Cybersecurity and Cybercrime: Intellectual Property and Innovation

Emile Loza de Siles

Cybersecurity and the industry, innovation, and issues it generates are profoundly transformative and intensely critical at every level and many or most social, corporate, and government functions.1 Cybersecurity legal issues cover a vast range: cyber warfare;2 national security;3 critical infrastructure defense;4 Internet access and freedom;5 data privacy and security;6 trusted software development and deployment;7 law firms’ protection of patent application, bank, and other confidential information;8 “hacking back” and other active cyber defense measures;9 information sharing by cyberattacked organizations;10 and more. This brief article begins the learning trek up that Matterhorn and outlines the relevance of cybersecurity and cybercrime to intellectual property and innovation.11

The Staggering Numbers

The global cybersecurity market for solutions and services will exceed $170 billion by 2020.12 The driver for that growth is cybercrime, the global financial impact of which is an estimated $375 billion to $575 billion every year.13 A 2014 global survey of some 9,700 executives found that cyberattacks rocketed up by 48 percent within a single year.14 By 2019, the costs of cybercrime to businesses will top $2 trillion worldwide,15 up from an estimated $1 trillion in 2012.16 Cybercrime-produced employment losses in the United States alone run more than 500,000 jobs.17 Beyond direct impacts and job losses, cybercrime also exposes companies to contract breach and other litigation risks.18 Reflecting this risk exposure and other trends,19 a 2014 PricewaterhouseCoopers survey sponsored by the U.S. Secret Service and others (Secret Service Survey) found that as much as 75 percent of corporate cybercrime in the United States may go unreported.20

These stunning statistics pale in comparison, however, to the inestimable value of cyber-compromised or – stolen intellectual property each year.21 Then-National Security Agency director and commander of the United States Cyber Command, General Keith B. Alexander said that cyber threats represent the “greatest transfer of wealth in history.”22 When he made this 2012 statement, cyber theft of intellectual property cost United States companies alone an estimated $360 billion per year.23 Cyber theft of intellectual property has become even more costly and destructive as criminal conduct has become more virulent and sophisticated. The threat curve has gone logarithmic. In 2015, executives in a global survey reported that cyber thefts of intellectual property have vaulted 19 percent over the prior year.24 Cybercrime undermines or even decimates innovation, innovator sustainability, and innovation-driven economic growth.25

In 2014, the Secret Service Survey revealed that 19 percent of the detected cyberattacks on the government industry sector compromised or resulted in the theft of intellectual property and other proprietary information.26 Another 24 percent of detected cyberattacks within this industry resulted in unauthorized access or use of data, networks, and systems.27 In the information technology and telecommunications industry, 31 percent of detected cyberattacks altered software applications, operating systems, or files, and 19 percent resulted in unauthorized access or use of data, networks, and systems.28 Losses of trade secrets and other proprietary information by detected cyberattacks are high across numerous industries, ranging from 19–23 percent of cyberattacks upon the financial, healthcare, and insurance industries.29

Undetected cyberattacks are even more concerning. As of 2012, 99 percent of cyberattacks were undetected.30 Among the tiny 1 percent of cyberattacks that were detected, detections only may have occurred after long periods of intrusion. For example, APT1, a cyberespionage unit tied to the Chinese government, maintained undetected access to its victims’ networks for an average of almost one year (356 days) and up to almost five years (1,764 days) before being outed.31

Black Hat Hackers

Insiders, competitors, nation states, organized crime syndicates, terrorists, and often unidentifiable others carry out or sponsor cyberattacks.32 Twenty-eight percent of Secret Service Survey respondents said that trusted insiders carried out cyberattacks against them.33 Forty-three percent of insider cyberattacks adversely impacted intellectual property rights.34 Given this intellectual property targeting, almost one-third (32 percent) of respondents said that insider cyberattacks were more damaging than outsider attacks.35 Insider attacks, however, are often kept out of the media, law enforcement reporting mechanisms, and the courts,36 despite the availability of potentially powerful relief under the federal Racketeer Influenced and Corrupt Organizations Act,37 the Computer Fraud and Abuse Act,38 and other laws.

State-sponsored cybercrime is also a significant and highly publicized threat. Companies increasingly find themselves on the front lines of the guerilla war in cyberspace.39 State-sponsored cyberattacks frequently target critical infrastructure and defense industries.40 A collective 38 percent of such attacks target the technology, telecommunications, energy, and aerospace and defense industries.41 The United States government charged five Chinese military operatives in May 2014 with hacking into the networks of U.S. manufacturers of nuclear reactors, solar panels, and other technologies.42 Executives surveyed in a 2015 global survey reported an 86 percent increase in state-sponsored cyberattacks on their organizations.43 Competitors are increasingly linked with nation states as the perpetrators or sponsors of cyberattacks in Asia Pacific and especially in China, as reported by nearly half (47 percent) of the surveyed executives there.44

Black Hat Innovation

Black hat innovation in cybercrime is booming. Threat actors, including malicious software authors and the cybercriminals that deploy that malware, are innovating so rapidly that 2015 is on target to be a record year.45 For example, Angler and other exploit kits draft closely behind Adobe Flash Player patch releases, exploiting more than 100 vulnerabilities within those patches this year alone and within mere days of those releases.46 Java exploitations follow a similar pattern, and software developers and security teams and vendors struggle to stay ahead.47

Open source–based applications, like Linux, were once believed to be more secure than proprietary counterparts.48 Heartbleed and Shellshock, the world’s biggest cyber exploits to date, put the lie to such beliefs in 2014.49 Some 500,000 highly trusted websites’ servers, including that hosting the U.S. Federal Bureau of Investigation’s website, were vulnerable to Heartbleed.50 Shellshock trumped that with millions of vulnerable devices.51

Ransomware now encrypts the victims’ hijacked data with attacks continuing to grow worldwide and expanding to mobile devices in 2014.52 Also in 2014, Energetic Bear, a hacker group tied to the Russian Federation, launched a new malware weapon, Havex, to break into, infect, and then transfer confidential information out of energy sector and other such industry control systems (ICS) in at least 23 countries.53 The sophistication and high degree of effectiveness of Havex and other ICS-capable malware modules, such as BlackEnergy II, represent significant monetary and time investments by cybercriminals.54

Cybercriminals also are professionalizing their teams to maximize profitability and to innovate their attack and obfuscation tactics.55 In “domain shadowing,” for example, threat actors compromise a domain name registration account, create subdomains thereunder, and then host transient websites for those subdomains at rapidly changing IP addresses.56 Domain shadowing, coupled with the encryption of the malware payloads injected into users’ systems upon visits to these transient sites, allows threat actors to delay or escape altogether detection by antivirus engines.57 Ransomware attacks extract payment from corporate and individual victims using difficult-to-track cryptocurrency at a price point sufficiently low as to often go unreported.58

White Hat Innovation

White hat cybersecurity innovation is also roiling, as is the funding push for that innovation.59 Worldwide, an estimated $22 billion changed hands in cybersecurity mergers and acquisitions during 2008 through the first half of 2011,60 with Intel’s $7.7 billion acquisition of McAfee accounting for about a third of that value.61

The boom continues. FireEye Inc. raised $304 million in its initial public offering in September 2013,62 and then four months later paid more than $1 billion in cash and stock to acquire Mandiant, a cyberattack response and intelligence firm.63 In October 2013, Cisco Systems Inc. paid some $2.7 billion for Sourcefire Inc., whose antihacking technology is deployed extensively by the U.S. government.64 In January 2014, Palo Alto Networks Inc. acquired two-year-old Morta Security,65 and two months later purchased startup Cyvera and its endpoint security technology for about $200 million.66 In June 2014, Cisco acquired ThreatGRID Inc. and its advanced malware analysis and intelligence technology.67 In April 2015, Raytheon contributed about $1.9 billion for an 80.3 percent stake in Websense and its cybersecurity platform technology.68 In May 2015, Palo Alto Networks announced plans to acquire CirroSecure to boost its software-as-a-service (SaaS) security offerings,69 and Fortinet paid $44 million for Meru Networks to tap into the enterprise secure wireless market.70 In June 2015, Cisco went public with its $635 million plan to acquire OpenDNS Inc., a private cloud security company.71 In July 2015, CrowdStrike, which fields a next-generation endpoint protection platform using a SaaS model, closed a $100 million Series C round of financing led by Google Capital.72 The investments go on and on, and white hat innovation should accelerate even more quickly as the industry grows and then consolidates.73

The U.S. Patent and Trademark Office (USPTO) also inaugurated a cybersecurity innovation initiative, holding its first cybersecurity partnership meeting in Silicon Valley in November 2014.74 The initiative’s launch was important in view of the U.S. Supreme Court’s recent decision in Alice Corp. Pty. Ltd. v. CLS Bank International,75 which some commentators have argued has significantly truncated software patentability in some areas.76

Alice and the need for more covert intellectual property strategies in the cybersecurity industry sharpen the debate on patent versus trade secret protection. Some recommend a combined patent and trade secret approach as the most robust strategy.77 However, a quick search of U.S. patents and published U.S. patent applications suggests that cybersecurity portfolios may be trending more toward trade secrets.78 But as trade secrets comprise an increasing proportion of these portfolios, insider cyberattacks targeting those secrets certainly may increase.

Toward Global Cyber Governance

Cybercrime is spurring policy79 and legal80 developments, including international developments. In April 2015, the Global Conference on CyberSpace convened at The Hague with cybersecurity and its multiple facets comprising one of the conference’s three major themes.81 Among those facets are needs for greater private-public cooperation and for improved international legal regimes to combat cybercrime. The Organization of American States (OAS) reiterates the urgency and importance of greater public-private engagement to cybersecurity.82 Technology industry leaders and scholars likewise call for a global cyber governance framework.83


Intellectual property and other proprietary information are the crown jewels of most organizations and high-value targets for cybercriminals of all stripes.84 Cybersecurity is unendingly transforming the world, business, and legal practice. It is imperative that intellectual property and indeed all practitioners develop competency85 on the topic or, at least, the ability to spot cybersecurity issues and a network of knowledgeable colleagues with whom to consult.


Emile Loza de Siles is the managing partner and founder of Technology & Cybersecurity Law Group, PLLC. Her representative clients include Fortune 500 and other information technology and innovator companies.