13 May 2024 | The 15th edition of The Apolitical View by Apolitical CEO and Co-Founder Robyn Scott. Subcribe to the newsletter


In this week's edition:

  • Government cyberattacks are rising
  • Ukraine’s AI media spokesperson
  • Iceland’s (accidental) presidential nominees

Every government wants to do digital transformation — and most citizens want their governments to be more digital. But digital transformation (even when it’s done well, which it often isn’t) comes at the price of increasing cybersecurity risks. And this is before we’ve even got near the age of quantum computing, which some argue could end privacy as we know it.

The price of nations' cyber vulnerability is becoming increasingly visible. Last week, the UK’s Ministry of Defence had its payroll data hacked. Another big government attack took place in January when hackers took down Sweden’s government services, just as the country prepared to enter NATO. The scale of the attack’s impact reflects how dependent government delivery can be on one ‘tentpole’ digital service provider: in Sweden’s case, it affected operations for 120 government offices and 60,000 public servants. The head of information security at the Swedish Civil Contingencies Agency pointed out that the country had digitised very rapidly, but had not invested as much time and resources into cybersecurity. January was a busy month – hackers also targeted 65 Australian government departments and agencies and stole 2.5 million documents in its largest-ever government cyberattack.

Cyberattacks can be a guide to geopolitical fractures and incidents can offer real-time insights into how a government’s ambitions are being received by others. In the last year, hackers have sent malware phishing emails to employees of South Korea’s naval shipbuilding sector, while another group breached the International Criminal Court’s IT systems amid an ongoing probe into Russian war crimes committed in Ukraine. And attacks on the USA’s critical infrastructure continue to ramp up.

The losses are big and the budgets are bigger. It’s estimated that Germany lost US$225 billion to cybercrime in 2023 alone (including private sector losses). More difficult to quantify is the loss of trust from citizens when crucial services, especially hospitals and power grids, are offline and unavailable due to cyberattacks — as has already happened in Ireland, Germany, Spain and the UK. In response, governments are preparing to spend much more to tackle the problem. Japan has said it is boosting its cybersecurity budget tenfold in the next five years, and quadrupling its military cybersecurity force to 4,000 people. The US’s 2023 budget for cybersecurity was US$71.79 billion — for perspective, that’s nearly half of Canada’s total military budget. Not all cybersecurity budget funding ideas are going well though. Last week, the Central Bank of Nigeria directed commercial banks to effect a 0.5% “cybersecurity levy” on all electronic transactions by bank customers from May, on behalf of the federal government, which has provoked a widespread backlash.

A global agreement on cybercrime is in the works, but it’s proving tricky. The UN is currently trying to draft an internationally binding treaty to tackle cybercrime. But there are significant disagreements over the scope, and the balance between security measures and protecting individuals’ human rights against overreaching laws. Things can’t be good when UN News’s own report summarises the mood at the last meeting as “pretty grim”.

But there are good examples to build on. The Council of Europe's Convention on Cybercrime was one of the first-ever international treaties (it dates back to 2001), and is widely considered an effective international legal instrument for addressing cybercrime. It has 68 signatories. National strategies on cybersecurity and regulatory frameworks are rapidly becoming more sophisticated and are offering more clear guidance. The UK, for example, has set up a Government Security Learning Academy to provide training and career pathways for government cyber professionals and its cybersecurity strategy places a strong emphasis on incident recovery and learning from attacks.

Digital government will be a key theme at the Public Administration Global Forum which we are pleased to be co-hosting with the World Bank at the end of May in DC. I hope to see you there.


The government of Ukraine recently unveiled an AI-generated spokesperson called Victoria Shi. Watch her X /Twitter debut here. A ‘digital person’ representing the Ministry of Foreign Affairs, she will provide updates on consular affairs to the media, with an accompanying QR code to combat misinformation. We can expect many more of these.

Robyn Scott

Apolitical CEO & Co-Founder


In my diary

I wrote this edition of The View from the English countryside where Apolitical co-hosted an annual event called the Public Sector Strategy Roundtable. This brings together an intimate group of senior government leaders from around the world to discuss strategy and foresight under the Chatham House Rule. I’ll share more insights in the next edition. In the meantime, if you’re interested in participating in future gatherings, do [drop me an email](mailto: theview@apolitical.co).


And finally...

Continuing the theme of the risks of digital government, Iceland’s first attempt at digitising its 2024 presidential endorsement process had some unintended consequences this month. Thanks to a confusingly designed website, at least 11 unwitting Icelanders found themselves participating in the presidential race. Among the presidential front runners were a comedian, the world’s first double-arm transplant receiver, and this journalist’s Aunt Helga. It’s been a boon for digital government UX (user experience) designers looking to emphasise the importance of clarity. A hasty webpage redesign now makes it glaringly obvious how to endorse without accidentally launching your own political career.


Got thoughts, feedback or ideas for what you'd like to see in this newsletter? Send them directly to me or leave a comment below.