Beijing's costly plans for cybersecurity 'self-sufficiency'

A new government initiative means potentially quadrupling multibillion-dollar domestic spend.

Workers in a Chinese office.

Workers in a Chinese office.

Photo: Getty Images

Amid China's multipronged efforts to command and secure its wealth of data, as well as hacking allegations being flung between the country and an alliance of Western nations and bodies including the U.S., the EU, Japan and NATO, Chinese regulators have announced plans to grow the country's cybersecurity industry as much as fourfold within less than three years.

The draft plan, published July 12 by China's Ministry of Industry and Information Technology, aims to grow the industry to 250 billion yuan ($38.7 billion) by 2023, citing growing demand from emerging technologies including 5G, IoT, the industrial internet, smart vehicles and cities, cloud and AI, as well as sectors including manufacturing, natural resources, health care, consumer products, finance, transportation, education and more.

Strengthening China's cybersecurity industry would support the country's 2017 Cyber Security Law and last month's Data Security Law, as well as the 14th Five-Year Plan released in March, an economic blueprint that dedicated an entire section on digitizing the nation and making everything from factories to cities "smart."

An ambitious goal

According to the draft industry plan, by 2023 telecom and other "crucial sectors" must also dedicate at least 10% of their IT budgets to cybersecurity investments. While the MIIT did not disclose its valuation of the existing market, it said the target would be achieved with a compound annual growth rate of "more than 15%," suggesting its estimate of the industry at present is around $29 billion.

But MIIT statements contrast starkly with analyst projections. According to figures released in May by the IDC, China's domestic cybersecurity market is worth only $10.2 billion in 2021. By comparison, the U.S.'s is worth $65 billion this year. While the market research firm predicts a high average compound growth rate of 16.8% for China's sector, it would still reach just $14.4 billion by 2023, less than half of what MIIT is expecting.

According to Samm Sacks, a cyber policy fellow at think tank New America, the MIIT sometimes sets overly ambitious goals, especially if, as in this case, it's able to influence both supply and demand.

"The growth of the digital economy has driven demand for cyber security," she told Protocol. "On demand, the spate of cybersecurity regulations and standards mean companies need to buy products and services to be compliant and keep up with best practices. On the supply side, state R&D subsidies and tax breaks create incentives for new entrants."

Already, cybersecurity startups have sprung up in response to a combination of venture capital and state support, with some looking to unseat industry incumbents such as Qihoo 360 Technology Co. Ltd. and Kingsoft, Sacks added.

While the plan does not include additional concrete measures for achieving growth, it outlines the need to ramp up education, funding and industrial incentives on both the national and local levels. For example, the draft plan says, funds earmarked for upgrades in the manufacturing sector could be used to purchase cybersecurity products. MIIT is also tasking local governments with facilitating the creation of pilot zones and asking companies to invest and pool their resources, such as via industry consolidation.

The plan's brief mention of promoting international cooperation focuses on the establishment of overseas research centers, joint laboratories and conferences.

"In other words, the plan refers more to the absorption of technology by Chinese entities from overseas sources rather than welcoming foreign companies to become players … in China," said Lester Ross, a partner and head of the Beijing office of WilmerHale, an international law firm. "China is indeed intent upon the pursuit of self-sufficiency in this industry which it regards as intimately linked to national security."

The bigger picture

On Tuesday, Chinese Foreign Ministry spokesperson Zhao Lijian hit back against the U.S., calling it "the world's largest source of cyber attacks" after the Biden administration and allies including the EU, Australia, the U.K., Canada, New Zealand, Japan and NATO jointly accused China of being behind a massive hack of Microsoft Exchange email servers.

Meanwhile, China's public, private and foreign sectors are grappling with an emerging national data governance regime that has seen the country's tech giants in the crosshairs of regulators for alleged misuse of data.

Earlier this month, just days after ride-hailing giant DiDi's $4.4 billion U.S. IPO, Chinese authorities announced a probe into the company over its collection and use of personal data, pulling dozens of its apps from app stores, fueling speculation that the company had transferred sensitive information to the U.S. despite a lack of clear charges and evidence. Sources close to DiDi have denied wrongdoing.

In the days that followed, the Cyberspace Administration of China, the country's internet regulator, ordered so-called "cybersecurity reviews" for any company with 1 million users or more that wants to list overseas, something some observers say is motivated by concerns over national security risks posed by firms offering IT products and services.

And according to a June report by the Wall Street Journal, Ant Group is in discussions with state-owned firms to create a credit-scoring company, effectively conceding its vast troves of consumer data to regulators after years of resistance.

These developments underline a recent seismic shift in the government's approach to data, which it now considers an essential economic resource to be tapped as well as protected.


Judge Zia Faruqui is trying to teach you crypto, one ‘SNL’ reference at a time

His decisions on major cryptocurrency cases have quoted "The Big Lebowski," "SNL," and "Dr. Strangelove." That’s because he wants you — yes, you — to read them.

The ways Zia Faruqui (right) has weighed on cases that have come before him can give lawyers clues as to what legal frameworks will pass muster.

Photo: Carolyn Van Houten/The Washington Post via Getty Images

“Cryptocurrency and related software analytics tools are ‘The wave of the future, Dude. One hundred percent electronic.’”

That’s not a quote from "The Big Lebowski" — at least, not directly. It’s a quote from a Washington, D.C., district court memorandum opinion on the role cryptocurrency analytics tools can play in government investigations. The author is Magistrate Judge Zia Faruqui.

Keep ReadingShow less
Veronica Irwin

Veronica Irwin (@vronirwin) is a San Francisco-based reporter at Protocol covering fintech. Previously she was at the San Francisco Examiner, covering tech from a hyper-local angle. Before that, her byline was featured in SF Weekly, The Nation, Techworker, Ms. Magazine and The Frisc.

The financial technology transformation is driving competition, creating consumer choice, and shaping the future of finance. Hear from seven fintech leaders who are reshaping the future of finance, and join the inaugural Financial Technology Association Fintech Summit to learn more.

Keep ReadingShow less
The Financial Technology Association (FTA) represents industry leaders shaping the future of finance. We champion the power of technology-centered financial services and advocate for the modernization of financial regulation to support inclusion and responsible innovation.

AWS CEO: The cloud isn’t just about technology

As AWS preps for its annual re:Invent conference, Adam Selipsky talks product strategy, support for hybrid environments, and the value of the cloud in uncertain economic times.

Photo: Noah Berger/Getty Images for Amazon Web Services

AWS is gearing up for re:Invent, its annual cloud computing conference where announcements this year are expected to focus on its end-to-end data strategy and delivering new industry-specific services.

It will be the second re:Invent with CEO Adam Selipsky as leader of the industry’s largest cloud provider after his return last year to AWS from data visualization company Tableau Software.

Keep ReadingShow less
Donna Goodison

Donna Goodison (@dgoodison) is Protocol's senior reporter focusing on enterprise infrastructure technology, from the 'Big 3' cloud computing providers to data centers. She previously covered the public cloud at CRN after 15 years as a business reporter for the Boston Herald. Based in Massachusetts, she also has worked as a Boston Globe freelancer, business reporter at the Boston Business Journal and real estate reporter at Banker & Tradesman after toiling at weekly newspapers.

Image: Protocol

We launched Protocol in February 2020 to cover the evolving power center of tech. It is with deep sadness that just under three years later, we are winding down the publication.

As of today, we will not publish any more stories. All of our newsletters, apart from our flagship, Source Code, will no longer be sent. Source Code will be published and sent for the next few weeks, but it will also close down in December.

Keep ReadingShow less
Bennett Richardson

Bennett Richardson ( @bennettrich) is the president of Protocol. Prior to joining Protocol in 2019, Bennett was executive director of global strategic partnerships at POLITICO, where he led strategic growth efforts including POLITICO's European expansion in Brussels and POLITICO's creative agency POLITICO Focus during his six years with the company. Prior to POLITICO, Bennett was co-founder and CMO of Hinge, the mobile dating company recently acquired by Match Group. Bennett began his career in digital and social brand marketing working with major brands across tech, energy, and health care at leading marketing and communications agencies including Edelman and GMMB. Bennett is originally from Portland, Maine, and received his bachelor's degree from Colgate University.


Why large enterprises struggle to find suitable platforms for MLops

As companies expand their use of AI beyond running just a few machine learning models, and as larger enterprises go from deploying hundreds of models to thousands and even millions of models, ML practitioners say that they have yet to find what they need from prepackaged MLops systems.

As companies expand their use of AI beyond running just a few machine learning models, ML practitioners say that they have yet to find what they need from prepackaged MLops systems.

Photo: artpartner-images via Getty Images

On any given day, Lily AI runs hundreds of machine learning models using computer vision and natural language processing that are customized for its retail and ecommerce clients to make website product recommendations, forecast demand, and plan merchandising. But this spring when the company was in the market for a machine learning operations platform to manage its expanding model roster, it wasn’t easy to find a suitable off-the-shelf system that could handle such a large number of models in deployment while also meeting other criteria.

Some MLops platforms are not well-suited for maintaining even more than 10 machine learning models when it comes to keeping track of data, navigating their user interfaces, or reporting capabilities, Matthew Nokleby, machine learning manager for Lily AI’s product intelligence team, told Protocol earlier this year. “The duct tape starts to show,” he said.

Keep ReadingShow less
Kate Kaye

Kate Kaye is an award-winning multimedia reporter digging deep and telling print, digital and audio stories. She covers AI and data for Protocol. Her reporting on AI and tech ethics issues has been published in OneZero, Fast Company, MIT Technology Review, CityLab, Ad Age and Digiday and heard on NPR. Kate is the creator of and is the author of "Campaign '08: A Turning Point for Digital Media," a book about how the 2008 presidential campaigns used digital media and data.

Latest Stories