As cyberattacks become more sophisticated and in some cases more destructive, at what point should the U.S. flex its muscles and say enough is enough?
Members of two House Oversight and Government Reform subcommittees sought to answer that question during a July 13 hearing on what cyber incidents should be considered acts of war and how the U.S. should respond.
Watch: Digital Acts of War — Evolving the Cybersecurity Conversation
Rep. Robin Kelly, D-Ill., ranking member of the IT Subcommittee, pointed to the indictment of seven Iranian nationals in March who are charged with breaching the network of a dam in suburban New York. Fortunately, the compromised computers were not connected at the time to the slough that controls water flow at the time. And, if it were, the dam in question is minor and couldn’t cause much damage.
“While the attack might not have targeted the nation’s vital infrastructure, it is almost certain that future attacks will,” Kelly said. “And when that does happen, how will we react? Do we hack the hackers or do we respond with physical force?”
Retired Gen. Keith Alexander, who formerly served as director of the NSA and commander of U.S. CYBERCOM and is now president and CEO of IronNet Cybersecurity, agreed we need clarity on these questions, if for no other reason than to prevent a vigilante reprisal.
“If we think about Sony firing back … that could get us into a war on the Korean peninsula,” he said, referencing the hack of Sony Pictures Entertainment in November 2014. “We don’t want that to happen. This is an inherent government responsibility, that means the government needs the ability to fire back when appropriate.”
There is a science to determining whether to respond, based partially on international norms, including a country’s right to defend itself.
“Cyberattacks are not necessarily armed attacks for the purpose of triggering a nation-state’s inherent right to self-defense,” DoD Deputy Assistant Secretary for Cyber Policy Aaron Hughes said.
Cyberattacks could rise to the level of an armed attack depending on the “nature and extent of injury or death to persons and the destruction of or damage to property,” he added, noting, “Cyber incidents are assessed on a case-by-case basis.”
Establishing a singular policy about what would trigger a kinetic or otherwise proportional response is trickier, though.
Nation-states don’t normally define redlines — specific actions that would lead to all-out war — in the other, physical domains, according to Chris Painter, State Department coordinator for cyber issues.
“And there’s no reason cyberspace should be different,” he said. “In fact, strategic ambiguity could deter most states from getting close to the threshold of an armed attack.”
But there is some guidance out there, mainly in the form of an international framework developed in 2011.
“The International Strategy for Cyberspace sets out a strategic framework for international cyber stability designed to achieve and maintain a peaceful cyberspace environment where all states are able to fully realize its benefits; where there is advantage to cooperating against common threats and avoiding conflict; and where there is little incentive for states to engage in disruptive behavior or attack one another,” Painter said.
The strategy benefits from three elements, he added:
“First, the affirmation that existing international law applies to state behavior in cyberspace. Second, the development of international consensus on and promotion of additional voluntary norms of responsible state behavior in cyberspace that apply during peacetime. And third, the development and implementation of practical confidence building measures — or CBMs — among states.”
When those lines are crossed, to-date the only responses from the U.S. have been indictments and economic sanctions.
Peter Warren Singer, strategist and senior fellow at New America, said indictments have value, not always because they lead to actual prosecutions but because they act as a means of publicly attributing an attack. But there are stronger options available that still fall short of dropping bombs.
“Creativity and flexibility will beat simplicity in this dynamic,” Singer said in his opening remarks. “Indeed, we may even steal ideas from one attacker’s playbook and apply them against another as a deterrence tool. From Snowden to Sony, data dumps have been among our most vexing cybersecurity incidents but they have not threatened our core national interests. By contrast, threatening to reveal the private financial data of an authoritarian regime’s leader, his family or allied oligarchs may be far more potent than a counter cyberstrike. We can sometimes see what regimes fears most by what they ban discussion of.”
At the same time, Singer chastised the administration and the international community as a whole for not responding more harshly to Russia attacking the Ukrainian power grid late last year.
“Norm building is not just about identifying which sorts of attacks should or shouldn’t be allowed to happen. It’s also for us to identify sorts of targets everyone can agree should be off limits,” he said.
But norms are degraded when there aren’t consequences for violating those standards, such as “the failure of the U.S. and international community to respond to the December hack of the Ukrainian power grid.”
“This is the first proven takedown of this kind,” Singer said. “It’s the long-discussed nightmare scenario. It’s a violation of a widely agreed norm not to target civilian infrastructure with the intent to cause widespread and disproportionate damage. And yet, in the story of action and consequence, we’ve had action, so far we’ve had no consequence.”




