US Must Project Cyber Warfare Capabilities to Deter Attacks

The United States must demonstrate its cyber warfare capabilities to help deter sophisticated attacks from Russia and other adversaries while building strategies on a battlefield still misunderstood by commanders and senior officials, a panel of defense experts told lawmakers recently.

"Cyber operations are a legitimate means of projecting national power, especially when proportionately supplemented by kinetic force, and we should advertise them accordingly," retired US Navy Admiral James Stavridis, the former leader of European Command, told the Senate Armed Services Committee in prepared remarks.

Russia, North Korea, China and other nations launch sophisticated attacks against the United States, including attempts to destroy infrastructure and undermine credibility of elections in America and France, Stavridis said. And the United States is often sheepish to strike back in shows of force, he added.

"Unwillingness to operate offensively in cyber-space is driven less by a fear of retaliation and more by a fear of compromising our intelligence community's sensitive tradecraft," he said.

Retired Air Force General Michael Hayden, former director of the CIA, said there is still a lack of consensus in the United States and the international community about what kinds of attacks warrant a response, and outdated thinking still suggests cyber assaults require an in-kind digital response, when other measures, such as conventional military strikes or sanctions, might be more appropriate. "One way to recognise practice is to practice," Hayden said.

In response to Russian election interference for example, the United States could have disrupted bank accounts linked to Russian oligarchs and revealed the extent of President Vladimir Putin's finances and property, Stavridis said.
Recent protests have rocked Russia following allegations of embezzlement by Prime Minister Dmitry Medvedev, and overt jabs over the wealth of Russian leaders would undermine the government there, he said.

Crippling intelligence-gathering networks would also restrict Putin's ability to surveil his own people, Hayden said, at a crucial time when he seeks to squash dissent.

James Clapper, former director of national intelligence, stressed throughout the hearing about shortfalls within the government to anticipate the response of adversaries once cyber operations are launched. "We can't count on equal or symmetrical retaliation," he said.

Senator John McCain, the committee's chairman, opened his remarks for the hearing with a quip signaling his frustration with a lack of vision and cohesion in cyber operations in the military and intelligence communities.
"The committee meets today to receive testimony on cyber policy, strategy and organisation, of which there is very little," McCain said.

His remarks are an echo of a hearing held in early May, when McCain said: "Our nation remains woefully unprepared to address these threats."

The panel offered various reasons why the United States appears unprepared to strike and vulnerable to attack in the cyber domain, chief among them is a lack of coherent guidance and command that is spread throughout the military branches and intelligence agencies, which results in redundancies and overlap.

Clapper and other officials have urged the separation of the National Security Agency and Cyber Command, the so-called "dual hat" organization led by Navy Adm. Michael Rogers, that has become too big for one commander, Clapper said.
Those organisations have different missions, Cyber Command focuses on offensive and defensive strikes while NSA's main efforts are in spying and intelligence-gathering, Stavridis said. Elevating the cyber mission to full combatant command would crystalise doctrine and send a message to adversaries on the seriousness of the United States to execute missions, he said.

The experts and members of the committee voiced the need for President Donald Trump to provide guidance in cyber operations after he missed a self-imposed deadline to deliver a strategy within 90 days of his inauguration. Shortly after the hearing concluded, Trump signed an executive order "aimed at strengthening the federal government's cyber security and protecting the nation's critical infrastructure from cyber-attacks," Reuters reported.
McCain reiterated concerns recently voiced by service chiefs that a disparate focus and investment in cyber warriors in the military leaves talent untapped and later poached by the private sector. "I don't see a clear career path for cyber warriors," he said.

Stavridis said none of the 126 airmen who recently completed their first tour with the Pentagon's cyber mission force were retained for a second tour. The Defense Department launched the initiative last year to consolidate forces in order to defend its networks, support commanders and protect US infrastructure. It staffs 5,000 troops across 133 teams as of October, according to a Pentagon news release. All 126 of those airmen were reassigned to Air Force missions "with no cyber nexus whatsoever," Stavridis said in written testimony.

Recent attacks have converged across the public and private sectors, targeting US power companies and corporations such as Sony, for instance, which became a victim of North Korean hacking.

The blurring of lines could lead to a Coast Guard-like cyber operations entity in the future, Clapper and the other experts suggested, which would blend military and law enforcement capabilities with an arm that occasionally responds to attacks affecting private citizens and businesses.
"We're kind of on the beach at Kitty Hawk," Stavridis said. "We have some work ahead."

Military.com

You Might Also Read:

Intelligence In The Age of Cyber Warfare:

Germany May Go Offensive After Russian Cyber Attacks:

National Security Chief Talks About The UK’s Cyber Dangers:

The Limits Of Cyber Warfare:


 

« Attitudes To Facebook Are Changing
A Major Development in Deep-Learning »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

Directory of Cyber Security Suppliers

Directory of Cyber Security Suppliers

Our Supplier Directory lists 7,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

SCADAhacker

SCADAhacker

SCADAhacker provides mission critical information relating to industrial security of SCADA, DCS and other Industrial Control Systems.

DFLabs

DFLabs

DFlabs is a pioneer in Security Automation & Orchestration technology, leveraging your existing security products to dramatically reduce the response and remediation gap.

Dubai Electronic Security Center (DESC)

Dubai Electronic Security Center (DESC)

Dubai Electronic Security Center (DESC) was founded to develop and implement information security practices in Dubai.

CYE

CYE

Utilizing data, numbers, and facts, CYE helps security leaders know what business assets are at risk and execute cost-effective remediation projects for optimal risk prevention.

H3Secure

H3Secure

H3 Secure focuses on Secure Data Erasure Solutions, Mobile Device Diagnostics and Information Technology Security Consulting.

Rezilion

Rezilion

Rezilion is a stealth mode cyber-security start-up developing a cutting edge technology that makes cloud environments self-protecting and resilient to cyber-attacks.

EVOKE

EVOKE

EVOKE is an award-winning Digital Transformation company that partners with its clients to build digital workplace solutions for organizational challenges.

Mobileum

Mobileum

Mobileum is a leading provider of Telecom analytics for roaming, security and risk management and end-to-end domestic and roaming testing solutions.

Deft

Deft

Deft (formerly ServerCentral Turing Group) is a trusted provider of colocation, cloud, and disaster recovery services.

Winbond Electronics

Winbond Electronics

Winbond is a Specialty memory IC company. Product lines include Code Storage Flash Memory, TrustME® Secure Flash, Specialty DRAM and Mobile DRAM.

Vala Secure

Vala Secure

Vala Secure is a cybersecurity and compliance consultancy that always stays ahead of regulations, future threats and ever-changing security environments.

Security BSides Cayman Islands

Security BSides Cayman Islands

Security BSides is a non-profit, community-driven event built for and by information security community members. Our aim is to help build an Information Security community in the Cayman Islands.

OSP Cyber Academy

OSP Cyber Academy

OSP Cyber Academy are a managed service provider of cyber, information security and data protection training.

AVANT Communications

AVANT Communications

AVANT is a premier distributor of next generation technologies with the resources and relationships needed to successfully navigate the ever-changing world of communications and IT infrastructure.

Winslow Technology Group (WTG)

Winslow Technology Group (WTG)

Winslow Technology Group is a leading provider of IT Solutions, Managed Services, and Cybersecurity Services dedicated to providing exceptional business outcomes for our customers since 2003.

Dynamic Standards International (DSI)

Dynamic Standards International (DSI)

Dynamic Standards International is a global standards development organization which develops certifiable ‘dynamic standards’ that pace with fast-evolving landscapes.