Tuesday, December 14, 2021

The Afghan Debacle Should Prompt China to Revise its South Asian Policy

This piece was first published by RUSI in London.  The views do not represent those of RUSI.

EXPERT PERSPECTIVE — While China has tried to rebalance its relations between India and Pakistan before, recent developments in Afghanistan should give it fresh impetus to do so.  Any future Cold War between the United States and China would be entirely different to the previous version for several reasons of which the most obvious is the economic and financial inter-dependency between the two countries. However, one similarity could survive in the form of proxy conflicts such as those seen in Angola, Afghanistan and Nicaragua in the 1980s.

A proxy conflict in South Asia would be extremely dangerous both because of the numerous geopolitical fissures which opposing sides would seek to exploit and the fact that India and Pakistan now have nuclear weapons and the means of delivery. In the previous Cold War neither New Delhi nor Islamabad had credibly deployable nuclear weapons and, although India leant clearly towards the Soviet Union and Pakistan towards the West, there was no proxy war in the Subcontinent, only further north-west in Afghanistan.

Relations between India and Pakistan are already dangerous enough without being drawn into a new Cold War. The Balakot episode of 2019 took both countries to the brink of war and was de-escalated more through luck than good judgement. Since then, China has become an active participant through its hostile operations along its disputed border with India in the Himalayas and, most recently, by appearing to endorse Pakistan’s preference for a Taliban-only government in Afghanistan.

I am told confidentially that China did question the wisdom of Pakistan’s judgement in August just as the Ashraf Ghani government collapsed but, crucially, it did not press the point. Beijing may have calculated that the Pakistan army could not have forced the Taliban to form an inclusive administration and that the influential Corps Commanders in Pakistan might even have resisted Chinese pressure at such a seminal moment.

Following the US withdrawal, Beijing will surely now recognise that it needs its own policy on Afghanistan; it can no longer outsource decisions to Pakistan. There is too much at stake including the threat from Uighur militants, Chinese investments in the mining sector and possible future Belt and Road Initiative (BRI) projects.


The Cipher Brief hosts private briefings with the world’s most experienced national and global security experts.  Become a member today.


Beijing will also know that the Indian government is infuriated by its loss of agency in Afghanistan after 20 years of political and economic investment there. Following what looks (at first sight) like a stunning victory for Pakistan, India will inevitably wish to make Islamabad pay a price. New Delhi is not short of options. It will doubtless see opportunities in the growing dissent in Baluchistan (and Gwadar in particular) against the BRI, and in the increasing disenchantment amongst Pashtuns in Khyber Pakhtunkhwa (formerly North West Frontier Province) and in the huge port-city of Karachi where Pashtuns represent some 20% of the population. India will also push its maximalist position on Kashmir by which Gilgit-Baltistan (through which several BRI projects traverse) is claimed as part of India.

China may also reflect on the cost/benefit of its activity along India’s northern border. In the long run China has much to lose by stirring up a region which offers India (and potentially the United States) a direct route via the Aksai Chin into China’s two least contented regions; Tibet and Xinjiang. It could be argued that, in the new era of hybrid warfare and imaginative cyber operations, direct access to a territory is less essential for a campaign of disruption. Possibly.  But China would be wise not to throw stones in such an extensively glazed region.


Go beyond the headlines with expert perspectives on today’s news with The Cipher Brief’s Daily Open-Source Podcast.  Listen here or wherever you listen to podcasts.


All of this argues for China to review its South Asia strategy with a view to a degree of rebalancing between India and Pakistan. The continuation of existing policy will see Afghanistan decline back to its pre-2001 status as an economic and social wasteland. It could witness Pakistan increasingly undermined by radical Islamist groups operating from Afghanistan, the tribal borderlands and inside the cities of the Punjab and Sind. It will see a frustrated India taking ever less flexible positions on regional issues and on Chinese access to its huge markets. And access to Himalayan waters will become the dominant theme in the region.

It is often forgotten that China attempted to rebalance its relations between India and Pakistan in 1996 in a remarkable speech delivered on 2nd December by President Jiang Zemin in Islamabad.  After a number of standard paragraphs about the “profound friendship” between China and Pakistan, Jiang then turned to the importance of ‘South Asia’ to Beijing and then, to an increasingly appalled audience, began praising the “the multi-dimensional exchanges and cooperation between China and the various South Asian countries”. The name of India never passed his lips but it was clear to all that China intended to rebalance its Indian and Pakistani relationships.

To grasp the ambition behind the speech two passages are worth repeating; “China and South Asian countries are all members of the developing world dedicated… to developing their economies and improving their peoples’ livelihood. They all need a peaceful and stable international environment and, particularly, a favourable surrounding environment.”

And “China will, as always, support South Asian regional cooperation, support the proposal and initiative for the establishment of South Asia Nuclear Free Zone and Indian Ocean Zone of Peace, and support all efforts designed to serve peace, stability and development in the South Asian region.”

The Indian nuclear tests just 18 months later killed the rebalancing in its infancy but the sentiments are arguably truer today than in 1996. If Pakistan and Afghanistan are to survive they need to open their borders with India and become transit routes to Central Asia. Now that the US has departed the stage only China can facilitate such ambitions. The alternative is more terrorism and instability in an area where there are far too many nuclear weapons. Even without a new Cold War Beijing’s current course is too dangerous.

Read more expert-driven national security insights perspective and analysis in The Cipher Brief

The post The Afghan Debacle Should Prompt China to Revise its South Asian Policy appeared first on The Cipher Brief.



from The Cipher Brief https://ift.tt/3IRJsor
via IFTTT

Monday, December 13, 2021

The Supply Chain is the Perfect Asymmetric Target

Robert Hannigan is a Principal Member of The Cyber Initiatives Group, powered by The Cipher Brief.

EXPERT PERSPECTIVE — Asked recently what risk he worried about most, alongside Taiwan and Ukraine, Cipher Brief Expert, General Stanley McChrystal said it was cyber security, particularly in the supply chain.

General McChrystal is part of a growing group of the most senior operational and strategic US commanders that include former Chairman of the Joint Chiefs of Staff, Admiral Mike Mullen, in seeing the supply chain threat as existential. Unless the supply chain can be secured, the whole infrastructure on which Western economies rest, not to mention their military defences, will be compromised.

Two factors have brought the otherwise dry subject of supply chain security to the top of the political risk table. One has been the pandemic, in which we have become painfully aware of the fragility of supply chains and the over-dependence of Western countries on external providers, particularly in China. We have also realised how little we actually understand about our supply chains: which companies are in them, who owns them, who controls them and how they can be disrupted.

The other factor has been the SolarWinds attack, almost exactly a year ago. The sophistication of this compromise of the software supply chain, which had probably been active for at least a year before it was discovered, captured headlines around the world. This was partly because SolarWinds Orion was in use by a whole range of government agencies and major companies. More acutely than many other earlier third-party compromises, it illustrated why supply chain companies are such attractive targets: their security is often poor and they represent a softer way into a vast range of customers, including many companies that would in themselves be a hard target. The supply chain is the perfect asymmetric attack.


The Cipher Brief hosts private briefings with the world’s most experienced national and global security experts.  Become a member today.


Interest in this is leading to some positive focus.

There are two challenges. The first is visibility. Governments and companies need to understand what the security of their tens of thousands of vendors looks like in real time. That means having the same attitude to the ecosytem of third parties as they would to their own networks. It also means understanding ownership and control and a range of other dependencies. It requires constant monitoring of the supply chain, not occasional compliance exercises. In the end, this will probably need to be required by regulation, but there is no need to wait for that.


Go beyond the headlines with expert perspectives on today’s news with The Cipher Brief’s Daily Open-Source Podcast.  Listen here or wherever you listen to podcasts.


Beyond visibility and understanding there needs to be action. We have to move from assessing the risk and admiring the problem to fixing it. This means taking a range of actions from helping vendors to remediate weaknesses to addressing issues of ownership. The UK’s new legislation giving government greater powers to intervene in mergers and acquisitions on national security grounds is long overdue and brings it into line with other Western countries. But these assessment processes will need to become dynamic and constant to reflect the ever-shifting nature of modern vendor ecosystems.

The complexity of the global supply chain is the creation of open economies and democratic societies; but unless it is secured it will ultimately undermine them.

Read more expert-driven national security insights perspective and analysis in The Cipher Brief

The post The Supply Chain is the Perfect Asymmetric Target appeared first on The Cipher Brief.



from The Cipher Brief https://ift.tt/3DKkSSM
via IFTTT

Tuesday, December 7, 2021

The Urgency of the Moment for Congress on AI and National Security

(Editor’s Note: This article is the fifth and final article in a series first published by our friends at Just Security that is dives into the foundational barriers to the broad integration of AI in the IC – culture, budget, acquisition, risk, and oversight. This article considers a modified approach to congressional oversight of the IC. The author’s full report examining all of the topics in this series in greater depth is available here.)

Throughout this series, I have explored the most pressing foundational issues impacting the Intelligence Community’s (IC) ability to meet the urgency of this moment in the global artificial intelligence (AI) race. The current bipartisan support for taking bold action to drive national security use of AI is key to the IC’s success. That support must propel change in the priority areas I have already identified: modernizing the IC’s budget and acquisition processes and enabling a risk-tolerant culture with a new IC AI risk assessment framework that helps IC officers navigate the uncertainty that necessarily accompanies technological innovation. There is one other area, however, that cannot be ignored if the IC is to keep pace with our nation’s adversaries and provide policymakers with accurate, timely, and impactful insights: congressional oversight.

Congressional oversight of the IC is critical. Congress is the eyes and the ears of the American people. Among other things, it is charged with evaluating IC program performance, and ensuring the IC is efficiently and effectively spending taxpayer dollars and properly executing national security activities consistent with statutory requirements and legislative intent.

But intelligence oversight is complicated and has not sufficiently evolved with the times. When it comes to assessing progress of IC programs, standard oversight processes typically track defined, pre-determined requirements, cost, and timelines. These metrics have worked reasonably well for large programs like the acquisition of satellites and buildings, for which there is a clear beginning, middle, and end, with easily identifiable milestones and a definite budget. However, AI is different; its development moves back and forth across a spectrum of activities often without discrete steps, and failure is a necessary part of the process as the technology evolves and matures. Traditional metrics are, therefore, less effective for AI, as the value (or lack thereof) of certain milestones may only become clear partway through the development process and desired end-states may shift.

The IC has four primary congressional oversight committees. In addition to the House Permanent Select Committee on Intelligence (HPSCI) and the Senate Select Committee on Intelligence (SSCI), which have oversight jurisdiction over the IC, the House Appropriations Committee Defense Subcommittee (HAC-D) and the Senate Appropriations Committee Defense Subcommittee (SAC-D) provide the IC’s money. These four committees (hereinafter collectively “Committees”) must consider a more adaptive approach to oversight, measuring progress and failure through metrics that are less rigid and better tailored for AI and other emerging technologies. In doing so, the Committees may lose a measure of certainty that impacts their most powerful lever – fiscal control over the IC. For that reason, the Committees and the IC must simultaneously build a greater degree of trust, transparency, and ultimately partnership.

Adaptive Oversight

Much like AI itself, congressional oversight of AI activities must evolve and adapt to the world of emerging technology. While there are a variety of rules that govern Congress’ oversight responsibilities, Congress has considerable latitude and discretion in the execution of that oversight, including how they measure executive branch progress. To improve IC oversight engagements, Congress and the IC must start with a shared strategic vision for what a successful AI project looks like and create an approach to oversight that is tailored to achieve this goal.

Current measures and metrics often focus on ensuring projects stay on track in terms of cost and schedule; there are well-defined outputs, such as number of tools built, and static timelines for delivery. Such demonstrable deliverables are objective, consistent, and easy to measure, but they are ill-suited to AI, the underlying technology for which is still evolving. To take full advantage of AI’s emerging possibilities, the IC must have the ability to test, adjust, and pivot as new algorithms and capabilities are developed and applied to different problem sets.


The Cipher Brief hosts private briefings with the world’s most experienced national and global security experts.  Become a member today.


Recognizing that detailed requirements and program schedules are not well-suited to measuring the success of software, which is the core of AI, the Defense Department is already considering changes to related oversight. Research by Google and others indicates that metrics aligned with DevSecOps, the industry best practice for rapid, secure software development, can better predict the performance of software teams. DevSecOps seeks to unify software development (Dev), security (Sec), and operations (Ops). Its metrics allow teams to focus on outcomes while adjusting for multi-dimensional, dynamic, and continuous improvement in technology along the way. Teams can move quickly, respond rapidly to user needs, and produce reliable software – all critical when it comes to scaling AI in the IC.

In addition, AI-related metrics must focus on key performance indicators that track the progress of how AI tools evolve rather than on only the final product to both create the opportunity for, and reflect the expectation of, value to the user earlier based on strong communication and feedback loops. Performance evaluation should center on delivery of incremental capabilities, drilling down on speed and functionality together in phases and time-boxing segmented activities, from staffing to new releases to bug-fixes.

The IC and the Committees must learn from industry best practices related to DevSecOps and software, and together develop relevant and adaptive metrics that can be consistently applied but are more aligned with AI’s attributes. This joint process would itself serve as an opportunity for learning and trust building. Once developed, the metrics must continue to drive accountability and demonstrate value, and if timelines slip, the IC must quickly inform the Committees and produce new targets. The IC should expect to use the new metrics first on low-risk activities and ensure the Committees understand the standards and benchmarks the IC is using so they can evaluate programs accordingly.

While pivoting to new metrics is a good start, the IC and the Committees also must remain open to iteration, allowing oversight to change if the initial approach is less than optimal.

Trust, Transparency, and Partnership

There is no dearth of oversight today – each year, there are hundreds of written reports, in-person briefings, phone calls, hearings, and other engagements between congressional overseers and the IC. However, current oversight engagements suggest a lack of confidence and trust in the IC; they are often excessively tactical and focused on execution details that provide neither a strategic perspective on the health of a program nor an understanding of potential long-term opportunities and risks. These engagements drive a continuous cycle of meetings and briefings, requesting deeper levels of detail, in an effort to achieve the desired understanding. Unfortunately, layering detail on top of detail does not produce strategic insight, and this approach is ultimately ineffective – the Committees do not feel sufficiently informed and the IC does not feel sufficiently supported, steering the relationship toward one that is more adversarial than collaborative.

Current oversight processes were not designed to be overly burdensome or act as roadblocks to progress. They were designed to give Congress appropriate insight and confidence that executive branch activities and spending are being carried out efficiently, effectively, and consistently with the law. Unfortunately, the processes have become onerous due to a history of issues that have undermined Congress’ trust and confidence in the IC. The IC must rebuild trust with Congress so overseers can step back from day-to-day operational details and engage with the community at a more appropriate strategic level.

The relationship between a Board of Directors (Board) and a Chief Executive Officer (CEO) in the private sector is a helpful model. The Board has ultimate responsibility for ensuring the organization is appropriately stewarding the resources entrusted to it, while the CEO manages the execution of a company’s day-to-day activities. According to the KPMG Board Leadership Center, the key to a healthy relationship between a Board and the organization it oversees is trust and transparency, where the Board has constructive conversations with the leadership team about significant decisions and issues as well as the opportunity to provide meaningful input before decisions are made, and the leadership team receives valuable feedback. It is not the Board’s role to “see every scrap of paper that the management team sees,” and it should not wade into tactical details of an issue unless the issue is related to strategy or risk.

Of course, the analogy is not perfect, but it can be instructive. The Committees, which are like the IC’s Board, have the responsibility to ensure the IC is appropriately stewarding its resources. In doing so, they also have the responsibility to leverage their knowledge and expertise to provide strategic advice and direction rather than diving into many levels of detail. But, as with the private sector, without the requisite trust and transparency it is difficult for the Committees to operate at the strategic level.

To rebuild trust, the IC and the Committees must fundamentally alter the nature of their interaction, engaging not only in formal ways but also increasingly in informal engagements to better manage expectations and reduce the element of surprise. The IC should seek the Committees’ views on significant activities before final decisions are made and work to incorporate their feedback when possible to build stronger support and buy-in from the Committees. Formal engagements are important, but informal engagements create relationships that lead to true partnerships.

IC Actions

As the IC seeks additional flexibility from the Committees, it should increase trust and transparency through a more informal and open posture with Congress that includes accommodation from deliberative process privilege as needed. This would require a significant cultural shift but, if done carefully, would pay enormous dividends.

Specifically, the DNI should propose two informal, private engagements with the Committees: 1) semi-annual conversations between Committee staff and high-priority AI project leads for conversation and feedback on progress, issues, concerns, and requirements; and 2) periodic IC leadership “coffee catch-ups” with Committee members to better drive the strategic relationship, provide the benefit of each other’s thinking at that moment, and develop a sense of partnership. These engagements should not track metrics or seek to accomplish specific tasks, but rather should create mutual understanding, open dialogue, and build trust around AI activities. AI project leads should share what is known and unknown about projects, potential outcomes, and any changes in spending the Committees may see in the coming months. The IC leadership coffees would, of course, produce benefits well beyond the IC’s AI activities.

It is unlikely that the information shared in these engagements would implicate the executive branch’s deliberative process privilege, which reflects the president’s constitutional authority to withhold certain information from Congress before a final decision has been made within the executive branch, because these discussions would not be tied to specific decision points. Nevertheless, to help navigate these conversations the DNI should clearly set expectations with the Committees that these conversations are not formal notifications and must not be used to later reprimand the IC. The DNI should also create IC legislative engagement principles to help IC officers appropriately engage. To the extent the IC does seek pre-decisional views from the Committees, the IC should look to the accommodation process, which allows the executive branch to provide information that might otherwise be privileged if necessary to facilitate the legitimate needs of the legislative branch.

Leaning forward in this way does come with risk that the Committees will inappropriately interfere in executive branch matters. Therefore, to truly build trust, the Committees must agree to be judicious in these engagements, focus on insightful strategic and risk-based questions reflective of their extensive experience and expertise, and not misuse the information to obstruct the executive branch’s authority to execute the law. Any actions to the contrary will undermine the progress made and likely end this more open dialogue. However, with agreed upon guidelines and parameters, these informal engagements would improve the AI dialogue between the IC and Congress, leading to deeper Committee understanding and, ideally, strengthening Committee support for legislation and funding of AI activities, even in times of loss or failure.

Committee Actions

As the Committees introduce more agility into their processes and adjust their oversight to accommodate AI, they should consider the following steps to increase their confidence in the IC’s activities.

First, to expand their capacity and institutional expertise, the Committees should re-organize staff along functional lines, as has already been done in some committees. Such a change would allow staff to develop a deeper understanding of various AI tools and technologies, apply that understanding strategically across IC elements, and get a more holistic cross-IC view of AI coordination and activities. While the more common model of organizing staff by IC element makes logical sense, expecting staff to understand everything an IC element does is unrealistic and unreasonable, especially given they are often single-threaded in their roles. Refocusing staff on specific functional areas and allowing them to become experts would greatly benefit not only the Committees’ oversight of those activities, but the IC elements they oversee. In addition, as many have recommended, Congress should recreate the Office of Technology Assessment – a congressional agency that provided impartial analyses of technology and science issues – to provide the Committees with access to deep technical experts when needed.

Second, the Committees should hold formal semi-annual closed substantive briefings on high-priority AI projects. In these briefings, the IC should provide enough detail for the Committees to understand progress against the new metrics and ask questions about the strategic direction of the programs, areas of risk, concerns, unexpected issues, and future legislative and funding requirements. These briefings would provide an official mechanism for the IC to show forward movement and elevate significant issues, and for the Committees to track high-priority AI activities across the IC.

Third, if the IC receives no-year or multi-year funding for AI, the Committees should hold a focused annual review of AI spending during the previous year. This review should include an understanding of what is going well and what did not go as expected so the Committees can provide a timely and critical check on the use of that money. If the funding has been executed in accordance with congressional direction – even if some of the activities have failed – the money should continue to flow. If the funding has not been executed properly or consistently with congressional direction, the Committees should have the ability to stop the funding immediately.

Conclusion

The executive branch has significant work to do to speed and scale AI into the IC: it must reform budget and acquisition processes; create an IC AI risk assessment framework to encourage reasonable and informed risk-taking; and build an IC culture that supports innovation and accepts a level of failure. But the IC’s success will be hard-fought and fleeting if the IC’s congressional oversight committees do not simultaneously re-examine their supervision of the IC.

The Committees, similar to a corporate board, provide an important check on the IC’s activities. To be successful in this new world of AI and emerging technology, the Committees must embrace a strategic reset, increased flexibility, and an adaptive approach to oversight. In return, the IC must lean forward with open and informal dialogue with the Committees. These adjustments will take practice to get right but, if successful, will dramatically change the IC’s partnership with the Committees for the better, providing the Committees with earlier and improved insights and leading to greater support and backing for the IC.

The issues highlighted in this series are not new; countless others have raised them and good people have worked hard to solve them over many years. We cannot wait any longer for implementation to take hold. China and other adversaries are at our doorstep, and the IC must move immediately to embrace the reality of a world awash in data moving at the speed of emerging technology. Now is the time to take advantage of the groundswell of support, remove unnecessary bureaucratic barriers, and take decisive action.

Additional detail and implementation steps in all of the areas discussed in this series can be found in The Integration of Artificial Intelligence in the Intelligence Community: Necessary Steps to Scale Efforts and Speed Progress, a full-length report produced through the American University Washington College of Law Tech, Law & Security program.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

The post The Urgency of the Moment for Congress on AI and National Security appeared first on The Cipher Brief.



from The Cipher Brief https://ift.tt/3GqDBoj
via IFTTT

Thursday, December 2, 2021

CIA Deputy for Digital Innovation Talks Mission, Partnerships and Espionage Challenges

CIA Deputy Director for Digital Innovation Jennifer Ewbank said recently “the cyber forces and other threats that we confront across the digital landscape are formidable and they are changing the very nature of the intelligence business.” 

Ewbank, who spent much of her career with the Agency running overseas operations, noted at The Cipher Brief Threat Conference, not only how U.S. adversaries have upped their digital game, but also how the agency has been “grappling with how to manage the explosion in volume and variety of data fueled by technological change,” saying, “It has transformed the intelligence business in many of the same ways it’s transformed the commercial marketplace and the global economy as a whole.

Below is her perspective on the evolving digital landscape, the hazards and opportunities within and what it means for the organization she leads at CIA. Her comments have been lightly edited for clarity. 


Jennifer Ewbank, Deputy Director for Innovation, CIA

Jennifer Ewbank is the Deputy Director of CIA for Digital Innovation, responsible for accelerating the development and integration of digital and cyber capabilities across all of CIA’s mission areas. She also focuses on enterprise information, technology, cyber operations and analysis, data strategy, artificial intelligence, open source collection, and reporting.


The cyber forces and other threats that we confront across the digital landscape are formidable and they are changing the very nature of the intelligence business. They represent a real danger to our national and economic security, but they’re not really a surprise. Six years ago, the CIA stood up a new Directorate of Digital Innovation. That’s the part of the organization that I now have the honor of leading. It was a move to redesign the intelligence enterprise to meet emerging threats in the digital domain, and to leverage these new capabilities for operational advantage and analytic insights.

The espionage business, as I see it is, is often thought of as the dark side, but it’s really about the art of the possible. Success requires creativity, ingenuity, dogged determination, and a healthy dose of optimism. You have to believe that you can do things that – at their core – may seem impossible. The Directorate of Digital Innovation (DDI) is charting the course for CIA’s art of the possible in the cyber and digital realm.

Today, DDI represents a multidisciplinary fusion of cyber offense, cyber defense, open-source collection, data science, artificial intelligence, and enterprise information technology, all of which are increasingly essential for the CIA’s success in a world of ubiquitous sensing, cyber threats, and the exponential increase of data.

Our enduring mission in DDI is to integrate CIA’s human, technical, and digital operations at scale, which is an important characteristic to counter our foreign adversaries at the speed of mission. To make this happen, we are charged with raising the digital acumen of CIA’s workforce to position the agency for success long into the future. However, DDI tackles none of this alone- it’s all about partnerships within the agency, with partners across the national security community, and with patriotic Americans.

I’ll share something I learned coming from the director of operations into this new directorate a few years ago: our workforce is tremendously skilled, capable, and highly agile. They work as integrated teams each day taking on some of our most daunting intelligence challenges: technologically, operationally, and analytically. We sit at the nexus of technological threats and the data explosion, and I believe our work becomes only more critical to the agency’s success with each passing day.

Personally, it’s a huge pleasure and an honor to lead the agency’s digital workforce. It’s an incredible team brimming with talent, creativity, and dedication. However, when we talk about the threats and opportunities across the digital landscape and their intersection with defensive and offensive operations, I speak to you as more than the head of a large organization in Washington. I have spent most of my own intelligence career overseas running operations and I’ve seen firsthand what our adversaries are capable of, as well as the power of integration. It’s a bit of a buzzword at times, but it is an extremely powerful thing.

I was there when we combined these new areas of digital expertise with our traditional strengths in technology and science, all in partnership with our core human intelligence tradecraft. I’ve been part of successes, large and small and have certainly seen my share of setbacks along the way. So, our discussion today of what’s happening in the digital landscape, the explosion of data in a highly-connected world of ubiquitous sensing, the onslaught of cyber threats we face from hostile actors, and how we as a service and as a country respond is more than just theoretical for me. It’s personal.

When the CIA was created in 1947, our principal rivals were the Soviets and their surrogates across Eastern Europe. In those early years, the agency dueled with the KGB on the streets of Moscow and the Stasi on the streets of Berlin and those kind of gritty and determined first generation officers operated under extremely challenging conditions, sparring with their Eastern Block foes while dodging surveillance and evading checkpoints. Tensions ran very high at that time. In 1956, when the east Germans discovered a CIA/MI6 tunnel under the streets of Berlin, our legendary base chief at the time went down there himself and from behind a machine gun, made sure that no unauthorized person was going to cross over into the American sector. Obviously now, the only tunneling most base chiefs and station chiefs are doing these days are struggling to set up VPNs on their MacBook, but some of the most consequential threats we face today are in the digital domain.

In recent years, we’ve experienced a seismic shift in the contours of that environment and with our mission responsibilities at CIA becoming progressively more challenged by these shark infested waters of the information environment, our agency has been grappling with how to manage the explosion in volume and variety of data fueled by technological change. It has transformed the intelligence business in many of the same ways it’s transformed the commercial marketplace and the global economy as a whole.

Challenge is present for everyone but for those of us in the intelligence arena, the stakes are particularly high. Our long-time strains continue with Russia and China has emerged as our most significant and daunting challenge but beyond the great power competition, there are lots of other state and non-state actors alike vying for power and influence too, and every single one of them is using these new technologies to support their cause. In the final analysis, our own competitiveness as an intelligence service and an intelligence community will depend on how fast we turn this evolving digital landscape to our own advantage relative to our adversaries.

As we know, foreign states have leveraged their cyber capabilities to steal information, influence foreign populations, and menace private industry with physical and digital infrastructure being favorite targets. We also know that data analytics and artificial intelligence capabilities being developed by digital autocracies to monitor and control their own societies are now arrows in their own quiver to target us. So, although an increasing number of others are dabbling in cyber, China, Russia, Iran, North Korea remain the core antagonists. Each is at the controls of highly developed, well-resourced cyber programs pointed like daggers at U.S. interests at home and abroad. Joining this fray as of late are the criminal ransomware outfits who have monetized hacking and are plotting as we speak to hold U.S. networks hostage at digital gunpoint just as they did with the recent Colonial Pipeline and JBS attacks.

The Chinese are clearly formidable players in the digital underworld and that’s something that had, for a few years, evaded much public notice. Barely concealing its ties to criminal hackers, the Chinese government views its competition with the west as a zero-sum equation where China’s rise must come at the expense of America’s decline. This has fueled brazen aggression lately as China saturates our networks with disruptive intrusions designed to undermine the security and competitiveness of our nation. Their systemic industrial level theft of our personal information and intellectual property is both shameless and unrelenting and part of a concerted campaign to chip away at our prosperity and diminish our economic might. China presents a prolific and very effective cyber espionage threat, a growing influence threat, and considerable, substantial cyber-attack capabilities.

China’s cyber espionage program is particularly formidable in two respects: its sheer size and its vast ungoverned, contract hacker ecosystem. Beijing also sees cyber as a primary means for conducting political warfare. A concept that includes virtually all means short of war, to achieve its national objectives.

One aspect of China’s influence campaign that’s particularly noteworthy and reflects this theme of scale is the broad array of languages and media used to disseminate Beijing’s messaging. In recent years, we’ve seen vast Chinese spam networks who have posted videos on YouTube in order to influence audiences both in the U.S. and around the globe.

Russia, too, remains a significant cyber threat. It has unleashed increasingly sophisticated espionage influence and attack capabilities against the West and Russian regional rivals. The Russians consider cyber hacks an acceptable tool for deterring adversaries and prosecuting conflicts and they view cyber espionage as routine business. We saw this with the recent software supply chain operation against Solar Winds where Russia’s foreign intelligence service executed a cyber espionage campaign against the U.S. by placing malicious code in broadly distributed software products. This was a brash demonstration of Moscow’s capabilities and proof if anyone needed it, that public and private organizations in the U.S. remain in Moscow’s crosshairs.

Alas, the Russians and the Chinese are not alone. Iran’s technical expertise and zeal for aggressive cyber operations further jeopardize the integrity of the United States and our allies’ networks. The Iranian track record includes attacks on critical infrastructure, which are particularly worrisome as demonstrated by their multiple cyber-attacks last year against Israeli water facilities. Iranian hackers recently targeted dozens of U.S. and Israeli defense firms according to press reports. So, it’s fair to say that Tehran is responsible for lots of other nefarious activities on the net, but we’ll leave it there.


The Cipher Brief hosts private briefings with the world’s most experienced national and global security experts.  Become a member today.


North Korea’s cyber program remains troublesome as well. The notoriously mercurial Pyongyang likely possesses the expertise to disrupt critical infrastructure and business networks in the United States judging by their track record. North Korean hackers also have long posed a very significant threat to the integrity and stability of the international financial system and have engaged in a variety of illicit activities to include cybercrime to generate revenue for the regime.

Last, but certainly not least, are cyber criminals motivated by simple financial gain. Their goal is to compromise our personal, financial, and health data to leverage it on underground black markets. Ransomware is just the latest incarnation and U.S. consumers and businesses alike remain susceptible to traditional fraud, extortion, and credit card theft proving that even criminals are leveraging digital innovation. The recent appearance of ransomware as a service has made ransomware available on a scale never before seen and when we consider the potential impact of ransomware attacks on critical infrastructure or government networks in the United States, the potential impact is really clear.

On the whole, our national and economic security are put at risk by all of these threats. There is, however, a flip side to this coin and technology as always is a two-way street. There are windows of opportunity for our organization and others in the intelligence community to strike back and turn the tables on rivals and competitors to gain the strategic advantage we need to succeed in the 21st century.

A central pillar of our strategy at the Director of Digital Innovation is to outmaneuver adversaries in the digital sphere which requires a wholesale embrace of the power of innovation. That power has become the bedrock of our organization underpinning so much of the mission success that we have been able to achieve. Adapting to this kind of shifting intelligence landscape has long been encoded in the very DNA of the Central Intelligence Agency. For us in DDI, it is foundational to everything we do and it’s why we put innovation in the name of the directorate. In a constantly evolving battle space where the rules of the road are rewritten with head spinning speed, we must embrace risk and we must embrace experimentation as the key to innovation and the process of unlocking new insights.

The coming decade will bring an unprecedented set of national security challenges that will demand an unprecedented response and to ensure CIA’s readiness for long term success, we made a few smart adjustments to our priorities regarding China, technology, our people, and partnerships to optimize the agency’s ability to confront future threats. We do all of this while maintaining our focus on never taking our eye off enduring challenges such as counter-terrorism and Russia. Perhaps for us, a useful guiding principle, comes from a Latin proverb made famous by the Roman poet Virgil, “Fortune favors the bold.”

Indeed, to prevail against 21st century foes whose technical mastery is matched only by their malicious intent, it’s imperative that we boldly develop new tradecraft, new tools, new platforms, and other mission solutions that provide decisive operational advantages. Every day we fail to innovate, fail to take chances, or fail to challenge ourselves and our conventional wisdom, we risk mission failure or worse, irrelevance. Innovation is not just the core of our mission; it is the life blood of American industry and any organization today enduring to be even modestly successful in this new digital landscape.

To illustrate the point: what is blue and gold, once owned by almost everyone and today no longer exists? Those of us old enough will remember that was a Blockbuster Video Membership Card. The collapse of this one-time empire is a cautionary tale for all of us and reveals the fate of any organization that fails to innovate in a hypercompetitive and data driven digital world. Blockbuster had a rapid collapse from the top of its industry to complete irrelevance in the span of just six years, all because it failed to innovate as others aggressively leveraged new technology and rapidly expanding digital infrastructure.

The Blockbuster story reflects in some ways the crossroads that we in the espionage business have reached today. However, it’s not a choice between dooming ourselves to Blockbuster’s fate or following some proven route already mapped out by others. It’s about our willingness to be explorers ourselves and to chart a very new course. Teams of cutting-edge designers and engineers at Netflix, Apple, Disney, and Amazon don’t sit around tinkering with their platforms just to meet a customer’s needs today and modernization is not the act of upgrading an inventory from VHS to DVD.

Success, in this new world, in this digital world, hinges on our ability to project requirements and solutions well into the future, to look out beyond the horizon, to anticipate and gamble on the future, as uncertain as it may be and the same holds true for the art of espionage in a world of dramatically fewer real secrets.

Social media, online digital news platforms, ubiquitous sensing, commercial collection, on land, at sea, in the air, and the internet itself mean that we don’t really lack insight even in far flung corners of the globe. The price of fuel in Moscow, the conditions at a port on the coast of Africa, the size of a pro-democracy demonstration in Hong Kong, it’s all available at our fingertips on our mobile devices while secrets, plans and intentions of despots and terrorists – the things that have yet to happen – are increasingly more difficult to uncover by traditional means.

Success can be unlocked through innovation and partnerships. We’re not alone in pursuing the technological solutions of tomorrow, and yes, being first does matter. Ask those in the Manhattan project, ask NASA, ask Netflix, ask China.  They aim to be the first to lead in the digital world as shown in the Made in China 2025 program and their complete commitment to AI dominance by 2030.

The Secret Service has a saying about schedules: if you’re early, you’re on time; if you’re on time, you’re late; if you’re late, just don’t bother coming. Similarly, we can’t think about catching up with the Chinese, the Russians, the hackers, hacktivists, or any of the others are out there trying to do us harm because at the moment when we’ve caught up, we’re already falling behind again. The race for decisive advantage in this digital realm is not about keeping pace, it’s about outpacing and about beating your competitor to the finish line. Innovation and partnership will help us do that.

Safeguarding the national and economic security of the United States is paramount to all of us. That’s why our organization values smart partnerships with fellow patriotic innovators in the private sector. Such partnerships promote greater exchanges of information, more efficient use of resources, and bring a broader range of expertise to problem solving. While our specific equities may differ, we can each say unequivocally that we all want the same thing fundamentally and we’re all on the same team. We all want to see the United States succeed and flourish and remain a global leader, all while reflecting the Western democratic ideals that we hold so dear. The private sector has always been America’s engine for innovation and change and it’s one of our greatest strengths as a nation.


Go beyond the headlines with expert perspectives on today’s news with The Cipher Brief’s Daily Open-Source Podcast.  Listen here or wherever you listen to podcasts.


Certainly, government and industry must be partners in innovation, but in the 21st century, technological innovation is mostly going to emerge from the private sector. Look no further than the artificial intelligence and machine learning realms where private sector innovation is helping us harness the power of data. More than any development in this fourth industrial revolution where the boundaries between the physical and digital worlds are blurring, artificial intelligence holds one of the keys to the future of espionage. It will help us manage this data tsunami at machine speed and will help free up humans for the higher order cognitive functions that are still only possible with the biological, not a digital brain.

In the artificial intelligence arena, the intelligence community must now learn how to be a fast follower with industry. They have to learn to not be the primary creators of cutting-edge technologies predominantly developed by the private sector. They must be fast followers. That’s why deep and sustainable partnerships with private industry and academia are so vital for the CIA and the intelligence community as a whole. They allow both sides to best serve America’s interests and adapt to these constantly changing waves of new technologies.

The DDI is taking steps to strengthen collaboration within the industry. One major component of our approach to industry partnerships is our creation of innovation hubs. We are focused on identifying best commercially available solutions, especially in the artificial intelligence and machine learning areas, and exploring how we can rapidly leverage these new solutions to mission problems. By working in an unclassified and collaborative laboratory space, our innovation hubs can bring new technologies to mission more rapidly, enable faster investment decisions about digital technologies, and ultimately reduce the time from ideas to solutions.

As I’ve said to our workforce on far too many occasions to count, I want us to get out of the U.S. government’s business of bringing yesterday’s technology to you tomorrow. Therefore, an enduring aspect of our mission as CIA’s digital Sherpas, is to stay informed of new commercial technologies and position CIA to be that fast follower with industry. This is why in 2017, we opened up CIA’s Silicon Valley Innovation Outpost which facilitates engagement with companies in the tech sector and academics in Silicon Valley. Just last year, during the pandemic, we launched the Northern Virginia Innovation Exchange, a space for knowledge sharing and problem solving where we work side by side with partners in industry.

Though I hate to admit it, despite our best efforts, we are a large government organization. And so we must address the impediments that stand in the way of bringing new technologies rapidly into the CIA; we’re working on that.

We’re working on speeding up our accreditation process, looking for new acquisition authorities, and doing as much as we can in the unclassified space where we can adopt new ideas and new solutions at a much more rapid pace. We’re engaging industry across the investment spectrum to leverage their expertise and knowledge of the marketplace and to promote a culture of continuous innovation in a large government organization that’s not hardwired to do that. Through outreach to companies and by working with Silicon Valley based accelerators, we are able to discover new technologies in the marketplace to meet our sometimes very unique mission needs in the CIA. It is pretty good progress in the first six years for an organization, but we are far from finished. Innovation is a process, it’s not an event. However, there is no finish line. The end of any innovation journey just signals the beginning of the next uncharted course. No one these days is flying kites in lightning storms, but that’s the type of entrepreneurial spirit that we’re seeking in our ranks. It’s the foundation I believe for our future as an agency and it’s a future that the DDI, as a transformative element of CIA in the digital age, eagerly embraces.

The challenges ahead are formidable, but with a whole of nation approach encouraging closer partnerships between government and industry, we can defend our values against those adversaries who wish us harm.

As for the DDI, we can accelerate the adoption of emerging digital technologies and integrate them with CIA’s traditional strengths in human intelligence and technical intelligence to counter threats to our nation and the shared interests of our allies around the world. Only one question remains for my team and CIA’s Directorate of Digital Innovation: if fortune indeed favors the bold, just how bold can they be? I have seen this amazing team in action, and I know that they will bring the fight to our adversaries across the digital landscape.

Jennifer Ewbank is Deputy Director for Digital Innovation at the CIA.  Her comments were made in late October at The Cipher Brief’s Annual Threat Conference.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

The post CIA Deputy for Digital Innovation Talks Mission, Partnerships and Espionage Challenges appeared first on The Cipher Brief.



from The Cipher Brief https://ift.tt/3rJZDhN
via IFTTT

https://pieces-auto-maroc1.blogspot.com/

 https://pieces-auto-maroc1.blogspot.com/