Aug 8th 2020

The Global Implications of China’s National and Cyber Security Laws

by Daniel Wagner

 

Daniel Wagner is CEO of Country Risk Solutions and author of the new book The Chinese Vortex: The Belt and Road Initiative and its Impact on the World.

 

The recent implementation of a new national security law in Hong Kong has brought to much of the world’s attention something that companies operating in  China have understood for years. The Chinese government’s 2015 National Security Law states that all information systems in China must be “secure and controllable”, which means that every company operating in China – whether domestic or foreign - is required to give the Chinese government their source code, encryption keys, and backdoor access to their computer networks in China. Hong Kong is just the tip of the iceberg. The Law has had profound implications for any Chinese company operating inside or outside of China, for their joint venture partners, and for foreign companies operating inside China.

In other words, businesses must hand the government the lifeblood of their companies and products, while also giving the CCP a free pass to spy on their networks. The Chinese government has arranged that, in order to do business in China, the information that Chinese agents once had to steal through cyberattacks are now automatically provided for the ‘privilege’ of doing business there. Incredibly, even the largest, best known, and most influential foreign companies that operate in China are doing just that.

A good example is IBM, which became the first major US tech company to agree to the new rules in 2015. IBM began delivering its technical knowledge to Chinese companies that had clearly stated their objective of replacing IBM’s markets in China. The company passed information about how to build its high-end servers and the software that runs the servers to Beijing-based Teamsun, which proudly declared its strategy to ‘absorb and then innovate’, enabling it to eliminate the capability gap between Chinese and American companies and create products that could replace those sold by companies in the US.[i]

That was not the first time IBM had done something similar. In 2014, the company sold its x86 server division to Chinese computer company Lenovo. The $2.1 billion sale included the x86 BladeCenter HT servers used in some critical US Navy systems, including its Aegis Combat System, which controlled the Navy‘s ballistic missile and air defense systems. When a business with products used in critical government and military networks reveals its code to another government, it becomes a national security issue.

The US Navy was subsequently forced to identify and purchase new servers, concerned that Chinese government agents could remotely access the systems by compromising routine maintenance. A vulnerability on Lenovo computers was subsequently discovered, which took advantage of the Lenovo System Update, leaving the door open for hackers. The servers were used by Navy assets, including its guided missile cruiser and destroyer fleets, and ballistic missile and anti-air defenses.[ii]

In 2015, Hewlett-Packard (HP) sold more than half of its networking and server operations to China, whose restrictions on foreign technology vendors pushed its banks, military, and major companies to stop buying foreign technology. HP gave up control of its then $4.5 billion business to remain in the Chinese market, selling 51% of its networking and server operations in the country to an arm of Beijing’s Tsinghua University.[iii] Presumably, the only reason HP was being allowed to remain at the time was because the Chinese government had not yet acquired what it perceived to be all of HP’s intellectual and material capital. That was 5 years ago. Multiply these examples exponentially and you begin to understand the implications of the National Security Law.

In 2017, China’s first Cybersecurity Law was enacted, which significantly increased compliance costs for multinationals, leaving them vulnerable to industrial espionage, and ultimately giving some Chinese companies an unfair advantage. While some aspects of the Law were welcomed as a milestone in much needed data privacy, it also had the effect of helping Beijing steal trade secrets and intellectual property from foreign companies. The Law is both extremely vague and exceptionally wide in scope, potentially putting companies at risk of regulatory enforcement that is not related to cybersecurity.

Among its key provisions are that:

 

·                All companies must undertake a security assessment before moving data out of China if it contains the personal information of more than half a million users or data is “likely to affect national security or social public interests”. That means that a ride sharing or food delivery service could therefore be labeled a national security risk;

 

·                “Critical infrastructure” companies must store “personal information and other important data” collected in China inside the country; and

 

·                “Important network products and services” must undergo a “national security review” before being sold in China (which is so vague that it could mean anything).

 

The Law is part of a drive by Beijing to shield Chinese data from the eyes of foreign governments. Under it, companies must introduce data protection measures—a novelty for many Chinese businesses—and data relating to the country’s citizens or national security must be held on Chinese servers. Companies must submit to a review by regulators before transferring large amounts of personal data abroad. “Critical” companies—whose designation encompasses sensitive entities such as power companies or banks, but also any company holding data that, if breached, could “harm people’s livelihoods”―must store all data collected in China within the country. These companies, and any services bought by them, must go through a “national security review” to ensure they and their data systems are “secure and controllable”.

The Law allows Beijing to demand access to computer program source code (usually known only by the software developer) and national security reviews may also permit China to delve even further into companies’ intellectual property.[iv] In conventional democracies, laws limit what companies may do with information and the extent to which governments can get their hands on it. China’s National Security and Cybersecurity Laws give the government unrestricted access to almost all personal and commercial data. The largest Chinese companies that hold data (such as Alibaba, Baidu, and Tencent) routinely obey government demands to access data.

The rest of the world’s companies and governments have to assume that any firm that is Chinese, operates in China, has access to Chinese citizens, whose information passes through China, or for which the Chinese government deems information relevant to national security is subject to these Laws, and that the government will do whatever is necessary to obtain the information they possess. That means that Huawei or any other firms that are owned or operated by Chinese private of public sector companies, or are otherwise answerable to Beijing, fall under the Laws’ guidelines from the government’s perspective.

It is time for the world’s governments and companies to wake up. Beijing’s reach is wide and deep. It is taking advantage of the West’s openness – and gaps and inconsistencies in our data protection protocols - to acquire information on all of us. The hacks on Anthem, Equifax, Marriott, and the US government are good examples of how they have already done so. American and Western companies need to take a hard look at the costs and benefits associated with operating in China and continuing to have Chinese partners. Those partners must comply with these Laws. American and Western companies that continue to operate with them may unwittingly well be aiding and abetting the Chinese government.

 

Daniel Wagner is CEO of Country Risk Solutions and author of the new book The Chinese Vortex: The Belt and Road Initiative and its Implications for the World.

This article first appeared in Diplomatic Courier.


[i] Philipp, Joshua, “CHINA SECURITY: IBM Shows Chinese Agents Its Source Code”, The Epoch Times, October 19, 2015, http://www.theepochtimes.com/n3/1881004-china-security-ibm-shows-chinese-agents-its-source-code/.

[ii] Philipp, Joshua, “US Navy Cruisers and Destroyers Look to Ditch Lenovo Servers”, The Epoch Times, May 7, 2015, http://www.theepochtimes.com/n3/1348839-us-navy-cruisers-and-destroyers-look-to-ditch-lenovo-servers/.

[iii] “HP Partners with Tsinghua to Create a Chinese Technology Powerhouse”, HP, May 21, 2015, http://www8.hp.com/us/en/hp-news/press-release.html?wireId=1950801#.WRxxM2jyvic.

[iv] Yuan Yang, “China’s Cyber Security Law Rattles Multinationals”, Financial Times, May 30, 2017, https://www.ft.com/content/b302269c-44ff-11e7-8519-9f94ee97d996.

 


This article is brought to you by the author who owns the copyright to the text.

Should you want to support the author’s creative work you can use the PayPal “Donate” button below.

Your donation is a transaction between you and the author. The proceeds go directly to the author’s PayPal account in full less PayPal’s commission.

Facts & Arts neither receives information about you, nor of your donation, nor does Facts & Arts receive a commission.

Facts & Arts does not pay the author, nor takes paid by the author, for the posting of the author's material on Facts & Arts. Facts & Arts finances its operations by selling advertising space.

 

 

Browse articles by author

More Current Affairs

Sep 24th 2020
EXTRACT: "China’s foreign minister, Wang Yi, recently declared that aggression and expansionism have never been in the Chinese nation’s “genes.” It is almost astonishing that he managed to say it with a straight face. Aggression and expansionism obviously are not genetic traits, but they have defined President Xi Jinping’s tenure. Xi, who in some ways has taken up the expansionist mantle of Mao Zedong, is attempting to implement a modern version of the tributary system that Chinese emperors used to establish authority over vassal states: submit to the emperor, and reap the benefits of peace and trade with the empire."
Sep 16th 2020
EXTRACT: "Seventy-five years ago, the prestige of the United States and the United Kingdom could not have been higher. They had defeated imperial Japan and Nazi Germany, and they did so in the name of freedom and democracy. True, their ally, Stalin’s Soviet Union, had different ideas about these fine ideals, and did most of the fighting against Hitler’s Wehrmacht. Still, the English-speaking victors shaped the post-war order in large parts of the world. The basic principles of this order had been laid down in the Atlantic Charter, drawn up in 1941 by Winston Churchill and President Franklin D. Roosevelt on a battleship off the coast of Newfoundland."
Sep 14th 2020
EXTRACT: "After Trump’s inauguration in January of 2017, millions demonstrated their disapproval. We can expect the same, no matter how this election turns out. With both sides framing this election in “end of the world” terms; with the president calling into question the legitimacy of the vote, even before it happens; and with the president warning his supporters that they may have to take up arms to defend him – we have a recipe for disaster that may occur in the days that follow this election. This may very well be the Armageddon election of our lifetime."
Sep 8th 2020
EXTRACT: "The Huawei case is a harbinger of a world in which national security, privacy, and economics will interact in complicated ways. Global governance and multilateralism will often fail, for both good and bad reasons. The best we can expect is a regulatory patchwork, based on clear ground rules that help empower countries to pursue their core national interests without exporting their problems to others. Either we design this patchwork ourselves, or we will end up, willy-nilly, with a messy, less efficient, and more dangerous version."
Sep 7th 2020
EXTRACT: "China’s footprint in global foreign direct investment (FDI) has increased notably since the launch of the Belt and Road Initiative (BRI) in 2013. That served to bring Chinese overseas FDI closer to a level that one would expect, based on the country’s weight in the global economy. China accounted for about 12% of global cross-border mergers and acquisitions and 9% of announced greenfield FDI projects between 2013 and 2018. Chinese overseas FDI rose from $10 billion in 2005 (0.5% of Chinese GDP) to nearly $180 billion in 2017 (1.5% of GDP). Likewise, annual construction contracts awarded to Chinese companies increased from $10 billion in 2005 to more than $100 billion in 2017."
Sep 2nd 2020
EXTRACT: "Emergence and spread of the coronavirus COVID-19 have created and still creating health issues, economic challenges, political crises and social conflicts around the world. These challenges and conflicts lead the international community to re-evaluate global governance and international structures, which is based on the second world-war and post-cold war. The pandemic will emerge a new era of international society that will not be similar to the pre-Corona world."
Aug 28th 2020
EXTRACT: "Russia has changed, and has been changing, since its beginnings in ancient Muscovy to its current condition as Putin’s realm. Some general features appear in much of Russian history. Most of its rulers have been authoritarian—but so, too, were most of England’s, France’s, and Germany’s. Many of its political and intellectual elites have considered Russia a special civilization deserving a place in the sun—but just as many have not, wanting to transform Russia into a Western state with Western values. Many Russians have been enamored of their country, but even more have probably damned it for destroying them and their children. What, then, is Russia? It is, and has always been, many, oftentimes contradictory, things—sometimes coexisting, sometimes getting the upper hand, always shifting, always eluding simplistic analysis. But, and this needs to be emphasized, the same holds true for every other country in the world."
Aug 26th 2020
EXTRACTS: "Double dips – defined simply as a decline in quarterly real GDP following a temporary rebound – have occurred in eight of the 11 recessions since the end of World War II. .............Financial markets aren’t the least bit worried about a relapse, owing largely to unprecedented monetary easing, which has evoked the time-honored maxim: “don’t fight the Fed.” Added comfort comes from equally unprecedented fiscal relief aimed at mitigating the pandemic-related shock to businesses and households.......This could be wishful thinking."
Aug 26th 2020
EXTRACTS: "There is no question that the re-election of President Donald Trump would endanger both the US and the world. Moreover, there is ample reason to fear that a close election could drive the US into a deep, prolonged constitutional crisis, and perhaps into civil violence.........One can only hope that the election will produce a decisive winner both in the Electoral College and in the popular vote. Yet, even then, tallying the final result may take time, owing to the massive increase in mail-in voting that is expected. Every ballot that has a postmark of November 2 or 3 (depending on the state) will be considered valid, which means that the final result will not be known until after Election Day. During that window of uncertainty, either or both campaigns may try to claim victory based on the current vote count. In any case, there is no chance that Trump will wait graciously in the Oval Office for days or weeks to receive the final tally. In interviews, he has already issued vague statements suggesting that he will not leave the White House if he loses; indeed, he seems to be actively preparing for such a scenario. If he follows through, the world’s leading superpower will find itself facing a protracted – and perhaps intractable – constitutional crisis.
Aug 26th 2020
EXTRACT: "the European Union is a community of values as much as an economic and trade bloc. But the behavior of member states such as Poland and Hungary has called into question their commitment to liberal democracy. Above all, in the US, President Donald Trump is widely criticized, even by lifelong Republicans, for not respecting or understanding the US constitution and the separation of the executive, legislative, and judicial branches. Does Trump even believe in democracy? Does he want all Americans to vote in November, regardless of race or party affiliation, or only those who will support him? And will he accept the election result if it goes against him? "
Aug 25th 2020
EXTRACT: "The fundamental difference in values between the West and China will remain indefinitely, and it is here that the West must draw the line. Any concession that entails a sacrifice of fundamental principles, for example in cultural matters, must be rejected. If this values-based approach results in economic disadvantages, so be it. By the same token, the West should abandon the conceit that it can push, force, or cajole China to become a democracy wrought in its own image. "
Aug 16th 2020
EXTRACT: "China is light years ahead of most of the rest of the world in deploying digital payment technology. Alipay or WeChat Pay apps are all that is necessary to accomplish almost anything that requires a payment in China; the country is largely already making paper money obsolete. "
Aug 15th 2020
EXTRACT: "Seven hundred fifty billion euros is less than 5% of the stock of US government debt held by the public. It’s a drop in the bucket, in other words. And a drop does not a liquid market in safe assets make. Even if this really is Europe’s “Hamiltonian moment,” ramping up EU issuance by a factor of 20 will take decades. "
Aug 14th 2020
EXTRACT: "But the race is not over. In the 2016 election, prices moved the most in the two months just before the election. Trump trailed Hillary Clinton in prediction markets throughout the campaign and was seen as favourite only on election day – showing that the underdog can recover. So despite Trump’s poor position now, he might still regain some ground."
Aug 11th 2020
EXTRACT: "Last year, in the midst of the country-wide protests against corruption, I was honored by a Lebanese humanitarian organization. I began my remarks paraphrasing Kahlil Gibran’s poem “You have your Lebanon, I have my Lebanon.” Like Gibran, I love the Lebanese people, their poetry, art, song, and love of life. I love their generous and welcoming spirit. I also love what Lebanon has given to the world – especially its gifted people. And I love the sheer beauty of the country – its majestic snow-capped mountains and its pristine seascapes. And, like Gibran, I do not love Lebanon’s petty bickering politicians who lead because of an accident of birth. Nor can I embrace the country’s system of sectarian privilege and the corruption that is endemic to the political-economic regime that has squeezed Lebanon dry to the benefit of their chosen ones. And I reject the armed militias, whether they be Christian, Muslim, or secular that in the past and in the present continue to torment those who challenge their dominance. I told the audience that the Lebanon I loved was in the streets making their voices heard demanding fundamental reform – an end to sectarianism, corrupt feudal elites, and rule by force of arms."
Aug 8th 2020
EXTRACT: "It is time for the world’s governments and companies to wake up. Beijing’s reach is wide and deep. It is taking advantage of the West’s openness – and gaps and inconsistencies in our data protection protocols - to acquire information on all of us. The hacks on Anthem, Equifax, Marriott, and the US government are good examples of how they have already done so. American and Western companies need to take a hard look at the costs and benefits associated with operating in China and continuing to have Chinese partners. Those partners must comply with these Laws. American and Western companies that continue to operate with them may unwittingly well be aiding and abetting the Chinese government."
Aug 5th 2020
EXTRACT: "James Murdoch is not the most obvious candidate for editorial heroism. His route to resigning from the News Corp board because of “disagreements over certain editorial content” has been circuitous and colourful."
Aug 4th 2020
EXTRACT: "Say what you will about the slippery slope the US government has been on since Trump came to power, America has a rich history of promoting creative thought, running head-first into particularly uncomfortable subjects, and encouraging robust debate internally and among its allies and partners. Once Trump leaves the scene, America is sure to be perceived as having briefly lost its senses and will come charging back into the mainstream of global thought, debate, and engagement. China has entered the global arena crippled by its own ideology. Ultimately, the US is better equipped to lead the world. It knows that, and so does most of the rest of the world. Someone had better tell Beijing."
Jul 29th 2020
EXTRACT: "The Chinese government has for years argued that its ‘nine-dash line’ of sovereignty over the entire Sea is based on centuries of maritime history, and that China’s claim is air tight. The Chinese Foreign Ministry has even asserted that ample historical documents and literature demonstrate that China was “the first country to discover, name, develop and exercise continuous, effective jurisdiction over the South China Sea islands”. "
Jul 23rd 2020
EXTRACTS: "Like many, I have long been critical of Europe’s Economic and Monetary Union as a dysfunctional currency area. Notwithstanding a strong political commitment to European unification as the antidote to a century of war and devastating bloodshed, there was always a critical leg missing from the EMU stool: fiscal union. Not anymore. The historic agreement reached on July 21 on a €750 billion ($868 billion) European Union recovery fund, dubbed Next Generation EU, changes that.................Unlike the United States, which appears to be squandering the opportunities presented by the epic COVID-19 crisis, Europe has risen to the occasion – and not for the first time."