Skip to content
NUPI skole

Researcher

Lars Gjesvik

Senior Research Fellow
Lars_Gjesvik_11.jpg

Contactinfo and files

larsg@nupi.no
+47 46427736
Original image

Summary

Lars Gjesvik is a senior researcher in the Research Group for Security and Defence at NUPI, where he also serves as the co-leader of the research center for digitization and cyber security. His research focuses on the intersection of private enterprise and state interests, security challenges, and power politics related to digitalization and emerging technologies.

He recently obtained his doctorate from the University of Oslo (in 2023), where he studied the interaction between private companies and state interests in the digital space, and the role of technology companies in shaping international politics. Gjesvik's expertise also includes issues related to the global surveillance industry, digital infrastructure such as submarine internet cables and cloud services, cyber security, and technology dependency.

In his previous work, Gjesvik has addressed national approaches to cyber security and public-private cooperation, as well as disinformation and influence campaigns

Expertise

  • Cyber
  • Security policy
  • International economics
  • Trade
  • Globalisation
  • Foreign policy

Aktivitet

Publications
Publications
Scientific article

Avskrekke hvem? Betydningen av strategisk kultur for cybersikkerhet

There is an ongoing debate in academia about if and how deterrence theory may be used in cyberspace. Deterrence was originally a theory developed for avoiding conventional and nuclear war. In the current discussion on cyber security, there has been pointed out a range of technical problems of transferring a theory about the physical world to cyberspace. We recognize these challenges of deterrence in cyberspace, but in this article we want to shed light on a different aspect of deterrence. That is the interplay between social and technical factors of deterrence in cyberspace. In this article we will discuss how deterrence as a strategy in cyberspace is influenced by the specific strategic culture of a country. We will use China as a case study to showcase our argument. Contrasts between Chinese and “Western” strategic culture results in concrete differences in how Chinese and Western countries act in cyberspace. By utilizing four components of deterrence theory (denial, punishment, entanglement and norms), we will show how an in-depth knowledge of a state’s security policy and strategic culture may be used to tailor a more effective deterrence and enforce the capacity of hindering unwanted activity.

  • Security policy
  • Cyber
  • Security policy
  • Cyber
Publications
Publications
Report

Critical communication infrastructures and Huawei

Recently, there have been growing cyber-safety concerns over telecom equipment made by the Chinese vendor Huawei. This has led many countries to ban Huawei from supplying equipment for building the next generation of mobile networks, 5G. Responses from mobile operators and the telecom community in general have been mixed. For instance, many European mobile operators have stated that these concerns are overblown and that such a ban would delay 5G rollout by two to three years in the best case. Moreover, some operators have directly questioned the ability of the other vendors to timely deliver a complete 5G network. However, these claims have mostly not been grounded in empirical data. This paper takes a multi-perspective approach to investigating this problem empirically. We start by categorizing responses from different countries to using Huawei equipment in 5G. We then analyze the importance and readiness of Huawei for supplying 5G equipment. This analysis is based on contributions to standards and patents. We also present a conceptual risk analysis framework to qualitatively evaluate the ability of a single vendor to cause considerable damage to critical communication infrastructures. This model aims at exploring a set of relevant axis. More specifically, we look at potential for harm in different political climates that is peace, crisis and war. Another axis is whether banning a particular vendor from supplying equipment for the upcoming mobile networks generation is useful without having a backward compatible ban. A third axis is the ability of a vendor to cause harm as a function of the type of supplied equipment, for example radio towers vs network management systems. Combining the analysis of readiness for supplying 5G and potential for causing harm allows us to roughly estimate the likely impact that a complete ban would have on 5G rollout in different parts of the world. We find that such a ban can possibly delay 5G by two years or more for operators with high dependence on Huawei. Consequently, we explore potential approaches that would both reduce vendor-related risk and do not significantly delay the rollout of 5G. These include heterogeneous multi-vendor deployments, equipment verification and testing, international collaboration as well as signing non-aggression treaties. Unfortunately, there is no technological solution that fully remedy this problem. Combining technical solutions with efforts to build trust between countries, enforce existing alignments or create new ones seems a promising way forward.

  • Security policy
  • Cyber
  • Foreign policy
  • Security policy
  • Cyber
  • Foreign policy
Bildet viser de nordiske landene sine flagg
Research Project
2018 - 2019 (Completed)

The Nordics and the International

Why is there not more Nordic cooperation on the international arena, when Nordic politicians so often express a willingness to develop cooperation in this field further? This project a...

  • Defence
  • Security policy
  • NATO
  • Foreign policy
  • The Nordic countries
  • International organizations
  • The EU
  • United Nations
  • Defence
  • Security policy
  • NATO
  • Foreign policy
  • The Nordic countries
  • International organizations
  • The EU
  • United Nations
Publications
Publications
Report

Comparing Cyber Security. Critical Infrastructure protection in Norway, the UK and Finland.

Cyber security and protecting critical infrastructures from digital harm are of increasing importance for governments around the globe. Tackling this issue is challenged by two distinct features of cyber security in Western states: Firstly, the transnational nature of digital risks and threats necessitates cooperation and engagements beyond the state, through international and regional organizations and institutions. Secondly, the considerable extent of private ownership forces states to rely on and engage with private companies, through regulation or public–private partnerships (PPP). Through comparative analysis of the approaches taken to PPP and European cooperation for energy and telecommunication in Finland, Norway and the UK, this report examines how states engage with these issues. The greatest difference is found to lie between the two Nordic states and the UK. This is not the result of divergent national perceptions and understandings, but of the more centralized and intelligence-centred approach taken by the UK in contrast to the whole-of-society trust-based approach of the Nordic states. Both approaches entail distinct benefits and drawbacks. The major concern in the Nordic states is the lack of public resources and capacity, as well as the fragmentation of responsibility and capabilities. Realizing the importance of culture, context and history in shaping how public authorities respond to cyber-security concerns is of vital importance for enabling better policies. This report concludes by presenting a set of best practices identified in the three case countries.

  • Security policy
  • Cyber
  • Europe
  • Security policy
  • Cyber
  • Europe
Publications
Publications
Report

Ten Years On: Reassessing the Stoltenberg Report on Nordic Cooperation

Ten years ago, the report ‘Nordic cooperation on foreign and security policy’ was presented to the Nordic foreign ministers at an extraordinary meeting in Oslo, Norway. Penned and fronted by Norway’s former foreign minister Thorvald Stoltenberg, the report proposed thirteen ways in which Nordic cooperation in the foreign and security domain could be formalized and strengthened. Generally well-received in the Nordic capitals, today, the report is regularly referred to in assessments of Nordic foreign and security cooperation, or when Nordic heads of government meet in public to discuss past and future accomplishments.

Research project
2019 - 2022 (Completed)

Digital sovereignty and autonomy (GAIA)

NUPI in collaboration with Simula Research Lab will map global data flows and their impact on national autonomy and sovereignty. ...

  • Security policy
  • Cyber
  • Diplomacy
  • Governance
  • International organizations
  • Security policy
  • Cyber
  • Diplomacy
  • Governance
  • International organizations
Research project
2019 (Completed)

Protecting Democracies from Digital Threats (PRODEM)

How are states responding to the threat of using digital technologies to subvert democratic processes? ...

  • Defence
  • Security policy
  • Cyber
  • Conflict
  • Defence
  • Security policy
  • Cyber
  • Conflict
Research project
2018 - 2019 (Completed)

Critical Digital Infrastructures (KRIDI)

Protecting critical infrastructures from digital threats is a key challenge for modern states, how should the state approach and make sense of the security of privately owned infrastru...

  • Security policy
  • Cyber
  • Conflict
  • Security policy
  • Cyber
  • Conflict
Publications
Publications
Scientific article

China's notion of cybersecurity: The importance of strategic cultures for cyber deterrence

This paper debates the importance of different strategic cultures in cyberspace through the example of China. More than any other form of security cyber security is interpreted and acted on differently by different states. While the idea that the Internet would be a liberalizing force throughout the globe was dominant for a long time, over the last few years it has become evident that states have different interpretations and values attached to Information and Communication Technologies (ICT). These differences in valuation in turns leads to different conceptualizations of cyber security, giving the term different meanings for different actors. As states disagree over what cyber security is, they are also likely to disagree on how it is to be achieved. This paper evaluates the impact of these differences in light of a frequently used concept in security studies, namely that of deterrence.

  • Cyber
  • Asia
  • Cyber
  • Asia
Publications
Publications
Scientific article

The Chinese Cyber Sovereignty Concept (Part 1 & 2)

Cyber sovereignty is a distinct concept from the more familiar term cybersecurity, which concerns protecting the infrastructure and processes connected to the Internet. Cyber sovereignty, on the other hand, is concerned with the information and content the Internet provides. China’s cyber sovereignty concept is based on two key principles: The first is that unwanted influence in a country’s “information space” should be banned. In effect, this would allow countries to prevent their citizens from being exposed to ideas and opinions deemed harmful by the regime. The other key principle is to move the governance of the Internet from the current bodies, which includes in them academics and companies, to an international forum such as the UN. This move would also entail a transfer of power from companies and individuals to states alone.

  • Security policy
  • Cyber
  • Asia
  • Security policy
  • Cyber
  • Asia
41 - 50 of 57 items