Cybercrime, intellectual property, and professional ethics
◈ 3 cardsLaw as a deterrent control. Classify a computer crime by the computer’s role, work the Convention on Cybercrime’s Articles 2 to 11, and place intellectual property and professional codes in the same frame.
Law as a deterrent control
This lesson belongs to the control taxonomy of L13.4, not to a separate legal course. Recall the three levers a control can pull: reduce the vulnerability, reduce the threat source's capability or motivation, or reduce the impact. Criminal law pulls the middle one. It does not patch anything and it does not restore anything — it changes the expected cost of offending, and it makes prosecution available as a response. So law is a management-class, preventive control operating on motivation, and it is weak in exactly the way you would predict: a control that works by deterrence is only as strong as the probability of being caught.
Before the taxonomy, one term. Cybercrime connotes the use of networks specifically; computer crime may or may not involve a network. The two are used loosely in practice, and being precise about the distinction costs nothing.
The computer's three roles
Computer crimes are classified by what the computer did in the offence.
Computer as target. The system itself is attacked — to acquire information stored on it, to control it without authorisation (theft of service), or to alter data integrity or interfere with availability. For every case in this category there is a second classification the exam wants: which security property was attacked — data integrity, system integrity, data confidentiality, privacy, or availability. Naming the property is a separate mark from naming the category.
Computer as storage device. The machine is a passive medium furthering some other unlawful activity: it holds the stolen password lists, the card numbers, the proprietary documents, the pirated software. Nothing was done to the computer; it is the filing cabinet.
Computer as communication tool. Traditional crimes carried out online — fraud, illegal sales, gambling, harassment. The offence would be an offence without a computer; the computer changed its reach and its cost.
These categories are not exclusive, and saying so is worth a mark rather than costing one. A single operation frequently occupies several: an intrusion that steals a customer database (target — confidentiality), stores it on a rented server (storage device), and advertises it on a forum (communication tool). Classify it under each role it genuinely occupies and justify the overlap in a clause; an answer that forces one arbitrary choice looks less careful, not more.
The Convention on Cybercrime, Articles 2–11
The 2001 Council of Europe Convention on Cybercrime matters because it is the first serious international consensus on what constitutes cybercrime — which is the point, given that the offender is routinely in a different jurisdiction from the victim. Its substantive offences are Articles 2 to 11. Learn them by number, because a vague list is worth much less than an articled one.
- Article 2 — illegal access, to the whole or any part of a computer system, without right.
- Article 3 — illegal interception, by technical means, of non-public transmissions, including electromagnetic emissions from a system.
- Article 4 — data interference: damaging, deleting, deteriorating, altering or suppressing data without right.
- Article 5 — system interference: seriously impeding the functioning of a system by acting on data.
- Article 6 — misuse of devices: producing, selling, procuring, distributing or possessing a device or program designed primarily to commit an Article 2–5 offence — or a password or access code — with the intent that it be so used.
- Article 7 — computer-related forgery: producing inauthentic data with intent that it be acted on as authentic, whether or not the data is directly readable.
- Article 8 — computer-related fraud: causing loss of property by data manipulation or system interference, with fraudulent or dishonest intent to procure an economic benefit without right.
- Article 9 — offences related to child pornography: production, offering, distribution, procurement and possession.
- Article 10 — offences related to copyright and neighbouring rights.
- Article 11 — attempt, and aiding or abetting.
A structure that makes the ten hold together: 2–5 are the core integrity offences, 6 is the tools offence, 7–8 are traditional crimes committed by computer — which is why they are called computer-related rather than computer offences — 9 is content, 10 is intellectual property, and 11 is inchoate liability.
Two precise distinctions the exam exploits. First, Article 5 carries a severity threshold — seriously impeding — that Article 4 does not. Deleting one file is data interference; taking the system down is system interference, and only the second requires seriousness. Second, Article 11's attempt liability covers only a subset (Articles 3, 4, 5, 7, 8 and parts of 9), while aiding and abetting covers all of 2 to 10.
One counting note that has caught learners out: an assignment may speak of eleven cybercrimes while Articles 2–11 supply ten substantive articles. The safe answer covers every offence in the list and states the count it is using, rather than silently producing a different number from the question's.
Choosing cases without inventing them
A question that asks for a recent real case per offence is asking you to do research, and the marks are for accuracy. Three rules keep an answer honest.
Name only what you can source. Give the incident, the year, and what publicly happened. Do not assert a defendant, a charge number or a court outcome unless you have checked it — a wrong name in a criminal context is worse than a missing one.
Where you cannot source a case, describe the shape. A qualifying Article 6 case is a prosecution or takedown directed at the operator of a service that sells intrusion tooling or credential lists to others, where the offence is the supply rather than any particular intrusion. That is a legitimate answer and it demonstrates you understand the article.
Prefer incidents with extensive public reporting, and describe them only at the level of what happened. Three that fit and that this course uses as illustrations: the Colonial Pipeline ransomware incident (May 2021), in which a fuel pipeline operator halted pipeline operations after a ransomware compromise of its business systems; the MOVEit Transfer mass exploitation (2023), in which a vulnerability in a widely used managed file-transfer product was exploited to extract data from very many organisations at once; and the Change Healthcare ransomware attack (February 2024), which disrupted healthcare claims and pharmacy processing across much of the United States for weeks.
Worked example — classifying three incidents
Colonial Pipeline (2021). Roles: computer as target primarily, with a communication tool aspect in the extortion demand. Properties attacked, for the target classification: availability above all — the operational decision to halt the pipeline followed from the compromise of the business systems — and data confidentiality where data was exfiltrated before encryption, and data integrity where files were encrypted in place. Convention articles engaged, in the abstract: Article 2 (illegal access), Article 4 (data interference — encrypting files is altering and suppressing them), Article 5 (system interference, and the seriousness threshold is plainly met), and Article 8 where an extortion payment is the economic benefit sought.
MOVEit (2023). Roles: computer as target, and computer as storage device for the exfiltrated data at rest on the attackers' infrastructure. Property attacked: data confidentiality and, because the data concerned identified individuals, privacy — note that those are two separate entries in the list and a strong answer distinguishes them. Articles: Article 2 (access without right), Article 3 where transmissions were intercepted, and Article 8 where extortion followed.
Change Healthcare (2024). Roles: computer as target. Properties: availability at enormous scale — the marks here are for observing that the harm was overwhelmingly the stopping of a service on which third parties depended, rather than anything done to Change Healthcare's own data — plus data confidentiality and privacy in respect of the health information involved. Articles: 2, 4, 5 and 8 again.
Notice the pattern the three cases make: the same four articles recur, because modern intrusion-plus-extortion incidents engage the core integrity offences almost by construction. That observation is itself worth a mark, and it is also the reason a good answer reaches deliberately for the less-travelled articles — 3, 6, 7, 10 — rather than describing the same ransomware case four times.
Why cybercrime is hard to police
A vicious cycle, and it is causal rather than a list. Low law-enforcement capability produces low arrest and prosecution rates; low prosecution rates embolden offenders and increase their number; victims lose confidence and under-report; under-reporting starves law enforcement of the cases and intelligence that would build capability; and the cycle closes.
Four structural difficulties feed it: the technical sophistication required and the shortage of experienced investigators; lack of resources — processing, communications and storage capacity beyond a jurisdiction's budget; the global nature of the offence, with the perpetrator in another jurisdiction and cross-border collaboration slow; and the inability to profile offenders, since the behavioural range is wide and no cybercriminal databases exist. Victims under-report for three reasons: lack of confidence in law enforcement, concern for corporate reputation, and fear of civil liability. And the memorable practical claim: successful use of law enforcement depends much more on people skills than on technical skills — on the relationships built before the incident.
Intellectual property, briefly but exactly
Three types of property: real (land and what is permanently attached), personal (moveable goods and effects), and intellectual — any intangible asset consisting of human knowledge and ideas. Three types of intellectual property:
Copyright protects the tangible or fixed expression of an idea, not the idea itself. The work must be original and put into concrete form. It confers five exclusive rights: reproduction, modification (the derivative-works right), distribution, public performance, and public display. Expression, not idea is the single most important sentence in the section, and it is the reason an algorithm needs a patent rather than a copyright.
Patents grant the right to exclude others from making, using, offering for sale, selling or importing the invention, in three kinds — utility (a new and useful process, machine, article of manufacture or composition of matter), design (a new ornamental design), and plant. Why this is a security concern and not merely a legal one: RSA was patented from 1983 until the patent expired in 2000, and during that period every implementation owed a licence fee. Patent status shapes which cryptography gets deployed, which is an architecture decision.
A trademark distinguishes goods by source; a servicemark does the same for services. A trademark cannot stop anyone making the same goods — only from using a confusingly similar mark.
The DMCA encourages copyright owners to deploy technological measures in two categories — those preventing access and those preventing copying — and then prohibits bypassing them, and prohibits the manufacture, release or sale of circumvention products, with criminal and civil penalties both for circumventing and for assisting circumvention. Five exemptions: fair use (deliberately not tightly defined), reverse engineering (permitted only if the user has a right to a copy and the purpose is interoperability, not duplicating functionality — learners consistently drop the second condition), encryption research, security testing (with the owner's authorisation), and personal privacy. The standing criticism, worth stating in an answer: research communities hold that the act inhibits legitimate security and encryption research. In digital rights management, four roles: content provider · distributor · consumer · clearinghouse — and the architectural point is that the distributor does not enforce access rights; the provider encrypts and the clearinghouse issues the licence, applies the usage rules and pays both provider and distributor.
Ethics, from principles rather than clauses
Ethics is a system of moral principles concerning the benefits and harms of actions and the rightness of their motives and ends. Computing ethics is not merely general ethics applied to computers, for two reasons: computer technology enables a scale of activity not previously possible, magnifying one individual's power to do harm; and it has created new kinds of entity for which no agreed ethical rules previously existed.
The hierarchy has three levels: obligations shared with all human beings; additional obligations arising from being a professional; and the specific obligations of one profession. Four computer roles generate ethical issues: repositories and processors of information, producers of new forms of asset (a program is a genuinely new kind of asset, and physical-property concepts may not transfer to it), instruments of acts, and symbols of intimidation and deception.
A professional code serves five functions: inspirational (a positive stimulus and a source of public confidence — but a code that stops here is vague and open to abundant interpretation), educational, supportive (backing a professional whose ethical decision brings them into conflict with an employer), deterrence and discipline (grounds for revoking a membership or licence), and public image. Seven themes are common across the major professional codes: dignity and worth of other people; personal integrity and honesty; responsibility for one's work; confidentiality of information; public safety, health and welfare; participation in professional societies; and the notion that public knowledge of and access to technology is equivalent to social power.
A complementary framework holds that those who design, develop or deploy a computing artifact are morally responsible for it and its foreseeable effects; that this responsibility is shared but not diluted by the number of people involved — shared responsibility is not a zero-sum game; that knowing use carries its own responsibility; that responsibility requires accounting for the sociotechnical system the artifact sits in; and that no one involved should deceive users about it.
Two dilemmas are the teachable ones. Whistleblowing — the conflict between professional duty and loyalty to an employer, where the organisational answer is to provide less extreme alternatives, such as an in-house ombudsperson plus a credible commitment not to penalise internal reporting. And conflict of interest — a consultant with a financial stake in a vendor must disclose it before recommending that vendor, and disclosure rather than abstention is usually the required act.
The book's own critique of the codes is good exam material: they emphasise responsibility to other people, which is right, but make little specific mention of computers, so they remain generic and do not address the four computing-specific roles above.