Going Through a Rough Patch: Danish and Norwegian Coping Strategies in the Transatlantic Relationship
Paper presentation at CAST Research Seminar on Nordic Security Policy.
Surveillance Technology at the Fair: Proliferation of Cyber Capabilities in International Arms Markets
State cyber capabilities are increasingly abiding by the “pay-to-play” model—both US/NATO allies and adversaries can purchase interception and intrusion technologies from private firms for intelligence and surveillance purposes. NSO Group has repeatedly made headlines in 2021 for targeting government entities in cyberspace, but there are many more companies selling similar products that are just as detrimental. These vendors are increasingly looking to foreign governments to hawk their wares, and policymakers have yet to sufficiently recognize or respond to this emerging problem. Any cyber capabilities sold to foreign governments carry a risk: these capabilities could be used against individuals and organizations in allied countries, or even in one’s home country. Because much of this industry operates in the shadows, research into the industry in aggregate is rare. This paper analyzes active providers of interception/intrusion capabilities within the international surveillance market, cataloguing firms that have attended both ISSWorld (i.e., the Wiretapper’s Ball) and international arms fairs over the last twenty years.1 This dataset mostly focuses on Western firms and includes little on Chinese firms, due to historical under-attendance of Chinese firms at ISSWorld. However, the overarching nature of this work will help policymakers better understand the market at large, as well as the primary arms fairs at which these players operate. This paper identifies companies explicitly marketing interception/intrusion technology at arms fairs, and answers a series of questions, including: what companies are marketing interception/intrusion capabilities outside their headquartered region; which arms fairs and countries host a majority of these firms; and what companies market interception/intrusion capabilities to US and NATO adversaries? The resulting dataset shows that there are multiple firms headquartered in Europe and the Middle East that the authors assess, with high confidence, are marketing cyber interception/intrusion capabilities to US/NATO adversaries. They assume that companies offering interception/intrusion capabilities pose the greatest risk, both by bolstering oppressive regimes and by the proliferation of strategic capabilities.2 Many such firms congregate at Milipol France, Security & Policing UK, and other arms fairs in the UK, Germany, Singapore, Israel, and Qatar. The authors found that 75 percent of companies likely selling interception/intrusion technologies have marketed these capabilities to governments outside their home continent. Five irresponsible proliferators—BTT, Cellebrite, Micro Systemation AB, Verint, and Vastech—have marketed their capabilities to US/NATO adversaries in the last ten years.3 This paper categorizes these companies as potentially irresponsible proliferators because of their willingness to market outside their continents to nonallied governments of the United States and NATO—specifically, Russia and China.4 By marketing to these parties, these firms signal that they are willing to accept or ignore the risk that their products will bolster the capabilities of client governments that might wish to threaten US/NATO national security or harm marginalized populations. This is especially the case when the client government is a direct US or NATO adversary. This globalizing shift is important for two reasons. First, it indicates a widening pattern of proliferation of cyber capabilities across the globe. Second, many firms in the surveillance and offensive cyber capabilities markets have long argued for the legitimacy of their business model by pointing to the perceived legitimacy of their customers; yet, their marketing strategies contradict this argument. As the recent indictment of several former US intelligence personnel working for the United Arab Emirates (UAE) confirms, capabilities originally focusing on one target set may be expanded for other intelligence uses.5 When these firms begin to sell their wares to both NATO members and adversaries, it should provoke national security concerns for all customers. This paper profiles these important trends for their practical security impacts, and to enable further research into this topic. The authors suggest that the United States and NATO create know-your-customer (KYC) policies with companies operating in this space; work with arms fairs to limit irresponsible proliferators’ attendance at these events; tighten export-control loopholes; and name and shame both irresponsible vendors and customers. The authors encourage policymakers to focus their efforts to rein in companies that sell these capabilities directly to adversaries, or those willing to ignore the risk that their capabilities may be misused. The dataset presented below is open for use by others who might similarly seek to bring some measure of light to an industry that remains so insistently in the dark.
Norden og alliansene: Sikkerhetspolitisk debatt og veivalg i 2021
Presentation of findings from the research project "Norden and the alliances".
Line Marie Breistrand
Line Marie Breistrand was a doctoral student at NUPI, working with China in international politics. In her doctoral project, she analyzes China's...
Rolf Tamnes
Professor Rolf Tamnes is a member of NUPI’s Research Group on Security and Defence. Tamnes holds a dr.philos (PhD) from 1991 and a cand.philol. (...
Psykisk helse, terrorisme, ekstremisme og radikalisering
The possible connection between mental health, radicalisation, extremism, and involvement of terror has received a lot of attention as of late. But what do we really know about this connection? What are we unaware of, and how can challenges related to this be handled? This policy brief goes through these questions and gives the knowledge status in this domain a clean-up.
Ad Hoc Crisis Response and International Organisations (ADHOCISM)
International organisations (IOs) are created with the aim of solving collective action problems when a crisis arises. Yet, member states have repeatedly established ad hoc crisis responses in situations where IOs might be expected to play a central role. ADHOCISM asks what is the impact of ad hoc crisis responses on international organisations? In this way, ADHOCISM wants to contribute to filling this knowledge gap through a systematic study of ad hoc crisis responses in two policy domains: security and health. With this paired comparison, ADHOCISM wants to tap into a broader empirical governance phenomenon. Ad hoc crisis responses are here understood as loose groups of actors that agree to solve a particular crisis at a given time and location outside of an existing international organisation in the same policy domain. Ad hoc crisis reponses can, in the short-term, lead to more rapid and effective crisis responses among like-minded states, but if international organisations are no longer seen as the principal instruments to confront global challenges, the risk is also that the relevance of these international organisations will diminish, and similar trends may unfold in other domains.
Anne Funnemark
Anne Funnemark was a Junior Research Fellow at NUPI. She was a part of the Climate-related Peace and Security Risks (CPSR) project and the MCDC Cl...
Huawei, 5G and Security: Technological Limitations and Political Responses
How did Chinese 5G providers, such as Huawei, become a security concern in the USA and Europe? Were the security concerns related to 5G and Chinese suppliers based upon technological features of the systems, or were they a product of geopolitical rivalry? How did European approaches to 5G distinguish themselves from those of the USA? This article addresses these questions using an interdisciplinary approach via the framework of securitization theory. The authors argue that the technological features of 5G made securitization more likely compared to 4G, and that screening and control of software was unlikely to defuse securitization concerns. They also show how Europe chose its own path for the securitization of 5G. In short, the article argues that the American macrosecuritization of China largely failed in Europe, whereas the niche securitization of 5G was more successful.
Nye våpen, gamle vrangforestillinger: Hvordan forstå Boris Johnsons atomvåpen-politikk
If you want to make Britain’s nuclear weapon policy make sense, you need to look inwards not outwards. Just as go-faster stripes please the owner, Britain’s new nuclear policy is better understood as a symbolic gesture performed mainly for its domestic audience. It is crucial here to understand the political function that publicly established force-limits have played British nuclear politics