Does cyber crime really cost £27 billion a year?
Security experts question the astronomical figure attributed to the cost of cyber crime in the UK.


A number of security experts have questioned the 27 billion figure placed on the cost of cyber crime.
A Government report released today estimated in the "most likely scenario" cyber criminals cost the UK 27 billion a year.
Furthermore, the Detica-authored report said the actual cost of cyber crime is likely to be far greater than that figure.
A significant chunk of that cost is due to intellectual property theft, amounting to losses of 9.2 billion per annum, the report suggested.
Businesses take much of the hit, with 21 billion lost every year thanks to hackers' efforts, according to the estimates.
To determine the figure, Detica brought together data from sources including information from the public domain, cyber security professionals, as well as business, law enforcement agencies and economics experts.
The security firm drew up a causal model, relating different kinds of cyber crime to their impact on the UK economy.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"We used the model to may cyber crime types to a number of broad categories of economic impact, which are generally consistent with the types of parameters used in macro-economic models of the UK," the report explained.
"We then calculated the magnitude of the cots of cyber crime using three-point estimates (worst-case, most-likely case and best-case scenarios), focusing in particular on IP theft and industrial espionage and its effect on the different industry sectors."
Figures released by Symantec earlier this week suggested cyber crime would cost the UK economy 1.9 billion in 2011.
The varying figures on the financial impact of illegal online activity in the UK has brought into question the validity of making such estimates.
Many in the security industry believe the 27 billion suggestion to be somewhat excessive.
Mikko Hyponnen, chief research officer at F-Secure, said in a tweet he found the figure to be "very high."
"In my view, there's more to be gained by highlighting the potential risks and explaining how to minimise them than in alarming people with abstract numbers that may or may not reflect reality," said David Emm, senior security researcher at Kaspersky Lab UK.
Sophos, meanwhile, has called for a more efficient way of measuring the cost of cyber crime altogether.
The company's senior technology consultant Graham Cluley called for a "proper mechanism for reporting cyber crime" before any figure is ascertained.
He suggested there was not enough detail on how Detica reached its estimates.
"An accurate measure of cyber crime is required in order to provide the proper support that computer users - in business and at home - need to defend against the threats," Cluley said.
"Once we know the true scale of the problem, and can produce reports that aren't dealt with skepticism, we can fund the computer crime authorities appropriately, and we can begin to measure if the UK's attempts to fight the problem are really working or not."
At the time of publication, Detica had not responded to a request for more information on how it came to the 27 billion figure.
Despite queries over the estimates, the report has been praised for spreading awareness of the threats facing UK businesses in particular.
Steve Durbin, global vice president of the Information Security Forum, said he could not comment on the figure but stressed where the report was correct was in noting the cost of cyber crime "is primarily borne by UK businesses."
"The cost of cyber crime is certainly significant and both private sector organisations and governments need to build a comprehensive picture of the threats to information security to be able to deal effectively with this growing trend," Durbin told IT PRO.
Tom Brewster is currently an associate editor at Forbes and an award-winning journalist who covers cyber security, surveillance, and privacy. Starting his career at ITPro as a staff writer and working up to a senior staff writer role, Tom has been covering the tech industry for more than ten years and is considered one of the leading journalists in his specialism.
He is a proud alum of the University of Sheffield where he secured an undergraduate degree in English Literature before undertaking a certification from General Assembly in web development.
-
Bigger salaries, more burnout: Is the CISO role in crisis?
In-depth CISOs are more stressed than ever before – but why is this and what can be done?
By Kate O'Flaherty Published
-
Cheap cyber crime kits can be bought on the dark web for less than $25
News Research from NordVPN shows phishing kits are now widely available on the dark web and via messaging apps like Telegram, and are often selling for less than $25.
By Emma Woollacott Published
-
The UK cybersecurity sector is worth over £13 billion, but experts say there’s huge untapped potential if it can overcome these hurdles
Analysis A new report released by the DSIT revealed the UK’s cybersecurity sector generated £13.2 billion over the last year
By Solomon Klappholz Published
-
"Thinly spread": Questions raised over UK government’s latest cyber funding scheme
The funding will go towards bolstering cyber skills, though some industry experts have questioned the size of the price tag
By George Fitzmaurice Published
-
96% of SMBs are missing critical cybersecurity skills – here's why
News The skills shortage hits SMBs worse as they often suffer from a lack of budget and resources
By George Fitzmaurice Published
-
Sophos Firewall Virtual review: Affordable network protection for those that like it virtualized
Reviews Extreme network security that's cheaper than a hardware appliance and just as easy to deploy
By Dave Mitchell Published
-
MSPs are struggling with cyber security skills shortages
News A shortage of tools and difficulties keeping pace with solutions were also ranked as key issues for MSPs
By George Fitzmaurice Published
-
Nearly 70 software vendors sign up to CISA’s cyber resilience program
News Major software manufacturers pledge to a voluntary framework aimed at boosting cyber resilience of customers across the US
By Solomon Klappholz Published
-
Sophos and Tenable team up to launch new managed risk service
News The new fully managed service aims to help organizations manage and protect external attack surfaces
By Daniel Todd Published
-
Ransomware groups are using media coverage to coerce victims into paying
News Threat actors are starting to see the benefits of a more sophisticated media strategy for extracting ransoms
By Solomon Klappholz Published