metamorworks

We Need a NATO/EU for Cyber Defense

The world’s democracies aren’t properly organized to fend off today’s authoritarian attacks, let alone reshape the internet and key industries to stop tomorrow’s.

The role of military cyber is expanding in the westernized democracies, from simply protecting the militaries’ own networks to supporting the national cyber defense of their economies. Whole-of-society defense strategies and more tightly integrated civil-security forces relations have emerged. These national efforts are critical to the survival of democratic societies in an increasingly cyber-enabled authoritarian world, but they do not go far enough.

Now is the time to take these internal civil-military defense efforts to the next step. We must build a NATO/EU equivalent for the cyber conflict age — call it a Cyber Operational Resilience Alliance, or CORA — to defend across the whole of the democratic community. 

Although NATO is building cooperation and coordination among the cyber components of allied militaries, it is not designed to tie together whole-of-society efforts to protect civil commercial infrastructure and the economic system that it sustains. And the EU is not designed for defense missions coordinating processes from intelligence to proactive coordinated operations. 

A CORA would operationally blend the cyber defense actions of aligned nations with the critical roles played by the telecommunications networks that provide the cyber backbones to these nations and by the critical IT capital goods industries that provide the tools, talent, and equipment that enable national cyberspaces to function. It would integrate these sectors to the extent needed for a shared cyber defense of these democratic allies for the near term. And it would buy time for a vital transformation: rebuilding the democracies’ share of cyberspace into a defensible substrate.

Related: An Alliance Too Far: The Case Against a Cyber NATO

Related: Rethink 2%: NATO ‘Defense Spending’ Should Favor Cyber

Related: In Cyberspace, Governments Don’t Know How to Count

After winning the Cold War, western powers slumped into complacency. The internet rose on infrastructure built with minimal concern for security. Cyberspace is now being exploited, literally to death, by a tsunami of state and nonstate actors. The internet is rapidly being fragmented into national cyber jurisdictions, responsibilities, and obligations. The free, open, safe, and globally available internet created in the democracies is dying.

For the first time, the United States and its allies face adversaries able to reach into all layers of the socio-technical-economic system through cyberspace at will, over time, deceptively, and opaquely. These adversaries can steal (or alter) critical information, using it to bury, bribe, bully, or blackmail corporate and political leaders. And they can leave backdoors to allow future actions from theft to destruction.

Rising authoritarian adversaries have developed “not directly kinetic but no less disruptive” campaigns intended to “hollow out” economic rivals. These include using state proxies to subvert democracies by slowly displacing or buying up their IT capital goods and telecommunications industries. There is no guarantee that in twenty years any democratic nation will have the resources in talent, technologies, and institutional will to counter authoritarian demands in technology or policy choices.

The overwhelming scale and variety of malignant cybered challenges – especially those by authoritarian states, their corporate state-champion proxies, and huge state-encouraged patriotic or mercenary criminal classes – have overmatched Western civil societies. The economic losses – estimated at 1 to 2 percent of annual GDP across the U.S. and her allies and partners – are alone enough to hamper the western democratic community in their efforts to secure their national cyberspace assets.

Western leaders are slowly making efforts to reverse the tide. The United States has at last included the defense of its economy as a national security mission for its key cyber unit. A handful of nations, France most recently, have recognized that defending their economies may require actions previously forbidden, such as persistently proactive cyber actions against foreign perpetrators. 

But individual national steps are insufficient. No single state, not even the United States, can resist the whole of the authoritarian world’s cyber onslaughts. So CORA’s first mission is to consolidate the cyber infrastructure of democracies. 

Why is scale important? The democratic community needs an IT capital goods industry and a telecommunications industry that can operate independently of the authoritarian world. The only practical way to do this is to create a market large enough to sustain them. The 35 or so nations that would form CORA would represent a market of more than 900 million people free of authoritarian proxy corporate subversion, hostile or coerced ownership, or tainted market competition.

After ensuring their survival, CORA would push these industries to reinvent the internet with products and protocols engineered from the outset for security. The organization would organize a massive joint investment in academic, commercial, and military cybersecurity R&D, shepherd a new internet into being, and foster the operational civil-military-commercial partnerships that would keep its members safe.

Operationally, CORA would coordinate the cybersecurity processes of governments, companies, organizations — and militaries. Coordinating the latter will enable more comprehensive tracking, analyzing, and modelling of threats; and the development of better ways to defend the government, commercial, and civilian sectors. CORA will integrate the various capabilities and skills of its members’ militaries, putting each to optimal use and organizing support and training as needed.

Militaries in a CORA would have much closer relations with their civilian peers through the joint operations, each contributing through the overarching framework and advancing in cyber competence collectively. The cyber defenders of the telecommunications backbone organizations operate and defend the cyber infrastructure of communities, with the IT capital goods providers generating the product design, maintenance, and commercial actors key to the health of the allied shared IT market. The researchers and students of the universities and labs would be the basic source of the transformation research. Policymakers would provide complementary legal regimes and overarching statutory guidance, as well as funding for both defense and transformation research expenses. 

But the CORA must be, first and foremost, be an operational alliance, not a planning, discussing, policy-exhorting group. Only such an organization will ensure that its member nations can act in unison with respect to system-wide socio-technical-economic cybered threats. Defense threat analysts would work with all three types of organizations directly and across allies to ensure a collective awareness of and response to emerging threats, campaigns, defense gaps, and losses and successes. Cyber defenders would operate in response to or in anticipation of attacks through joint allied centers or in national operations centers hosted by states designated as leads in specialized capacities. 

As goes the democracies’ collective cyber defense, so goes the United States’ future wellbeing. An international CORA is vital.

All the ideas in this work are solely those of the author and do not reflect the position of any element of the U.S. government.

X
This website uses cookies to enhance user experience and to analyze performance and traffic on our website. We also share information about your use of our site with our social media, advertising and analytics partners. Learn More / Do Not Sell My Personal Information
Accept Cookies
X
Cookie Preferences Cookie List

Do Not Sell My Personal Information

When you visit our website, we store cookies on your browser to collect information. The information collected might relate to you, your preferences or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. However, you can choose not to allow certain types of cookies, which may impact your experience of the site and the services we are able to offer. Click on the different category headings to find out more and change our default settings according to your preference. You cannot opt-out of our First Party Strictly Necessary Cookies as they are deployed in order to ensure the proper functioning of our website (such as prompting the cookie banner and remembering your settings, to log into your account, to redirect you when you log out, etc.). For more information about the First and Third Party Cookies used please follow this link.

Allow All Cookies

Manage Consent Preferences

Strictly Necessary Cookies - Always Active

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data, Targeting & Social Media Cookies

Under the California Consumer Privacy Act, you have the right to opt-out of the sale of your personal information to third parties. These cookies collect information for analytics and to personalize your experience with targeted ads. You may exercise your right to opt out of the sale of personal information by using this toggle switch. If you opt out we will not be able to offer you personalised ads and will not hand over your personal information to any third parties. Additionally, you may contact our legal department for further clarification about your rights as a California consumer by using this Exercise My Rights link

If you have enabled privacy controls on your browser (such as a plugin), we have to take that as a valid request to opt-out. Therefore we would not be able to track your activity through the web. This may affect our ability to personalize ads according to your preferences.

Targeting cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.

Social media cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks. They are capable of tracking your browser across other sites and building up a profile of your interests. This may impact the content and messages you see on other websites you visit. If you do not allow these cookies you may not be able to use or see these sharing tools.

If you want to opt out of all of our lead reports and lists, please submit a privacy request at our Do Not Sell page.

Save Settings
Cookie Preferences Cookie List

Cookie List

A cookie is a small piece of data (text file) that a website – when visited by a user – asks your browser to store on your device in order to remember information about you, such as your language preference or login information. Those cookies are set by us and called first-party cookies. We also use third-party cookies – which are cookies from a domain different than the domain of the website you are visiting – for our advertising and marketing efforts. More specifically, we use cookies and other tracking technologies for the following purposes:

Strictly Necessary Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Functional Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Performance Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Social Media Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Targeting Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.