Last week’s disclosure of the Pentagon’s position on cyber warfare and the integration of cyber into the general strategy for conflict spurred a ton of conversations. While this comes as no surprise to most individuals involved in the vast and rapidly expanding cyber conflict domain, some familiar concerns have been raised once again.
First is attribution. Tracing cyberattacks to their true source continues to be challenging. To increase the level of confidence in these actions require integration of “all source intelligence” and will not likely rely solely on cyber forensics. Do we have the cyber forensic capabilities in conjunction with the intelligence for cyberattack attribution to the level that this is required?
Second is another familiar topic: the degree of vulnerability of the U.S. critical infrastructure. Vulnerabilities and other risks and exposures of the U.S. critical infrastructure appear in the media in a much too frequent basis – daily! If the U.S. military used cyber weapons in a conflict, there is a high degree of likelihood that a retaliatory strike would be very likely to take place. Given the frequency of vulnerability disclosures – is the U.S. military prepared to defend our critical infrastructure that is privately owned?
The third topic is interesting to say the least. Given the Pentagon’s strategy and all the reports that military recruiters are targeting Silicon Valley for resources – scarce resources in a limited talent pool will be stretched even further. One comment really struck me and that was “It looks like tech start-ups in general and the valley specifically are now competing with the Pentagon to attract the technical talent they want/need.” If start-ups and Silicon Valley are now in competition for tech talent who do you think would win? This brought back the topic of a cyber draft!
Things are certainly getting more interesting by the second.




