What is the Impact of Cybercrime on the Global Economy?
Gavin Connolly, Dara Clarke, Stephen Byrne
TY
Table of Contents
Introduction
Economic impact of Cybercrime to Ireland
Economic Impact of Cybercrime to Ireland
Economic Impact of the HSE ransomware attack of 2021
The Cost of Cybersecurity for Ireland
The Cost of Cybersecurity for Ireland
The Cost of Cybersecurity for Ireland
Interview with Mark Lane, Lecturer in cybersecurity at TUD
As part of our research into this project, we interviewed Mark Lane, lecturer in cybersecurity at the Technological University of Dublin (TUD) and founder of Zerodays CTF, which for the last 10 years has brought young people all over Ireland into the cybersecurity scene. We wanted to hear his input into the importance of cybersecurity and how businesses across Ireland are vulnerable if the investment into cybersecurity isn't made. We asked him five questions about the most important aspects of cybersecurity in Ireland. We would like to sincerely thank Mark for taking his time to answer our questions.
Interview with Mark Lane, Lecturer in cybersecurity at TUD
1. Are cyberattacks becoming a threat to the Irish government?
Yes, cyberattacks are an increasing threat to the Irish government. In recent years, Ireland has experienced a sharp rise in cyber incidents targeting government agencies and critical infrastructure. One of the most high-profile attacks was the 2021 ransomware attack on the Health Service Executive (HSE), which disrupted healthcare services nationwide and cost the government millions in recovery efforts. This attack demonstrated how cybercriminals are not just targeting businesses but also public institutions, leading to potential risks for national security, economic stability, and public safety.
Additionally, Ireland’s growing digital economy and role as a European tech hub make it an attractive target for both cybercriminals and state-sponsored actors. Government agencies manage vast amounts of sensitive data, and any breach could have severe consequences. While steps have been taken to improve national cybersecurity, including the establishment of the National Cyber Security Centre (NCSC), continuous investment in defensive capabilities, training, and public-private collaboration is essential to counter this evolving threat landscape.
Interview with Mark Lane, Lecturer in cybersecurity at TUD
2. Is the Irish government investing enough into cybersecurity?
While the Irish government has made progress in strengthening national cybersecurity, current investment levels still fall short of what is required to adequately defend against increasingly sophisticated cyber threats. The National Cyber Security Strategy 2019-2024 outlines Ireland’s approach to improving its cyber resilience, but critics argue that funding and resources remain insufficient, particularly when compared to other European nations.
For example, in 2023, the Irish government allocated €22 million to the National Cyber Security Centre (NCSC)—a significant increase from previous years but still relatively low compared to the UK’s £2.6 billion National Cyber Strategy investment. Cybercriminals and nation-state actors are continuously evolving their tactics, and without substantial long-term funding, Ireland risks falling behind in its ability to protect critical infrastructure, businesses, and government systems. Increased investment in cybersecurity talent development, public-private partnerships, and proactive threat detection measures is essential to ensure Ireland remains resilient against cyber threats.
Interview with Mark Lane, Lecturer in cybersecurity at TUD
3. Which country poses the biggest threat to Irish businesses?
While cyber threats can originate from anywhere, Russia and China are often cited as the biggest state-sponsored cyber threats to Irish businesses, particularly in sectors involving sensitive data, finance, and technology. Russia has been linked to cyber espionage campaigns targeting European countries, and with Ireland being home to key global tech and financial services companies, it is an attractive target for intelligence gathering and disruption.
China, on the other hand, has been accused of engaging in cyber espionage to steal intellectual property and trade secrets from businesses worldwide. Given Ireland’s role as a major hub for multinational corporations, particularly in pharmaceuticals, software, and finance, Chinese cyber actors may seek to exploit vulnerabilities in these industries.
However, it’s not just state-sponsored threats that Irish businesses need to worry about—cybercriminal groups from around the world, including Russia, Eastern Europe, North Korea, and beyond frequently deploy ransomware and phishing attacks against Irish firms. The Conti ransomware gang, for instance, was linked to the devastating 2021 HSE cyberattack. In short, Irish businesses face cyber risks from multiple international actors, and robust cybersecurity measures are critical to mitigating these threats.
Interview with Mark Lane, Lecturer in cybersecurity at TUD
4. Do Irish businesses need to be made more aware of the threats cyber-attacks can pose?
Absolutely. While awareness of cyber threats has improved in recent years, many Irish businesses, particularly SMEs (small and medium-sized enterprises), remain underprepared for cyberattacks. According to research, a significant percentage of Irish companies lack adequate cybersecurity measures, making them easy targets for ransomware, phishing, and data breaches. Many business owners believe they are “too small” to be attacked, but cybercriminals often target SMEs precisely because they tend to have weaker defenses.
More needs to be done to educate Irish businesses on basic cybersecurity hygiene, incident response planning, and threat awareness. The government and industry groups should work together to provide accessible training programs, resources, and incentives for businesses to invest in cybersecurity. Initiatives like Cyber Ireland and the National Cyber Security Centre (NCSC) could play a bigger role in driving awareness. Without proactive education and investment in cybersecurity, many Irish businesses remain at serious risk of financial and reputational damage from cyber incidents.
Interview with Mark Lane, Lecturer in cybersecurity at TUD
5. What is the most cost-efficient method of cybersecurity for low-profile Irish businesses with small budgets?
For low-profile Irish businesses with limited budgets, implementing cybersecurity best practices doesn’t have to be expensive—many effective measures are low-cost or even free. The most cost-efficient approach involves a combination of basic security tools, employee training, and common-sense cyber hygiene practices.
By implementing these low-cost but highly effective cybersecurity measures, even the smallest businesses can significantly reduce their risk of falling victim to cyberattacks. For those with slightly larger budgets, outsourcing cybersecurity to a managed security provider (MSP) can also be a cost-effective option.
Cost of Cybersecurity for everyday people
Survey on Cybersecurity for everyday people
We decided to carry out a survey; to highlight the knowledge people have on cybercrimes and how important it is to have cybersecurity measures in place at home. We received 43 responses which gave us a good indication of reliable data. We also wanted to investigate whether people had suffered cyber-attacks themselves and the financial reprocussions of these attacks. In question 1, we asked fellow students if they had previously heard of a cyberattack.
Survey on Cybersecurity for everyday people
In question 2, we asked students if they had ever previously experienced a cyberattacks, to understand the percentage of people in our school that had experienced a cyberattack. The majority of students stated that they had previously experienced a cyberattack, which shows the importance to invest in high-quality cybersecurity software on devices.
Survey on Cybersecurity for everyday people
In question 3, we surveyed students on the types of cyber-attacks that they had experienced. 3 had experienced Malware, 15 experienced Scam Email/ Text Message, 2 experienced social engineering, 5 experienced password stealing and 4 had experienced other types of cyberattacks. While Scam Email/ Text Message proved to be the most common type of household cyberattack, this question conveyed the range of methods used to infiltrate people's data.
Survey on Cybersecurity for everyday people
In question 4, we asked people if they had previously lost money to a cyberattack. While we were relieved to see the majority of people hadn't, we were disappointed to see that 16 people had lost money to a cyberattack, which out of a pool of 43, is a significant number.
Survey on Cybersecurity for everyday people
In question 5, we asked people the amount of money that they had lost to cyberattacks, if any. The majority of people lost funds in the range of €0-€15. 8 people lost money in the range of €50-€100. 1 person lost money in the range of €100-€200 wile 3 people lost over €200. We were very taken aback to see that 3 people out of 42 had lost over €200 to a cybercrime.
Survey on Cybersecurity for everyday people
In question 6, we asked students if they had purchased anti-virus software for their device. This provides us with the cybersecurity aspect of the survey, finding out if people are aware of the risks associated with cybercrime if anti-virus software is not purchased. A staggering 63% of people had not invested in anti-virus software which is a huge issue and is maybe the reason why 3 people suffered a collective loss of at least €600 from cyberattacks.
Survey on Cybersecurity for everyday people
In question 7, we asked students what anti-virus software brand they had chosen if they had elected to purchase the software. Norton SafeSearch proved to be the most popular with 38% of people choosing it. 14% chose Avast Antivirus and 24% chose McAffee Antivirus. Nobody uses Bitdefender antivirus and 24% of people use a different brand to the ones we provided.
Impact of Cybercrime on the UK
The Economics of Cybercrime for Russia
The Economics of Cybercrime for Russia
The Economics of Cybercrime for Russia
Economic impact of cybercrime on the Russia-Ukraine war
Cyber criminal bosses
Russian ransomware
Russian Ransomware
The Economics of Ransomware
Economics of large Cyber attacks worldwide
The impact of AI on cybersecurity
The impact of AI on cybercrime
Global Goals
Major Cyberattacks during 2024
In February 2024, Change Healthcare of the United States of America suffered a catastrophic cyberattack. The culprit was identified as a Russian group known as BlackCat (ALPHV). Change Healthcare primarily look after electronic payments and medical claims within the healthcare sector of the US. This data infiltration led to nationwide disruptions. Medical claims and electronic payments were halted. UnitedHealth Group estimated the direct cost of the attack at approximately $2.87 billion and the company paid a further $6 billion in assistance of healthcare providers that had been affected due to the attack. UnitedHealth CEO Andrew Witty later confirmed that the organisation paid the ransom to BlackCat at a cost of $22 million, further increasing profitability for the cybercrime group. This attack exposed the weakness in cybersecurity measures in healthcare while also highlighting the economic efficiency of BlackCat.
Major Cyberattacks during 2024
Major Cyberattacks during 2024
Major Cyberattacks during 2024
Major Cyberattacks during 2024
In September of 2024 Transport for London (TfL) experienced a cyberattack that disrupted services. The greatest impact was on disabled passengers who relied on TfL's Dial-A-Ride service, yet again highlighting the huge impact cyberattacks can have on daily life. Initially, TfL believed that no data had been compromised; however, further investigation revealed the extent of the breach. The attack had allegedly compromised the personal data of approximately 5,000 customers, including sensitive information such as home addresses and banking details. Concerned that this could be a ransomware attack, the IT security teams at TfL took swift action by shutting down and restricting access to several systems to contain the damage. However, this resulted in significant operational disruptions and financial losses. TfL reported that the incident cost the organisation £30 million. £5 million has been since spent spent on response efforts, investigations, and implementing enhanced cybersecurity measures.
Conclusion
In conclusion, we found that cybercrime has a significant impact on the global economy. Unfortunately, the figure is growing with every passing year, and measures must be put in place to ensure that cybercrimes are put to a stop. For context, regular, day-to-day crime in the UK costs the nation approximately £38 billion. Police, Investigators, Courts, prisons and more are there to resist the amount of crime. However, many won't know that the annual cost of cybercrime in the UK is $27 billion and is over 2/3 of the annual cost of crime. Despite some cybersecurity measures in place, cybercrime does not receive near the attention that regular crime does, exposing the risks cybercrime poses.
Conclusion
We conclude that cybersecurity must be increased as cybercrime gangs are recruiting people who don't require a lot of experience or qualifications. They provide them with the ransomware software, and they steal. Cybercrime now costs the US 0.78% of the national GDP. This figure is increasing. International cooperation to prosecute cybercriminals and affiliated gangs must be increased, as international cybercrime is the most difficult to trace. We conclude that Irish businesses are vulnerable and that people at home must purchase anti-virus software for their devices at home. Yet, the measures the NCSC has taken are positive, and hopefully will limit cyberattacks in upcoming years.
Reflections
References