Beijing's costly plans for cybersecurity 'self-sufficiency'

A new government initiative means potentially quadrupling multibillion-dollar domestic spend.

Workers in a Chinese office.

Workers in a Chinese office.

Photo: Getty Images

Amid China's multipronged efforts to command and secure its wealth of data, as well as hacking allegations being flung between the country and an alliance of Western nations and bodies including the U.S., the EU, Japan and NATO, Chinese regulators have announced plans to grow the country's cybersecurity industry as much as fourfold within less than three years.

The draft plan, published July 12 by China's Ministry of Industry and Information Technology, aims to grow the industry to 250 billion yuan ($38.7 billion) by 2023, citing growing demand from emerging technologies including 5G, IoT, the industrial internet, smart vehicles and cities, cloud and AI, as well as sectors including manufacturing, natural resources, health care, consumer products, finance, transportation, education and more.

Strengthening China's cybersecurity industry would support the country's 2017 Cyber Security Law and last month's Data Security Law, as well as the 14th Five-Year Plan released in March, an economic blueprint that dedicated an entire section on digitizing the nation and making everything from factories to cities "smart."

An ambitious goal

According to the draft industry plan, by 2023 telecom and other "crucial sectors" must also dedicate at least 10% of their IT budgets to cybersecurity investments. While the MIIT did not disclose its valuation of the existing market, it said the target would be achieved with a compound annual growth rate of "more than 15%," suggesting its estimate of the industry at present is around $29 billion.

But MIIT statements contrast starkly with analyst projections. According to figures released in May by the IDC, China's domestic cybersecurity market is worth only $10.2 billion in 2021. By comparison, the U.S.'s is worth $65 billion this year. While the market research firm predicts a high average compound growth rate of 16.8% for China's sector, it would still reach just $14.4 billion by 2023, less than half of what MIIT is expecting.

According to Samm Sacks, a cyber policy fellow at think tank New America, the MIIT sometimes sets overly ambitious goals, especially if, as in this case, it's able to influence both supply and demand.

"The growth of the digital economy has driven demand for cyber security," she told Protocol. "On demand, the spate of cybersecurity regulations and standards mean companies need to buy products and services to be compliant and keep up with best practices. On the supply side, state R&D subsidies and tax breaks create incentives for new entrants."

Already, cybersecurity startups have sprung up in response to a combination of venture capital and state support, with some looking to unseat industry incumbents such as Qihoo 360 Technology Co. Ltd. and Kingsoft, Sacks added.

While the plan does not include additional concrete measures for achieving growth, it outlines the need to ramp up education, funding and industrial incentives on both the national and local levels. For example, the draft plan says, funds earmarked for upgrades in the manufacturing sector could be used to purchase cybersecurity products. MIIT is also tasking local governments with facilitating the creation of pilot zones and asking companies to invest and pool their resources, such as via industry consolidation.

The plan's brief mention of promoting international cooperation focuses on the establishment of overseas research centers, joint laboratories and conferences.

"In other words, the plan refers more to the absorption of technology by Chinese entities from overseas sources rather than welcoming foreign companies to become players … in China," said Lester Ross, a partner and head of the Beijing office of WilmerHale, an international law firm. "China is indeed intent upon the pursuit of self-sufficiency in this industry which it regards as intimately linked to national security."

The bigger picture

On Tuesday, Chinese Foreign Ministry spokesperson Zhao Lijian hit back against the U.S., calling it "the world's largest source of cyber attacks" after the Biden administration and allies including the EU, Australia, the U.K., Canada, New Zealand, Japan and NATO jointly accused China of being behind a massive hack of Microsoft Exchange email servers.

Meanwhile, China's public, private and foreign sectors are grappling with an emerging national data governance regime that has seen the country's tech giants in the crosshairs of regulators for alleged misuse of data.

Earlier this month, just days after ride-hailing giant DiDi's $4.4 billion U.S. IPO, Chinese authorities announced a probe into the company over its collection and use of personal data, pulling dozens of its apps from app stores, fueling speculation that the company had transferred sensitive information to the U.S. despite a lack of clear charges and evidence. Sources close to DiDi have denied wrongdoing.

In the days that followed, the Cyberspace Administration of China, the country's internet regulator, ordered so-called "cybersecurity reviews" for any company with 1 million users or more that wants to list overseas, something some observers say is motivated by concerns over national security risks posed by firms offering IT products and services.

And according to a June report by the Wall Street Journal, Ant Group is in discussions with state-owned firms to create a credit-scoring company, effectively conceding its vast troves of consumer data to regulators after years of resistance.

These developments underline a recent seismic shift in the government's approach to data, which it now considers an essential economic resource to be tapped as well as protected.

The fast-growing paychecks of Big Tech’s biggest names

Tech giants had a huge pandemic, and their execs are getting paid.

TIm Cook received $82 million in stock awards on top of his $3 million salary as Apple's CEO.

Photo: Mario Tama/Getty Images

Tech leaders are making more than ever.

As tech giants thrive amid the pandemic, companies like Meta, Alphabet and Microsoft have continued to pay their leaders accordingly: Big Tech CEO pay is higher than ever. In the coming months, we’ll begin seeing a lot of companies release their executive compensation from the past year as fiscal 2022 begins.

Keep Reading Show less
Nat Rubio-Licht
Nat Rubio-Licht is a Los Angeles-based news writer at Protocol. They graduated from Syracuse University with a degree in newspaper and online journalism in May 2020. Prior to joining the team, they worked at the Los Angeles Business Journal as a technology and aerospace reporter.

COVID-19 accelerated what many CEOs and CTOs have struggled to do for the past decade: It forced organizations to be agile and adjust quickly to change. For all the talk about digital transformation over the past decade, when push came to shove, many organizations realized they had made far less progress than they thought.

Now with the genie of rapid change out of the bottle, we will never go back to accepting slow and steady progress from our organizations. To survive and thrive in times of disruption, you need to build a resilient, adaptable business with systems and processes that will keep you nimble for years to come. An essential part of business agility is responding to change by quickly developing new applications and adapting old ones. IT faces an unprecedented demand for new applications. According to IDC, by 2023, more than 500 million digital applications and services will be developed and deployed — the same number of apps that were developed in the last 40 years.[1]

Keep Reading Show less
Denise Broady, CMO, Appian
Denise oversees the Marketing and Communications organization where she is responsible for accelerating the marketing strategy and brand recognition across the globe. Denise has over 24+ years of experience as a change agent scaling businesses from startups, turnarounds and complex software companies. Prior to Appian, Denise worked at SAP, WorkForce Software, TopTier and Clarkston Group. She is also a two-time published author of “GRC for Dummies” and “Driven to Perform.” Denise holds a double degree in marketing and production and operations from Virginia Tech.

Hybrid work has some distinct advantages when it comes to onboarding.

Photo: LogMeIn

Jo Deal is the chief human resources officer at LogMeIn. She is responsible for leading global people strategy with a focus on attracting, developing and engaging talent.

The desire for change that sprung up during the pandemic resulted in the highest attrition levels in decades and a fierce war for talent playing out in the market. The Great Resignation forced managers to suddenly make hiring their top priority, and recruitment partners became everyone’s best friend as leaders scrambled to replace key roles within their teams.

Keep Reading Show less
Jo Deal
Jo Deal serves as LogMeIn’s Chief Human Resources Officer. She is responsible for leading global people strategy with a focus on attracting, developing and engaging world class talent by expanding LogMeIn’s reputation as one of tech’s most desirable career destinations, and by providing a collaborative learning environment where employees can grow their careers.
Boost 2

Can Matt Mullenweg save the internet?

He's turning Automattic into a different kind of tech giant. But can he take on the trillion-dollar walled gardens and give the internet back to the people?

Matt Mullenweg, CEO of Automattic and founder of WordPress, poses for Protocol at his home in Houston, Texas.
Photo: Arturo Olmos for Protocol

In the early days of the pandemic, Matt Mullenweg didn't move to a compound in Hawaii, bug out to a bunker in New Zealand or head to Miami and start shilling for crypto. No, in the early days of the pandemic, Mullenweg bought an RV. He drove it all over the country, bouncing between Houston and San Francisco and Jackson Hole with plenty of stops in national parks. In between, he started doing some tinkering.

The tinkering is a part-time gig: Most of Mullenweg’s time is spent as CEO of Automattic, one of the web’s largest platforms. It’s best known as the company that runs, the hosted version of the blogging platform that powers about 43% of the websites on the internet. Since WordPress is open-source software, no company technically owns it, but Automattic provides tools and services and oversees most of the WordPress-powered internet. It’s also the owner of the booming ecommerce platform WooCommerce, Day One, the analytics tool and the podcast app Pocket Casts. Oh, and Tumblr. And Simplenote. And many others. That makes Mullenweg one of the most powerful CEOs in tech, and one of the most important voices in the debate over the future of the internet.

Keep Reading Show less
David Pierce

David Pierce ( @pierce) is Protocol's editorial director. Prior to joining Protocol, he was a columnist at The Wall Street Journal, a senior writer with Wired, and deputy editor at The Verge. He owns all the phones.


Peloton’s terrible, horrible, no good, very bad year

2022 just started, and Peloton has already halted bike production and is talking about mass layoffs. How did the pandemic darling get here?

How did Peloton go from pandemic star to sinking ship? One answer is the classic problem of supply and demand.

Image: Peloton; Protocol

It’s been a hell of a ride for Peloton. The headlines have been practically nonstop, from 2019’s cringey wife ad to 2021’s series of unfortunate “Sex and The City” events. But in 2020, Peloton could do no wrong. The at-home fitness company saw a 172% spike in sales over the course of that year, buoyed by the pandemic forcing wealthy gym-goers to stay home.

But nothing is ever easy or certain when it comes to Peloton. In the past week, Business Insider reported that Peloton is considering laying off 41% of its sales and marketing staff and closing down stores. CNBC learned that the company has hired McKinsey & Co. to help cut costs. And yesterday, CNBC reported that Peloton is temporarily halting production of its bikes. Peloton shares promptly plunged 24%.

Keep Reading Show less
Lizzy Lawrence

Lizzy Lawrence ( @LizzyLaw_) is a reporter at Protocol, covering tools and productivity in the workplace. She's a recent graduate of the University of Michigan, where she studied sociology and international studies. She served as editor in chief of The Michigan Daily, her school's independent newspaper. She's based in D.C., and can be reached at


Netflix looks to expand gaming with major IP deals, Fortnite-like updates

Remarks made to investors and recent job postings hint at big ambitions for Netflix’s nascent gaming efforts.

Netflix may be taking some cues from games like Fortnite and Apex: Legends for its own video game initiative.

Photo: Cameron Venti/Unsplash

Two months after launching mobile games to all of its members, Netflix is looking to double down on gaming: The company told investors Thursday that it wants to expand its portfolio of games “across both casual and core gaming genres.” Recent job offers suggest that this could include both live services games as well as an expansion to PC and console gaming, and the company's COO hinted at major licensing deals ahead.

Keep Reading Show less
Janko Roettgers

Janko Roettgers (@jank0) is a senior reporter at Protocol, reporting on the shifting power dynamics between tech, media, and entertainment, including the impact of new technologies. Previously, Janko was Variety's first-ever technology writer in San Francisco, where he covered big tech and emerging technologies. He has reported for Gigaom, Frankfurter Rundschau, Berliner Zeitung, and ORF, among others. He has written three books on consumer cord-cutting and online music and co-edited an anthology on internet subcultures. He lives with his family in Oakland.

Latest Stories