Understanding Online Harms and the Threat Ecosystem

Online harms encompass a broad and evolving set of behaviours that go beyond what is prohibited by criminal law. This article is part of a “Trust & Safety as Response to Online Harms” series which unpacks the concept of online harms, analyses the threat and response ecosystems, and argues that durable solutions depend on a coordinated, whole-of-society framework.

By Alexander Woon, Provost’s Chair and Lecturer, Singapore University of Social Sciences, School of Law

At a glance

  • Online harms are widespread but poorly defined: They extend well beyond cybercrime and include a broad range of harmful behaviours that fall outside formal legal thresholds.
  • Threat actors are diverse: Online harms can be caused unintentionally by individuals, or deliberately by lone actors, coordinated groups, or professional organisations.
  • Responses require a whole-of-society approach: Governments, technology companies, civil society and individuals all play complementary roles in addressing online harms.

Share this insight

Online harms are among the most urgent problems faced by the modern world. In an era of pervasive internet use, many of us now spend much of our lives online. We work online, play online, socialise online, and conduct commerce online. Despite the amount of time we spend online, the internet remains a relatively recent invention, and many people have yet to develop adequate online safety instincts.

In the physical world, children are often taught from a young age to look both ways before crossing the road. In the online sphere, however, it is unclear that most people possess comparable safety instincts. Weak passwords are commonly used, personal information is freely shared, and misinformation and disinformation are circulated unthinkingly.

This raises a fundamental question: how can societies build a culture of online safety, and who should be responsible for doing so? Addressing this question requires a clearer understanding of what constitutes “online harms” and who is responsible for perpetrating them.

What are “online harms”?

It is easy to think of examples of online harms, many of which now dominate news cycles. Election interference, the circulation of misinformation and disinformation, scams, hacking, cyberbullying and online harassment are familiar phenomena.

Despite their prevalence, however, the concept of “online harms” remains poorly defined. While these examples clearly qualify as harmful, they do not capture the full picture.

A common starting point is to equate online harms with cybercrime. For instance, the Singapore Police Force publishes an annual report on scams and cybercrime. Yet cybercrime is only a subset of online harms. Criminal behaviour represents the most serious form of harm, but it is also the hardest to prove and act upon. Many harmful online behaviours fall short of the legal threshold required for criminal liability. For example, unintentionally circulating false information is not an offence in Singapore, but such actions can nevertheless cause harm.

Criminal law also tends to evolve slowly. Legal frameworks often lag behind emerging forms of online harm. Doxxing — the intentional disclosure of someone’s personal information online to harass or intimidate them — was not specifically criminalised in Singapore until 2019, even though incidents of harmful doxxing were well known long before then.

To understand online harms more fully, it is therefore necessary to look beyond the law. One useful, though far from definitive, reference point is how social media platform providers define and act against harmful content. These platforms are an important barometer because they are where people spend a significant amount of time online, and consequently where exposure to online harms is most likely to occur.

Major platforms adopt broadly similar but not identical approaches. YouTube’s Community Guidelines group issues under headings such as spam and deceptive practices, sensitive content, violent or dangerous content, regulated goods and misinformation. Facebook’s Community Standards address a wide range of issues including fraud, scams, harassment, child safety, privacy violations, cybersecurity, inauthentic behaviour, hate speech and locally illegal content. TikTok’s Community Principles are organised around categories such as safety and civility, mental and behavioural health, integrity and authenticity, regulated goods and privacy.

This non-exhaustive survey highlights two key points. First, there is a rough consensus around many types of online harms. Second, there is no universally accepted definition. Community guidelines are often broadly phrased, leaving significant room for interpretation. What one platform considers “sensitive content” may differ substantially from another, even where similar terminology is used.

The implication is that online harms cannot be understood as a single phenomenon. Rather, the term encompasses a wide range of behaviours that operate in different ways and affect different segments of society.

The threat ecosystem

Given the diversity of online harms, it is unsurprising that the actors who perpetrate them are equally varied. As a general framework, these actors can be grouped into several broad categories.

First, there are individuals who unintentionally cause harm. These include users who, often in good faith, circulate false or misleading information without appreciating its potential impact.

Second, there are individuals who intentionally cause harm. This group includes scammers, disinformation actors, cyberbullies and online stalkers. While the harm is deliberate, its scale is often constrained by the limited reach and resources of a single individual.

Third, there are groups of individuals acting together. Informal groups may coordinate harassment campaigns, online pile-ons, or doxxing-driven attacks. Compared to lone actors, groups are capable of causing greater harm due to their amplified reach and collective effort.

Finally, and most seriously, there are professional organisations dedicated to online harms. These include organised crime syndicates, advanced persistent threat actors, and in some cases state-sponsored cyber operations. At this level, online harms can become sustained, sophisticated and systematic.

The response ecosystem

Facing this diverse threat landscape is a correspondingly diverse set of responders.

Governments play a central role. They have a responsibility to protect their societies from online harms just as they do from physical ones. Governments possess the authority to enact and enforce laws, but legislative and regulatory responses often take time to develop and implement.

Technology companies and platform providers also play a critical role. Large multinational firms such as Google, Meta, TikTok, Microsoft and Apple must protect users while complying with local laws. Although they lack the formal enforcement powers of governments, platforms are often able to act more quickly and upstream, implementing policies and interventions that prevent or mitigate harm before it escalates.

Civil society organisations, academia and non-governmental groups contribute research, advocacy and alternative perspectives. While they lack enforcement authority or direct access to platform controls, these actors help shape norms and inform both public policy and platform governance.

Finally, individuals themselves must not be overlooked. End users are often treated as passive recipients of protection, but personal responsibility remains essential. No system is foolproof. Education and individual vigilance are therefore critical components of online safety.

Understanding who causes online harm and who responds is an essential first step. Yet one emerging function sits at the intersection of prevention and enforcement.

Online harms are complex, evolving and not easily contained within existing legal or institutional boundaries. They span a wide range of behaviours and actors, and require responses that extend beyond criminal enforcement to include platform governance, civil society engagement and individual responsibility. Understanding online harms as a system—rather than a single problem—is therefore essential to building effective and durable responses. As digital environments continue to expand, so too does the need for roles that operate across prevention, moderation and enforcement, helping to translate policy intent into practical safeguards.

 

Read more in the second part of this Trust & Safety series, as we examine this profession, its role in addressing online harms, and why it is becoming increasingly important.

Share this insight

Explore further

Cite this article

Wei-Ming, A. J. W. (2026, March 6). Understanding Online Harms and the Threat Ecosystem. Tech For Good Institute. Retrieved from https://techforgoodinstitute.org/insights/perspectives/understanding-online-harms-and-the-threat-ecosystem/

Keep pace with the digital pulse of Southeast Asia!

Never miss an update or event!

Mouna Aouri

Programme Fellow

Mouna Aouri is an Institute Fellow at the Tech For Good Institute. As a social entrepreneur, impact investor, and engineer, her experience spans over two decades in the MENA region, South East Asia, and Japan. She is founder of Woomentum, a Singapore-based platform dedicated to supporting women entrepreneurs in APAC through skill development and access to growth capital through strategic collaborations with corporate entities, investors and government partners.

Dr Ming Tan

Senior Fellow & Founding Executive Director

Dr Ming Tan is Senior Fellow at the Tech for Good Institute; where she served as founding Executive Director of the non-profit focused on research and policy at the intersection of technology, society and the economy in Southeast Asia. She is concurrently a Senior Fellow at and the Centre for Governance and Sustainability at the National University of Singapore and Advisor to the Founder of the COMO Group, a Singaporean portfolio of lifestyle companies operating in 15 countries worldwide. Ming was previously Managing Director of IPOS International, part of the Intellectual Property Office of Singapore. Prior to joining the public sector, she was Head of Stewardship of the COMO Group.


Ming also serves on the boards of several private companies, Singapore’s National Volunteer and Philanthropy Centre, Singapore Network Information Centre (SGNIC), and on the Digital and Technology Advisory Panel for Esplanade–Theatres on the Bay, Singapore’s national performing arts centre. Her current portfolio spans philanthropy, social impact, sustainability and innovation.