{
  "id": 480023,
  "title": "Why countries shouldn't outsource their cyber security",
  "url": "https://urgent.news/2026/08/10/why-countries-shouldnt-outsource-their-cyber-security",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-10T14:00:00.000Z",
  "source": {
    "name": "The National UAE",
    "slug": "the-national-uae",
    "url": "https://www.thenationalnews.com/opinion/comment/2026/08/10/cybersecurity-technology/"
  },
  "original_language": "en",
  "account": "In a laboratory, engineers are currently intentionally causing damage to systems. They may be examining a chip meant for a car’s brakes or the firmware in devices found in countless homes. This work is done to find weaknesses before anyone else can exploit them – threads that a criminal group or hostile state could follow. The results of successful security efforts are often unseen, as their purpose is to prevent failures. Security laboratories serve as a country’s immune system, and like an immune system, they are typically only noticed when they fail. For many years, technology has been tested and certified in isolated environments. Hardware engineers checked hardware, software teams focused on software, and network specialists concentrated on networks. However, attackers have found ways to bypass these compartmentalizations. Modern products are now integrated systems, combining silicon, firmware, operating systems, applications, radios, cloud services, and AI models. The most dangerous vulnerabilities often exist at the junctions between these layers. In Abu Dhabi, the Emergency Management and Crisis Management and Disaster Relief Department, in collaboration with the Government Enablement Department, has released an awareness guide on cyber security during crises in both Arabic and English. The guide highlights key recommendations and preventive measures. One recent example is BlackLotus, the first malware in 2023 that bypassed the boot protections of a fully patched Windows machine. It hides within the operating system, where most defenses cannot reach, and remains even after a system reinstall. To detect such threats, one must understand the entire system, not just its individual components. There are three major threats that loom over the next decade. The first is the rapid speed of offensive attacks. Last year, autonomous systems in America's Darpa AI Cyber Challenge analyzed over 50 million lines of code and discovered 18 new, previously unknown vulnerabilities in real software. Each discovery took an average of under an hour and cost $150 (Dh550) each. The economics of finding flaws is shifting, and defenders will not have an advantage by default. The second threat is the emergence of AI systems as targets themselves. As models are integrated into agents that can perform actions such as sending emails, moving money, or changing records, the prompts themselves become an attack surface. Researchers demonstrated that a single crafted email could silently make a mainstream corporate AI assistant leak internal data, without requiring any action from the user. The third threat is more subtle and existential. A powerful enough quantum computer could break much of today’s encryption, and adversaries are already collecting encrypted data to decrypt later. The United States finalized the first post-quantum encryption standards in 2024, emphasizing the need for migration now, not when the technology arrives. AI serves both as a new adversary’s tool and our force multiplier. It aids our researchers in reverse-engineering binaries, creating fuzzing harnesses, and analyzing forensic evidence at a scale no human team could achieve. This line cannot be moved: AI increases our productivity but does not increase our accountability. While a machine can uncover a flaw, deciding its implications and the appropriate national response remains a human task. A critical point is that you cannot outsource the ability to determine whether the technology your nation runs on can be trusted. This is already embedded in the international system. Under the Common Criteria arrangement, nations mutually recognize each other’s security evaluations only up to a certain level. Above that threshold, each country must conduct the evaluations independently. Consequently, several governments have established dedicated national facilities to examine technology at the level of silicon and source code, revealing engineering defects and vulnerabilities that certificates or paperwork alone would not have detected. This experience underscores the importance of independence alongside capability. An evaluation funded or influenced by the party being evaluated must constantly strive to maintain objectivity. Sovereign capability allows a nation to independently decide whether to trust a technology, mitigate its weaknesses, or refuse its use entirely. This option is unavailable to a country without its own lab. While a security laboratory does not announce its presence, it operates quietly beneath the systems upon which modern nations rely. The investment case is clear. Although the equipment is expensive and the skilled personnel are scarce, the alternative is far more costly. According to a 2024 IBM study, the average data breach costs $4.88 million. With connected devices projected to increase from around 20 billion to 40 billion by 2030, the consequences of failing to monitor our own technology will only escalate. Sovereignty does not imply isolation. The best labs maintain deep connections with universities, industry, and trusted international partners, but the ultimate judgment remains at home.",
  "summary": "Somewhere in a lab, right now, an engineer is deliberately breaking something. Perhaps a chip destined for a car’s braking system, or the firmware inside a device that will sit in a million homes. They are looking for the flaw before anyone else finds it – the loose thread a criminal group or a hostile state could pull. You will never read about the attacks this prevents. That is the strange…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}