• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • SPECTRA banner
  • Curtiss-Wright banner

BATTLESPACE Updates

   +44 (0)77689 54766
   

  • Home
  • Features
  • News Updates
  • Defence Engage
  • Company Directory
  • About
  • Contact

Measuring Cybersecurity Success at the Summit By James Andrew Lewis

September 27, 2015 by Julian Nettlefold

Advanced Cyber Security-GB V2.indd22 Sep 15. If press reports are accurate, it is a welcome development that the United States and China (in response to the threat of sanctions) have begun negotiations on cybersecurity in preparation for the upcoming summit. The Obama administration has a unique moment of leverage on cyber security with China and must be careful not to squander it. We cannot expect the summit to “fix” the problem – this will be a long process if it is serious – but we can look for certain outcomes that can demonstrate whether these presidential talks point to progress or are just another gesture.

If the only thing to emerge is an endorsement of the 2015 UN Group of Government Experts Report, hold your applause. The United States and China agreed to this report in June and presidential endorsement does not greatly improve the situation. The norms in the report, while useful, do not deal with the principle source of tension with China – espionage and theft of intellectual property and the UN Report includes annoying language proposed by Russia and aimed at the United States that any accusation of hacking must be “substantiated.”

An agreement not to attack critical infrastructure in peacetime is of symbolic value only. Neither China nor the United States intends to attack the other’s critical infrastructure in peacetime. This language is already in the June UN Report.

A Summit endorsement of a ‘Code of Conduct” for cyberspace would be a major U.S. concession to the Chinese that the United States should not give without some significant and verifiable benefit in return. The code was drafted by Russia and China and its principle aim is to diminish the application of human rights and free access to information. If a reference to the Code of Conduct appears, the United States could try to argue that it meant some other code, but this nuance will be lost on most of the world which will perceive that the initiative in cybersecurity is shifting to Russia and China.

If there is no reference to cyber espionage and no process to work on it, any summit agreement has not addressed the most important source of tension between the two countries. The Chinese will likely not want any reference to espionage in any document – no country would – but language that talks about the need to continue discussions to address other significant issues between the two counties and which identifies a process to do so would indicate success.

If the summit agrees to simply restart the bilateral cybersecurity working group, it will indicate a lack of seriousness on China’s part. The working group was seen by China as a concession to the United States intended to channel American discontent into harmless exchanges. It was not senior enough to reach agreement and not connected to any larger negotiation that could have produced agreement. A working group is useful only if it is subsidiary to political-level talks.

The Summit would be successful if it was able to define and initiate a political level negotiation (e.g. at the sub-cabinet level), like the arms control negation with the Soviets in the 1970s and 1980s. These talks should be open ended. A corollary would be to create regular military-to-military talks on cybersecurity between the Peoples Liberation Army and senior U.S. military officials. The Chinese have resisted such talks even though it is the PLA that is largely responsible for hacking. The Foreign Ministry has not been a serious interlocutor on cybersecurity. Given the difficulty of the problem, the lack of trust, and the importance of cyber espionage to powerful constituencies in China, the most tangible result would involve agreement on process since there is really no near-term “fix.”

Cybersecurity can’t be addressed in a vacuum. It is not sui generis but a product of the larger security and trade issues that dog the evolving bilateral relationship. At a minimum, there should be a recognition that China’s new, restrictive laws and rules that apply to American tech companies are as important a part of the cybersecurity problem as critical infrastructure protection and a serious negotiation must address them. This means that anything that emerges from the summit must create linkages (another term from the arms control lexicon) among issues that the United States currently keeps separate – critical infrastructure, intellectual property protection, governance and trade. This broad approach runs counter to the bureaucratic division in the U.S. government, but it will be more difficult to reach a sustainable agreement if they are not included in any agenda. This, of course, argues for a senior, political level negotiator who can transcend bureaucratic stovepipes.

There is always a temptation at summits to focus on deliverables and to prefer good news to bad, but this gives the other side an advantage and settling on a “good news” deliverable means the problem of cybersecurity will continue to be a source of tension and any agreement will be ineffective and unsustainable. The best outcome would be to begin a serious, senior level negotiating process that addresses the full range of issues. The worst outcome would be one that endorsed already-agreed report language and restarted unproductive working level discussions. The summit will not solve the cybersecurity problem, but if it is done right, it can be the beginning of a solution.

James Andrew Lewis is a senior fellow and director of the Strategic Technologies Program at the Center for Strategic and International Studies in Washington, D.C.

Commentary is produced by the Center for Strategic and International Studies (CSIS), a private, tax-exempt institution focusing on international public policy issues. Its research is nonpartisan and nonproprietary. CSIS does not take specific policy positions. Accordingly, all views, positions, and conclusions expressed in this publication should be understood to be solely those of the author(s).

© 2015 by the Center for Strategic and International Studies. All rights reserved.

 

Filed Under: News Update

Primary Sidebar

Advertisers

  • Pythia
  • Teledyne
  • Exensor
  • Visit the Oxley website
  • Blighter
  • SPECTRA
  • Britbots logo
  • Faun Trackway
  • Systematic
  • CISION logo
  • ProTEK logo
  • ProTEK logo
  • ssafa logo
  • IEE
  • EXFOR logo
  • sibylline logo
  • Team Thunder logo
  • Comtech logo
  • GoExporting logo
  • ECHODYNE logo
  • Supercat logo
  • Galvion logo
  • Leonardo DRS logo
  • MTC logo
  • IDC logo
  • DSEI logo
  • DVD2024 logo
  • SDSC logo
  • TELEDYNE FLIR logo
  • VeteranUK logo
  • Matrix Space logo
  • ST Engineering logo
  • EWS logo
  • sentinel photonics logo
  • capua logo
  • Curtiss-Wright logo
  • Brave1 logo
  • Drone Evolution logo
  • AEI Systems logo
  • EOS logo
  • NMSUK logo
  • Openworks logo
  • Sandown Park logo
Hilux UKDSE AARTOS ST Engineering Future Artillery

Contact Us

BATTLESPACE Publications
41 St Georges Drive
London SW1V 4DG

+44 (0)77689 54766

BATTLESPACE Technologies

An international defence electronics news service providing our readers with up to date developments in the defence electronics industry.

Recent News

  • Protek Selected By Dutch Armed Forces

    May 2, 2026
    Read more
  • PARLIAMENTARY QUESTIONS

    May 1, 2026
    Read more
  • MANAGEMENT ON THE MOVE

    May 1, 2026
    Read more

Copyright BATTLESPACE Publications © 2002–2026.

This website uses cookies to improve your experience. If you continue to use the website, we'll assume you're ok with this.   Read More  Accept
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT