From: Carnegie Endowment for International Peace
Wyatt Hoffman, Ariel (Eli) Levite
Faced with limited capacity and resources, governments need to develop a complementary, legitimate space for private sector active cyber defense.
The cyber revolution and ever-growing transfer of human activities into the virtual world are undermining the social contract between modern states and their citizens. Most governments are becoming unable and unwilling to protect citizens and private enterprises against numerous, sophisticated cyber predators seeking to disrupt, manipulate, or destroy their digital equities. Inevitably, states are focused on protecting governmental assets and national infrastructure, leaving themselves with modest residual capacity and resolve to underwrite other cybersecurity risks. Faced with this reality, private entities are reluctantly but increasingly complementing their passive cybersecurity practices with more assertive “active cyber defense” (ACD) measures. This approach carries substantial risks, but if guided by bounding principles and industry models, it also has the potential for long-term, cumulative benefits.
Regulating an Emerging International Market
The limitations of governance. States are struggling to find a viable formula to regulate emerging private sector cyber activity. The challenge is compounded by the global and rapidly evolving nature of the cyber domain. Consequently, in many countries, national laws governing this space are either absent, vague, or difficult to operationalize. International understanding and conventions to harmonize national responses are also largely absent, complicating efforts to manage cross-border incidents with political ramifications.
Leave a Reply