Agile Cyber Deterrence: Policy Options for Cyber Middle Powers against Strategic Cyber Attacks

No ratings

Presented at CODEBLUE2018@TOKYO 2018 by

The escalating global cyber threat environment requires a revision of obsolete national cyber strategies, especially in regards to Cyber Middle Powers - such a Japan’s and Germany’s - policies and capabilities. While other nations such as the US and China have already formulated new cyber deterrence strategies and doctrinal approaches, Germany is still in the testing phase for new cyber strategy models such as KdoCIR (the new German Military Cyber Command) and AIC (the new German DARPA-like organization for disruptive Cyber Research Projects). I am one of the architects of AIC and want to talk about the deliberations behind these new developments.Starting point is the realization that every digitally connected nation needs an effective answer to strategic cyberattacks. If traditional cyber defense models do not provide answers in the sense of deterrence and cost imposition for the strategic aggressor, a broad, inclusive cyber deterrence theory and practice based on an emerging, integrated mix of in-domain and out-domain measures (defensive and offensive in nature) will become necessary. This is what we call “Agile Cyber Deterrence“. This then leads to the question of how exactly such a strategy could look like on the policy and operational level? My research is based on interdisciplinary work and comparative analysis of cyber conflict data and was conducted mainly at the ISPK and Fraunhofer SIT in Germany. According to our results, a) Cyber operations have introduced a completely new way to distribute power, b) The special virtual (technological) character of the operative domain "cyber" requires a new approach to classic deterrence models,and c) Cyber strategists must go beyond the obsolete concept of isolated critical infrastructures and confront cyber security as a systemic risk affecting every actor, from the military to companies, to private citizens.To do so, we have developed four agile deterrence pillars which I will present in my talk in detail:1.The development of an emerging taxonomy describing which types of activities the new model should prevent, 2.The development of preventive mechanisms and capabilities, 3. The development of cost imposition mechanisms and capabilities, 4. The development of auxiliary measures and capabilities.