Abstract
The Internet facilitates a level of interoperability that generates considerable innovation and opportunity. Yet threats to governments, businesses, and individuals who use the Internet are increasing exponentially. This article deploys an anthropological understanding of risk in order to examine public sector action and capacity with respect to the multidimensional challenge of cyber-security. Our objectives are threefold: to gain a fuller appreciation of the interplay of political, technological, organizational, and social dimensions of cyber-security; to understand how this interplay is further shaped by clashing values and perceptions of risk; and to offer some prescriptive insight into the sorts of roles for government most likely to maximize systemic resilience and learning in an increasingly interdependent and virtual environment. Governments, the private sector, and civil society must engage in more shared responsibilities and collective learning in what is a highly fragile and dynamic cyberspace.
Keywords
Introduction
The lesson of the past two decades is that the nation will not get serious about cybersecurity until the costs of not doing so are more apparent—probably after some component of our economy is destroyed by a catastrophic cyber-event. (Goldsmith & Hathaway, 2010)
The Internet facilitates a level of interoperability between organizations, sectors, and countries that generates considerable innovation and opportunity. Digital infrastructure is rapidly becoming the lifeblood of the global economy, as every major industrial sector widens its reliance on electronic systems and online connectivity—from power supply to banking to telecoms to manufacturing. Similarly, governments themselves have vigorously pursued e-government efforts as platforms for both new channels of online service delivery and new mechanisms of information sharing and public engagement (Roy, 2008; United Nations, 2010).
Widening degrees of interoperability thus open up opportunities for innovation, democratization, and “mass collaboration” (Eggers, 2005; Parker & Gallagher, 2007; Williams, 2008). Yet at the same time, whether or not the cyber-infrastructure that results is secure is perhaps the key determinant for the future of e-government, e-commerce, and digital life more generally. Threats to businesses and individuals who use the Internet are increasing exponentially. One recent survey of Internet security by Websense Security Labs during the first half of 2009 found danger to be rampant: malicious websites grew by 233%; 87.7% of e-mails sent world over is spam and 95% 1 of user-generated comments to blogs, chat rooms, and message boards are spam or malicious in nature; and 37% of malicious attacks included data-stealing code. The consequences are significant: while online fraud alone rose to more than one half of billion dollars in the United States in 2009, 2 a global, industry-led study presented at the 2009 World Economic Forum estimated total costs accrued by all businesses due to cyber-crime to have neared U.S.$1 trillion in 2008. 3 In addition to these business costs, this trend raises equally important questions about data protection and privacy rights, which could erode people’s trust in on-line systems—be they public or private. It is not surprising, therefore, that in 2009 the Obama administration’s Cyberspace Policy Review stated that: “Threats to cyberspace pose one of the most serious economic and national security challenges of the 21st century for the United States and our allies” (Goodyear, Goerdel, Portillo, & Williams, 2010, p. 8). Canada is one of those allies, the United States’ largest trading partner and one of the most connected nations in the world. With the United States as an important point of reference—and with continental governance critically important to all aspects of defense and security arrangements in Canada, the American experience is of great consequence in this regard.
Our objectives are threefold: to gain a fuller appreciation of the interplay of political, technological, organizational, and social dimensions of cyber-security; to understand how this interplay is further shaped by clashing values and perceptions of risk; and to offer some prescriptive insight into the sorts of roles for government most likely to maximize systemic resilience and learning in an increasingly interdependent and virtual environment. Our methodology—one based upon an inter-disciplinary review of scholarly research and media coverage, as well as ongoing data-gathering and outreach activities on the part of the authors in the realms of e-government and critical infrastructure protection 4 —place values and institutional context at the heart of our analysis. The article is organized as follows: Following this introduction, the section Cultural Theory and Cyber-Security adopts a cultural theory-based approach in order to dissect and present four different “types,” each of which represents different values, understanding of risk and preferred institutional arrangements; the section then uses these four types to examine how each views the dangers and opportunities associated with cyber-security. Building on this analysis, the section Devising New Capacities: From Rhetoric to Action offers some reflection on the main challenges and opportunities for public sector authorities in dealing with cyber-security risk and fostering a governance regime able to maximize collective learning and resilience. Finally, the section Conclusion provides some concluding remarks.
Cultural Theory and Cyber-Security
Douglas (1982, pp. 191–192) describes a person’s value system in terms of the grid/group typology that she developed based upon the following: Grid, which we will refer to here as regulation, measures the strength of formal or informal rules and social norms; and Group, which we will call integration, measures the extent to which community constraints are imposed on an individual. At the intersection of regulation and integration, Douglas sees different “types” of value systems emerging. Each of these different “types” has different beliefs about what constitutes risk. The central assumption is that there is a relationship between modes of social organization and responses to risk, and that risk and culture are adequately represented by the dimensions of the grid/group scheme. (see Figure 1 )

Cultural theory typology.
Based on this grid/group typology, Hood (1998) 5 and Thompson, Ellis, and Wildavsky (1990) examine the four “types” in more detail. They argue that each type has a distinct set of values, understanding of risk and preferred governance arrangement. Each governance arrangement has a corresponding set of potential strengths and weaknesses as well as a fundamentally different ethos in terms of how to address risk individually and/or collectively. The contours of each arrangement are reviewed briefly in turn.
A hierarchist (high regulation/high integration) understands good governance to mean a stable environment that supports collective interest and fair process through rule-driven hierarchical organizations, which includes adequate specialization and standardization. Any departure from this rule-bound hierarchy represents risk for hierarchists. When problems or shortcomings arise, hierarchists typically assign blame according to unclear and/or weak rules, or a lack of expertise within the organization.
An individualist (low regulation/low integration) understands good governance to mean minimal rules and interference with free market processes. Individualists understand risk to be government regulation of the economy or government’s management of public services. When problems or shortcomings arise, they typically blame faulty incentive structures.
An egalitarian (low regulation/high integration) understands good governance to mean local, communitarian, and participative organizations. Egalitarians understand risk to mean hierarchies and organizations outside their system. When problems or shortcomings arise, egalitarians typically blame externals: “management,” “the executives,” “the system,” and “Wall Street.” They often blame governments for usurping local powers and processes.
A fatalist (high regulation/low integration) understands good governance to mean “resilience”—the capacity to bounce back, or withstand the pressures of unanticipated setbacks. Fatalists feel that having faith in formal planning is itself an inherent risk (for fatalists—Man plans; God laughs). When problems or shortcomings arise, they blame “random chance” and “the cards that you were dealt.” In such a world, risks abound and mitigation is futile.
While any one “type” might seem extreme, Hood (1998) argues that hybrids often form when different types work together. In the case of cyber-security, for instance, the government is likely to contract with private industry by way of tapping into industry’s potential for creativity and innovation while government can safeguard concepts such as fairness.
These hybrid forms can be tenuous arrangements, however. When a hybrid system is under stress or fails, participants will revert to their preferred type. Because all types have Achilles’ heals, participants will blame the failings of hybrid governance structures on the type with which they do not identify. Faced with a dynamic policy arena of competing interests and stakeholders, it is generally the case that governments move between types over time. Hood (1998) notes that governments tend toward one type; they experience the failures to which the type is susceptible and—by way of responding to the failures—they shift to another type. They employ the practices of the second type until they experience the failures related to this second type, and then they shift again, often back to the first type. To cultural theorists, then, it is quite natural to witness a highly deregulated Internet evolve through periods of increased regulation.
In sum, Cultural Theory has a potentially powerful impact when employed as a heuristic device. The theory suggests people understand risk according to their own bias, setup governance structures to protect their preferred systems and blame failings of governance on the shortcoming of other “types.” The theory can help to explain the recurring nature of certain risk debates, guide our reasoning about potential shortcomings in specific institutional designs, and detect the types of failures to which these types of design are susceptible.
With Respect to Cyber-security
Hierarchists argue that the present state of play in the cyber world constitutes a market failure, similar to the tragedy of the commons (Bauer & van Eeten, 2009; Hardin, 1968). The entire economy depends on the successful running of the Internet. If, however, everyone looks after his/her own private interest, collectively we will be worse off. Internet failures are low probability/(potentially) high-consequence failures. Such a dynamic fails to create the necessary incentives at the individual level to invest in the security of those systems. And in fact, these low-probability failures are becoming more common place and the interdependent nature of the systems means that individual decisions not to spend on security places the entire network at risk of disruption and cascading failures. In addition, market solutions such as private “cyber” insurance have not yet (and indeed, are unlikely) to emerge because the failures are too difficult to model, and therefore impossible to cost (Jaeger, Renn, Rosa, & Webler, 2001). Finally, a strong regulatory response can help to protect other (social) values that may be at risk in a strictly deregulated environment, such as privacy concerns.
The hierarchist tendencies of governmental response to the Internet and cyber-security risks are very much displayed by many key reforms being implemented by the Obama administration. Legislation adopted by the US House of Representatives in June 2010 (pending Senate review and final adoption) approves the following provision sought by the Obama administration since its arrival: “Creating a National Office for Cyberspace within the White House to coordinate and oversee the security of agency information systems and infrastructure. This office will have strong budgetary oversight powers.” 6 The Office—an initiative fitting comfortably within the bureaucratic paradigm—is mandated to enforce compliance of system-wide rules and policies on many aspects of technology management and planning: in doing so, the emphasis is on hierarchical action and direct control.
Yet individualists reject a number of assumptions upon which hierarchists base their argument. The Internet has flourished because it is largely unregulated. Any effort to do so will kill “the golden goose”: government’s tendency toward unimaginative regulation and standardization will result in inappropriate and inflexible rules (which, in any event, individualists will try to work-around when it is in their interest to do so); these rules will increase the transaction costs and decrease choice and efficiencies unnecessarily. They will make the market less innovative and adaptive to emerging opportunities.
Individualists defend the market. First, there is little evidence to suggest that people have lost faith in the Internet, so why would government feel compelled to regulate it, as government regulates the aviation sector or medical sector? 7 In fact, businesses will take steps in their interests, which is more efficient and are better informed. They would point to the heightened efforts by financial companies to increase security requirements in light of increased incidents of fraud as evidence of the market’s capacity to respond without formal government regulation.
For egalitarians, the Internet—at its best—can facilitate new communities, from biking clubs to peace movements to on-line dating. In many respects security is not high on their agenda; transparency is. The Internet, therefore, should bring about new forms of government: radical models of direct democracy and more transparency (and related scrutiny) of government and industry.
Alas, egalitarians are often let down. Egalitarianism is routinely characterized as a low-trust environment. They are suspicious of both the “opportunists” of Wall Street and the “self-serving, power-hungry” bureaucrats in government. Egalitarians point out that the Internet is a public good, owned privately (Bauer & van Eeten, 2009). Despite its promise of greater democracy, the Internet will be used to consolidate power in the hands of fewer and fewer, leaving the vulnerable even more so. The “digital divide” is used as evidence: online government services are viewed as mere window-training. Briefly, the Internet has failed to bring about real institutional change.
For egalitarians, governments will never accept the full potential of direct democracy as it would be a direct threat to existing power structures. In terms of cyber-security in particular, securing data and electronic systems is merely an act of reinforcing these power structures: it excludes people. Some will get access; some will not. The decisions will be left to those who already have power. Moreover, whether it is in the interests of improving marketing strategies for Wall Street firms or chasing individuals or governments in the name of the War on Terror, the Internet will be used routinely to breech privacy laws.
For fatalists, networks are unreliable; they are fragile; no-one is in control; the interdependence can create unpredictable and cascading failures. There is no “all-encompassing framework” that will manage the security of the Internet, as bureaucrats are wont to pursue. Indeed, the interdependence is beyond our understanding. Fatalists are not short of evidence in the modern age: natural disasters and technical failures—either intentional or accidental—underscore the fragility of modern systems and the uncomfortable regularity of “worst case scenarios” (Clarke, 2006). For fatalists, failures will occur. The critical question, therefore, is can one live with them? The news is not all bad here. In fact many systems fail every day, and the interdependence of the systems present weaknesses as well as opportunities to recover. Catastrophic failures or failures that generate irreversible harm might have to be abandoned, however. Because the systems are beyond our comprehension, it is not at all easy to determine which systems failures will lead to these catastrophic or irreversible events. In short, the reach of a system cannot be understood until it fails. The Internet is the quintessential example.
With respect to cyber-security and governmental action in North America, then, at this critical juncture it is our view that three key points warrant further consideration. First, President Obama has sharpened attention on the risks of cyber-security to an unprecedented degree—creating opportunities for more resource investments, media attention, and public debate, a shift likely to lead to bolstered hierarchist tendencies by way of response. Secondly, however, the private sector is a key player—as owner and operator of major portions of critical telecommunications infrastructure and electronic online systems: while markets can generate innovation to mitigate cyber-security risks, competitive and proprietary concerns often limit information sharing and concerted action. Thirdly, consistent with the nature of online space and activity and many emerging cyber-threats (Cornish, 2009), there may be merit (and indeed necessity) in looking to hybrid arrangements that include egalitarianism and fatalism more deliberately: doing so creates significant challenges for government in moving beyond its hierarchist orientation to mobilize resources and actions in manners conducive to these more horizontal, adaptive, and often spontaneous institutional types. Further attention is therefore devoted to these challenges in the next section.
Devising New Capacities: From Rhetoric to Action
This section aims to build on the preceding institutional constructs of risk and further examine the specifics of governmental action. The purpose here is to further probe and address the challenges associated with the now recognized need to devise workable governance hybrids that can overcome the limits of the hierarchist government model and instill more networked, collaborative, and resilient strategies. Such strategies, as do the threats stemming from cyber-security, must draw from all four of the aforementioned value quadrants of risk management.
As noted, the election of President Obama and his emphasis on technology matters generally creates both positive and negative potential for bolstered governmental action. The President has unquestionably galvanized leadership at the highest level: My administration will pursue a new, comprehensive approach to securing America’s digital infrastructure. This new approach starts at the top with this commitment from me: from now on, our digital infrastructure, the networks and computers we depend on every day, will be treated as they should be—as a strategic national asset. Protecting this infrastructure will be a national security priority. We will ensure these networks are secure, trustworthy and resilient.
8
Accordingly, the Obama Administration’s 2009 Cyberspace Policy Review highlights the need for a national dialog involving government, industry, and the public at large—emphasizing the need for co-ordinated action across all levels of government as well as across sectors (Goodyear et al., 2010). At the same time, reflecting their hierarchist ethos of government, leadership, and responsibility are centralized within the confines of the White House and the new Presidential, cyber-security appointee. Within the Canadian Government, by contrast, cyber-security leadership is much more diffused and horizontal across a number of security agencies (mainly within the public safety and security portfolio), the CIO Office (within the Treasury Board, a central agency and the management board of Government), and Industry Canada (the lead Department overseeing the telecommunications sector). Both due to the US model of greater centralization now taking shape, and critics such as the Auditor General of Canada (2010) that have found significant systemic shortcomings in government’s electronic infrastructures, it stands to reason that there will be greater bureaucratic and political pressure for more centralized leadership and direction.
Here we witness clashes between vertical and horizontal lines of accountability: government understanding that it cannot act alone but nonetheless driven by conflicting pressures to act unilaterally and collaboratively. Within governments, these pressures play out in specific units or individuals assigned leadership; across sectors they reflect government’s dual role of orchestrating processes for inter-sectoral co-ordination and dialog on the one hand, and regulating and policing wherever necessary on the other hand. In terms of this latter point, the hierarchical orientation of government authorities playing a guardian role is one that co-evolves in a dynamic and often tense manner with the individualist tendencies of market actors.
As Jacobs, Reich, and others remind us (Roy, 2007), strong guardian authorities are required to counter-balance and at times oversee the increasingly open and globalized marketplace and resulting commercial orientation of individuals and companies competing in the private realm. Yet regarding cyber-security, the over-arching challenge is in finding innovative ways to expand government’s role in an intelligent manner, balancing hierarchist and individualist, state and market capacities in recognition of the fact that it is unlikely to be governments themselves that create the tools and mechanisms necessary to ensure a safe and resilient digital infrastructure, but instead: (a) ideas stemming from innovation and experimentation within the marketplace; and (b) an alignment of public and private interests via collaborative efforts between both sectors. Thus, governments must not only work to preserve and indeed strengthen the positive aspects of open, fair, and thriving markets (thereby carefully balancing guardian and commercial forces—i.e., not over-extending regulatory, legal, and policy regimes in ways that dampen market dynamism), but they must also become smart and effective agents within such markets in terms of procurement decisions and in setting out the parameters of public—private co-ordination.
A critical and often contested issue here is transparency. Shaped by the proprietary concerns about intellectual property and the secrecy-driven traditions of government, inter-sectoral interaction is often legalistic or collusive. Markets and individualist orientations toward risk provide an important piece of any cyber-security puzzle—provided there is a sufficient amount of openness in terms of how markets and industries are functioning, and as well in terms of interactions between private sector specialists and public authorities. Consistent with an emphasis on openness generally and open source-driven developments such as cloud computing, the US Government’s model of transparency in terms of stimulus spending (one that features a separate, independent oversight body reporting in near-real time online 9 ) provides a model of what could take place in the realm of cyber-security. Such an effort to gather and share information via independent monitoring could greatly contribute to not only immediate and reactive forms of democratic accountability, but also perhaps more importantly ongoing capacities for fostering collective intelligence across society as a whole.
A key challenge here is that government alone cannot initiate collective action within the marketplace, nor shape behavior in those dimensions of civil society with individualist or egalitarian tendencies and values. Growing calls for industry self-reporting and self-monitoring are thus important in mobilizing market-based assessments of risk—and reactions to such assessments. Recently, the Intelligence and National Security Alliance (INSA, 2009) provided a thoughtful analysis of public–private partnering in a variety of contexts—with the aim of devising a suitable framework for sectoral collaboration specifically in the cyber-security realm. As a point of departure for high-level guidance they propose two fundamental dimensions to such an undertaking: An executive committee composed of representatives from individual, business, and government organizations referred to here as a Cyber Security Panel, which represents the interests of businesses and individual users. A partner government organization responsible for some oversight, regulation, and enforcement, focused on net security. Government is essential because only government has the authority and ability to fully investigate cyber incidents that may occur across networks and only government has the ability and legitimacy to regulate industry where private citizens’ interests are at risk (as with privacy) (INSA, 2009).
This type of high-level collaboration—formalized in such a manner, is important in signaling the necessity of sectoral collaboration. Further, such a forum could bring to light the significant shared externalities of firms and industries—transforming the “widespread agreement that this long-term trend of grabbing the economic gains from information technology advances and ignoring their security costs has reached a crisis” (Goldsmith & Hathaway, 2010), into concrete proactive measures and better planning for emergency preparedness and responses to incidents when they occur.
Yet to proceed in such a manner, governments must pursue strategies that facilitate multiorganizational collaboration while at the same time account for the competitive context of markets. Public authorities must recognize the disincentives that will constrain industry’s willingness to share proprietary information (Langford & Roy, 2008). It is unlikely industry will share information about their vulnerabilities: liability issues and concerns about brand and reputation are important vices here. Sector level forums can thus agree to a certain level of confidentiality provisioning where essential—yet a higher level mechanism for public and private dialog can at the same time build the conditions for trust and more information sharing. Shaping the mindset of markets in terms of expectations and incentives is particularly important, especially as evidence points to a strengthening correlation between cyber-vulnerabilities and a loss of shareholder value (Andoh-Baidoo, Amoako-Gyampah, & Osei-Bryson, 2010).
The Obama Administration Cyber-Policy Review is thus an important moment for private industry—either to engage better as a partner with government in devising ways to share more information more openly, or risk more direct interventions by public authorities (especially in the aftermath of a large-scale crisis or breach).
This emphasis on transparency and openness can also be an important linkage to egalitarians—sceptical of industry and government capacities (especially existing ones), but more open to the formation of new communities, akin to the self-governance dynamic becoming so prevalent in an online, inter-connected world (Roy, 2010; Shirky, 2008). Consistent with embracing the growing reach and prowess of web 2.0 and social networking sites outside of government (Eggers, 2005; Williams, 2008) and the more networked democratic ethos taking hold (Roy, 2008; Stoker, 2005), the imperative facing public sector authorities is forge innovative mechanisms that leverage the collective mobilization of all stakeholders and the public at large. Such mobilization can then align governmental authority with new collaborative capacities via communities and movements devoted to fostering greater collective security online—as well as shared reactive response capacities for breaches and breakdowns when they occur.
This latter point suggests at least some potential for common ground with fatalists—awaiting the large catastrophic event as the only sufficient mobilizing force that will yield a basis for better understanding cyber-security as a dynamic (and largely uncontrolled) system. Fatalism should not be dismissed, and certainly should not be mischaracterized as an aversion to government action: as per the recent lamenting of the Obama security strategy by the chief architect of the cyber-policy review, 10 fatalism also stems from the possibility that governments are incapable of orchestrating collective and innovative action in an environment where risk remains contested and subversive.
Some organizations leverage fatalism by engaging the efforts of external agents to create organized attempts to breach security systems presently in place. This type of effort is one that may well become increasingly prevalent in the future—as a critical lesson from fatalism is the often problematic nature of many cause and effect relationships in the realm of cyber-security, and the necessity to respond on occasion to events that cannot be anticipated. If governments cannot do so internally, they must learn to nonetheless leverage more networked capacities for quick responses and adjustment in concert with outside actors (aligned in some manner with public authorities).
The key objective here is systemic resilience—both within government and also across all sectors. Accordingly, government and industry must re-conceptualize interdependence as a source of resilience as well as vulnerability. Interdependence in modern systems such as the Internet represents a source of strength: on any given day there are many failures in systems, but the interdependence results in redundancies which allow the system as a whole to adapt and continue to function.
One promising idea moving in such a direction—attempting in some manner to align and link governmental authority with a more grassroots, spontaneous form of extended community, is offered by Irvine and Palmer (2010) in their proposed blueprint of a Cyber National Guard (in the United States although the authors acknowledge and endorse the need for an international capacity for this type of mechanism). Responding to the Obama Administration’s Cyber Space Policy review that calls for new processes over the mid-term between the government and the private sector to “assist in preventing, detecting, and responding to cyber-incidents,” the notion of a Cyber National Guard is one of networked resilience through public funding and leadership coupled with private support and assistance—and driven by voluntary engagement and a communitarian-type ethos to both reactive and proactive forms of mobilization (Irvine & Palmer, 2010).
The authors suggest, for example, such a body could greatly assist public awareness and education efforts, an approach that can to some degree marry the randomness and resilience of fatalists with an egalitarian-minded emphasis on shared preparation and building a culture of “cyber hygiene” (Irvine & Palmer, 2010, p. 59). Key here is government’s willingness and ability to share authority in a manner that acknowledges the necessity of beyond hierarchist capacities. The creation of a US Cyber-Challenge—a nation-wide talent search to mobilize and nurture a cadre of 10,000 young Americans with cyber-security skills, is a useful example of this type of grassroots initiative encouraged by government but working outside of the hierarchist confines of public sector. 11
Looking to egalitarianism and fatalism, then, can assist government in fostering new outreach capacities more aligned with the networked realities of the Internet itself. Egalitarian models improve our understanding of shared public spaces—their opportunities and risks and how to manage both. Fatalism reminds us of systemic fragility and the importance of redundancy. Both these spheres scan also prove critically important in lessening the secretive and proprietary tendencies of states and markets—opening up more contributions from civil society. Moreover, the risks in not leveraging these societal mindsets in more open governance forums and mechanisms stem from their more subversive forms of associational activity, such as criminality and terrorism that may grow in manners increasingly undetected and certainly under-appreciated by ill-informed citizenries and their democratic representatives (McAfee, 2009).
In short, governance experimentation is critically important in terms of both proactive preparation and mitigating the sorts of threats emerging in cyber-space. It is only by way of such hybrid strategies that governments can respond, both proactively and reactively, to the multifaceted risks of an ever-more digitally and socially networked world.
Conclusion
In terms of cyber-security and public sector capacity for recognizing, mitigating, and responding to risk, this article has argued that the hierarchist tendencies of government are at a minimum insufficient. Importantly, government has sent important signals that it will work collaboratively with the private sector and civil society. Indeed, such an approach is necessary. Still, moving from rhetoric to meaningful and sustained action remains problematic. Civil society has not fully engaged with this issue; and private sector will be reluctant to plan with government if industry perceives government’s mindset as compliance and control.
As reflected in the quotation at the outset of this article, even informed observers sympathetic to the role of government believe that the sorts of innovative responses required are unlikely to emerge without the significant prodding in the form of a cataclysmic event (Sunstein, 2008). Furthermore, even if such a large-scale event were to occur, the problem will only be compounded by government’s tendency to respond to risks emerging from a crisis through the hierarchist lens: witness the centralization of security and intelligence functions since 9–11 in the United States and Canada.
We contend, therefore, that it is precisely this mindset and approach to risk management that must change in order to address cyber-security systemically and intelligently and to improve collective capacities for identifying and preventing breaches and failures before they occur, and better mobilizing resources and solutions when they do—including in unanticipated ways. This fundamental shift requires recognition of the limitations of the hierarchist and individualist approaches, which tend to characterize most debates. Government action alone is unrealistic; so too is an unregulated, self-governing Internet. Governments, the private sector, and civil society must engage in more shared responsibilities and collective learning in what is a highly fragile and dynamic cyberspace. Clearly too, governments must work more effectively in concert with one another—both within and across national jurisdictions in order to ensure that greater interoperability does not simply mean exposing one another to heightened risks. As companies and civil society embrace less hierarchical and more fluid governance systems, the public sector must be similarly experimental in promoting openness and adaptation. Notwithstanding the need for some recognition of intellectual property rights and secrecy in extreme situations, the pursuit of more interoperable systems means that public safety and collective resilience are increasingly dependent upon a secure cyber-infrastructure that, in turn, requires wider sharing of information in terms of both process and performance. Only such broader openness can further galvanize the public in a pro-active manner (as opposed to reactionary responses if and when a major breach occurs).
While President Obama has begun to galvanize public interest and attention on cyber-security as a strategic imperative the jury is still out on whether such attention can translate into the sorts of innovative capacities hinted at in parts of the Cyber Space Policy Review. Ideally, such high-level political attention can be coupled with a new openness—within and across all sectors, in order to spur greater information sharing and concerted experimentation. For Canada, the main and critical lesson from the US experience at present is to reframe cyber-security as less a technocratic agenda than one deserving of political attention and public dialog before, and not after, significant events galvanize forces in a media-frenzied, politically charged, and reactionary setting. The risks of inaction are compounded in the Canadian case by virtue of the fact that any major cyber-security crisis galvanizing such reactions in the United States will compel Canada to more directly align efforts with those south of the border, and with far less opportunity for input and design than is presently the case.
Footnotes
Notes
A special thanks to Obbia Barni for her research and editing assistance.
The author(s) declared no conflicts of interest with respect to the authorship and/or publication of this article.
The author(s) received no financial support for the research and/or authorship of this article. The research support of the Social Sciences and Humanities Research Council is also gratefully acknowledged.
