British Policing Faces The Future

The UK Police is struggling to cope in the face of changing and rising crimes, as a result of falling staff numbers, outdated technology, and fragmented leadership. There has been a 27% increase in crime in the last eight years in the UK. 

The UK House of Commons Home Affairs Committee has also just released their Policing for the Future report which was published on 22nd October and is about the changing trends in crime and policing and the overarching problems facing the police service in England and Wales. 

The main issues raised are funding and investment and that there are three specific areas of growing pressure on policing, online fraud, child sexual abuse, and safeguarding vulnerable people. 

The use of internet-enabled smartphones and tablets has increased drastically during the last decade, and data suggests that 86% of people go online “daily or almost daily” in 2018, compared with 35% in 2006.

Unsurprisingly, this explosion in internet use has been accompanied by an upsurge in online crime, including fraud. 

Earlier this year, it was reported that victims of online fraud are turning to private investigators, due to dissatisfaction with the police response. This report explores the police response to fraud, particularly online, including key trends in offending, the role of Action Fraud, the quality of the police response, capacity and structural issues, and the role of industry. 

Cyber skills and training are also crucial issues that are reported.

Prevalence and trends

The Office for National Statistics (ONS) estimates that there were 3.2 million fraud offences in the year ending March 2018, including 1.7 million cyber-related offences (54% of the total). 

Based on these figures, approximately one in six offences are incidents of online fraud, and fraud (more broadly) is now the most commonly-experienced crime, accounting for 42% of all estimated offences. 

New questions on fraud and computer misuse were only added to the Crime Survey for England and Wales in October 2015, so long-term trends are difficult to assess, although City of London Police (the national lead force on fraud) have said that “Fraud and cyber-crime have grown exponentially”.

The latest annual fraud indicator estimated that fraud costs the UK £190 billion per year, including £134 million from online banking fraud and £568 million from plastic card fraud. 

Action Fraud

Action Fraud is run by the City of London Police, although the contact centre is contracted out, and it works alongside the National Fraud Intelligence Bureau (NFIB). 

Action Fraud has repeatedly attracted negative press attention, after a series of administrative problems and reports of poor service. It was reportedly forced to apologise to almost 2,500 people in 2013, after their crime reports went missing due to an IT error.

Recently Action Fraud has undergone reform, with £35 millions of government funding spent on improvements to the helpline and website, including a new online reporting tool. 

Since October 2016, the call centre has been available 24/7 and the Home Office has invested £5.5 million in a new IT system for Action Fraud and the NFIB. Nevertheless, The Times reported in May 2018 that only cases involving losses of over £100,000 are being passed to a human investigator, with others being “dismissed by a computer algorithm as unworthy of investigation”. 

In August this year, it was reported that Action Fraud only picks up two-thirds of phone calls, with an average wait of 11 minutes and 8 seconds.

The force argued: “The volume of fraud means that investigative resources need to be prioritised towards the most harmful and organised frauds and, where offenders cannot be identified or offenders are based outside the UK, criminal justice outcomes are not always achievable”. 

Giving evidence to us, Temporary Commander Dave Clark, then the national lead officer for online fraud, emphasised that “Action Fraud does not investigate anything. [It] is simply a call centre and an online reporting facility”.

Cases are sent to the force where there are relevant lines of inquiry, such as a local bank account, postal address, internet address or telephone number, rather than where the victim is based, if the crime crosses force boundaries.

Overseas offenders account for a substantial proportion of offences, with approximately 14,000 criminals identified outside the UK in 2017. Organised criminal groups also play a prominent role: last year, for example, Europol disrupted a group which stole more than 8 million euros from over 130,000 payment card holders in 29 EU countries.83

Criticism of the Police Response

A series of reports have been highly critical of the police response to online fraud. A 2015 study of digital crime by HMIC, covering six out of the 43 forces, found “very few police officers and staff who understood either their own roles and responsibilities or those of their force in relation to the investigation of fraud.” 

HMIC found a particularly poor level of knowledge, at all ranks, of the functions of Action Fraud and the NFIB. It also criticised an “absence of strategic leadership and direction” on digital crime in all but one of the forces examined. 

The Public Accounts Committee (PAC) subsequently said that the Home Office “must prioritise efforts to improve the collection and reporting of data on fraud”, and called for the department to work with the City of London Police to establish “opportunities to identify, develop and share good practice in a more systematic way”.

Case Outcomes

Action Fraud received over 23,000 crime reports per month, on average, during 2016/17; in the same reporting year, 71,133 cases were disseminated to forces, and there were 37,632 “Home Office outcomes”–this includes judicial (8,214) and non-judicial (29,245) outcomes. 

The latter category can include failure to identify a suspect and a determination that prosecution would not be in the public interest, among other outcomes. These figures suggest that little more than one in five (22%) recorded outcomes involved charges or summons, and that as little as 3% of cases reported to Action Fraud may result in charges or summons. 

A report published by the Home Office in June examined the causes of attrition in fraud and cybercrime cases. It concluded that a number of factors contributed to cases being dropped after referral to forces, including confusion in police forces about who is responsible for investigating these crimes; the sheer number of cases disseminated, “and the risk that there are so many crimes they are unmanageable for forces”; a lack of recording of non-judicial outcomes; and a lack of clarity regarding inter-force cooperation, when cases cross force boundaries.

The proportion of fraud cases being investigated is shockingly low, in the context of 1.7 million offences per year and substantial costs to the UK economy, as well as to individual victims. 

The private sector could do much more to reduce the demand on policing from online fraud. This problem can only be addressed effectively with a whole-system approach, including by regulatory reform, if necessary, to force companies to be ‘secure by design’. 

Key private sector companies, those whose customers create the most substantial workload for the police and NCA, should also employ analysts internally to facilitate evidence-gathering by law enforcement agencies. 
If industry partners will not do so voluntarily, the Government should consider imposing statutory requirements on companies to cooperate with law enforcement agencies.

At force-level, there is a clear need to upskill the existing workforce and bring in more staff and officers with advanced cyber skills. 

Parliament.uk:

You Might Also Read:

Machine Learning Algorithms & Police Decision-Making

UK Victims Lose £28m To Cybercrime In 6 Months

« The Pentagon Prepares A Cyber-Attack On Russia
Social Media Companies Scan For Potential Terrorists »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

ZenGRC

ZenGRC

ZenGRC - the first, easy-to-use, enterprise-grade information security solution for compliance and risk management - offers businesses efficient control tracking, testing, and enforcement.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

European Defence Agency (EDA)

European Defence Agency (EDA)

EDAs mission is to improve European defence capabilities. Programme areas include Cyber Defence.

Cyber Risk Policies

Cyber Risk Policies

CyberRiskPolicy.com is a joint venture between the Poindexter Surety Group of companies and Gibbs Cyber Security.

CyberSmart

CyberSmart

CyberSmart is a platform that allows you to maintain compliance, achieve certification and secure your organisation.

Silicom Denmark

Silicom Denmark

Silicom Denmark is a premier developer and supplier of FPGA-based interface cards for cyber-security, telecommss, financial trading and other sectors.

Honeynet Project

Honeynet Project

The Honeynet Project is a leading international non-profit security research organization, dedicated to investigating the latest attacks and developing open source security tools.

Blancco Technology Group

Blancco Technology Group

Blancco Technology Group is a leading global provider of mobile device diagnostics and secure data erasure solutions.

Secure Recruitment

Secure Recruitment

Secure Recruitment is a specialist Executive Search business that focuses its efforts on attracting specific exceptional talent in Cyber Security.

Identifi Global Recruitment

Identifi Global Recruitment

Identifi Global is one of the UK's leading Cyber Security & IT Recruitment specialists.

Tier1Asset (T1A)

Tier1Asset (T1A)

T1A is Europe’s leading IT refurbisher. We offer certified data erasure using blancco on site and at our facilities, providing environmentally sound disposal of your used equipment.

Splone

Splone

Splone is a Berlin-based IT security research team and consultancy. We help improve IT-security by offering red team assements, penetration tests, audits and customized consulting.

Billington CyberSecurity

Billington CyberSecurity

Billington CyberSecurity is a leading, independent education company with an exclusive focus on cybersecurity.

Nettoken

Nettoken

Nettoken is the first identity management platform designed for everyday internet users, to encourage awareness and control of our ever expanding digital footprint and personal cybersecurity.

Censinet

Censinet

Censinet provides the first and only third-party risk management platform for healthcare organizations to manage the threats to patient care that exist within an expanding ecosystem.

Helix Security Services

Helix Security Services

Helix Security provides IT & information security consultancy to government and businesses across New Zealand.

SEALSQ

SEALSQ

For the last 25 years, SEALSQ have been developing secure semiconductor chips, secure embedded firmware, and tested hardware provisioning services to serve the vision of a safer connected world.

Cyderes

Cyderes

Cyderes (Cyber Defense and Response) is a global, pure-play, full life-cycle cyber security services provider formed from the merger of Herjavec Group and Fishtech Group in 2022.