Why Asia-Pacific must move beyond digital sovereignty
ANOTHER successful edition of the Singapore International Cyber Week (SICW) has taken place, and the attendees’ sense of collective responsibility to enhance cyber resilience is heartening. The platform that SICW provides is more critical now than ever. Accelerating domestic digital transformation has become a global norm – and for good reason.
But this laudable shift has also increased our attack surface and rendered more critical services vulnerable to cyber incidents. And the threat actors have noticed. Resources abound that document the corresponding uptick in cyberattacks, particularly on governments. As the imperative for digital resilience grows, we must simultaneously address its biggest threat – an alarming trend often referred to as “digital sovereignty”.
Under digital sovereignty, individual economies consider their digitalisation agendas purely in terms of what can be leveraged exclusively within their borders. Digital sovereignty deliberately excludes foreign and multinational resources from the many tools that can support domestic economies and security. This exclusion comes in many policy shapes.
Data localisation is an increasingly prevalent policy tool deployed in the name of digital sovereignty, where governments restrict or outright prohibit the free flow of data across their borders. According to the Information Technology and Innovation Foundation, between 2017 and 2021, the number of countries adopting these kinds of data restrictions grew from 35 to 62, with the number of discrete localisation laws within these countries growing from 67 to 144.
The irony is that these measures, however well-intended, fundamentally undermine the domestic digital resilience and economic growth that digital sovereignty aims to foster.
Collaboration is an essential element of digital resilience. The best resilience models are multi-layered and distributed. Winnowing that mesh of defences to only what can be developed and delivered domestically similarly winnows your resilience. This is not a hypothetical scenario.
On the eve of Russia’s imminent invasion in February 2022, Ukraine reversed data localisation requirements to permit the migration of its critical government data to commercial cloud environments. Doing so allowed Ukraine to distribute its data – digitally secure and physically safe – around the world so that the data could remain accessible to its government and people.
The threats need not be man-made either. In October 2022, a fire and power outage at the Pangyao data centre – a densely concentrated locus of servers and IT infrastructure in South Korea – disrupted service to millions. What could have been an isolated incident became a single source of failure.
Localisation not only exacerbates physical risks, but it also undercuts our ability to mitigate digital risks. Cybersecurity defences are most effective when they can leverage large swaths of data. Malware signatures, threat actor techniques, and effective response measures can all be crowdsourced from across the globe to ensure that everyone can benefit from everyone else’s experiences, like a digital immune system.
That pool of information, and thus the organisational immune system’s ability to respond, is decimated without the free movement of data across borders. Limited data also means limited insight to prevent and detect more traditional harms; e-commerce sites, insurance companies, financial services firms, and many other ubiquitous service sectors all rely on global information sharing to reduce fraud.
Nor do cyberthreats necessarily respect borders. When the same attack affects multiple countries, data localisation measures curtail those countries’ ability to work together to respond and recover.
By eliminating global economies of scale, localisation also drives up compliance and operational costs for private cybersecurity services. Worse, these costs can disproportionately affect those least equipped to bear them. Resource-constrained small and medium-sized enterprises (SMEs), unable to field a comparable team in-house, must often rely on third-party cybersecurity service providers. The economic ripple effects of localisation make it cost-prohibitive to access that comparative advantage.
Meanwhile, countries boasting smaller market sizes suffer from service provider atrophy, as multinational companies find it harder to justify the higher costs of investing in markets that offer lower returns.
Governments should be applauded for taking a proactive approach to building secure, reliable, and resilient economies. But that approach should evolve away from the deceptively appealing goal of “digital sovereignty” and move towards the more effective goal of “digital resilience”.
We should practise what we preach at SICW every year and work across borders with stakeholders from government, industry, and academia so that we can bolster global cybersecurity – together. Let us take advantage of this annual forum to discuss how we can achieve the goals underlying digital sovereignty, but without compromise.
Conversations about strong encryption, key management, and tailored controls for sovereign customers are all great places to start. We have a collective responsibility to protect the digital ecosystems we are creating. Let us rely on our collective ingenuity and innovation to fulfil that responsibility, rather than go it alone.
The writer, a former US ambassador, is president and CEO of Crowell & Moring International