Why countries shouldn't outsource their cybersecurity
Somewhere in a lab, right now, an engineer is deliberately breaking something. Perhaps a chip destined for a car’s braking system, or the firmware inside a device that will sit in a million homes. They are looking for the flaw before anyone else finds it – the loose thread a criminal group or a hostile state could pull. You will never read about the attacks this prevents. That is the strange…
Somewhere in a lab, engineers are deliberately breaking technology to uncover vulnerabilities before criminals or hostile states exploit them. These security labs function as a country's immune system, which goes unnoticed until a failure occurs. Traditionally, technology has been tested and certified in isolated compartments, with separate teams checking hardware, software, and networks.
However, modern products are integrated systems where silicon, firmware, operating systems, applications, radios, cloud services, and AI models are all combined into one object. The most dangerous vulnerabilities often lie at the junctions between these layers.
Recent examples include BlackLotus, the first malware that defeated Windows' boot protections in 2023 by hiding beneath the operating system and surviving reinstallation. To detect such threats, security labs must understand the entire stack, including vulnerabilities in radio protocols, firmware, and control systems. Three major threats loom over the next decade: offense at machine speed, AI systems as targets in their own right, and the existential threat posed by quantum computers breaking current encryption.
While AI provides advantages such as aiding in reverse-engineering binaries and triaging evidence, it also presents new attack surfaces and tools for adversaries. Countries must decide on their own terms whether to trust technology, mitigate its weaknesses, or refuse its integration. International Common Criteria arrangements typically allow nations to mutually recognize each other's security evaluations up to a certain level, but above that threshold, every country must perform independent evaluations themselves.
This is why several governments have established dedicated national facilities to examine technology at the silicon and source code levels, uncovering defects and vulnerabilities that certificates or paperwork cannot reveal.
Independence is crucial for maintaining objectivity and avoiding compromise. A lab funded and controlled by the party being evaluated may have a vested interest in proving its objectivity. Sovereign capability enables a country to make informed decisions about trusting technology, implementing mitigations, or refusing its adoption.
This option is unavailable to nations lacking their own security laboratories. Although the cost of establishing such labs is high, the alternative costs significantly more, with average data breaches costing around $4.88 million. As connected devices continue to increase, the cost of not being able to trust the technology we rely on will only grow.
Written by urgent.news from The National Business's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.