
First published in Vancouver Sun, March 1, 2011
The recent spate of cyber-attacks against Canada, emanating from China, aren’t the first and won’t be the last assaults on Western computer networks, which is why Canada and its closest allies need to get serious about protecting cyberspace. The good news is that military, government and industry leaders in allied countries are already at work applying the principles of collective defense to this newest theatre of operations. The bad news is that the bad guys have gotten a head start.
Some argue that cyber-attacks aren’t a threat to real-world security. They’re wrong. Just consider the worrisome words of the head of the UN agency on information technology, who fears “the next world war could happen in cyberspace,” or ask our friends in
Estonia weathered what some call “Web War I” in 2007, when Russian nationalists unleashed a withering volley of “distributed denial of service” attacks that crashed networks across the country, including those supporting government agencies, media outlets, the mobile-phone system and the country’s largest bank.
A year after Estonia, Russian cyber-militiamen launched a digital invasion ahead of the Russian military’s ground invasion of Georgia, crippling government networks and servers.
If
According to the German government, victimized by massive cyber-attacks in 2007-08, “The People’s Republic of China is intensively gathering political, military, corporate-strategic and scientific information in order to bridge their technological gaps as quickly as possible.”
In fact,
The British government worries that utilities-network upgrades carried out by a Chinese telecom firm may have given
To prevent cyber-skirmishes from triggering real-world conflicts, several nations are calling on the UN to “create norms of accepted behavior in cyberspace,” as The Washington Post recently reported. But given that two of the countries calling for cyber-cooperation are
A more likely source of peace and security in this new frontier is developing the assets, doctrine and resolve to deter and, if necessary, answer in kind cyber-attacks. As Gen. James Cartwright, vice-chairman of the U.S. Joint Chiefs of Staff, has argued, it’s time to “apply the principles of warfare to the cyber-domain.”
Toward that end, NATO’s new Strategic Concept, the first reworking of the alliance’s mission statement since 1999, calls on the allies to enhance their capacity to “defend against and recover from cyber-attacks.” After
Gen. Keith Alexander, who heads the Pentagon’s new Cyber Command, likens “freedom of action in cyberspace in the 21st century” to “freedom of the seas…in the 19th century and access to air and space in the 20th century.” As Adam Smith noted long before there was such a thing as cyberspace, it’s “the first duty of the sovereign” to protect society from “violence and invasion.” What serves as the launching pad for violence, invasion or threat—land, sea, sky, space or cyberspace—diminishes neither the danger nor the sovereign’s duty to confront it.
Of course, cyber-defense is not solely the responsibility of the military. Businesses and civilian agencies play a key role in detecting, preventing and preparing for cyber-attacks.
As it did in defending against the Soviet threat during the Cold War,
The $90 million pledged to protect
These are prudent steps. As Ene Ergma, the speaker of the Estonian parliament, observed after Web War I, “Cyber-war doesn’t make you bleed. But it can destroy everything.”
2902 N. Meridian Street, Indianapolis, IN 46208 | 317.472.2050 | | 501 (c)(3)