Looking at the eSentire / Cybersecurity Ventures 2022 Cybercrime Report that appears to be the source of the numbers Google is using, I see the following claims:
It appears to me that the report is intended to enable the collection of business email addresses as the top of a sales funnel, as evidenced by the fact that you need to provide your name, company name, role, and a business email address to download the report. As such, I wouldn't take any of their numbers particularly seriously - I doubt they do.
As a sanity check, $8T / year in cybercrime costs is an average annual cost of $1,000 per person annually. This is not even remotely plausible.
I had looked into this for a previous research project. For what it's worth, I don't think there are any perfect sources, but my own BOTECs led me to believe the number people are usually after is $10B-$100B ~$30B-$300B:
I agree the eSentire >$3T number should be trusted very little. It doesn't have any public methodology and got critcised soon after the original estimates came out in 2015 as part of companies trying to 'one up' each other:
In early 2015 Inga Beale, CEO at the British insurer Lloyd’s, claimed that cybercrime was costing businesses globally up to $400 billion a year. Several months later Juniper Research released a report which said cybercrime will cost businesses over $2 trillion by 2019. Microsoft CEO Satya Nadella stated $3 trillion of market value was destroyed in 2015 due to cybercrime….
The other 'trillion dollar' source that sometimes gets cited is McGuire (2018), who puts it at $1.5T. They do give a methodology of where this comes from, but...
There are (at least) two different meanings of "costing" in large-scale economic impact thinking. The narrow meaning is "actual amount spent on this topic". The more common (because it's a bigger number) meaning is "how much bigger would the economy be in the counterfactual world that doesn't have this feature".
The article linked from Wikipedia says
The damage cost estimation is based on historical cybercrime figures including recent year-over-year growth, a dramatic increase in hostile nation-state sponsored and organized crime gang hacking activities, and a cyberattack surface which will be an order of magnitude greater in 2025 than it is today.
Cybercrime costs include damage and destruction of data, stolen money, lost productivity, theft of intellectual property, theft of personal and financial data, embezzlement, fraud, post-attack disruption to the normal course of business, forensic investigation, restoration and deletion of hacked data and systems, reputational harm, legal costs, and potentially, regulatory fines.
Which puts it in the second category - most of these costs are NOT direct expenses, but indirect and foregone value. That doesn't make it wrong, exactly, just not comparable to "real" measures (which GDP and GPP isn't either, but it's more defensible).
It's extremely unclear whether LLM adoption and increasing capabilities will shift the equilibrium between attack and defense on these fronts. Actually, it's almost certain that it will shift it, but it's uncertain how much and in what direction, on what timeframes.
It's further unclear whether legislation can slow the attacks more than they hinder defense.
Mostly, it's not a useful estimate or model for reasoning about decisions.
Many sources report that cybercrime costs the global economy trillions of dollars per year. It is the top Google search result and it is quoted on Wikipedia. But I am not able to track down how the number was computed, or find criticism of these numbers.
This would be insanely high if true: the world GDP is only 100 trillion / year, and the software industry is only around 1 trillion / year (according to a quick Google search). Does the software industry really produce less value than the cost of cybercrime? This is not impossible, but that is an extraordinary claim that requires strong evidence.
Why I care about this: LLMs might help with cybercrime, and it might be tempting for regulators to ban the creation or deployment of new LLMs that are projected to cause cybercrime damages above e.g. 10 billion / year. But if cybercrime is over a trillion dollars per year, just a 1% increase in cyberattacker productivity would be over 10 billion / year. Does this logic imply that meaningful improvements to software should be banned because they likely create billions in expected damages?
Either the trillions-of-dollars numbers are fake, or this has some weird implications for LLMs and software regulation in general.