One thing you can say about the cyber conflict domain it is that is continuously changing and last week was no different. Last week ADM Mike Rogers, director of the National Security Agency, told the Senate Armed Services Committee, “We need to think about how do we increase our capacity on the offensive side to get to that point of deterrence?”
That is a very tall order given the cyber capabilities of several other nations and the pace with which this domain is changing. How many warnings must we be given by those that have a clear and complete picture (classified side and unclassified private sector side) before we do what we need to do to at least keep up with this threat, much less get ahead of the threat?
What will it mean to increase our capacity on the offensive side? There are a few sure things we can count on. One of the top things would be to increase the research and development of advanced cyber weapons. Another sure thing would be to work with our close allies to increase our cyber threat intelligence capabilities. Another much more controversial area focuses on recruiting individuals specifically to fill roles in our offensive cyber capabilities. That will be a challenge for several reasons. One individual I spoke with suggested that a specific cyber draft might not be that far-fetched an idea.
The final area that is gaining supporters is to train and allow critical infrastructure providers the ability to return fire in the cyber domain if they are attacked. There are passionate, well thought out arguments on both sides of this issue for sure. One side says vigilante activities have no role in our approach to addressing cyber capabilities. Those on the other side point to the right of self defense and say that if the government can’t protect us we need to protect ourselves.
One survey found that over a third of those asked admitted to returning fire in cyber space. I myself had to notify certain government entities when I discovered that when one company returned cyber fire it attacked an unwilling and unknowing intermediary whose servers had been compromised and used by others in the attack; and of course, the company they targeted and hit with return fire was in a foreign country.
This entire area of offensive measures in cyber space is one area that everyone must monitor very closely!




