Public, private sectors partnership is crucial to ensure cyberspace safety, official says

Sir Jeremy Fleming, former director at the UK Government Communications Headquarters. Screenshot
Short Url
Updated 02 October 2024
Follow

Public, private sectors partnership is crucial to ensure cyberspace safety, official says

RIYADH: Genuine partnership between the public and private sector is crucial to ensure technology safety within cyberspace, a former director at the UK Government Communications Headquarters said. 

Speaking in a panel discussion titled “Pathways to De-escalation: Shared priorities for reducing tensions and advancing stability in cyberspace” on the first day of the Global Cybersecurity Forum in Riyadh, Sir Jeremy Fleming explained that the private sector has many of the levers needed to facilitate and highlight cyber threats effectively.

This falls in line with the fact that on the domestic front, working with the private sector offers governments a chance to leverage insights and expertise to improve digital defense. 

According to the Global Cybersecurity Index 2024, almost 63 percent of countries reported having inter-agency processes for cybersecurity within their governments.

“Big technology companies have as good a radar on what’s happening in cyberspace as governments do, and so that leads to two conclusions for me. The first is that there is no point in governments talking to each other about cyberspace. There has to be a genuine partnership with the private sector because the private sector has many of the levers we need to make sure that this technology is safe, to make sure that threats are called out,” Fleming said. 

“Now, there is a space in all of that for, for secret stuff, there’s a space for the things that only governments can do. But again, that has to be in tandem with the private sector,” he added. 

Fleming further highlighted the importance of effective communication within the sector.

“The second thought is that I spent the last 15 years thinking and talking about cyber, but if you ask me to give you a crisp definition of it, I’m still struggling. And so, I think we have a communication problem here in how we talk about cyber and how we engage our populations in making sure that it stays at the top of the agenda,” the former director of GCHQ said.

“The debate we’re having at the moment about artificial intelligence and particularly safety is a way into this,” he added.

Also speaking during the same panel, the former President of the European Commission and former Prime Minister of Portugal, Jose Manuel Barroso, shed light on child protection within cyberspace. 

“There are some areas where I believe international cooperation can be relatively sincere; one of them is child protection,” Barroso said.

“I don’t see any reason why the governments, in spite of geopolitical interests and differences, should not consider child protection a global public good,” he added.

Barroso continued to highlight that cybercrime will increase because there are politically and economically malign actors, and some of the technologies, including AI, generative AI, and others, make the digital space even more difficult to manage.

“It’s true that according to some experts, some of those innovations can also help us fight cybercrime, it’s true. But the reality is that the digital space is becoming increasingly difficult to manage from a security point of view, for states, for companies,” he said.

“So, my first word is let’s prepare. Preparedness is the key at the national level. At the regional level, in the European Union, we are doing something. We have a European Agency for Cyber Security. I believe it’s not sufficient,” the former president of the European Commission added.

Also present at the panel, former US Secretary of Defense Mark Esper tackled what businesses need in order to navigate the digital economy.

“As businesses try to navigate more and more the digital economy, they’re going to need more consistency, more predictability. They cannot afford patchworks of regulatory law or privacy and data sharing, things like that. So, we’re going to need to smooth out, smooth out that electronic environment,” Esper said.

“In cyberspace, it’s an asymmetric tool that rich countries, poor countries, strong countries, weak countries, organizations or people or even governments can use that tool against others to gain an advantage or to level the playing field,” he added.

The former US secretary of defense emphasized how cyberspace is not static, but instead, is dynamic.

“As you see increasing advances in artificial intelligence and quantum sciences and advanced logarithms and software, it’s going to make this offense-defense component all the more challenging out there,” he said.

Experts from technology, public policy, defense, and other sectors will gather in Riyadh for the two-day Global Cybersecurity Forum.  

The event will focus on fostering collaboration under the theme “Advancing Collective Action in Cyberspace,” with the goal of enhancing multi-stakeholder engagement and driving joint initiatives on key strategic priorities.  

The program will feature five core sub-themes, each addressing a crucial aspect of cybersecurity.


OPEC+ sticks to output policy, doubles down on compliance

Updated 57 min 29 sec ago
Follow

OPEC+ sticks to output policy, doubles down on compliance

LONDON/DUBAI: A meeting of top OPEC+ ministers has kept oil output policy unchanged including a plan to start raising output from December, while also emphasizing the need for some members to make further cuts to compensate for overproduction.

Several ministers from the Organization of the Petroleum Exporting Countries and allies led by Russia, or OPEC+ as the group is known, held an online Joint Ministerial Monitoring Committee meeting on Wednesday.

“The JMMC emphasized the critical importance of achieving full conformity and compensation,” OPEC said in a statement after the meeting. “Furthermore, the committee will continuously assess market conditions.”

Oil prices dropped below $70 a barrel in September for the first time since 2021, but have since rallied above $75 on concerns a possible escalation in the Middle East following Iran’s military attack on Israel could disrupt output from the region.

OPEC+ is cutting output by a total of 5.86 million barrels per day, or about 5.7 percent of global demand, in a series of steps agreed since late 2022.

The group plans a 180,000 bpd increase in December as part of a gradual unwinding of its most recent layer of voluntary cuts extending into 2025. The hike was delayed from October after prices slid.

Countries’ compliance was in focus at the meeting, sources who attended told Reuters, and is expected to remain so in coming weeks, particularly that of Iraq and Kazakhstan.

Those nations have promised what are known as compensation cuts of 123,000 bpd in September and more in later months to make up for their previous over-production.

Iraq, Kazakhstan and Russia told the meeting that they had delivered on their promised cuts in September, the OPEC statement said.

But this will have to be verified by the second week of October by secondary sources — the consultancies and price reporting agencies that the group uses for determining its members’ output levels, the statement added.

The JMMC usually meets every two months and can make recommendations to change policy.

It will hold its next meeting on Dec. 1, ahead of a full meeting of OPEC+.


Saudi Arabia calls for harmonized international efforts to ensure cybersecurity

Updated 02 October 2024
Follow

Saudi Arabia calls for harmonized international efforts to ensure cybersecurity

RIYADH: Saudi Arabia’s Crown Prince Mohammed bin Salman on Wednesday emphasized the need to “harmonize international efforts” to ensure cybersecurity and “protect children in cyberspace,” the Saudi Press Agency reported.

In a message read at the opening ceremony of the two-day Global Cybersecurity Forum in Riyadh, the crown prince stated: “Cyberspace is closely linked to the growth of economies, the prosperity of societies, the security of individuals, and the stability of nations.”

According to SPA, he noted that due to the cross-border nature of cyberspace, it is essential to harmonize international efforts to seize the opportunities it presents and “face the challenges it presents, by investing in people.”

The event convenes high-level international figures, including former prime ministers, top government officials, decision-makers, policymakers, thought leaders, and CEOs from more than 125 countries. Welcoming the participants, the crown prince said: “The Kingdom of Saudi Arabia has always been a force for good for the benefit of humanity and human prosperity around the world. It has continuously worked to uphold the principle of cooperation and strengthen international collaboration toward efforts that support development and prosperity for all nations. It has initiated several initiatives aimed at achieving these genuine goals in all sectors.”

He added: “Believing in the importance of investing in people in this vital and promising domain, in 2020 we launched two global initiatives. The first relates to protecting children in cyberspace, and the second focuses on empowering women in the field of cybersecurity. The institute for the Global Cybersecurity Forum is entrusted with overseeing both initiatives, as well as implementing the associated projects.”

He highlighted the progress made by these initiatives, particularly the increased understanding of needs at the global level that has led to new and inspiring visions, enabling the GCF to develop impactful initiatives and programs, publish research and studies, and formulate new frameworks and strategies. These efforts empower decision-makers worldwide to develop policies and programs that enhance child protection in cyberspace and promote women’s participation in the field of cybersecurity.


Women’s risk management, attention to detail give edge in cybersecurity, forum told

Updated 02 October 2024
Follow

Women’s risk management, attention to detail give edge in cybersecurity, forum told

RIYADH: Women are playing an increasingly vital role in the cybersecurity industry, leveraging their strengths in risk management and attention to detail, according to the chair of the Cyberpsychology Department at Capital Technology University. 

Speaking at the Global Cybersecurity Forum in Riyadh, Mary Aiken noted that women’s focus on evaluating risks and their intuitive understanding of threats result in stronger decision-making and strategic outcomes for organizations. 

This comes as women are projected to make up 30 percent of the global cybersecurity workforce by 2025, with that figure rising to 35 percent by 2031, according to Cybersecurity Ventures. 

Aiken highlighted that attention to detail is a crucial skill in cybersecurity roles like data analysis, emphasizing that women excel in this area.

“The research says you get better strategic decision-making, you get better risk management because women are very focused on evaluating risk and have good intuitive perceptions around risk,” she said. 

Aiken also pointed out that women often demonstrate high levels of verbal fluency, which contributes to their effectiveness as leaders in the cybersecurity field. “They actually make good leaders and cyber leaders,” she noted. 

Additionally, she emphasized that diplomatic skills and empathy, often seen as gender-based traits, play a key role in attracting and retaining talent in the industry. 

Also present on the panel, Chief Information Officer at Paladin Capital Group Christopher Steed emphasized that despite the benefits of gender diversity, only 2 percent of venture-backed startups in 2023 were women-led. In the cybersecurity field, that number is slightly higher, ranging between 10 percent and 13 percent. 

“Our numbers when it comes to women-led startups are actually higher than that; however, I think it’s also important to broaden the definition. It can’t just be women-founded; it can’t just be women in C-level positions. It’s also the employee base,” he added. 

David Hoffman, professor of cybersecurity policy at Duke University, echoed these sentiments, sharing his experience with female students leading in cybersecurity competitions. 

“Our national championship cyber team has predominantly been led by women, but that doesn’t mean they aren’t already facing an uphill struggle and barriers that some of their male colleagues and peers do not,” he concluded. 

The Global Cybersecurity Forum, which runs from Oct. 2 to 3, focused on enhancing collaboration in cyberspace under the theme “Advancing Collective Action.” 

The event gathers global leaders from technology, public policy, and defense sectors to address strategic priorities in the cybersecurity landscape. 


US National Cyber Director calls for global cybersecurity overhaul at Riyadh forum

Updated 02 October 2024
Follow

US National Cyber Director calls for global cybersecurity overhaul at Riyadh forum

RIYADH: Cyberspace has become increasingly fragile due to decades of prioritizing innovation and market efficiency over security, according to experts at the Global Cybersecurity Forum in Riyadh. 

The discussion highlighted that attackers, often organized in syndicates, have outpaced defenders, who are typically constrained by operating in silos, making cybersecurity a global challenge that requires collective action.

US National Cyber Director Chris Inglis stressed the inherent vulnerabilities in digital infrastructure, attributing it to the rapid pace of technological development. 

“For 50 years, as we’ve developed the internet and all of the associated technologies, innovation and market efficiency have been the predominant drivers, and safety has always been the poor third child in the corner,” he said. 

This oversight, he highlighted, has left many systems challenging to defend, with resilience often being an afterthought.

Inglis emphasized the importance of moving beyond isolated defense strategies, advocating for closer collaboration between governments, private sectors, and international bodies. 

He proposed a new “social contract” for cyberspace, fostering shared responsibility to address existing vulnerabilities and emerging threats. 

According to Inglis, frameworks for information sharing and collective action are key to closing the gap between attackers and defenders.

The conversation also turned to the increasing role of artificial intelligence in cybersecurity. 

While acknowledging that AI is currently being used more effectively by attackers, Inglis expressed optimism about its potential to serve as a powerful defensive tool. 

“At the moment, generative AI tends to be more frequently used by the attacker, so that at the moment is something where the attackers are ahead of the defenders. That’s not necessarily the way it needs to be,” Inglis stated. 

He called for a more strategic approach to AI development, with a focus on ensuring that it remains under human control and aligned with ethical standards. “We should not, must not, develop AI for its own sake. We have to develop it because we have some plan in mind of what we want it to do,” he emphasized.

Inglis outlined key actions needed to bolster global cyber resilience. These include establishing information-sharing protocols, encouraging collaboration across sectors, and leveraging government resources to complement private sector capacities, particularly in critical areas like finance. 

Governments, he suggested, have unique access to intelligence that can inform broader defense strategies, while the private sector excels at innovation and rapid deployment of solutions.

The panel also stressed the need for proactive measures to stay ahead of evolving threats. The global community can create a safer, more resilient digital environment by prioritizing security in future innovations and ensuring that AI technologies are developed responsibly. 

These remarks echo the notions raised during the discussions at the UN General Assembly in September, where global leaders called for robust AI governance to prevent its misuse in spreading misinformation and destabilizing democratic processes. 

Concerns over cybersecurity developments were raised at another panel at the forum in Riyadh by Paul Selby, chief information security officer at the US Department of Energy.

He painted a bleak picture of the current state of global defensive capabilities in the industry, but added: “Now, what gives me hope? This gives me hope that we're all here. We're all talking about it. The first step in correcting any problem is recognizing the problem,.” 

He added that the cost of attacks through supply chain risk management, or as a result of not having supply chain risk management, was $46 billion in 2023 and that is expected to rise to $60 billion in 2025.

“There was last year, 245,000 malware instances in Open Source Software. That's more than double the previous four years,” he added.

“Our adversaries are moving faster than we are reacting," Selby stressed, underscoring the need for a united global response.


Saudi Arabia can pave the way in combating online child abuse, says expert

Updated 02 October 2024
Follow

Saudi Arabia can pave the way in combating online child abuse, says expert

RIYADH: Saudi Arabia could become a global leader in combating online criminals who target children in cyberspace, according to an expert.

Speaking to Arab News at the Global Cybersecurity Forum in Riyadh on Oct. 2, Iain Drennan, executive director of WeProtect Global Alliance, emphasized that identifying vulnerable users is crucial to preventing online crimes against children.

Saudi Arabia is hosting the GCF to advance collective actions and ensure a safe online space for everyone globally.

“It is incredibly important to integrate child online protection elements into our conception of cybersecurity. Saudi Arabia, with its pivotal role between east and west, between north and south, can bring together lots of the different voices that we need to have in the room to be able to move forward in this space,” said Drennan.

He added: “Looking from a child online protection perspective, it’s about identifying some of these most vulnerable users and ensuring that it’s not the responsibility on them to manage their own protection. It’s not even the responsibility of parents and caregivers. It should be the responsibility of governments and of the private sector to ensure that the tools are in place, that it’s safety by default.”

During the talk, Drennan stressed that collaboration among countries is necessary to ensure children can safely enjoy the benefits of the Internet and the digital world. “This is a problem that cuts across borders. So, you could have a child in Saudi Arabia using a social network that’s headquartered in the US, targeted by an abuser in another country entirely. So there needs to be collaboration between all of those different countries to be able to ensure that child is protected,” he added.

According to the cybersecurity expert, events like the Global Cybersecurity Forum will play a pivotal role in combating child exploitation online, as they gather global leaders and industry experts to address potential threats.

“Gatherings like the Global Cyber Security Forum play a really important role in bringing the global majority and the countries where the big tech platforms are headquartered together, so that we can develop solutions. A big part of that is information sharing,” he said.

Drennan noted that organized crime groups view online illicit activities as a business for financial gain.

In January, the World Economic Forum cited data from the International Monetary Fund and the Federal Bureau of Investigation, predicting that the global cost of cybercrime will surge to $23.84 trillion by 2027, up from $8.44 trillion in 2022. He pointed out that online criminals are increasingly using advanced AI technologies, like deepfake, to create intimate images for blackmailing children.

“What the criminals really trade on is the blame and the shame that the victims feel. And the other issue we have now is AI. AI is making that whole process a lot faster because they don’t need to trick victims into providing real images. They can create a deepfake and still blackmail, threatening to send it to family or friends unless they pay,” said Drennan.

He added that addressing online child protection is crucial for Saudi Arabia, given the young population's interest in online gaming. “It is definitely a key issue for Saudi Arabia to address cybercrimes. Sony Interactive Entertainment is one of our members, and they say Saudi Arabia is one of their key growth markets in terms of gaming. So, we know that children are online,” he said.