West Midlands Cyber

Online Harm and CyberDIVA

Deepfakes, sextortion and technology-facilitated abuse expose weaknesses spanning platforms, identity, safeguarding and enforcement. Addressing online harm requires interventions across the system rather than isolated technical controls.

Contents

CyberDIVA: Tackling Online Harm Through West Midlands Research and Collaboration

Cyber security is usually discussed through the protection of systems, organisations and infrastructure. Online harm exposes the limits of that framing. The same digital environment that creates risks to networks and data also enables harassment, coercion, impersonation, stalking, image-based abuse and other forms of technology-facilitated violence whose consequences are experienced by individuals rather than machines.

Addressing those harms requires a correspondingly broader model of cyber capability. Technical investigation matters, but so do safeguarding, policing, platform governance, education, policy, behavioural research and support for people affected by abuse. No single institution possesses all of those capabilities, and the underlying problem moves easily between organisational boundaries.

CyberDIVA — Dark Web Investigation of Violence and Abuse — provides a significant West Midlands example of how that challenge can be approached. The Innovate UK-funded project is led by Dr Anitha Chinnaswamy at Aston University in partnership with Forensic Pathways, with support from the Department for Science, Innovation and Technology and West Midlands Police, including the Regional Cyber Crime Unit. It combines research, digital forensics, responsible AI, education and cross-sector collaboration to investigate cyber violence against women and girls and translate that work into practical resources and policy insight.

The originating analysis, CyberDIVA and the Architecture of Online Harm, examined the project in the wider context of an increasingly complex online-harms ecosystem. Its central argument remains important: technology-facilitated abuse cannot be addressed effectively as a collection of isolated incidents when the conditions enabling that abuse are distributed across platforms, identities, technologies, institutions and human behaviour.

For the West Midlands cyber economy, CyberDIVA is important for another reason. It demonstrates that regional cyber capability is not confined to commercial security products or conventional technical services. Research institutions, forensic specialists, police, policymakers, safeguarding organisations and technology businesses can combine around difficult societal problems, generating knowledge and interventions that have relevance well beyond the region.

Explore the community and innovation perspective. The West Midlands Cyber Hub looks at how CyberDIVA brings together research, technology and regional collaboration to address online harm, in the companion article “CyberDIVA: Tackling Online Harm Through West Midlands Research and Collaboration”.

Key Takeaways

  • CyberDIVA demonstrates an interdisciplinary approach to cyber violence against women and girls, combining academic research, digital forensics, responsible AI, policing, policy and safeguarding rather than treating online abuse as a purely technical problem.
  • The project is translating research into practical intervention through an online safety toolkit developed with input from schools, third-sector organisations and corporate partners.
  • Technology-facilitated abuse exposes a coordination problem because responsibility is distributed across platforms, police, schools, regulators, government, safeguarding organisations and technology providers.
  • The growth of AI-generated and increasingly immersive digital environments makes the problem more complex by reducing the cost of producing convincing synthetic content and expanding the ways identities and experiences can be manipulated.
  • For the West Midlands, CyberDIVA illustrates how regional cyber ecosystems can create distinctive capability by connecting research with operational institutions and real social problems rather than concentrating exclusively on conventional cyber security markets.

Online Harm Is a Cyber Problem with Human Consequences

The boundary between cyber security and online safety has historically been relatively distinct. Cyber security has concentrated on systems, networks, information and organisations, while online safety has addressed harmful content, safeguarding and user behaviour.

Technology-facilitated abuse makes that separation increasingly difficult to sustain.

An account takeover can become the mechanism through which someone is impersonated. Compromised personal information can enable stalking or coercion. Weak identity controls can facilitate fraudulent profiles. Intimate images can be obtained through compromise, manipulation or social engineering before being distributed through digital platforms. Generative AI can create synthetic material without the victim ever having produced the underlying image or recording.

The technical event and the human harm are therefore often part of the same chain.

CyberDIVA concentrates specifically on violence and abuse affecting women and girls, including harms occurring within hidden, encrypted and illicit online environments that have received less attention than abuse taking place on mainstream social platforms. Aston University describes the project as responding to operational, investigative and policy gaps created by the comparatively limited examination of these environments.

That focus is important because visibility shapes intervention. Harm occurring publicly can potentially be observed by platforms, researchers, safeguarding organisations and law enforcement. Activity moving into private groups, encrypted communications or hidden services becomes harder to identify and investigate.

The cyber dimension is consequently not incidental. Technical architecture affects where harm occurs, how visible it is, what evidence remains and which institutions are capable of responding.

The Scale of Technology-Facilitated Abuse Demands Better Evidence

The development of CyberDIVA follows earlier research examining cyber violence against women and girls. Reporting around the project identified nearly 70,000 incidents of technology-facilitated abuse between 2021 and 2024, including more than 50,000 officially recorded incidents involving harassment and malicious communications. Women aged between 16 and 34 were identified as the most heavily affected group, alongside a significant number of victims under 16.

These figures provide evidence of scale, but they should not be interpreted as a complete measurement of online harm.

As with cybercrime more generally, recorded incidents are shaped by visibility and reporting. Victims may not recognise that behaviour constitutes an offence, may not know where to report it or may decide against reporting because of concerns about consequences or the likelihood of action. Activity occurring within less visible online environments creates an additional detection problem.

CyberDIVA’s emphasis on forensic investigation is therefore significant. Better policy requires better understanding of how abuse operates technically, how perpetrators use different digital environments and where existing investigative or safeguarding mechanisms encounter practical limitations.

The objective is not simply to generate a larger headline estimate. It is to improve the evidence through which interventions can be designed.

That distinction is particularly important in an area susceptible to moral panic and rapidly changing terminology. Effective policy needs to distinguish between harms, technologies and behaviours rather than treating the internet, social media, the dark web and artificial intelligence as interchangeable sources of risk.

CyberDIVA Connects Research with Practical Intervention

One of the stronger characteristics of the CyberDIVA model is that research is not treated as the final output.

The project has developed an online safety toolkit intended to strengthen prevention and response. Aston University states that the resource was refined through structured feedback from schools, third-sector organisations and corporate partners including BT, with the intention of ensuring that it reflects operational requirements rather than remaining a purely academic intervention.

The wider CyberDIVA platform includes structured safety lessons, practical activities, resources for parents and guardians, and guidance intended to improve recognition of potentially harmful online behaviour. The project is also developing policy work intended to contribute to national discussion around digital governance and systemic accountability.

This research-to-practice pathway is important.

Universities possess expertise in investigation, behavioural research, data analysis and technology. Police understand evidential requirements and operational constraints. Safeguarding organisations understand how harm presents in communities and the difficulties victims encounter. Technology companies understand aspects of platform and system design. Policymakers influence the regulatory environment within which those actors operate.

The value emerges when those forms of knowledge interact.

A technically sophisticated intervention that cannot be used safely by schools or families has limited preventive value. A safeguarding framework that misunderstands how technology is actually being exploited will struggle to keep pace with changing behaviour. Policy developed without operational evidence can create requirements that look coherent institutionally while remaining difficult to implement.

CyberDIVA’s relevance therefore extends beyond its subject matter. It provides an example of how interdisciplinary cyber research can be structured around translation rather than publication alone.

Fragmentation Is Part of the Online-Harms Problem

The CyberDIVA conference held at Aston University in February 2026 brought together government, policing, academia, safeguarding practitioners and technology expertise around a common problem. The programme included research on the dark web, the launch of the CyberDIVA toolkit, policy discussion, safeguarding perspectives, survivor experience and an immersive cyber challenge delivered by the Regional Cyber Crime Unit.

The breadth of that agenda reflects the institutional structure of online harm.

Responsibility is distributed across government departments, police forces, regulators, schools, local authorities, platforms, charities, technology companies and specialist services. Each operates with different powers, information, incentives and thresholds for intervention.

Fragmentation is not automatically evidence of failure. Complex problems legitimately require different institutions. Police should not perform the role of schools; technology companies should not determine criminal justice policy; regulators and support organisations have different responsibilities.

The problem arises where the interfaces between those institutions are poorly understood.

A victim may encounter harmful activity on a platform, report it to the service, approach the police, seek support from a specialist organisation and need intervention from a school or employer. Evidence may need to move between systems operating according to different definitions and processes.

The resulting difficulty is architectural rather than simply organisational. Improving one component does not necessarily improve the path through the system.

Regional collaboration can be useful precisely because it creates opportunities to examine those interfaces at a scale where institutions can work directly with one another.

Platform Architecture Influences the Conditions in Which Harm Occurs

A serious analysis of online harm also needs to move beyond the assumption that platforms are neutral environments in which harmful individuals happen to behave badly.

Digital architecture influences behaviour.

Recommendation systems determine what users encounter. Identity systems influence how easily individuals can create or abandon accounts. Messaging architectures determine whether interactions are public, private or encrypted. Moderation systems affect how quickly harmful behaviour is identified. Reporting mechanisms determine how easily users can seek intervention. Commercial incentives influence which design changes receive priority.

None of this removes responsibility from perpetrators. It establishes that individual behaviour occurs within systems whose design can increase or reduce opportunity.

The original CyberDIVA analysis emphasised this architectural dimension, arguing that online harms need to be considered alongside the incentives and structures of modern digital platforms rather than exclusively through awareness campaigns directed at potential victims.

That is an important distinction for cyber policy.

Security engineering has long accepted the principle that systems should be designed to reduce foreseeable misuse rather than relying entirely on users behaving correctly. Similar reasoning can inform online safety. Where predictable forms of abuse repeatedly exploit particular features, identity mechanisms or reporting weaknesses, design becomes part of the intervention space.

This does not imply that every social problem has a technical solution. It means technical design is one of the factors that determine how easily harmful behaviour can scale.

AI Changes the Economics of Online Abuse

Artificial intelligence makes the architectural problem more significant because it changes the cost and scalability of creating deceptive material.

Synthetic images, audio and video can increasingly be produced without specialist technical expertise. Language models can generate persuasive text at volume. Automated systems can assist impersonation, social engineering and the creation of multiple identities.

The underlying behaviours are not all new. Harassment, fraud, impersonation and coercion predate generative AI. What changes is the production function.

Material that once required technical skill, substantial time or access to a victim’s genuine content can become easier to create, modify and distribute. That reduces some of the constraints that previously limited scale.

The policy response needs corresponding precision. Treating all AI-generated material as inherently harmful would be neither accurate nor useful. The relevant questions concern the behaviours AI enables, the safeguards surrounding particular systems, the ability to establish provenance and the mechanisms available when synthetic content is used abusively.

CyberDIVA’s combination of digital forensics and responsible AI research is therefore particularly relevant. The challenge is not merely identifying that AI exists within the problem but understanding how it alters investigation, prevention and evidential requirements.

For the wider cyber sector, this is another example of security moving closer to questions of identity, authenticity and trust rather than remaining confined to network protection.

Digital Identity Is Becoming a Security and Safety Boundary

Many forms of online harm depend on ambiguity about identity.

A perpetrator can create an account pretending to be another person, establish several identities, manipulate an existing relationship or distribute material in ways that make attribution difficult. Conversely, anonymity can also be important for legitimate users, including vulnerable people seeking information or support.

Identity policy therefore involves competing requirements.

Systems need enough confidence to reduce impersonation and abuse without creating unnecessary surveillance or eliminating legitimate privacy. Platforms need mechanisms for responding to harmful accounts without assuming that government-issued identity verification is appropriate in every context. Investigators need sufficient evidence to attribute serious behaviour while respecting legal safeguards.

Cyber security has relevant expertise here because identity and access management already concern authentication, trust, privilege and evidence. Online safety introduces different consequences but many related architectural questions.

As synthetic content becomes more convincing, establishing who created information, whether media has been altered and whether an account genuinely represents the claimed person becomes increasingly important.

This creates an emerging area of overlap between cyber security, digital identity, content provenance and safeguarding.

For a regional cyber ecosystem, that overlap can generate research and innovation opportunities extending well beyond conventional security operations.

Survivors and Frontline Practitioners Need to Shape the System

A further strength of the CyberDIVA approach is its inclusion of people with direct experience of online abuse alongside technical and institutional expertise.

Survivor perspectives were incorporated into the project’s public work, while consultation with schools, third-sector organisations and other partners contributed to development of the toolkit.

This matters because technically plausible interventions can produce unintended consequences when the lived context of harm is poorly understood.

A recommendation to preserve evidence, for example, may have implications for someone trying to remove harmful material from immediate view. Stronger identity requirements can reduce some forms of impersonation while creating privacy concerns for vulnerable users. Reporting processes designed around organisational convenience can force victims to describe traumatic experiences repeatedly.

These are design problems as much as ethical considerations.

Security engineering increasingly uses threat modelling to understand how systems can fail under hostile behaviour. Online-safety interventions benefit from an analogous approach in which abuse cases, survivor experience and frontline practice inform assumptions about how systems will actually be encountered.

Co-creation does not remove the need for rigorous technical evaluation. It improves the quality of the problem definition against which that evaluation occurs.

The West Midlands Can Develop Capability Around Cyber and Social Harm

CyberDIVA also demonstrates something about regional specialisation.

Cyber clusters are frequently assessed through company numbers, investment, employment and technical specialisms. Those indicators matter, but they capture only part of the capability generated within a region.

The West Midlands combines universities, policing capability, local government, technology businesses, cyber providers and a substantial voluntary and community sector. Birmingham’s scale and diversity create a setting in which complex questions concerning technology, safety and public services can be investigated against real operational demand.

CyberDIVA converts part of that institutional mix into a research and innovation capability.

The project is listed among the Government’s Cyber Local projects for 2025–26, placing it explicitly within an approach intended to develop cyber capability through regional initiatives.

Its value should not be reduced to the existence of a funded project, however. Regional innovation becomes economically and socially meaningful when collaboration produces capability that persists beyond an individual funding cycle.

That might include reusable research methods, specialist expertise, stronger relationships between police and academia, products capable of wider adoption, policy evidence or new areas of commercial and academic specialisation.

The relevant question is therefore what remains after the project itself.

Research Translation Should Be a Cluster Function

This provides a wider lesson for the West Midlands Cyber Cluster.

Universities generate cyber research across technical, behavioural and policy disciplines. Businesses possess commercial and operational problems. Police and public bodies encounter threats and harms that may not be visible through academic datasets. Community organisations understand consequences that can remain outside conventional cyber metrics.

A cluster can create value by improving the pathways between those groups.

That does not mean every research project needs to become a startup or every social problem needs a commercial product. Translation can take several forms: policy evidence, practitioner guidance, training, operational tools, shared datasets, new research questions or technologies capable of commercial development.

CyberDIVA demonstrates several of those routes simultaneously. Research contributes to a toolkit; operational partners contribute to the research; the project informs policy discussion; and collaboration creates a body of regional expertise around a problem with national relevance.

This is the type of activity through which a regional cyber ecosystem can develop intellectual and institutional depth rather than functioning primarily as a network of businesses attending common events.

The distinction matters because durable clusters are built around repeated exchanges of knowledge, capability and demand.

Regional Collaboration Can Address Problems That Do Not Fit Institutional Boundaries

Technology-facilitated violence against women and girls is an instructive problem for regional cyber policy precisely because it refuses to fit neatly within a conventional organisational structure.

It is simultaneously a policing problem, a safeguarding problem, a technology problem, a platform-governance problem, an educational problem and, in some cases, a cyber security problem. Attempting to assign ownership exclusively to any one of those domains leaves important interfaces unmanaged.

CyberDIVA’s contribution is to bring several of those perspectives into a common programme and connect research with practical intervention.

That approach should not be mistaken for a claim that collaboration itself solves online harm. Partnerships can generate activity without producing outcomes, just as strategies can create institutional alignment without changing what victims experience.

The appropriate test is more demanding: whether collaboration produces better evidence, more useful interventions, stronger investigative capability, improved prevention and policy that reflects how technology-facilitated abuse actually operates.

For the West Midlands, that is also the test of regional cyber collaboration more broadly.

The strongest regional ecosystems do not simply convene organisations that already share an interest in cyber security. They create relationships through which problems that sit between institutions can be addressed more effectively than those institutions could manage independently.

CyberDIVA provides a practical example. It connects university research, forensic capability, policing, government and safeguarding around a form of harm whose technical and human dimensions cannot sensibly be separated.

That makes the project significant beyond online safety. It demonstrates a model of regional cyber capability in which research, operational practice and public purpose reinforce one another.

If that capability can be sustained, evaluated and extended, the West Midlands will have developed something more valuable than another isolated cyber initiative: a mechanism for turning interdisciplinary regional expertise into responses to digital problems whose consequences are increasingly national.