Ken Hu0:04
Good morning, ladies and gentlemen. Thank you very much for joining us today. It's a great honor for me to be here to welcome all of you—the representatives from the EU, our customers, our partners, and many journalists from all over the world. It's a great honor for me to take this opportunity to share our thoughts on how we're going to address the challenge of cybersecurity in this fast-changing digital world.
I'm always pleased to be back in Brussels. For me, this city is leading the efforts to address many challenges, from global warming to education, from economic development to changes in the workplace. Here in Brussels, policymakers are looking for solutions to the changes that we all face. This includes cybersecurity. Last year at the European Business Summit, I announced our plans to open this cybersecurity transparency center here in Brussels. If we look at the events in the past months, it's clear that now this facility is more critical than ever.
We're getting into a digital world very fast, and we all agree that trust is the foundation for a healthy digital environment. But as technology evolves, it's becoming more difficult for us to build that trust. Right now, from our perspective, we have four main challenges.
First, faster-developing digital technology brings many new security challenges. For example, traditional telco networks have evolved from closed networks to internet-based networks, which are much more open than before. More and more digital content and services are migrating to the cloud. As small devices go online and our smartphones become more powerful, our networks have much greater attack surfaces than ever before.
Second, as a global community, we lack a common and unified understanding of cybersecurity. Governments, business communities—we all talk about the importance of cybersecurity. However, the fact is both public and private sectors lack a basic common understanding of this issue. As a result, different stakeholders have different opinions and different expectations on cybersecurity, and there is no alignment of responsibilities in some cases.
Third, our industry as a whole lacks a unified set of technical standards for security as well as systems for verification. This is complicated by the global supply chain. Digital products include components from many different countries with many different standards, or even no standards at all. This is a fact. So there is an urgent need to invest in security standards and verification systems at the national level, and there is a need to invest heavily in professional resources and skills. This is a task for the whole society.
The fourth challenge is governance. In some countries, cybersecurity management lacks legislative support, and cybersecurity enforcement is not mature. These are all real challenges for all of us. We fully understand the cybersecurity concerns that people have in this digital world, and we believe that cybersecurity is a challenge we all share.
To address these challenges, we believe that mutual understanding is the starting point. To build a trustworthy environment, we need to work together. So what's the solution? Let me share with you in detail.
At Huawei, we have a principle called the ABC principle for security. It's very simple: A—assume nothing; B—believe nobody; C—check everything. The ABC principle. We believe that both trust and distrust should be based on facts, not feelings, not speculations, not baseless rumors. We believe that facts must be verifiable, and verification must be based on standards.
So to start, we need to work together on unified standards. Based on a set of common standards, technical verification and legal verification can lay the foundation for building trust. This must be a collaborative effort because no single vendor, government, or telco operator can do it alone.
Second, we need to work together to clarify and align our responsibilities. This includes the stakeholders of regulators, standards organizations, telcos, and technology providers like Huawei. As technology providers, our responsibility is to fully comply with the standards. But that's not enough. Security must be embraced as a great social responsibility for the business firm. That means embodying trust in end-to-end processes and enhancing security through innovation in the corporate culture. This is the approach we would take.
For telco carriers, their responsibility is to ensure the cyber resilience of their own networks following industry standards. Telco carriers need to build robust processes to identify cybersecurity risks, and they need to develop risk mitigation plans and protect the data of their customers.
Finally, governments and standards bodies need to work with all stakeholders on standards development. This is their shared responsibility. These efforts should focus on a holistic approach, including security standards, security verification mechanisms, and enforcement.
In Europe, we have very good experience in driving unified standards and regulation. For example, the GDPR, which is a shining example of this. GDPR sets clear standards, defines responsibilities for all stakeholders, and applies equally to all companies operating in Europe. As a result, GDPR has become the golden standard for privacy protection around the world. We believe that European regulators can also lead the way on similar mechanisms for cybersecurity.
Yesterday, I met with Andrus Ansip. We also talked about developing a GDPR-like scheme for cybersecurity in Europe. We hope that will lay a fair ground for all service providers and technology providers to contribute their credibility to the digital development in Europe.
For example, right now the GSMA is making great progress with the NESAS security assessment scheme. We believe that all stakeholders should get behind this framework. Ultimately, the standards we adopt must be verifiable for all technology providers and all carriers.
Ladies and gentlemen, our open, digital, and prosperous Europe requires a secure and trustworthy digital environment. That means meeting the challenges of today and tomorrow to lay the foundation for trust in the digital environment for both now and in the future. Transparency, integrity, and accountability are essential.
Today, we're opening the Huawei Cybersecurity Transparency Center to help build this environment. This center will provide a platform to enhance communication and joint innovation with all stakeholders. It will also provide a technical verification platform for all of our customers. At Huawei, we strongly advocate independent and neutral third-party certification. Our cybersecurity transparency center was supported by the EU, which also gives us a dedicated platform for constructive discussion, sharing best practices, and jointly addressing risks and challenges with our customers and all of our partners.
We welcome all regulators, standards organizations, and Huawei customers to use this platform to collaborate more closely on security standards, verification, and secure innovation. Together, we can improve security across the entire ecosystem and help build mutual, verifiable trust.
Over the past 30 years, Huawei has served more than 3 billion people around the world. We support the stable operation of more than 1,500 carrier networks in over 170 countries in the world. In this time, we have maintained a solid track record in cybersecurity. We are so proud of that.
At Huawei, our promise is security or nothing. We take this responsibility very seriously. Cybersecurity is our top priority across product design, development, and lifecycle management, and it's embedded in all of our business processes.
Looking into the future, we want to do more. We will keep investing in our cybersecurity and technical capability. This center is an important milestone in this commitment. We also commit to working more closely with all stakeholders in Europe to build trust on objective facts and verification. This is the cornerstone of a secure digital environment for all of us in Europe.
Ladies and gentlemen, as a city, as an institution, Brussels reminds us of what collective effort and a clear vision can achieve. As people, as organizations, as companies, we strongly believe that we are always more effective, we are always stronger when we work together. Thank you very much.