to 2021, the number of crimes committed in cyberspace increased by almost 95%, which represents roughly 10% of total registered crime.[1] Moreover, these statistics also include entrepreneurs and business companies, who also become the target of cyber attacks. This can have an impact not only on damage to the reputation and significant financial losses, but it can also lead to disruption of the company's operation and damage to the rights of a third party. We will take a closer look at this issue in this article.

What is cybercrime?

Cybercrime is a term derived from the term cyberspace, which according to § 2 letter and) Act No. 181/2014 Coll., on cyber security: "a digital environment enabling the creation, processing and exchange of information, formed by information systems, and services and networks of electronic communications". It is possible to add that the exchange of information and the connection of these systems is what constitutes this space and not only what it is used for. Cybercrime is therefore a term originating in cyberspace it deviates from the standard division of criminal activity and categorization of crimes. It is not tied to a specific territory, objects or objects of attack. Therefore, it is not possible to strictly consider it as a separate branch of law, on the contrary, we can see in it certain features similar to other branches of criminal law.

If we were to look for a pure definition of cybercrime, we would hardly find it. The question is whether it is even possible to define cybercrime somehow. This term is constantly evolving and responding to dynamic changes in cyberspace. If we were to try to define it in some way bindingly, at the time of writing this definition could already be out of date. This could cause difficulties both for law enforcement and for society as a whole, which, as a target of this crime, must try to keep up with the perpetrators in terms of prevention and protection.

Even our legislation does not work with an official definition or a defined content of cybercrime. It can therefore be positively described as "criminal acts, the common denominator of which is that a computer acts as a carrier of hardware and software equipment and data, either as the object of an attack or as a tool of the perpetrator. "[2]

Terms such as computer, information or Internet crime may appear to be synonymous with cybercrime, but in reality they hide important nuances. These are, for example, different tools and objects of attacks, but also a different method of prevention or detection.

Threats to entrepreneurs

In recent years, the number of cyber attacks has increased dramatically and companies of all sizes and industries face the risk of data theft or various hacker attacks. By their actions, the perpetrators can paralyze their operation to such an extent that systems collapse, partial functions show errors, and thus they can put the entire company out of business. This brings with it several specific threats, depending on what the company does and what its focus is. Offenders can disable the functioning of the payment gateway, break into databases or shut down systems, whose task is to preserve some material in the appropriate quality (e.g. cooling equipment or equipment guaranteeing the maintenance of a certain hygiene standard). Damage can therefore range both in the order of "negligible amounts" and even in the millions or billions.

In view of the problematic definition of the concept of cybercrime, in the Czech legal system we do not find a special factual basis under which all criminal acts connected with cyberspace would fall. We do have a crime unauthorized access to the computer system and unauthorized intervention in the computer system or information carrier according to § 230 of the Criminal Code (hereinafter referred to as "TrZ"), a crime provision and storage of computer system access device and password and other such data according to § 231 of the Criminal Code or a criminal offence unauthorized access to a computer system or information carrier due to negligence in § 232 of the Criminal Code, but we classify other cybercrimes under de facto elements, the characteristics of which do not fundamentally include cyberspace. One can talk, for example, about sabotage (§ 314 of the Criminal Code), damage to another's property (§ 228 of the Criminal Code), under water (§ 209 of the Criminal Code), extortion (§ 175 of the Criminal Code) or o unauthorized handling of personal data (§ 180 of the Criminal Code) and Fr damage to the rights of others (§ 181 of the Criminal Code). We will now look in more detail at some specific forms of cybercrime that can affect businesses.

Spreading malware

Malware is short for malicious software, which is designed to cause damage to computers and computer networks. Among its most common forms are viruses, worms, Trojan horses, spyware or ransomware. Malware in all its forms can spread in a variety of ways, including e-mail, placing an infected link on a website or social network, visiting the infected site itself, inserting infected disks into a computer, or "simple" social engineering.

Malware infection of a computer can be manifested by its slowing down, spontaneous shutdown or restart, loss of data or pop-up of hitherto unknown dialog windows.

From the point of view of the focus of this article, the most problematic feature of malware is its availability. By simply clicking on a link that looks safe at first glance, employees themselves can easily infect the company's computer and system by mistake, for example when they receive a fraudulent e-mail.

DDoS attacks

DDoS attacks or Distributed Denial of Service are one of the types of cybercrime which aims to overwhelm a server or network such an amount of traffic that it becomes unavailable to its users. Attackers send a large number of fake requests to the target server through a network of infected computers, crippling it. We distinguish several types of DDoS attacks, namely volumetric attacks that focus on overwhelming the server with a large amount of data, protocol attacks that exploit weaknesses in network protocols to overwhelm the server, and application attacks that target specific applications running on the server.

An example of a DDoS attack can be given, for example, in connection with the publication of a new product on an e-shop. As an entrepreneur, you have this publication scheduled, and the moment it happens, a large number of customers will flock to your website. Although there may be a delay in the response of the server due to the large rush of people interested in this new product, you are prepared for it and the server will not so-called "fall". But suddenly the server starts receiving an enormous amount of fake requests. These will overwhelm the server and prevent it from processing real orders from your real customers. This leads to the unavailability of the e-shop, subsequent financial loss, and if we take it to extreme consequences, the perpetrators can also steal sensitive data during a DDoS attack, which is followed by the next subsection.

Leakage and misuse of personal data

The leakage and misuse of personal data has an impact not only on the company as a possible target of attack, but above all on its clients, employees or suppliers or other third parties. Again, it depends on what the company is doing. Certain types of personal data are stored, for example, by construction companies and others by companies operating in the healthcare field. Regardless of the focus, the leakage and subsequent misuse of personal data is without a doubt a serious act that affects even persons who at first glance have no connection with the company in question.

Data leakage can be caused by the activity of hackers, who break into the company's computer systems and steal data. Another way can be the aforementioned malware or ransomware. The human factor cannot be neglected either, when data leakage may be the result of human error. An employee can accidentally send this data to the wrong person, can negligently lose the device on which personal data is stored, or allow data leakage by not following security rules and measures, making the work of criminals much easier.

Such a leak can cost the company not only a good reputation, loss of clientele or possible civil disputes, but it can also be found to be a violation of the GDPR. GDPR or Regulation 2016/679 of the European Parliament and of the Council of 2016 on the protection of personal data sets out the rules for the protection of this type of data and applies to all companies that process the personal data of natural persons in the European Economic Area. The Office for the Protection of Personal Data can impose on the company a fine of up to EUR 20.000.000 or 4% of global annual turnover. At the same time, it is necessary to follow the prescribed procedure for reporting a data breach, to inform the subjects whose data was stolen, and to take corrective measures.

A legal person as a perpetrator of cybercrime

A legal person may not only be the target of a cyber attack, but also the perpetrator, as follows from the negative list in § 7 Act No. 418/2011 Coll., on the criminal liability of legal entities and proceedings against them (hereinafter referred to as "MOLE").

At the same time, it is not possible for the criminal offense to be committed by a legal person, because in view of the absence of the ability to legally act on its behalf (or in its interest or within its activities) a natural person must always act. In Section 8, paragraph 1 TOPO, these natural persons are defined as a statutory body or its member, a person performing a managerial or managerial activity or, for example, an employee performing work tasks.

This issue, i.e. the imputability of the actions of natural persons, is addressed by the domestic legal system in § 8 paragraph 2 TOPO. In principle, legal entities can commit all of the above, whether it is unauthorized handling of personal data, unauthorized access to a computer system or the spread of a computer virus.

Protecting society from cybercrime

The European Union is currently providing a means of protection in the form of the NIS 2 security directive. It is supposed to transpose this into the Czech legal system amendment to the law on cyber security. This directive, which entered into force at the beginning of 2023 and follows the already existing NIS directive, is aimed at cyber security against hacker attacks inside organizations and aims, among other things, to increase their resilience. This directive comes with stricter requirements for organizations compared to its previous version. These are regular risk assessments, implementation of security measures or reporting obligations. At the same time, NIS 2 affects a larger number of organizations. It may not only concern companies in critical infrastructure, such as energy, transport or healthcare, but also, for example, postal service providers, manufacturers and suppliers of key products and services, or it may concern companies operating in the field of waste management.

So the best defense against cybercrime is sufficient protection and prevention. Every company should thus ensure the correct implementation of technical and organizational measures. This includes in particular:

  • antivirus software, adequate encryption of data and regular updating of the company's software so that it does not unnecessarily expose itself to threats due to its vulnerability,
  • staff training about cyber security, about the threats that work with technology brings and also about the proper handling of sensitive data. Employees should thus be able to recognize a fraudulent e-mail or website in the basics, they should be instructed in the creation of strong passwords and their management, which consists, for example, in changing them regularly, and last but not least, it is important to emphasize safe movement on the Internet at corporate devices.
  • regular data backup, so that the data can possibly be restored,
  • constant interest in trends in cybercrime in order to adapt its measures accordingly,
  • "crisis plan" with a precisely defined procedure for how to act and how to react in the event that the company becomes the target of cybercrime.

záver

Cybercrime is a growing threat. The development of technology constantly expands the range of possible dangers, and this requires constant evaluation of possible risks and consideration of more sophisticated means of protection. The consequences of a cyber attack for legal entities can consist not only in the loss of a good reputation, but above all in financial losses and possible sanctions, for example, from the Office for the Protection of Personal Data. Given these circumstances, the topic of cybercrime is crucial for business corporations. Corporate law must reflect this threat and provide companies with tools for preventing and solving cyber attacks. In conclusion, we therefore allow ourselves to appeal for regular reflection of current risks both in internal company documents and in the training carried out and in the setting of sufficient security measures.[3]

Source: epravo.cz

Do you need help editing internal scripts to protect your company from cybercrime? Or do you suspect that someone has already attacked your company, but you don't know how to solve the matter?

Lucie Špičková

Mgr. Lucie Špičková, Attorney


[1] Report on the activities of the public prosecutor's office for the year 2022 [online]. Supreme State Prosecutor. 22/6/2023. [cit. 26 February 2]. https://verejnazaloba.cz/wp-content/uploads/2023/06/Zpráva-o-činnosti-2022-_textová-část.pdf

[2] Kuchta, J. Current problems of computer crime, including its prevention. Journal of legal science and practice. 2016, year 24, No. 1, p. 6.

[3] The writing of this article was based, among other things, on the Student Scientific and Professional Activity of the author Eva Hrdličková on the topic "Cybercrime from a criminal law perspective", 2024.

Have you read this far?

Subscribe to our newsletter

Enter your email here so you don't miss any news from our office.
More articles

Thank you for visiting our site.

If you would like to receive a selection of current legal news, we would like to offer you the opportunity to subscribe to our newsletter. Simply fill in your e-mail address.

Law firm Vych and partners