Opens profile photo
Follow
Justin Sherman
@jshermcyber
Tech, policy, geopolitics @ Global Cyber Strategies, , . Columnist . Tech advisor . He/him. Views my own.
Washington, DCglobalcyberstrategies.substack.comJoined October 2018

Justin Sherman’s Tweets

US security reviews of foreign investments are taking on a bigger technology and data focus. In 2021, ~54% of the total notices CFIUS received were from US businesses in the finance, information, and services sector. Check out more data and analysis:
Quote Tweet
NEW: TikTok’s not alone. The US government is expanding its security reviews of foreign investments in the United States—and technology is a major focus. Here’s the data 🧵 globalcyberstrategies.substack.com/p/tiktoks-not-
Show this thread
1
missed this last week... it was already out of hand with DIB, NSCAI, and others but why!!! we need a Commission on If There Are Other People In the World Besides Eric Schmidt this literally feels like madlibs but the noun is always Eric Schmidt
Quote Tweet
NEW, from me: Former Google CEO Eric Schmidt is joining another Washington commission, this one on biotechnology. But this time, a person close to him says he will donate the profits from his investments in the biotech space to charity: cnbc.com/2023/01/31/goo
Show this thread
1
2
Importantly, the new authorities CFIUS received in 2018, from the Foreign Investment Risk Review Modernization Act (FIRRMA), gave it new power and expanded scope vis-à-vis technology- and data-related risks. The ongoing debate about TikTok is just one example of this in practice.
Image
1
Show this thread
Within the finance, information, and services sector in 2021, CFIUS received the most notices from companies classified as Professional, Scientific, and Technical Services, followed by companies classified as Publishing Industries & Data Processing, Hosting, and Related Services.
Image
1
Show this thread
CFIUS has received a generally higher number of notices in recent years from the Finance, Information, and Services sector — spiking to 147 notices in 2021. These 147 notices account for ~54% of the total notices CFIUS received that year.
Image
1
Show this thread
The Committee on Foreign Investment in the United States (CFIUS) receives a variable number of notices from companies — and launches a variable number of investigations — each year. Generally, though, it has received more notices and launched more investigations in recent years.
Image
1
Show this thread
NEW : many policymakers working on security risks of non-US tech companies, products, and services are barreling past two key questions: what approaches enable a spectrum of risk identification and mitigation? and what is the review process?
2
5
Show this thread
US military "has been monitoring a suspected Chinese surveillance balloon that has been hovering over the northern U.S. for the past few days, and military and defense leaders have discussed shooting it out of the sky," per two US and one defense official
2
so uh, you have ONE WEEK to set up your Mаstօԁοո account in a way where you can reconnect with people you knew on twitter, because i'm pretty sure this will kill services like movetodon, fedifinder, and debirdify which let you find your friends from twitter on Mаstօԁοո
Quote Tweet
Starting February 9, we will no longer support free access to the Twitter API, both v2 and v1.1. A paid basic tier will be available instead 🧵
Show this thread
8
425
Show this thread
In several lectures already this week , undergrad + grad students have repeatedly asked how it's legal for many companies to broker health data. Today, announced enforcement against GoodRx for unauthorized disclosures of consumer health data.
2
8
Show this thread
This case is really a huge deal. For years, we've read stories of health apps sharing data with G/FB/data brokers. With this case, the FTC is saying that apps sharing personal health data without explicit permission violates the Health Breach Notification Rule.
Quote Tweet
FTC enforcement action to bar GoodRx from sharing consumers’ sensitive health info for advertising: bit.ly/3HNmvUT /1
Show this thread
2
76
Show this thread
Russia's state-owned telecom names (1) import substitution, (2) "information security" (but mainly focused in the discussion on cybersecurity threats), (3) financial challenges, and (4) staffing/talent problems as some of Russia's biggest 2023 tech issues. More here:
Quote Tweet
NEW: Russia faces 4 major tech challenges in 2023, according to state-owned telecom Rostelecom. From financial challenges to staffing issues, these mentions provide important insights into Russia's tech sector and capabilities. globalcyberstrategies.substack.com/p/russias-2023
3
NEW: Russia faces 4 major tech challenges in 2023, according to state-owned telecom Rostelecom. From financial challenges to staffing issues, these mentions provide important insights into Russia's tech sector and capabilities.
4
We found the Meta Pixel collecting sensitive data on patient portals, tax-filing sites, and beyond. Repeatedly, organizations said they didn’t know the pixel was doing this. It’s time to be proactive about user privacy—we’ll walk you through it:
19
NEW: Inside a Nazi homeschooling group run by the Lawrences, a couple from Upper Sandusky, OH, and parents of four young children. The group has almost 2,500 member and the founders say its aim is "making sure that children become wonderful Nazis” 1/6
1,245
24K
Show this thread