THE BROAD VIEW

Lessons from F1 in information security

In safeguarding info and data, regulation and innovation can go hand in hand – as on the racetrack

    • F1 governing body FIA has introduced new regulations in recent years designed to mitigate safety and environmental concerns, but also level the playing field and foster competition in a sport that sometimes sees too much domination from a specific team or driver.
    • F1 governing body FIA has introduced new regulations in recent years designed to mitigate safety and environmental concerns, but also level the playing field and foster competition in a sport that sometimes sees too much domination from a specific team or driver. PHOTO: AFP
    Published Sat, Sep 9, 2023 · 05:00 AM

    FORMULA 1’s (F1) popularity has boomed in recent years, mostly due to a famous documentary that has managed to reignite the world’s interest in this spectacular sport, now raking in an audience of more than 20 million for each race this season. Such is the pull of F1. The Singapore Grand Prix, always an unpredictable and spectacular race, is just around the corner, and I can’t wait to see what this year’s edition has in store for us.

    Reflecting on the unrelenting quest for performance that F1 requires, I often find myself making analogies between the sport and my own industry, and my latest musing led me to reflect on the fine balance between innovation and regulation that both F1 and information security need to strike.

    How do we define security regulations in a way that doesn’t damage organisations’ capacity to innovate? Let’s look at the lessons we can draw from F1 and this year’s new regulations that can help organisations navigate modern information-security challenges.

    Greater regulation: Help or hindrance?

    Conscious of the safety and environmental issues that persist in F1, its governing body, the FIA, has introduced new regulations in recent years designed to mitigate them. However, these are also intended to level the playing field and foster competition in a sport that sometimes sees too much domination from a specific team or driver. Reactions to the new regulations were mixed, with some saying that they hinder innovation, while others viewed them as a necessity for the sport’s longevity.

    Likewise, regulations in information security are often welcomed with reservations. Laws, regulations, standards or guidelines designed to improve security and protect organisations as well as people’s privacy and sensitive data are constantly being introduced by governments and regulatory bodies. But these regulations often raise other questions about whether they damage the industry’s ability to innovate. A recent example is the European Union’s Artificial Intelligence (AI) Act, the first regulatory framework designed to regulate AI, which has sparked debate around its potential negative impact on innovation.

    Harder for small businesses

    In information security, one of the main criticisms against regulation is how it impacts smaller businesses or startups that usually lack the resources to comply with heavy regulations. The time and money they spend focusing on compliance are time and money they can’t spend in developing new ideas and innovative products, and potentially bringing healthy disruption within the industry, which in turn damages competition. Defining regulations also takes time, and by the time they are implemented, they may not factor in innovations that happened in the meantime.

    Looking at F1, we can find similar issues. Every small upgrade on a car can make a world of difference on the track, and taking risks, investing in new technologies and innovating are the essence of this sport. But some in the industry argue that adjusting to new regulations may divert teams’ time and focus from the ever-going search for performance, and that with less freedom to innovate without boundaries, we may see fewer teams or drivers breaking through, which might damage competition around the paddock.

    But the facts seem to be proving those critics wrong. Behind Red Bull and Max Verstappen’s outrageous domination, which has been the only constant so far this season, a fierce battle is taking place among other teams, in what seems a rather more balanced playing field than in previous years. Testament to this is MacLaren’s incredible resurrection, or Alex Albon’s grit in an arguably less powerful Williams, to name a few. And no one is significantly slower than in the previous year. If anything, this F1 season shows us that despite more regulations, teams are still innovating, and the two are not incompatible.

    Striking a fine balance

    Ultimately, success comes down to being able to create a vision and take advantage of the regulatory frameworks to innovate. Instead of seeing those regulations as a challenge to overcome, they can be seen as a blueprint of the foundations the security industry can build upon and innovate. This is the kind of mindset that, for example, brings new developments in data analytics and machine learning each time new data-protection regulations are implemented.

    Most regulations are defined to safeguard a society’s values – such as citizens’ online privacy and security in our industry – and they are therefore essential in maintaining consumer trust. In adjusting to the cyber threat landscape, it is important to ensure that we foster innovation, while keeping this societal purpose top of mind.

    Seven-time world champion Lewis Hamilton likes to say, “we win and lose together”. Likewise, regulation and innovation go hand in hand, and one does not need to be compromised for the other.

    The writer is chief information security officer at Netskope