News: 1697625973

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Governments resent their dependence on Big Tech

(2023/10/18)


Senior politicians gathered at Singapore International Cyber Week (SICW) this week to discuss the current state of cybersecurity have articulated their discomfort with finding themselves dependent on Big Tech.

"Large tech companies wield an unprecedented level of influence over economies and societies. At the same time, they enjoy a remarkable degree of freedom from regulation and accountability for their activities and the content they carry," [1]opined Singaporean minister Teo Chee Hean at Monday night's opening address.

Teo pointed out that private industry owns and controls significant parts of the technology stack that the majority of the world depends on, and the vast amount of data such systems contain. The revenue Big Tech squeezes from this data exceeds the GDP of many countries.

[2]

That strength means governments rely on the private sector for cybersecurity and other necessities in the digital domain. Meanwhile, these companies ultimately "make their own decisions," such as which nations they boycott or the content they carry.

[3]

[4]

Teo said it's somettmes hard to know how government and Big Tech can work together given that national security, defense, and social governance have long been the exclusive domain of governments. An added complication is that Big Tech companies are often foreign entities.

"Their interests may not always align with public or national interests," he said.

[5]

A big part of the problem, according to Jen Easterly, director of the US Cybersecurity and Infrastructure Security Agency (CISA), is that the tech industry prioritizes getting to market quickly over security – a situation she labelled a "crazy malalignment" that results in an unacceptable "shaky technology platform" the world ends up relying on.

"We have perversely normalized a world where the technology that underpins the critical services that we rely on for water, for healthcare, power, transportation, communication – the devices we rely on every minute every day – are all built on insecure foundations," said Easterly. "We don't need more security products. We need more secure products."

Easterly was particularly keen to have tech companies prioritize security before generative AI becomes the "most powerful technology and most powerful weapon of our time."

[6]

The CISA director called on CEOs, boards, and other business leaders to treat cyber risk like they do equity, franchise, or liquidity risk.

"The days of delegating cyber risk to infotech people – your chief info officer, then fire them when you have a breach – must be over," she declared.

Easterly then scoffed at Microsoft's [7]Patch Tuesday , comparing it to a consumer getting a car recalled once a month, and holding it up as proof that vulnerabilities and flaws have been normalized.

Regardless of what disasters flow from poor security, it's far too late to be having any conversations regarding reining in reliance on tech vendors. And for countries in distress or at war, like Ukraine, the unquestionably vital necessity of Big Tech is even more stark.

[8]Generative AI slashes cloud migration hassles, says McKinsey partner

[9]So, the US, China, and Russia walk into an infosec conference

[10]Ukraine accuses Russian spies of hunting for war-crime info on its servers

[11]President Biden still wants his cybersecurity labels on those smart devices

Anton Demokhin of the Ministry of Foreign Affairs of Ukraine credited Big Tech with giving his nation the ability to focus on its war with Russia. Demokhin credited a number of companies with providing resources – from cybersecurity support to the use of cloud to back up resources that would otherwise be at risk of being destroyed during Russia's invasion.

"That's given us the momentum to deal with challenges and war and cyberattacks," said Demokhin.

But the question, at least for Australia's National Cyber Security Coordinator, Darren Goldie, centers around where to divide the duties of government versus Big Tech, ultimately deciding how much power to continue to give to industry.

Goldie asserted it was best to utilize expertise, which is rarely located within government.

Goldie said Australia is pursuing threat sharing and blocking capabilities.

"Threat blocking tries to raise the bar with one private entity asking another one to block," stated Goldie. "If you have a threat that everyone agrees should be taken down, you could ask a telco to take it down."

He then posed the question: if threats and ongoing blockades persist, when does a nation reach a point where it becomes uneasy about outsourcing this responsibility?

There appears to be no end in sight to what could be privately offloaded within the domain of digital infrastructure.

"Critical infrastructure has been outsourced to private industries," surmised Danish tech ambassador Anne Marie Engtoft Meldgaard on Tuesday.

Denmark became the first country to appoint an ambassador to tech, with the same responsibilities as a conventional ambassador to a sovereign nation, in 2017. Meldgaard replaced the first person to have that role, Casper Klynge, in 2020.

"There's quite a lot of us tech ambassadors who have been appointed to represent our countries in a much more mature, concerted effort and dialog with tech," said Meldgaard. "And on the other side, Big Tech has been hiring diplomats too; recognizing the need for engaging interchangeably with governments."

When Klynge left Silicon Valley under Denmark's Ministry of Foreign Affairs, he promptly joined Microsoft.

"The time for tech platform as neutral actors is over," Meldgaard declared. ®

Get our [12]Tech Resources



[1] https://www.pmo.gov.sg/Newsroom/SM-Teo-Chee-Hean-at-the-SICW-Summit-2023

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZTABL3FaZYedwohOt0jtgwAAABM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZTABL3FaZYedwohOt0jtgwAAABM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZTABL3FaZYedwohOt0jtgwAAABM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZTABL3FaZYedwohOt0jtgwAAABM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZTABL3FaZYedwohOt0jtgwAAABM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2023/10/11/microsoft_patch_tuesday_turns_20/

[8] https://www.theregister.com/2023/10/11/generative_ai_cloud_migration/

[9] https://www.theregister.com/2022/10/19/singapore_international_cyber_week/

[10] https://www.theregister.com/2023/09/26/ukraine_russian_war_crimes_report/

[11] https://www.theregister.com/2022/10/20/biden_administration_iot_security_labels/

[12] https://whitepapers.theregister.com/



Doctor Syntax

Dependence was their own decision although lack of decision might be more accurate. Decision by default, shall we say?

Neil Barnes

Big tech has good salesbods. The points that are being made though are significant and serious... if your infrastructure (both civic and military) cannot be shown to immune not only to external actors but also to the manufacturers, should you be using it? The supplier may not be your friend tomorrow.

The benefits of hindsight

Lurko

Taking a high level view, dependence has crept in, rather than been an obvious decision point to accept the risks. Imagine outsourcing welfare payments processing using legacy systems to a third party data centre - that would just be seen as economic and sensible rather than a government welfare department trying to build, equip and operate its own processing. The decision to then buy and adapt an ERP from a major software house would likewise be seen as probably wiser than trying to build your own bespoke system (opinions may vary), but again, think that this is for a government welfare department who aren't IT experts. That of course exposes you to the full data stack the ERP provider is built on, and thus their vulnerabilities - but still, would the welfare department have done better if they'd built from scratch. Next up, the ERTP provider pushes the customer to adopt SaaS, and again that's seen as the modern thing to do.

So at what point would it have been prudent to say "hold on, it looks like this would save us money, but we'll lose control of our core systems"? There's very few people would agree that many (or any) government departments are suitably clued up to design, build and operate their own systems, or to do so at a viable cost. If anything, the pressure is on from everybody that the government should save money on administration. Who's going to vote for a government that says "nope, not buying commercial IT, we need it bespoke or FOSS, and we'll put up government spending to pay for all the staff and development work we'll need, not just for new systems, but for world-class security on every government asset?"

The same arguments apply to the private sector, and are why big business is in near universal thrall to the SApacle duopoly. Whether this is a good or bad thing is hypothetical, we are where we are. But hat raises the question this conference ponders but does not answer, where do we go from here?

Re: The benefits of hindsight

David M

Government departments clearly don't have the skills or resources to build their own IT systems, but what they do need is a few senior people who understand both the workflows and the technology well enough to ask the right questions, to define appropriate requirements, including for security, and to be able to monitor private sector development and deliverables to ensure those requirements are being met. I suspect that a lot of problems stem from the fact that nobody in the organisation has much of a clue about IT, so it's easy for suppliers to pull the wool over their eyes.

Anonymous Coward

You don't actually have to depend on big tech, you chose to do so because it's cheaper upfront to buy a premade solution and use some else's data centers and network. You also don't have to be as responsible for hunting bugs and security problems.

As for patch Tuesday being like a car recall every month, given the poor security of automotive software that would activate be an improvement.

Bullshit and I told you so

b0llchit

...discomfort with finding themselves dependent on Big Tech.

Wow! That must hurt to admit that they are a collective bunch of idiots trusting the untrustworthy with your data. As if the signs were not on the wall from the start and they hadn't been told by the knowledgeable. But being good politicians, they have a plan to shift the blame. They will blame "the other guys" and again may shine in the light of utter bullshit eaten up by other idiots.

Colour me shocked

cat_mara

You mean the incessant “public sector bad, private sector good” drum you politicians have been beating for the past 50 years, or near as, has left you in thrall to the private sector? Who could have imagined this outcome?!

Oh, grow up

JimmyPage

"Large tech companies wield an unprecedented level of influence over economies and societies. At the same time, they enjoy a remarkable degree of freedom from regulation and accountability for their activities and the content they carry," opined Singaporean minister Teo Chee Hean at Monday night's opening address.

That is almost the bumper sticker for Western capitalism. Power and money with naff all oversight, regulation or where possible competition

And for all their performance handwringing, all I can see from where I live is governments are aspiring to the same. Certainly here in the UK where it seems you are robbed with the threat of prison for your taxes, and yet discover that no one in government is actually responsible for anything.

ChoHag

"It's best to utilize expertise, which is rarely located within government."

I sense a theme

cschneid

Elsewhere, [1]buyer's remorse haunts 3 in 5 business software purchases .

[1] https://www.theregister.com/2023/10/18/it_software_buyers_remorse/

How about governments get their shite together

Anonymous Coward

Europe has GDPR. Australia has their Essential 8. US has DISA & FedRAMP. The list goes on & on. They are all bitchy and whiny about where their physically resides....usually because their government wants Big Tech to spend millions on a new data center inside their country.

Security knows no such bounds. Security doesn't care where your data resides or what government policies it falls under. If it is vulnerable to compromise, then it will be attacked.

If the public sector wants better security from the private sector, make it easier for the private sector to deliver. If the governments of the world adopt a unified security standard then we can all stop playing the stupid games - in EMEA we do it this way, in APJ we do it that way, and NAM is a completely different animal....

That would never happen though because governments don't like to play nice with each other. They all like to claim they are somehow more special than each other. But again, the attackers know no such bounds & limitations.

Higgins: Doolittle, you're either an honest man or a rogue.
Doolittle: A little of both, Guv'nor. Like the rest of us, a
little of both.
-- Shaw, "Pygmalion"