Microsoft Executive Calls For Improved Information Sharing Between Governments and Companies
Brad Smith said information sharing is critical for preventative measures against cyberattacks.
Benjamin Kahn
WASHINGTON, September 20, 2021—Microsoft Vice Chair Brad Smith called for improved information sharing between countries to prevent cyberattacks on critical infrastructure.
While participating in a Washington Post Live discussion on September 20, Smith pointed toward certain sectors and aspects of society that should be protected from cyberwarfare. He specifically mentioned that a country’s digital supply chains, healthcare systems, and electoral processes should be considered off limits.
“I think the sobering fact of life is that unfortunately the world typically comes together to do what needs to be done only after it has experienced some kind [disaster],” he said.
“If we said we won’t harm civilians in a time of war, why should we for a moment, tolerate this kind of harm to civilians in what is supposed to be a time of peace?” Smith likened the SolarWinds attack to tampering with a blood supply to harm recipients.
A webinar in June hosted by the Stimson Center heard that a cybersecurity framework between countries is key to combatting cyberattacks.
Information sharing with private companies
In addition to reaffirming a commitment to not cause civilian harm, Smith also called for improving coordination and information sharing between private companies and stated that these efforts are enhanced by government leadership.
“I think any day when we’re sitting down and talking about how we can collaborate more closely among companies, that’s probably a good day.” Smith lauded efforts by the Biden Administration to facilitate information sharing between tech companies to prevent further attacks like the one SolarWinds suffered, “We are going to need a government that can work as a single well-coordinated team and the team is going to need to include participants in an appropriate way from the private sector as well. I’m hopeful, encouraged and I would dare say even optimistic.”
Last month, Comcast Cable’s chief product and information officer Noopur Davis said the private sector is falling behind on information sharing during cyberattacks, and that companies in the tech industry are reevaluating their strategies and how they share information to prevent such acts. Some have noted that companies are still not prioritizing cybersecurity.
Senator Angus King, I-Maine, has even called for new rules requiring companies to disclose when they’ve been breached in a hack.
Shortage of cybersecurity workforce
Smith noted, however, that there is still a lot of work that needs to be done. He described a “substantial shortage” of cybersecurity professionals, which he stated is one of the reasons organizations are not able to move quickly enough to keep pace with bad actors and implement best practices.
“There is a real opportunity for us to work together for community colleges to do more [and] for businesses to do more to train their people,” he said.
Overall, Smith stated that things are moving in the right direction but emphasized that the international community—governments and otherwise—need to establish better methods of federating data that is secure from bad actors but accessible to the necessary parties.