The Emerging Domain Of Cyber War

Cyber warfare is the use of technology to attack a nation's computers or information networks, causing comparable harm to actual warfare, be it damage, death or destruction. It has many advantages as great distances can be crossed in seconds or even less, without the need for planes, tanks, soldiers or ships or satellites and it can be done often without the opponent knowing what is actually happening.

It can take down computer security, knock-out electricity and power systems and can also be used to steal military secrets, engage in propaganda and fake news, which increases the fear and misunderstanding in the population who often don’t know that it is under attack.

There is argument and debate regarding the definition of cyber warfare. There are differing views about what the term cyber war actually means, and some say that there have not been any cyber-attacks that can be described as warfare. 
However, the pace, frequency, and intensity of cyber-attacks are now greater than ever. As the physical realm inevitably merges with the cyber one, forming a new kind of infrastructure, cyber attacks on this infrastructure can have a catastrophic impact on our energy, waste, water, transportation, and telecommunications facilities. 

Most countries are completely under-prepared to protect their people and property against such attacks and it is predicted by Juniper Research that the cost of cyber crimes will exceed $5 trillion over the next five years.

Russia and China are developing cyber weapons to use in any future cyber conflict and the US, France, UK and Israel are just as active as nation states leading the way in these endeavors. The Stuxnet malware was one example of a cyber war attack which was a joint cyber venture between Israel and the USA to destroy Iran's nuclear programme capability. 

What Is Cyber War?

Cyber warfare refers to the use of digital attacks, like computer viruses and hacking, by one country to disrupt the vital computer systems of another, with the aim of creating damage, death and destruction. A shadowy world that is still filled with spies, hackers and top secret digital weapons projects, cyber warfare is an increasingly common, and dangerous, feature of international conflicts. 

Future wars will see hackers using computer code to attack an enemy's infrastructure, fighting alongside troops using conventional weapons like guns and missiles.

Right now the combination of an ongoing cyber warfare arms race and a lack of clear rules governing online conflict means there is a real risk that incidents could rapidly escalate out of control. The state of international relations is dominated by the Coronavirus epidemic, causing big problems for governments and organisations who find they now have to manage numerous  homeworking employees.

The cyber security issues have increased significantly as systems security is now under so much more pressure as employees often ignore their organisations cyber security requirements.

Security compliance is the central nervous system of an organisation’s cyber posture. It disseminates intelligence and coordinates offensive and defensive measures to protect the organisation from foreign intrusion. Using artificial intelligence, security professionals can peel away the complex layers of government and shed light on the underlying infrastructure and its vulnerabilities.

Just like normal warfare which can range from limited skirmishes to full-on battles, the impact of cyberwarfare will vary by target and severity. 

In many cases the computer systems are not the final target, they are being targeted because of their role in managing real-world infrastructure like airports or power grids. Knock out the computers and you can shut down the airport or the power station as a result. Cyber warfare takes place at a speed physical warfare is simply incapable of. It is fast, sudden, and uninhibited by the size of forces, complexity of the terrain, location, or the unity of alliances. Rather than relying on a human force, bad actors use automated minions to wreak havoc. 

The speed at which we detect, analyse, and respond to security incidents will affect who wins this war. Blockchain and AI can be used to accelerate the security process.

  • The blockchain’s shared distributed ledger can be used for storing security events and incidents to provide an immutable source of truth.  
  • AI can analyse that data to predict threats based on patterns and anomalies. Humans may be smarter but robots are faster. If supervised correctly, robots can evolve and execute tasks with less bias, fewer mistakes, and reduced downtime.

The greatest security threats to an organisation are the people who operate it. If security is too complex, people will either avoid or circumvent the process. 

In the future the most likely targets are military systems thereby preventing commanders from communicating with their troops or seeing where the enemy is therefore giving an advantage to the enemy. Education is key to promoting organisational cyber security hygiene. Organisations must build a culture of awareness to respond to any crisis, the organisations must constantly measure, assess, and improve the cyber security maturity model. This can be achieved by using AI to analyse the workforce and make strategic, targeting investments to elevate the workforce’s understanding of security.

AI can be used to identify clusters of people who follow security policies as well as those who take shortcuts. Training resources can then be used in a more efficient, targeted manner.

Most developed economies rely on computerised systems for everything from power to food and transport, many governments are very worried that rival states may target critical national infrastructure. Supervisory control and data acquisition (SCADA) systems, or industrial control systems, which run factories, power stations and other industrial processes, are a big target, as Stuxnet showed.

These systems can be decades old and were rarely designed with security as a priority, but are increasingly being connected to the internet to make them more efficient or easy to monitor. 

But this also makes these systems more vulnerable to attack, and security is rarely upgraded because the organisations operating them do not consider themselves to be a target. Recently Britain’s most senior cyber general Gen Sir Patrick Sanders, who heads the UK’s strategic command said the UK possesses the capacity to “degrade, disrupt and destroy” its enemies’ critical infrastructure in a future cyber conflict, in a rare acknowledgement of the military’s offensive hacking capability. 

As the cyber war arms race escalates, none of the suggested cyber-peace initiatives has gained much traction. Critics point out that cyber-attack motives are hard to define, a cyber espionage or reconnaissance intrusion can often look a lot like a cyberwar attack in progress, and determining the identities of the hackers responsible can often be even harder.

What the world needs now is an international treaty to monitor and restrain the possibilities for cyber earfare.

IT Pro:      Oodaloop:       ZDNet:     Wired:       Guardian:

You Might Also Read:

Cyber Warfare, Intelligence & Malware:

 

« Is Big Tech 'Fixing' The US Election?
Iranian Government Agencies Hacked »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

ASIS International

ASIS International

ASIS International is a global community of security practitioners with a role in the protection of assets - people, property, and/or information.

National Defence Radio Establishment (FRA) - Sweden

National Defence Radio Establishment (FRA) - Sweden

The National Defence Radio Establishment (Försvarets Radioanstalt), is the Swedish national authority for Signals Intelligence, also providing Information assurance services to government authorities.

evoila

evoila

evoila GmbH is one of the leading providers in consulting, analysis, implementation and management of cloud infrastructure.

Claranet

Claranet

Claranet are experts in modernising and running critical applications and infrastructure through end-to-end professional services, managed services and training.

Bowbridge

Bowbridge

Bowbridge provides anti-virus and application security solutions for SAP systems.

TCN

TCN

TCN is an advanced System Integrator and Infrastructure Company in Albania.

Fortalice

Fortalice

Fortalice provide customizable consulting services built on proven methodology to strengthen your business cyber security defenses.

SafeTech Informatics & Consulting

SafeTech Informatics & Consulting

Safetech's OTShield detects, prevents and analyses cyber-attacks in SCADA and Industrial IoT systems by utilising state of the art deception techniques.

CoursesOnline

CoursesOnline

CoursesOnline.co.uk is a database listing IT security courses from providers across the UK.

Inetum

Inetum

Inetum (formerly Gfi Informatique) is an agile IT services providing digital services and solutions, and a global group that helps companies and institutions to get the most out of digital flow.

McCrary Institute - Auburn University

McCrary Institute - Auburn University

The McCrary Institute seeks practical solutions to real-world problems in the areas of cyber and critical infrastructure security.

Avancer Corporation

Avancer Corporation

Avancer Corporation is a multi-system integrator focusing on Identity and Access Management (IAM) Technology. Founded in 2004.

Contextual Security Solutions

Contextual Security Solutions

Contextual Security Solutions is a leading provider of penetration testing services and IT security & compliance audits.

Liquis Inc.

Liquis Inc.

Liquis, founded in 2002, is one of the largest facility decommissioning services companies in the U.S.

Knownsec

Knownsec

Knownsec provides customers with cloud defense, cloud monitoring, and cloud mapping products and services with "AI + security big data" as the underlying capability.

Secure Halo

Secure Halo

Secure Halo has been protecting the intellectual assets and sensitive information of the federal government and private sector for 20+ years, through our proactive approach to risk and cybersecurity.