Monday, 5 October 2015

CCL Opening of its new Digital Forensics Training Academy

www.cclgroupltd.com

I am looking forward to the launch on Thursday 8th October

The opening of this additional 10,000 sq ft building at 34 Cygnet Court in Stratford upon Avon, for CCL’s Training Academy and additional space for the growing team of Digital Forensic analysts, is an important milestone in our 30-year history and celebrates the next phase of our exciting business growth.

This comes at the same time as our recent acquisition of another Digital Forensic business (Blackthorn Technology) based in the centre of London. With an unprecedented increase in demand for our Digital Data Investigations (DDI) services and Cyber Consultancy, we are looking to increase our staff to 150 by the end of 2015 and to over 180 by the end of 2016.

Empowering our clients with knowledge and skills has been one of the cornerstones of CCL since its inception and although we have been providing high quality training for a number of years the NEW CCL Training Academy places us at the very forefront of technical training providers in the UK.

Our new facility, which has the capacity to train over 40 delegates per day, offers a range of courses with subjects covering; Digital Forensics, Cyber Security and Digital Investigations. Ranging from Python scripting for use in forensics investigation, through to Dark-Web investigations for intelligence officers, crime and fraud investigators. Over 80% of the courses have original material content based on our extensive experience and expertise.

Sunday, 4 October 2015

Reengineering Crime Recording




Reengineering Crime Recording


There are many deep questions people ask. What is crime? How is it recorded? What are the rules for recording? Is it a complete representation of all criminality?

Recent attention has focused on a change that will dramatically alter the amount of crime recorded and change the relationship between “normal” crime and its digital cousin. The Crime Recording system will also alter people’s perception of what crime is, how it’s recorded and how it’s investigated. These recent changes have created a debate that no doubt will have at least two sides and probably no ends.

The vision of Crime Recording in England and Wales is that it is renowned for being the best crime recording system in the world: one that is consistently applied; delivers accurate statistics that are trusted by the public and puts the needs of victims at its core. A brave statement. The new change should be focused on those aims.

The rules for Crime Recording are regularly reviewed and each force is inspected as to how it then executes and enforces the rules. Individual Force Crime Registrars are held accountable for crime recording performance. Police and Crime Commissioners continue to hold Chief Constables accountable for their ability to record crime accurately, effectively and in compliance of the rules.

All the data from Crime Recording systems across England and Wales is collated and published by the Office of National Statistics (ONS) having been removed from the Home Office to make them appear more independent and therefore reliable.


Over the past weekend the media announced that the crime statistics from ActionFraud (the UK response to fraud and computer crime), would be added to National Police Crime figures published by the ONS. The net result will be a 40% increase in crime overnight. The announcement, made by the Commissioner of the City of London Police, may not be great news for those who have heralded a reduction in recorded crime around the UK.


However there is little doubt that this will lead to a much more accurate assessment of criminality in England and Wales. Yet even with the addition of ActionFraud data, it is unfortunately not the full picture of criminality.



Police Crime Recording still excludes a small range of data recorded elsewhere, for example:

·         Where the Serious Fraud Office (SFO) has been solely responsible for an investigation and arrest of a suspect, although the police charge the suspect and submit papers to the Crown Prosecution Service on behalf of the agency. The SFO has primacy of investigation.

·         Where the police provide information, but no other assistance, to a Department of Business Innovation and Skills fraud investigation.

·         Where the police offer custody facilities to customs officials who have apprehended smugglers and Her Majesty’s Revenue & Customs (HMRC) has primacy of investigation.

·         Where the police accompany customs officials in raiding a ship suspected of smuggling and HMRC has primacy of investigation.

·         The Department of Work & Pensions (DWP) provides the police with the names of benefit fraud offenders for intelligence purposes. The DWP has primacy of investigation.

·         The police assist DWP officials in surveillance work that leads to the apprehension of benefit fraudsters. DWP has primacy of investigation

These examples are cited in the Crime Recording Rules. They all involve operational activity by Police for which there is no Police Crime Record for national statistics purposes. Each of the agencies keep separate accounts which need to be considered alongside “Police Recorded Crime” to get a full picture of criminality in England and Wales. Until now crime reported to ActionFraud was also excluded

Some other crime incidents do not have to be recorded by the Police. For example, if the National Fraud Intelligence Bureau (NFIB) has recorded an incident, and has not allocated it for investigation, and determined there are insufficient lines of enquiry to warrant further investigation. This assessment will be managed by the NFIB (which currently sits under the remit of the City of London Police). This data is however used for NFIB briefings with other Departments and Central agencies as well as industry but is not part of Police Crime Recording.



Most people would probably accept that incidents of online or cyber-crime (where the offence is committed within a digital environment rather than merely to perpetrate a “normal” crime) should be recorded and investigated. That simplistic approach is slightly frustrated for many reasons which can discourage victims from reporting incidents to the police such as:

·         Where there are multiple victims across the globe or in the UK making the investigation too costly or unmanageable

·         Where the likelihood that offenders live or operate in countries without mutual assistance for investigations, or extradition treaties.

·         Where the embarrassment caused to companies of having been attacked and the consequential loss of confidence amongst its customers.

·         Where the victim considers the cost of reporting (staff downtime, disruption etc.) to exceed the potential loss.



The reality is that such incidents do not become part of the rich picture of recorded crime. However, these incidents are sometimes within the knowledge of major cyber-security companies and of course the victims. There is an argument that they should all be included in the National Police Crime statistics.

Bringing all this information together to create a full and accurate picture of cybercrime and fraud sounds simple. However, unless this data can be collated, analysed and disseminated within a usable timeframe, it will be of little value. There has to be a balance between collating all relevant and accurate data about online criminality, and providing something useful and timely for investigation and prevention.

The ActionFraud data will help to provide greater granularity to f criminality in England and Wales but at the expense of a substantial shift upwards in crime numbers overall. Such granularity, however, can help to tackle broad national issues, but unless the data is relevant to locally instigated criminality, and is available to local officers, it will only be relevant to national agencies. It is believed the move by ActionFraud will not deliver localised data for all reports.

Even with ActionFraud data, the picture of cybercrime and fraud will still be incomplete. Data on cybercrimes and attacks including hacking and other digital related criminality is sometimes held by other centrally based Agencies or businesses.

For example, the UK Computer Emergency Response Team has led a number of Regional Cyber Information Sharing Partnerships (CISP) to allow industry and business to share incidents of cybercrime. These incidents, unless they lead to a prosecution or investigation, will probably not make it to the Police Crime statistics.



Looking at some recent incidents there are many different cyber focused crimes


Any sporting or social event can create the opportunity for scams and fraud. The current Rugby World Cup is no exception. To be able to respond with an effective investigation or to warn and prevent further offences requires swift and effective dissemination of intelligence and data through ActionFraud which is what ActionFraud and National Fraud Intelligence Bureau were established to deliver. Such advice is regularly provided to Forces and other organisations.


A crime involving “parcel mules” who steal from major distributors such as Amazon is not strictly a Cybercrime but is a fraud and/or theft dependent upon how it is executed. Unlikely to be identified at an early stage and possibly creating a lower level response from the Police if at all, the most that can be achieved is broad prevention strategy. Yet, with effective analysis by ActionFraud and the NFIB, offenders could be brought to justice. Bringing the ActionFraud data into line with Police Crime Data will make such an outcome much more likely

The need for prevention advice and swift investigative ability is highlighted by a recent case


In this instance using social engineering and digital skills a company was duped into giving away its data and allowing criminals to escape with £1M. Clearly this is a serious crime owing to both the substantial financial loss and gain. However, many much smaller, similar offences could be perpetrated without victims knowing for some time, or even ever at all. Yet these lesser offences are possibly held within NFIB or ActionFraud and so bringing them into the main Crime Recording system is a positive move

In this digital age you don’t need a sawn off shotgun and a mask to rob people, far easier to do it from the garden in your far away timeshare with your iPad. Understanding the difference between the two crime styles and the overlaps is an important aspect of crime recording and more importantly crime investigation.

Responding to the many types of online/digital crime and incidents requires the collection, analysis and dissemination of effective crime data enabling investigations, both proactive and reactive, as well as prevention campaigns. England and Wales have the institutions to deliver that including ActionFraud, CERTs and CISPs in addition to existing Crime Recording systems in police forces and the National Crime Agency. Bringing the data together, however unpalatable it will be in the short term, will improve our understanding of online criminality and help us to prioritise police resources accordingly

No discussion of crime policy should ignore the current financial restrictions facing Police Forces. There is no intention to create an additional workload when there may not be sufficient staff to manage even the current demand. By bringing the ActionFraud data into mainstream crime recording it will lead to a massive increase in the total crime recorded, it is suggested that it will be 40%. However, that crime already exists and this is a more open and honest way or reproducing it. The public will want to have some confidence that these crimes are being investigated properly or are at least used to prevent further offending.

If ActionFraud is operating as it was designed, and the NFIB is disseminating appropriate crimes for local investigation then crime has not “Increased” by bringing the data into Police Recorded Crime. It is just that people will have a better and fuller understanding of online criminality. Additionally it will allow far greater effort in tackling those crimes that affect people on a daily basis such as spamming, hacking and identity theft. Having a more open and transparent approach to crime recording allows policy makers and the electorate to make much more informed decisions about how public spending should be used.

Further changes that could make the investigation of cybercrime and fraud much more effective might include the following

  1.  A much greater emphasis on training in cybercrime and digital forensics for all police officers and staff ( College of Policing is starting to deliver this)
  2. Greater collaboration between Police and Industry. (The CISPs and other projects as well as Police and Industry led fora are making this relationship closer)
  3. Tighter legislation to protect against Identity Theft
  4. Moving ActionFraud within the direct responsibility of the National Crime Agency or more closely to CERTs
  5. Investing more in Preventative campaigns including those targeting Small and Medium Enterprises and building on the Regional initiatives
  6. Expanding CISPs to cover all regions and sectors
  7. Investment in research to consider the impact of preventative campaigns and reduction strategies
  8. Greater public awareness of specific focus days such as Safer Internet Day
  9. Greater collaboration internationally between Police and Industry
  10. A clear joined up strategy between police forces including regional units and national agencies to analyse, investigate and prevent cybercrime.


Thursday, 24 September 2015

Owing to a serious illness the blog was suspened.
However it will be worked again from the 1st October 2015

Wednesday, 11 February 2015

Safer Internet Day.......Hitting the right buttons reaching to May15

Yesterday was Safer Intenet Day or #SID15
Considerable coverage across a range of media raising awareness in many languages on various fora to issues of safety online. But did it work, and how would we know?
As far as I can see there are no real measures in place of what is success or failure. No stats on # usage, amount of posts or number of people joining in.
Or more importantly what has changed.
It could be argued that the day was not about "Targets" or "Deliverables" but a timely and valuable assessment of how people protect themselves.
Aimed at some real risk and high profile aspects of social media usage, such as sexting, SID15 really sought to transform the activities, particularly risky ones, of young people. Yet are they the right audience? Are silver surfers, or elderly iPaders more or less vulnerable in their digital behaviour at home than a "youth" madly plucking their Samsung on the bus to school, surrounded by "advisers". 
Put simply we don't know. We can estimate risk based on reported cases through ActionFraud or police figures, or we can survey and hope people tell the truth. In either case we may be able to secure some consensus of the problem but probably not all.
However the one thing we probably can safely assume is that if we don't raise awareness through SID15 and similar events we run the risk of complete complacency, and that's not a great place to be.

Probably over the next few months we have the chance to raise these issues as we stroll towards the next election.
Here are some questions to ask candidates if you are stuck

What is your party going to do to make all people safe online?
How will you equip police to tackle online abuse, identity theft and cybercrime?
What will you do to protect the national critical infrastructure from hacking?
How will you train people to protect themselves and to manage offending behaviour when they see it? How will you help them secure the evidence?
What can your party do to ensure that digital evidence is secured quickly without disrupting the lives of innocent people?
How will you make ISPs and other industry leaders accountable for protecting our society online?

I am sure there are more

As the BT Share launch once said. Have you seen SID?
 
Yes I have and was encouraged. 

Many people did something. But was it enough and if not how do we use
the opportunity of May15 to put it right



Wednesday, 5 November 2014

New Jersey State Police and Heroin Deaths

Last week I had the privilege to vist the New Jersey State Police including their state of the art Regional Operations Intelligence Centre.
One of the presentations was particualrly pertinent in the light of the current comments on drug abuse approaches. 
They suffer in the region of 1300 heroin deaths a year and just under 9000 near misses out of a population of 8M which by any UK measure is high. However it has really driven the relationship between Heath and Law Enforcement. Whilst relationships at an operational level are usually excellent, at the strategic level and collaboration level it becomes a little disjointed. Anyone interested in exploring how to make Police and Health work  together would do well to consider the approach they have taken. Yes, it does involve sharing data, but not directly personal and it does help to focus attention.
An example of that approach is a willingness to really drive the issue of Heroin abuse as a health issue rather than just, "Arresting" their way out of the issue. 
Below is an example of one of the initiatives
http://www.northjersey.com/news/n-j-police-get-ok-to-carry-nasal-spray-that-can-halt-heroin-overdose-1.1036480
For those interested in the tactical equipment end of policing the NJ State Police can show you a wide range of kit.


Wednesday, 10 September 2014

SMILE day 2

We started the day with some exceptional awards for people who had made major contributions to the Police use of Social Media.

Each recipient provided a story of hope and expectation. Hope in the sense that it restored faith in the quality and commitment of Policing across the globe, particualrly in light of much recent negativity. That hope sustaining my belief that the vaste majority of cops do work hard and will deliver. 
The expectation is that if these winners can achieve so much, imagine what can be achieved if their stories and accounts are repeated, borrowed with pride and replicated virally.

So the awards impressed. I have to say I am so pleased for Mike Brown. An individual who much deserved his award as Top Cop. He has known the ups and downs of corporate attention, ignorance and support, challenge and authority. I have nothing but respect for the way he has calmly managed all this and it is with great delight that his talents are now being used nationally. He remains a traveller, seeking improvement on his bumpy road. An asset of true value and an ambassador. 

His presentation given later was dynamic and well informed, points argued from the head and the heart yet delivered professionally without notes or PowerPoint. 

He had the misfortune to follow a highly emotional yet brilliant presentation by Alex and Paul from RCMP New Brunswick. Telling the very recent story of how they managed the death of three colleagues in an informative and well structured manner, was itself an exemplar of the word professional. Holding the audience spellbound, yet imparting learned wisdom and knowledge was an amazing sight. Very powerful yet filled with aspects of the case that inspired. Their colleagues will not be forgotten.

In between the awards and the RCMP Babak Ahghar gave us an incredible insight into the world of the EU. He discussed an array of EU bodies and their respective contributions and initiatives. From CENTRIC to Athena he discussed some of the work he is undertaking at Sheffield Hallam. Highly informative and again well worth following up

Following Mike Browns delivery Hootsuite gave a really useful account of one of the more valuable tools for helping organisations to manage its interaction through Social Media. A tool many use for simply managing separate profile feeds has a great deal more to offer at an organisational level. Hootsuite UK described its connections with UK Police and many other public and private agencies and organisations, helping them to maximise their use of social media.

The theme of professionalism was extended by David Bailey (Staffs Police) painting an image of a Force in control of its Social Media engagement, flexibly grabbing opportunities to share and to answer. Extolling the virtues of a wide range of SM opportunities, providing examples of cases and initiatives across a host of platforms. Very well delivered and informative.

After David came Simon Cole. As Chief of Leicestershire he has driven Socail Media and is an exemplar of a much engaged senior officer, directing, guiding challenging yet "doing" social media. He is amongst a now steadily increasing group of Chiefs who have crossed the rubicon and have embraced the value and potential of social media. 

So a very useful day full of excellent speakers topped off with an inquisitive audience. 

See #SMILEcon on Twitter for all the links pictures and comments from the presenters and audience

Stuart

 

Tuesday, 9 September 2014

Some thoughts to make you SMILE

Today was the first day of the SMILE conference.
Social Media Internet Law Enforcement

An opportunity for police and others to consider how Social Media (SM) can be used more effectively. Bringing subject experts, experienced officers and staff, Comms experts and a range of presentations provides everyone with an opportunity to share, learn network and enjoy the benefits and opportunities of SM whilst appreciating the challenges and pitfalls

Some very powerful presentations provided much scope for debate and thought. Chief Constable Chris Sims in his usual straight talking and impactive manner, opened proceedings supported by WMPs PCC David Jamieson. Both were themselves supported by a collection of excellent images of policing over the years. 

Ian Hopkins DCC in GMP gave a powerful rendition of the values and integrity that should support SM, but linked it clearly to a range of highly valuable benefits and operational successes. Leadership in SM at its best from the two largest forces outside London. 

I enjoyed Dan Bartons input, he is head of Comms in the West Mids Police. He showed exactly what can be achieved by a strategic and integrated approach.

I had never heared of Eau Claire and assumed it was a perfume. In fact it's a great area of Wisconsin policed by some real forward thinking leaders. Kyle Roder gave an impassioned address about their approach to SM. A really impressive delivery.

There then followed a mixed group including West Mids Fire, London Ambulance, and West Mids Police. Again some very personal perspectives on the challenges of making and applying SM strategies.

After the CCL presentation (see next post) we heard from Pascal Renes from Belgium covering the challenges of managing SM across the many separate police forces in Belgium. More creativity much more insight. 
Then to top it all a non stop delivery across the web from Peter Sloly of Toronto Police. So many excellent points and issues raised. It would be unfair to summarise in a short paragraph

The total delivery for the day included a whole panoply of issues and ideas. No one can have failed to have been impressed with the variety.

So some thoughts from me

SM cannot just be imposed on staff, they need to feel part of it
You can't wait to give direction about SM to your staff. Your either keep up, or you will lose them
SM benefits are wide and strategic and far outweigh any minor discrepancies
There are however real dangers of officers or staff giving away operation details or becoming corrupted.
No organisation is too small or too big to offer learning to others.
SM is here to stay. It can't be banned or denied, only guided and harnessed. 
There does need to be a way to stop stupidity and certainly an approach to prevent criminality 
Matching the risk and threat with appropriate response is highlyvaluable 

I am certainly looking forward to tomorrow's inputs. 

Finally a massive thanks to Lauri Stevens without whose dedication commitment and energy this would fail.


Popular Posts in last 7 Days