Executive Summary
While the proposed U.S. ban of the social media app TikTok may seem novel, its actually just the most recent high-profile incident in a string of cases of countries banning products or services over alleged cybersecurity concerns. The authors have studied more than 75 such events involving more than 31 countries going back almost 20 years. They suggest that the current trend should worry any business with an international scope, and suggest thatbusiness executives need to not only follow the best practices to improve the cybersecurity of their digital product and services, they must also prepare for political risks. Managers, as well as consumers, may encounter extreme disruptions to international trade.
Earlier this summer, the U.S. government announced it was considering banning Chinese social media apps, including the popular app TikTok. In August, President Trump signed two executive orders to block transactions with ByteDance, TikToks parent company, and Tencent, which owns the popular messaging service and commercial platform WeChat, andanother executive orderrequiring ByteDanceto sell or spin off its U.S. TikTok business within 90 days, as well as to destroy all its copies of TikTok data attached to U.S. users. As companies including Microsoft, Walmart, and Oracle have expressed interest in buying the app,TikTok is suing the U.S. government, accusing the Trump administration of depriving it of due process.
The proposed ban, according to the Trump administration, is intended to safeguard the privacy of U.S. citizens and shield data about them and government officials from the Chinese government. Trumps August 6 executive order claims TikTok could allow China to track the locations of Federal employees and contractors, build dossiers of personal information for blackmail, and conduct corporate espionage. But, is TikTok really a threat? And if it is, what are the possible consequences of these actions by the U.S.?
As researchers who have studied similar bans on technologies, we believe that this chain of events could have sweeping impacts on the business community, which will likely not be confined to the tech sector.
If data collection by a company with overseas connections comprises a threat, there are threats all around. The data that TikTok collects pales in comparison to, say, what most American tech companies (as well as banks, credit agencies, and hotels) collect, both visibly and less so. Many institutions that collect sensitive data have already been hacked it is estimated that there is a cyber attack every 39 seconds and much of that information is for sale on the Dark Web. If the Chinese government wanted the kind of information TikTok could collect, it could be obtained in many other ways.
What will likely prove a more pressing threat to U.S. customers is much more low-tech: Setting a precedent of banning everyday technologies could quickly spiral out of control and seriously disrupt almost all international trade.
While the case against TikTok may seem novel, its actually just the most recent high-profile incident in a string of cases of countries banning products or services over alleged cybersecurity concerns. In our research, we have studied more than 75 such events involving more than 31 countries going back almost 20 years, though most occurred in the past five years. For example, in 2017, Germany bannedMy Friend Carly a doll from the U.S. that you could talk to you because the conversation was processed by servers in the U.S. In 2016, Russia blocked access to LinkedIn, stating that LinkedIn refused to store personal data of Russian users in Russia. In 2017 U.S. blocked the Russian security company Kaspersky over its alleged ties to the Russian government.
These cases build on a trend of high-profile bans, such as when China blocked Facebook, Twitter, and Google (2009), and when BlackBerry was banned or threatened with a ban in India, Pakistan, Saudi Arabia, and United Arab Emirates (2010).
Because any product that contains a computer or service that uses a computer nowadays just about everything can introduce cybersecurity risks, the frequency and impact of these events is increasing. (My electronic toothbrush has a computer in it and is connected to the Internet.) Examining the millions of lines of software or firmware in these products and services is not currently feasible, therefore decisions are made based on the perceived risks, which can be impacted by factors such as trust and capability to manage cybersecurity risks. There have been restrictions imposed on products and services as diverse as: medical devices, videoconference services, software products, security software, social media, security cameras, banking IT systems, drones, smartphones, smart toys, online content services, satellite communications, AI software, and financial services such as international fund transfers and payment systems.
According to the Organization for Economic Cooperation and Developments Digital Trade Service Restrictiveness Index, 13 of the 46 majority economies have increased their digital trade restrictions between 2014 and 2019, while only four countries reduced their restrictions.
In general, there are four strategies for managing risks: accept, avoid, mitigate, and transfer. There aremany practical options that countries and companies can adopt to manage cybersecurity risks from cross-border digital products/services. Unfortunately, banning products is becoming increasingly common and doesnt appear to be a particularly sustainable strategy.
The proposed ban reinforces a growing belief that America is no longer the leading guarantor of global business, but rather a potential threat to it a notion that is profoundly reshaping the world economy and threatening American businesses. TikTok and WeChat both have massive user bases (800 million and close to 1.2 billion, respectively). Removing WeChat from the Apple Store could cause Apples iPhone sales to fall by around 30% according to one prominent analyst. In an August call with White House officials, more than a dozen major U.S. multinational companies raised concerns that banning WeChat could undermine their competitiveness in the Chinese market.
The second-order cost of sabotaging the international business environment with these policies could be much higher:86% of companies in the U.S.-China Business Council have reported experiencing negative impacts on their business with China. The biggest impact was lost sales because customers shift their suppliers or sourcing due to uncertainty of continued supply. Companies worried about a U.S. ban may just initiate aDe-Americanization plan to remove or replace U.S. components in their products and supply chains. For example, in February 2019, WorldFirst, a U.K-based international money transfer service that many big Amazon sellers relied on, closed its U.S. business as a precursor to its acquisition by Chinese-based Ant Financial. This was considered the only way to avoid U.S. regulators blocking the deal over national security concerns. On the other hand, the Chinese company Hikvision found alternatives to most of its U.S. components so that being added to the U.S. trade blacklist had a limited impact on its business.
Business executives need to realize that in addition to following the best practices to reduce the perceived cybersecurity risks from their digital product/services, preparing for political risks is also necessary. TikTok implemented several practices to mitigate the risks, including: storing U.S. user data in the U.S. and backing it up on Singaporean servers, blocking access to its data from its mother company ByteDance, hiring an American CEO and operations team, beefing up its lobbying team, withdrawing from Hong Kong based on the concerns over Chinas new national security law, launching a transparency center for moderation and data practices in Los Angeles, banning political and advocacy advertising from its platform, and setting up a global headquarters outside of China. TikTok and its employees are preparing to battle the ban in separate lawsuits.
Though these practices have not yet helped TikTok to void the ban, they will probably be major arguments in its lawsuit against the U.S. Furthermore, these practices may be important directions that all companies might need to follow for doing international business in the new normal to address concerns over cybersecurity risks.
In reality, banning is more likely to increase not reduce risk, because it builds up distrustamong countries and companies. Other countries may retaliate by banning U.S. companies and the situation could rapidly spiral.
In recent years, governments have tried to increase their ability to access the data contained on these devices and services. For example, WhatsApp advertises that it secures your conversations with end-to-end encryption, which means your messages and status updates stay between you and the people you choose. But, several times, most recently in October 2019, the U.S., UK and Australia have applied pressure on Facebook to create backdoors that would allow access to encrypted message content. So far, Facebook and WhatsApp have refused. If such backdoors are allowed and become commonplace, then every Internet-connected device will essentially be a spy device and likely be banned by every other country.
The abuse of national security threat is snowballing and leading to an escalating trade war that could disrupt world trade. We saw a similar situation caused by the Smoot-Hawley Tariffs in the 1930s. The goal was to protect U.S. farmers and other industries that were suffering during the Great Depression by raising tariffs and discouraging import of products from other countries. But, not surprisingly, almost all of the U.S. trade partners retaliated and raised their tariffs. That resulted in U.S. imports decreasing 66%and exports decreasing 61% making the Great Depression much greater. In general, there are rarely winners in trade wars, and probably not in cyber trade wars.
Acknowledgement: This research was supported, in part, by funds from the members of the Cybersecurity at MIT Sloan (CAMS) consortium and the MIT Internet Research Policy Initiative. Both authors contributed equally.
More:
The TikTok Ban Should Worry Every Company - Harvard Business Review
- Google researchers have cracked a key internet security tool - Recode [Last Updated On: February 26th, 2017] [Originally Added On: February 26th, 2017]
- Letter: Internet security is in jeopardy - INFORUM [Last Updated On: February 26th, 2017] [Originally Added On: February 26th, 2017]
- New internet security device launched to safeguard schools against child abuse - Phys.Org [Last Updated On: February 26th, 2017] [Originally Added On: February 26th, 2017]
- Everything You Need to Know About Cloudbleed, the Latest Internet Security Disaster - Gizmodo [Last Updated On: February 26th, 2017] [Originally Added On: February 26th, 2017]
- Data from internet-connected teddy bears held ransom, security expert says - Fox News [Last Updated On: February 28th, 2017] [Originally Added On: February 28th, 2017]
- Emsisoft Internet Security 2017.2.0.7219 - TechCentral.ie [Last Updated On: February 28th, 2017] [Originally Added On: February 28th, 2017]
- What you need to know about 'Cloudbleed,' the latest internet security bug - Globalnews.ca [Last Updated On: February 28th, 2017] [Originally Added On: February 28th, 2017]
- Google cracks longtime pillar of internet security - MarketWatch [Last Updated On: February 28th, 2017] [Originally Added On: February 28th, 2017]
- BullGuard | Internet Security and Antivirus protection ... [Last Updated On: March 2nd, 2017] [Originally Added On: March 2nd, 2017]
- Internet Storm Center - SANS Internet Storm Center [Last Updated On: March 2nd, 2017] [Originally Added On: March 2nd, 2017]
- Internet-connected 'smart' devices are dunces about security - ABC News [Last Updated On: March 11th, 2017] [Originally Added On: March 11th, 2017]
- Derry internet security expert warns that advanced internet technology 'a risk to us all' - Derry Now [Last Updated On: March 11th, 2017] [Originally Added On: March 11th, 2017]
- Firewall Test, Web Tools and Free Internet Security Audit ... [Last Updated On: March 11th, 2017] [Originally Added On: March 11th, 2017]
- Internet security in the spotlight: How is the internet safer today than it was 20 years ago? - Mobile Business Insights (blog) [Last Updated On: March 11th, 2017] [Originally Added On: March 11th, 2017]
- Jim Mullen: Unsocial internet security | Columnists | auburnpub.com - Auburn Citizen [Last Updated On: March 11th, 2017] [Originally Added On: March 11th, 2017]
- Internet security company launches a perfume line to promote cybersecurity - Mashable [Last Updated On: March 12th, 2017] [Originally Added On: March 12th, 2017]
- Internet security - Wikipedia [Last Updated On: March 12th, 2017] [Originally Added On: March 12th, 2017]
- Are you undermining your web security by checking on it with the wrong tools? - The Register [Last Updated On: March 18th, 2017] [Originally Added On: March 18th, 2017]
- Bruce Schneier on New Security Threats from the Internet of Things - Linux.com (blog) [Last Updated On: March 18th, 2017] [Originally Added On: March 18th, 2017]
- Carpe Diem: home internet security - KFOX El Paso [Last Updated On: March 18th, 2017] [Originally Added On: March 18th, 2017]
- Motivation Monday: home internet security - KFOX El Paso [Last Updated On: March 18th, 2017] [Originally Added On: March 18th, 2017]
- Medical records of 26m patients at risk because of GP surgeries' failing internet security - The Sun [Last Updated On: March 18th, 2017] [Originally Added On: March 18th, 2017]
- Free Internet Security | Why Comodo Internet Security Suite ... [Last Updated On: March 18th, 2017] [Originally Added On: March 18th, 2017]
- Internet Security Software | Trend Micro USA [Last Updated On: March 18th, 2017] [Originally Added On: March 18th, 2017]
- Fix crap Internet of Things security, booms Internet daddy Cerf - The Register [Last Updated On: March 21st, 2017] [Originally Added On: March 21st, 2017]
- Internet of Things security: What happens when every device is smart and you don't even know it? - ZDNet [Last Updated On: March 21st, 2017] [Originally Added On: March 21st, 2017]
- CUJO is cuter than Wall-E, and it's the only internet security device you'll ever need - Yahoo News [Last Updated On: March 21st, 2017] [Originally Added On: March 21st, 2017]
- The Senate just voted to undo landmark rules covering your Internet privacy - Washington Post [Last Updated On: March 25th, 2017] [Originally Added On: March 25th, 2017]
- What the Cloudbleed disaster says about the state of internet security - Information Age [Last Updated On: March 25th, 2017] [Originally Added On: March 25th, 2017]
- Google Has Declared Symantec Harmful To Internet Security - UPROXX [Last Updated On: March 25th, 2017] [Originally Added On: March 25th, 2017]
- Internet Security Analysts: North Korea Is Planning a Global Bank Heist - Breitbart News [Last Updated On: March 28th, 2017] [Originally Added On: March 28th, 2017]
- Internet Security Firm Confirms WikiLeaks 'Vault 7' At Least 40 Cyberattacks Tied to the CIA - The Ring of Fire Network [Last Updated On: April 14th, 2017] [Originally Added On: April 14th, 2017]
- Homeland Security warns of 'BrickerBot' malware that destroys unsecured internet-connected devices - ZDNet [Last Updated On: April 20th, 2017] [Originally Added On: April 20th, 2017]
- A Global Industry First: Industrial Internet Consortium and Plattform Industrie 4.0 to Host Joint IIoT Security ... - Business Wire (press release) [Last Updated On: April 20th, 2017] [Originally Added On: April 20th, 2017]
- Mucheru urges private sector to boost investment in internet security - The Standard (press release) [Last Updated On: April 25th, 2017] [Originally Added On: April 25th, 2017]
- Cloudflare debuts a security solution for IoT - TechCrunch [Last Updated On: April 28th, 2017] [Originally Added On: April 28th, 2017]
- Russian-controlled telecom hijacks financial services' Internet traffic - Ars Technica [Last Updated On: April 28th, 2017] [Originally Added On: April 28th, 2017]
- Avira Internet Security Suite v15.0.26 - TechCentral.ie [Last Updated On: April 28th, 2017] [Originally Added On: April 28th, 2017]
- NSA To Limit Some Collection Of Internet Communication - NPR [Last Updated On: April 29th, 2017] [Originally Added On: April 29th, 2017]
- Report Indicates '10 Concerts' Facebook Trend Could Compromise Your Internet Security - Complex [Last Updated On: April 29th, 2017] [Originally Added On: April 29th, 2017]
- "Improving the World" through Internet Security: Chatting with David Gorodyansky, CEO of AnchorFree - Huffington Post [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Don't Fall For This Tech Support Scam Targeting PC Users - KTLA [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Yikes! Antivirus Software Fails Basic Security Tests - Tom's Guide [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Watch Hackers Sabotage an Industrial Robot Arm - WIRED [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Decoding Internet Security: Spear phishing - Washington Post [Last Updated On: May 5th, 2017] [Originally Added On: May 5th, 2017]
- From the Desk of Jay Fallis: To internet vote, or not to internet vote - BarrieToday [Last Updated On: May 7th, 2017] [Originally Added On: May 7th, 2017]
- Crippling cyberattack continues to spread around the world - Los Angeles Times [Last Updated On: May 14th, 2017] [Originally Added On: May 14th, 2017]
- Cyber Security Experts: Russia Disproportionately Targeted by Malware - Voice of America [Last Updated On: May 14th, 2017] [Originally Added On: May 14th, 2017]
- The Latest: 29000 Chinese institutions hit by cyberattack - ABC News [Last Updated On: May 15th, 2017] [Originally Added On: May 15th, 2017]
- Cyberattack Aftershock Feared as US Warns of Its Complexity - New York Times [Last Updated On: May 15th, 2017] [Originally Added On: May 15th, 2017]
- This week's poll: Priorities for improving internet security - The Engineer [Last Updated On: May 18th, 2017] [Originally Added On: May 18th, 2017]
- Akamai Releases First Quarter 2017 State of the Internet / Security Report - PR Newswire (press release) [Last Updated On: May 18th, 2017] [Originally Added On: May 18th, 2017]
- Do Macs get viruses? - PC Advisor [Last Updated On: May 18th, 2017] [Originally Added On: May 18th, 2017]
- Massive Ransomware Attack Underscores Threats To Internet Security - Benzinga [Last Updated On: May 19th, 2017] [Originally Added On: May 19th, 2017]
- Security News This Week: Hoo-Boy, Mar-a-Lago's Internet Is Insecure - WIRED [Last Updated On: May 20th, 2017] [Originally Added On: May 20th, 2017]
- Internet security firm calls for law to compel information sharing to ... - The Star, Kenya [Last Updated On: May 22nd, 2017] [Originally Added On: May 22nd, 2017]
- Check It Out: No need to unplug after reading books on internet security - The Columbian [Last Updated On: May 22nd, 2017] [Originally Added On: May 22nd, 2017]
- How to beat security threats to 'internet of things' - BBC News - BBC News [Last Updated On: May 25th, 2017] [Originally Added On: May 25th, 2017]
- Best Mac antivirus 2017 - Macworld UK [Last Updated On: May 25th, 2017] [Originally Added On: May 25th, 2017]
- Avira, Kaspersky Top Windows 10 Antivirus Tests - Tom's Guide [Last Updated On: May 25th, 2017] [Originally Added On: May 25th, 2017]
- Paranoid about internet security? Here are the most secure OS options - The American Genius [Last Updated On: May 28th, 2017] [Originally Added On: May 28th, 2017]
- Blockchain Offers Hope for the Broken Internet - Fortune [Last Updated On: May 28th, 2017] [Originally Added On: May 28th, 2017]
- New uses for RFID and security for the internet of things - Phys.Org [Last Updated On: May 31st, 2017] [Originally Added On: May 31st, 2017]
- Security Best Practices for the Internet of Things - Web Host Industry Review [Last Updated On: May 31st, 2017] [Originally Added On: May 31st, 2017]
- Internet infrastructure security guidelines for Africa unveiled - Premium Times [Last Updated On: May 31st, 2017] [Originally Added On: May 31st, 2017]
- In addressing internet security issues, make sure to provide solutions - Minneapolis Star Tribune [Last Updated On: May 31st, 2017] [Originally Added On: May 31st, 2017]
- Whistic Partners with the Center for Internet Security to Extend the ... - PR Web (press release) [Last Updated On: June 1st, 2017] [Originally Added On: June 1st, 2017]
- Internet Security Alliance: NIST framework metrics should focus on threats - Inside Cybersecurity (subscription) [Last Updated On: June 1st, 2017] [Originally Added On: June 1st, 2017]
- China cyber-security law will keep citizens' data within the Great Firewall - The Register [Last Updated On: June 1st, 2017] [Originally Added On: June 1st, 2017]
- Cyber security: Africa gets Internet security guidelines - TheNewsGuru [Last Updated On: June 1st, 2017] [Originally Added On: June 1st, 2017]
- China to Implement Its First Law on Internet Security After Ransomware Attack - Sputnik International [Last Updated On: June 1st, 2017] [Originally Added On: June 1st, 2017]
- Decoding Internet Security: Ransomware - Washington Post [Last Updated On: June 1st, 2017] [Originally Added On: June 1st, 2017]
- Internet security upgrade on course - Business Daily (press release) (blog) [Last Updated On: June 1st, 2017] [Originally Added On: June 1st, 2017]
- What's the Safest Laptop For Internet Security? - HuffPost [Last Updated On: June 2nd, 2017] [Originally Added On: June 2nd, 2017]
- Every Day Is Internet Security Day - The Chief-Leader [Last Updated On: June 3rd, 2017] [Originally Added On: June 3rd, 2017]
- 5 Reasons why internet security is crucial in 2017 - Techworm [Last Updated On: June 3rd, 2017] [Originally Added On: June 3rd, 2017]
- Are Pop-Ups An Internet Security Threat? - Good Herald [Last Updated On: June 4th, 2017] [Originally Added On: June 4th, 2017]
- 3 Ways Software Programs Can Help With Internet Security in 2017 - Geek Snack [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]
- Inside Social Security: Make every day your internet security day - Santa Ynez Valley News [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]
- SOCIAL SECURITY: Every day is internet security day - Palm Beach Post [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]