February 21, 2022

The Cyber Social Contract

In the spring of 2021, a Russia-based cybercrime group launched a ransomware attack against the largest fuel pipeline in the United States. According to the cybersecurity firm Mandiant, the subsequent shutdown and gas shortage across the East Coast likely originated from a single compromised password. That an individual misstep might disrupt critical services for millions illustrates just how vulnerable the United States’ digital ecosystem is in the twenty-first century.

Although most participants in the cyber-ecosystem are aware of these growing risks, the responsibility for mitigating systemic hazards is poorly distributed. Cyber-professionals and policymakers are too often motivated more by a fear of risk than by an aspiration to realize cyberspace’s full potential. Exacerbating this dynamic is a decades-old tendency among the large and sophisticated actors who design, construct, and operate digital systems to devolve the cost and difficulty of risk mitigation onto users who often lack the resources and expertise to address them.

Cyberthreats represent a betrayal of what advocates promised at the dawn of the digital revolution.

Too often, this state of affairs produces digital ecosystems where private information is easily accessible, predatory technology is inexpensive, and momentary lapses in vigilance can snowball into a continent-wide catastrophe. Although individually oriented tools like multifactor authentication and password managers are critical to solving elements of this problem, they are inadequate on their own. A durable solution must involve moving away from the tendency to charge isolated individuals, small businesses, and local governments with shouldering absurd levels of risk. Those more capable of carrying the load—such as governments and large firms—must take on some of the burden, and collective, collaborative defense needs to replace atomized and divided efforts. Until then, the problem will always look like someone else’s to solve.

Read the full article from Foreign Affairs.

  • Podcast
    • July 9, 2024
    Quantum Computing in US-China Competition

    A conversation between Bonnie Glaser and Sam Howell discussing the quantum computing, its applications, and its place in US-China competition.PRINT ARTICLEChina Global Podcast...

    By Sam Howell & Bonnie Glaser

  • Reports
    • June 11, 2024
    Catalyzing Crisis

    Executive Summary The arrival of ChatGPT in November 2022 initiated both great excitement and fear around the world about the potential and risks of artificial intelligence (A...

    By Bill Drexel & Caleb Withers

  • Commentary
    • Just Security
    • June 6, 2024
    Open Source AI: The Overlooked National Security Imperative

    Now a global technological superpower, China does not want to repeat the mistakes of its past and is actively positioning itself to be the world’s AI leader....

    By Keegan McBride

  • Commentary
    • The Washington Post
    • May 30, 2024
    To Win the Chip War, the U.S. Must Prioritize Revolutionary Research

    Taking big bets on moonshot technologies is the only approach that can sustain Moore’s law and guarantee that the United States continues to lead in the technologies of tomorr...

    By Jordan Schneider, Arrian Ebrahimi & Chris Miller

View All Reports View All Articles & Multimedia