The biggest challenges for US tech firms in 2019: GDPR-like privacy protections, large security breaches becoming routine, and anti-government employee protests
Susan Fowler / New York Times : Tweets: @susanthesquark , @moiragweigel , @nytopinion , @mer__edith , @nytopinion , @wslack , @bradfordcross , and @alexstamos Tweets: Susan Fowler / @susanthesquark : My latest:The United States is under siege from foreign governments and malicious hackers. And Silicon Valley's products are the battlefields where the war is being fought. http://www.nytimes.com/... Moira Weigel / @moiragweigel : This take on the new tech worker movements completely ignores political philosophies and goals that organizers at Google, Amazon, Microsoft, and elsewhere have repeatedly, publicly stated, since at least December 2016, often at significant personal risk. http://www.nytimes.com/... @nytopinion : When it comes to security breaches, writes @susanthesquark, “being the best in the world when it comes to security and following the best security practices have not protected these companies, and, ultimately, they have not kept our data safe.” http://www.nytimes.com/... Meredith Whittaker / @mer__edith : Yikes! Painting the tech worker movement as broadly anti-govt + naively libertarian is a misinformed take that ignores extensive contradictory evidence, including many clear statements from workers + major organizing unrelated to govt (e.g. Google walkout) http://www.nytimes.com/... @nytopinion : “At the end of the day, the only people who will have a chance at holding tech companies accountable and demanding better privacy protections will be ordinary people like you and me. And I think that we will fail.” By @susanthesquark http://www.nytimes.com/... Will Slack / @wslack : This piece is exhaustively cited, and while I think some of the points are a bit hyperbolic, it's an excellent summary of challenges as good-faith systems are tested by malicious actors. http://twitter.com/... Bradford Cross / @bradfordcross : important and well written article! modern warfare is fought in information, security, and finance domains. In 2016, we believed these systemic risks were so critical that we started both @MerlonTweets for money laundering risk and @towerstreetHQ for security risk. https://twitter.com/... Alex Stamos / @alexstamos : A good piece, well done @susanthesquark! I'm glad you discussed the risk of human infiltration by US adversaries into Silicon Valley companies. Probably the most difficult threat from RU/CN for the tech giants to prepare for. http://twitter.com/...
Context & Ripple Effects
Writing at the close of 2018, Susan Fowler frames Silicon Valley's products as the battlefield where foreign governments and malicious hackers are fighting the United States — and predicts three pressures will define 2019: GDPR-style privacy rules landing on US firms, breaches becoming routine, and employees turning anti-government protest into a workplace force. The argument lands amid a broader reassessment of how big tech got here: recent books argued its power came less from disruption than from ducking regulation, squeezing workers, and strangling competitors.
What makes the piece worth revisiting is how directly the later coverage confirms each thread — worker activism hardening into open conflict with management, and governments worldwide moving against tech power with an urgency no single industry had seen before.
First-order effects
- US firms face new compliance burdens as GDPR-like privacy protections arrive, while Google, Amazon, and Microsoft employees — the organizers Fowler cites — escalate protest activity inside the companies.
- Security teams at major platforms must treat large breaches as an operating assumption rather than an anomaly, with products themselves positioned as attack surfaces in a state-level conflict.
Second-order effects
- Management pushes back on internal dissent: tensions among investors, managers, and activist employees grow as companies try to limit workplace discussion of social issues, per later reporting on the investor-manager-employee standoff.
- Firms get pulled deeper into government-aligned security work with murky oversight — Google's undisclosed counter-terrorism operation against a hacking group shows the ethical exposure when corporate infrastructure serves allied states.
Third-order effects
- If the pattern holds, the regulatory ducking that built big tech ends: governments move to limit tech-company power globally, validating the books' diagnosis and converting privacy and labor disputes into structural policy.
- Employee activism becomes a durable governance check — the surveillance-tool protests where workers refuse to comply and demand protections mark the shift from episodic walkouts to standing internal opposition.
The trend: Big tech's three unpriced liabilities — regulatory exemption, insecure products, and a restive workforce — are converging into a single contest over who governs the industry: firms, their employees, or the state.