TMCnet News

'Lack of Law to Address Cybercrimes is Dangerous' [interview]
[July 04, 2011]

'Lack of Law to Address Cybercrimes is Dangerous' [interview]


Lagos, Jul 04, 2011 (Daily Trust/All Africa Global Media via COMTEX) -- Adewale Jones, the Vice President of Association of Telecoms Companies of Nigeria (ATCON), in this interview says many Nigerians may continue to fall victims of hackers because there is no law to address cybercrimes.

What is hacking? Hacking is an unauthorized use of computer and network resources. When the term first emerged, it had to do with gifted students, programmers, academics, professionals with computer science or related background who enjoyed learning more about how computers work. To them, hacking was a form of art. At the time, those concerned were interested in programming and had credible skills in various computer programmes. As far as these people were concerned, hacking was a real life application of their skills in solving problems. It provided them an opportunity to demonstrate their computing/programming abilities. Their intention was not to engage in any criminal act or harm anyone. It was basically an innocent method of figuring out how the computer worked. This however is not so anymore.

In recent times the term has acquired a negative connotation. This is because hackers break into computers and computer networks without authorisation to steal, cause havoc and harm to those who own the system. This is no doubt a form of computer misuse. Most of the culprits are teenagers and young adults with criminal intentions e.g theft of online account information, pass word, identity etc. They also hack to attack the computer by releasing viruses, trojan horses and worms; intimidate the user by collecting unauthorised information, to attack and deny service etc.


How safe are Nigerian computer users? Nigeria as a country is at the centre of criminal hacking. Every now and then the news is that young Nigerians engage in gaining unauthorised and illegal access into computer systems by making the computer to perform a function. An example is the cracking of security codes of ATM cards in other to illegally steal money belonging to the user of the card. In some developed societies, an unauthorised interaction with a computer system without even actual access would qualify as hacking.

Our challenge in Nigeria is that there is no law to address hacking as a criminal offence. There was an executive bill - The Cyber security and Critical Infrastructure Bill - which was submitted to the National Assembly in 2005 but did not see the light of day. That bill was fashioned along the lines of the Council of Europe Cybercrime Convention 2001 popularly called the Budapest Convention. This Bill adequately addresses issues bothering on illegal access, illegal interception or interference with computer systems. If that law is passed, then from a legal framework point of view the issue of hacking would have been addressed.

Be that as it may, the emplacement of the law is not enough. There is need for its enforcement. Law enforcement as we know is a challenge in Nigeria.

What other things can Nigerians do to protect their documents from being hacked into? There is also need for users of computer systems at the various levels - individual, institutional and national - to take proactive security measures which is not the case today. Such should among others: -Incorporate various security measures into computer systems. This must be dynamic in approach because technology changes regularly.

- Establish practices for addressing vulnerabilities.

- Computer users need to be more knowledgeable about the risks they face.

- Those who manage computer systems should implement workable strategies to protect their systems.

- Organisations, institutions and governments should develop skilled personnel in cyber operations security.

- Address computer/network security issues as an integral part of the growth process of organisations, institutions and governments.

- There is need for increased collaboration at all levels to identify problems and trends on the subject of hacking - Organisations, institutions and governments should implement dynamic security policies at all levels in addition to conducting research into insider threats.

- Governments need to grow computer forensics.

- There is need for organisations to subscribe to some certification in the area of information security management. One of the most common is ISO 27001 which is essentially hinged on the ISO 17799 standards. The standards prescribe some information security controls considered germane to emplacing best practices in this area. Only First Bank is certified under this arrangement today.

The promotion of Computer Emergency Response (CERT) teams at all levels are critical to addressing some of the issues raised above. Nigeria must ensure this is emplaced to avoid the Estonian experience when for days the whole country's computer system was shut down.

[ Back To TMCnet.com's Homepage ]