Posted on Leave a comment

Should cybersecurity be nationalised?

Up front: the honest answer is, I don’t think anybody is proposing that. Yet.

I don’t know of any plan to put cybersecurity under state ownership, and I am misleading you if I suggest otherwise.

But at a recent industry discussion, an argument surfaced that gets you surprisingly close to that territory. Furthermore, Bill Gates warnings made me think about the issue further.

At the Singapore Press Club event, the question arose as to who is supposed to pay for keeping you safe, and who is answerable when you aren’t.

(The session ran under Chatham House rules, so I’ll share the thinking without naming anyone.)

Private good versus public good

For decades cybersecurity has been treated as a private good. Your company faces a threat, so your company buys protection, out of your own budget. Simple, and until recently, fair enough.

The argument made at this event however, is that this premise is quietly stopping being true. Cybersecurity, it was suggested, is becoming a public good — and we haven’t caught up to what that means.

A public good, is something whose benefits spill well beyond the person who pays for it. And for now, that’s cybersecurity to a tee. When one company hardens its defences, it doesn’t just protect itself — it removes a stepping stone that attackers would have used to reach everyone that company connects to. Your security is increasingly my security, whether or not I ever meet you.

The comparison that made it click was street lighting. No individual shopkeeper pays to install the lamp post outside their door. The city does, because a dark street is one where crime affects for the whole neighbourhood. Note how it’s done (this is important). The government doesn’t run a street-lighting department that builds the lamps itself. It pays a private company to install and maintain them. Privately delivered, publicly funded.

That’s the model the argument points toward for cybersecurity. Not the state taking over. The state paying, while private firms do the work — because the benefit is shared, so the bill should be too.

Also Read: Singapore’s cybersecurity paradox: Leading in digital, lagging in defense

Why private good is breaking

Today, every company is expected to defend itself against threats that are increasingly beyond any single company’s ability.

One line from the discussion put it perfectly. “I don’t build my own air force. I don’t defend my bank against a foreign special forces unit. When the threat is a nation state, I expect the nation to defend me.”

Yet in cyber, we routinely ask a private company or a small business to hold the line against state-sponsored attackers. And with quantum computing on the horizon, the adversary who will eventually be able to break today’s encryption isn’t some criminal gang. Realistically, it’s a state actor. Asking a company to defend itself against is unrealistic, and yet somehow we’ve normalised the notion.

The strain shows most at the bottom of the market. In Singapore, the government has found that around nine in ten businesses surveyed had experienced a cyber incident in the past year, and the costs when it happens are often severe. But the vast majority of companies aren’t large enterprises. They’re small firms, frequently with nobody whose actual job is cybersecurity. They can’t afford enterprise-grade protection, and increasingly they’re the soft entry point attackers use to reach everyone else. The people who need protection most can afford it least — and their exposure is now everyone’s exposure.

Who pays?

If cybersecurity really is becoming a public good, two questions follow.

The first is: who pays? If the benefit is shared, is it right that each company still shoulders the full cost alone? Singapore already nudges in the collective direction, requiring baseline certification in sensitive sectors like healthcare, using government procurement to demand minimum standards, funding schemes that help smaller firms get covered. None of that is nationalisation. But all of it is the state accepting that it has a stake in security it doesn’t directly own.

The second question came from the floor at the event, and it hung: if cybersecurity is a public good, who is independently accountable when preventable failures expose citizens’ data — the hospital records, the national digital identity, the bank accounts? And what enforceable standards protect public trust before the next breach, rather than after it?

That question didn’t get a clean answer. Perhaps an answer doesn’t exist yet. The gap between the benefits shared, costs private, and accountability is unclear. This is the space into which public policy tends to eventually move.

Also Read: The demand for SMB cybersecurity is inevitable, the supply was never built correctly

What this means for now

Leaders don’t need to wait for the policy debate to resolve to act on what it’s telling you.

If your organisation’s security affects the people and businesses around you then framing it purely as your own private cost could already be an out of date notion. Expect that framing to change: more sector requirements, more security conditions written into contracts, more pressure to prove you meet a standard before you win the work, not after you lose the data.

The organisations that will navigate this passage well are the ones that refrain from treating cybersecurity as a grudging line item and treat it as part of the trust they offer everyone they deal with.

That’s what this shift is really about. When what you’re protecting is no longer just your own information, but the confidence of an entire network that depends on you, security stops being an IT question and becomes a matter of reputation.

So — is Singapore about to nationalise cybersecurity? No. But it is, like everywhere else, edging toward treating it as something we all have a stake in and, eventually, all help pay for.

Recognise it. Position yourself as trustworthy custodians rather than reluctant spenders. You will be the ones still standing when accountability catches up with ambition.

Editor’s note: e27 aims to foster thought leadership by publishing views from the community. You can also share your perspective by submitting an article, video, podcast, or infographic.

The views expressed in this article are those of the author and do not necessarily reflect the official policy or position of e27.

Join us on WhatsAppInstagramFacebookX, and LinkedIn to stay connected.

The post Should cybersecurity be nationalised? appeared first on e27.

Leave a Reply

Your email address will not be published. Required fields are marked *