A (global) solution for cybercrime

Beyond SolarWinds: Securing Cyberspace

The recent ransomware cyberattack on the Colonial Pipeline in the US has exposed how vulnerable critical infrastructure is to hackers, whether they are motivated by money or politics. What can we do about this?

Part of the way forward is acknowledging that there is no longer a distinction between cyber and physical security. The world runs on tech, so people are right to worry about it, Microsoft President Brad Smith said during a livestream discussion on cybersecurity hosted by GZERO Media and Microsoft. The conversation, "Beyond SolarWinds: Securing Cyberspace," held in collaboration with the Munich Security Conference as part of their "Road to Munich" series, was moderated by former US Homeland Security senior official Juliette Kayyem.

The latest attack is different in scale, but not new. And one of the reasons these hacks are likely to become more frequent, he added, is that our defenses are not keeping up with the threats.

Ian Bremmer, president of Eurasia Group and GZERO Media, agreed. Cybersecurity, he explained, is a top risk because there is new tech and no architecture to stop cybercriminals. Moreover, the US relations with the two other countries with similar cyber-offensive capabilities — China and Russia — are at their worst point in decades, with no chance of a reset anytime soon.

Two months before the Colonial Pipeline hack, the cybersecurity buzz was all about SolarWinds, another major cyberattack on thousands of firms, including US government agencies, blamed on Russia. Smith said that SolarWinds showed how sophisticated hackers have become, and Wilson Center President Emerita Jane Harman added that the US bungled its response because a private firm found out before anyone else.

The silver lining from both attacks, Harman noted, is that they pushed the Biden administration to issue an executive order that mandates private corporations to immediately inform the government of such cyberattacks.

Meanwhile, the US needs to rethink its military procurement. For Ian Bremmer, the Pentagon spends a lot on tech to upgrade legacy hardware, but nowhere near enough on cyber — the opposite of what China's doing. That's right, Harman noted, but the DOD and Congress will likely push back.

The wider problem, however, is that we now live in the world where governments are not solely responsible for defending our critical infrastructure, Smith said. How the private sector responds is equally important.

Biden's executive order, he added, is no panacea but it is the most significant step forward in decades because it mandates companies that do business with the federal government to take this issue a lot more seriously. And that'll influence how software is developed across America because the federal government contracts out so much of its IT work.

More broadly, the chances of a more sustainable solution to the problem lie in more international cooperation, said Wolfgang Ischinger, chairman of the Munich Security Conference.

Although governments no longer have the monopoly on power to do harm to each other, the US should still reach out to its allies to fight cybercrime together. This may sound like a dream right now, he admitted, but then again so did nuclear disarmament at the height of the Cold War.

For Smith, who has long called for a Cyber Geneva Convention to set global norms, the reasons now are the same as in the aftermath of World War II: we have a moral and legal responsibility to protect civilians, who are ultimately the most vulnerable to the consequences of cyberattacks.

"Beyond SolarWinds: Securing Cyberspace," a Global Stage live conversation on cyber challenges facing governments, companies, and citizens, was recorded on May 18, 2021, and was held in collaboration with the Munich Security Conference as part of their "Road to Munich" series. Sign up for alerts about more upcoming GZERO events.

More from GZERO Media

Syrian forces head to Latakia after fighters linked to Syria's ousted leader Bashar Assad mounted a deadly attack on government forces on Thursday, March 6, 2025.

REUTERS/Mahmoud Hassano

Nearly 50 people were killed on Thursday in the deadliest clashes Syria has seen since the overthrow of Bashar Assad. Pro-Assad militants attacked security checkpoints around the western coastal town of Jableh, a stronghold of the former regime.

The Liberian-flagged tanker Ice Energy, chartered by the US government, takes Iranian oil from Iranian-flagged Lana (formerly Pegas) as part of a civil forfeiture action off the shore of Karystos, on the Island of Evia, Greece, in May 2022.
REUTERS/Costas Baltas/File Photo

The Trump administration is reportedly considering a strategy to disrupt Iran’s oil exports by stopping and inspecting Iranian oil tankers at sea. The US would use the Proliferation Security Initiative, established in 2003 to prevent the trafficking of weapons of mass destruction, as a legal justification for the inspections.

Donald Trump issues a proclamation from the Oval Office
REUTERS/Kevin Lamarque

US presidents don’t typically talk to organizations the US government has labeled terrorist groups, but Donald Trump is not a typical US president.

President Donald Trump addresses a joint session of Congress at the US Capitol on March 4, 2025.

Win McNamee/Pool via REUTERS

You didn’t need to sit through all 99 minutes of Trump’s peroration to know that he gave himself an A++ on his first six weeks in office, writes GZERO Publisher Evan Solomon. But if Trump gets to grade himself, maybe it’s time for a more objective report card — one that looks at two criteria: Trump as a dealmaker and Trump as a manager.

The Energy Security Hub at the 2025 Munich Security Conference featured in-depth discussions on energy innovation, security, and market viability. Fatih Birol, IEA executive director, discussed growing global energy demand, especially the rapid rise in electricity outpacing overall growth. He noted electricity demand is projected to increase six times faster than total energy in 10 years, underscoring the need for electrification and grid expansion. As energy systems become decentralized and digitalized, the CEO of E.ON, Leonhard Birnbaum, said: “You’re either fully digitized – or you’re done.” Key takeaways: Energy security requires developing and securing electricity grids Technological openness is a unifying element for getting to net zero Bridge the “Valley of Death” to scale markets New global partnerships will help Europe stay competitive Public acceptance will strengthen democracy You can read the full Executive Summary from the BMW Foundation here.

a crowd of people outside of a white building

In a 5-4 split decision, the US Supreme Court on Wednesday ordered the Trump administration to disburse nearly $2 billion in foreign aid funds for work completed by contractors and grant recipients under the US Agency for International Development and the State Department. Does this tell us much about how the top court will handle future Trump-related cases?