So we shouldn’t pat ourselves on the backs too fast that all is solved by banning this or that company or blaming this or that superpower. It is understandable that, in the absence of strong cyber defences, Australia and a number of others have chosen simply to avoid the hypothetical risk posed by China in banning its leading supplier of 5G equipment and services. But the Huawei debate, wrapped up in the current geopolitical contest, could be a distraction from the need to mount comprehensive cyber defences and prevent authorities from taking a pragmatic, sustainable approach to a global problem.
Notably, Huawei has fought back, including with legal actions and by opening up its equipment and source codes for scrutiny in testing centres around the world, in countries such as Belgium, Canada, Germany and the United Kingdom. It offered a testing centre to Australia, but was rebuffed. This month it opened, in Dongguan, China, its “largest global cyber security and privacy protection transparency centre”, which claims to offer scrutiny of how Huawei prevents backdoors, malware and malicious behaviour.
But this attempt to answer Huawei’s critics is providing an engineering answer to a geopolitical problem. The real issue is plummeting trust in China. Yet whether China engages in cyberattacks is not the real question; it surely does, just like the United States, Russia and many others. In cybersecurity, zero-trust in all actors is the more appropriate strategy. “Zero-trust” is how the experts interviewed in my research on cyber risks have characterised a robust approach; to defend against threats, no matter their source.
Governments, firms and individuals everywhere need to invest much more in cybersecurity. Unfortunately, there may never be 100 per cent cybersecurity (just as in any other form of security), but in the 21st century all nations arguably need a “Cybersecurity Force” as an integral part of national defence.
A Cybersecurity Force should have the capacity to activate firewalls with lightning speed and to protect national data without snooping on it. That is why it should not be housed within national intelligence agencies, who play cyber offence, but as a part of national defence. It should have the power to demand inspection of all equipment and source codes at all times, and the capacity to take over a network if the supplier firm refuses to cooperate with a cybersecurity baseline.