Few people would dispute it is becoming more difficult to keep up with the pace of change in the cyber domain. Many organizations have come to recognize the risks of falling behind in this area. This is multi-faceted and includes creative development of innovative products and services that will drive our economy as well as a national security policy that addresses the cyber domain. This is no small undertaking.
However, some in the defense/intelligence community have lost their patience waiting for this guidance. Just recently, James Clapper, the Director of National Intelligence James Clapper, was said to be “seeking an explanation for the administration’s delay in developing a cyber deterrence policy and utilizing the many tools available to it to achieve substantive deterrence.” A lofty objective to be sure — particularly given the pace of change.
Given the tools and techniques that are commonly employed to obscure the true identity of those that are really behind the attack, some serious concerns have begun to surface. This is the soft-spot when it comes to a cyber deterrence policy. There are those that believe a cyber deterrence policy will become a potent deterrent for those looking to launch cyberattackers against U.S. systems by warning/intimidating the malicious actors with the threat of a substantive response by the United States. However, such a policy has soft spots, such as how tools and techniques commonly obscure the true identity of perpetrators. Now Or consider cyber deterrence in the context of responding to a virtual state/entity like Anonymous. What is there to attack? There are no real physical assets or hard cyber assets – only their members.
While these are certainly examples of the limitations of a cyber deterrence policy, that does not mean there is not value from using a well-crafted policy as a deterrent.! Nor would this be This is not a one-and-done type of policy. Given the pace of change in the cyber domain, this will surely need to be updated frequently.




