Deterrence & Cyber Attacks On The US Electoral System

 

The sanctions and expulsions announced recently against Russia raise important questions about how the United States can effectively deter cyberattacks of this kind in the future, and how effective the measures announced will likely be in doing so.

 

Deterring future cyber-meddling in US elections will require convincing adversaries, Russia and others, that any future such meddling will either be:

A. Ineffective and/or

B. Too costly to be worthwhile.

There are at least two ways to make such operations ineffective:

  • First, the United States could seek to dampen or counter the influence on the actual electoral debate, for example, by swiftly exposing them, a resilience strategy akin to what was sometimes called passive defense during the Cold War.​
  • Second, the United States could seek simply to make such operations impossible by developing highly effective cyber-network defenses, a strategy akin to what was sometimes called active defense.

To make it clear that cyber operations against future elections will be costly, the United States must also demonstrate both a capability and a will to strike back in the future, in other words to punish those states and actors that might contemplate using their cyber capabilities in this way.

Demonstrating a capability to punish is relatively easy, indeed almost unnecessary. The United States has a broad arsenal of military, diplomatic, financial and other means at its disposal to inflict costs on any country that might seek to use cyber tools to interfere in its elections.

Demonstrating the will to do so is much, much more difficult. It requires making clear that the United States judges the stakes at hand to be so important that it would be willing to make use a broad range of tools from its arsenal, even if the costs of doing so were high, to punish future leaders who conducted cyberattacks against US elections.

Given these requirements, how much will the US response help deter future attacks?

On the helpful side, the measures should help make future enemy cyber operations easier to detect and thus riskier and more likely to fail. The Department of Homeland Security and the Federal Bureau of Investigations will now make certain information about Russian cyber capabilities available to the private sector. How much of an effect this will have, however, remains to be seen.

Also on the helpful side, the expulsions and the sanctions impose some cost on the perpetrators while also demonstrating some will on the part of the United States to make some sacrifices because expulsions may eventually be met with reprisals in kind from Moscow, not-with-standing President Vladimir Putin's announcement that he won't retaliate in kind to the expulsions.

Yet whether accepting this cost is enough to impress the Kremlin and deter future action is debatable.

If it truly wishes to deter future action, the United States may thus move toward a stronger declaratory posture by going further in emphasising (publicly and privately to the Kremlin) the very high importance of the integrity of the US democratic process in the future.

The recent White House statement refers to international law and harm to US interests, but it might have stated more forcefully that attacks on the US democratic process are utterly unacceptable and will not be tolerated.

Criticisms of the response on the basis that it does not use existing cyber tools to retaliate are misplaced.

First of all, the US response leaves that possibility open by stating that “we will continue to take a variety of actions at a time and place of our choosing, some of which will not be publicised.” So the United States might still exercise the cyber options it has.

There is no reason to assume that a cyber response is necessarily the best deterrent against cyber-attacks.

If it doesn't, however, that's not necessarily a mistake. There is no reason to assume that a cyber response is necessarily the best deterrent against cyber-attacks. Meanwhile, using existing military cyber tools would have been escalatory while removing options that the United States would better reserve for wartime. Some cyber weapons, once used, can't be used again.

A US cyber operation that exposed corruption within the regime now or later might have some deterrent effect. However, exposing corruption would be mostly cost-free for the United States, so it doesn't underscore US will or stake. It's also difficult to repeat.

A better option would perhaps be to demonstrate a capability to expose corruption, perhaps by exposing the tip of the iceberg, while leaving much of the capability in reserve, to keep the proverbial powder dry so that it can deter future attacks.

A single response does not need to constitute a complete cyber deterrence posture and the measures announced recently should not be judged as such. Effective deterrence in the cyber domain can only emerge out of a consistent set of actions, policies, and declarations over time.

Looking ahead, however, the United States will need to emphasize consistently the importance of the integrity of the electoral process. The time may soon come when the United States needs to demonstrate its willingness to sacrifice to protect it.

Rand:    

Electoral Influence: 40yrs Of Kremlin Interference:       German Spy Chief Fears Russian Interference In 2017 Elections:

 

« Uber Wants Self-Flying Vertical Takeoff Cars
How To Automate Cyber Defense »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

Assure Technical

Assure Technical

Assure Technical offers a holistic approach to Technical Security. Our expertise and services span across the Physical, Cyber and Counter Surveillance domains.

Ridgeback Network Defense

Ridgeback Network Defense

Ridgeback is an enterprise security software platform that defeats malicious network invasion in real time. Ridgeback champions the idea that to defeat an enemy you must engage them.

AFCON Control & Automation

AFCON Control & Automation

AFCON is a leading global provider of software solutions and services for the smart management of Control & Automation systems in the age of Digital Transformation.

Basis Technology

Basis Technology

Basis Technology provides software solutions for text analytics, information retrieval, digital forensics, and identity resolution.

SEWORKS

SEWORKS

SEWORKS provides offensive and defensive app security that ensures mobile and web apps are safe from dangerous hacking threats.

Modux

Modux

Modux focus on a number of core competencies across cyber security including; cyber intelligence & analytics, penetration testing and training.

Bridewell

Bridewell

Bridewell provide cost effective Security & Risk Assurance Services across Information Security, Cyber Security, Technology Risk, Security Testing and Data Privacy.

CultureAI

CultureAI

CultureAI deliver intelligent cyber security awareness education and tools that build resilient security cultures where employees help defend.

Combined Selection Group (CSG)

Combined Selection Group (CSG)

CSG are Global Talent Experts, we operate across 7 specialist sectors, including Information Technology and Cybersecurity, and take a pro-active approach to executive search and headhunting.

Ordr

Ordr

Ordr Systems Control Engine. The first actionable AI-based systems control engine for the hyper-connected enterprise. You’re in control.

Kintent

Kintent

With Kintent, compliance becomes a habit, is simple to understand and achieve, and is continuously testable so that your customers can see that you are adhering to all your trust obligations.

Stronghold Cyber Security

Stronghold Cyber Security

Stronghold Cyber Security is a consulting company that specializes in NIST 800, the Cybersecurity Framework and the Cybersecurity Maturity Model Certification.

FCI

FCI

FCI is a NIST-Based Managed Security Service Provider (MSSP) offering Cybersecurity Compliance Enablement Technologies & Services to Financial Services organizations.

The Security Bulldog

The Security Bulldog

The Security Bulldog distills and assimilates open source cyber intelligence to enable security teams to understand threats more quickly, make better decisions, and accelerate detection and response.

NormCyber

NormCyber

NormCyber provide award-winning cyber security and data protection as a service for midsize organisations.

HYCU

HYCU

HYCU was born of the need to simplify data protection and provide equivalent levels of backup and recovery support across on premises, public cloud, and SaaS workloads.