A New Age of Warfare

The US is cyber-attacking Russia’s power grid, just as Russia is hacking the US and both are engaged in offensive hacking in ways that are more aggressive than in the past. But Is this hacking really much different from what’s gone on for many years? Does it boost the chances of a cyber arms race or a cyberwar?

One thing is clear: Cyberspace is now seen by senior miltary officers and officials as just another “domain” of warfare, along with air, land, sea, and space. But there’s something different and more dangerous about this domain: 

It takes place out of sight, its operations are so highly classified that only a few people know what’s going on there, and it creates an inherently hair-trigger situation, which could unleash war in lightning speed with no warning. All the major cyber powers, the United States, Russia, China, Israel, France, Britain, and perhaps to some extent, Iran, Syria, and a few others, have been able to hack into one another’s “critical infrastructure” such as, power grids, financial systems, transportation lines, water works, which have been hooked up to computer networks for the past 25 years. From time to time, these countries have actually hacked into these things.

In one sense, these intrusions are no different from any other form of intelligence gathering. In another sense, though, they’re very different. 

With cyber operations, once you’ve hacked into a network, you can disrupt or disable it. Exploring a network and destroying it involve the same technology, personnel, and know-how; it takes just one step, and next to no time, to go from exploring to destroying. In a crisis, one or more of these countries might launch a cyberattack, if just to preempt one of the other countries from doing it first. The very existence of the implants makes a preemptive attack more likely.

There’s another disturbing development in cyberwar: The whole enterprise has slipped out of the oversight and control of our political leaders. 

Last summer, President Donald Trump signed a classified directive giving US Cyber Command leeway to mount cyber offensive operations at its own initiative. Before then, such operations, even tactical operations on the battlefield, had to be personally approved by the president. The premise of the old policy, during the Bush II and Obama administrations, was that cyber weapons were something new: Their effects were somewhat unpredictable and could spiral out of control. 
One consequence is that Cyber Command now feels less constrained about going on the offensive. 

Richard Clarke, the former cybersecurity chief in President Bill Clinton’s White House and co-author of a forthcoming book on cyberwar called The Fifth Domain, said in an email, “The Trump administration may be trying to create a situation of Mutually Assured Destruction, similar to the 1960s strategic nuclear doctrine.” However, Clarke added, “Cyber is different in many ways.” First is the issue of what strategist’s call “crisis instability”, the hair-trigger situation, in which one side might launch an attack, in order to preempt the other side launching an attack. 

There is also the uncertainty of “attribution”, the country attacked might not know for certain who planted the malicious code and might mistakenly strike back at an innocent party, thus triggering an inadvertent war.

US Cyber Command was founded in 2009. It has since grown enormously, in size, scope, mission, and, since last summer’s directive, autonomy. Cyber offensive technology has been around for much longer still. Cyberwar technology has evolved far more quickly than the thinking about how to use the technology in wartime. 

With last summer’s directive taking its use out of the control and supervision of our political leaders, the decisions to use it will be made entirely by the military officers who developed the technology, and whose budgets depend, in part, on its growing prominence.

Slate:           I-HLS:

You Might Also Read:

The ‘Rules’ Of Modern Warfare Are Being Rewritten:

 

 

« Cyber Criminals Have Created An Invisible Internet
Russia's National AI Strategy Takes Shape »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

Promon

Promon

Promon is an application security vendor providing Self-Protection abilities to Mobile apps and Desktop applications.

Information Security Research Group - University of South Wales

Information Security Research Group - University of South Wales

The Information Security Research Group has an international reputation in the areas of network security, computer forensics and threat analysis.

CANVAS Consortium

CANVAS Consortium

The CANVAS Consortium aims to unify technology developers with legal and ethical scholar and social scientists to approach the challenges of cybersecurity.

Ntrepid

Ntrepid

Ntrepid products provide protection from web threats and enable organizations to safely conduct their online activities.

Slovak Security Policy Institute (SSPI)

Slovak Security Policy Institute (SSPI)

Slovak Security Policy Institute is an independent non-governmental organization that focuses on research and analysis of security challenges including defence and cyber security.

Netsafe

Netsafe

Netsafe is an independent, non-profit New Zealand organisation focused on online safety. We help people stay safe online by providing online safety education, advice and support.

Egyptian Supreme Cybersecurity Council (ESCC)

Egyptian Supreme Cybersecurity Council (ESCC)

ESCC is responsible for developing a national strategy to face and respond to the cyber threats and attacks and to oversee its implementation and update.

Mend.io

Mend.io

Mend.io (formerly known as WhiteSource) is an application security company built to secure today’s digital world.

APERIO

APERIO

APERIO, the global leader in industrial data integrity, helps its customers drive profitability and sustainability while mitigating risk in their industrial operations.

SYSGO

SYSGO

SYSGO is the leading European provider of real-time operating systems for critical embedded applications in the Internet of Things (IoT).

Vijilan Security

Vijilan Security

Vijilan provides 24/7 SOC services to MSPs/VARs. Our Security Operations Center is global, and our services are exclusive to the Channel.

GetHacked.ca

GetHacked.ca

GetHackded.ca is a certified company offering penetration testing and specialized cybersecurity services.

Zyston

Zyston

Zyston's solutions provide end-to-end management of your cybersecurity needs. Our range of services help protect your business where it needs it the most.

HEROIC Cybersecurity

HEROIC Cybersecurity

HEROIC’s enterprise cybersecurity services help improve overall organizational security with industry best practices and advanced technology solutions.

Tidal Cyber

Tidal Cyber

We formed Tidal for one simple reason—we believe that defenders need and deserve tools and services that make achieving the benefits of threat-informed defense practical and sustainable.

Elitery

Elitery

Elitery is an IT-managed service company that focuses on cloud and cybersecurity services.