Self-Help in Cyberspace: Defining the Scope and Limits of Private Sector Cyber Defense

No ratings

Presented at CODEBLUE2018@TOKYO 2018 by

Cyber attacks targeting the private sector are increasingly frequent, widespread, and severe. Yet the roles and responsibilities of governments and the private sector for cyber defense remain largely ambiguous. In the absence of sufficient governmental protection, corporations worldwide have begun to explore or engage in aggressive defensive activities to combat sophisticated cyber threats. This includes certain "active cyber defenses," often of questionable legality. An emerging transnational market for such services threatens to create a gap in global governance of risky and destabilizing activities such as "hacking back." This presentation centers on the need for international rules of the road to define the proper scope and limits of private sector "self-help" in cyberspace. Drawing from a range of historical experiences with governance of similar private sector security activities in the physical world, this presentation explores pragmatic approaches to circumscribing the space for defensive activities and promoting responsible conduct. The objective here is not to resolve the complex legal dilemmas raised by these activities but to outline a pragmatic approach toward shaping the incentive structure for private sector behavior.