Cyber Persistence Theory provides the most detailed exposition yet of the sophisticated concepts underlying “defend forward” – or “persistent engagement” to use its wonkier name. The book is a relatively short read (157 pages of text and 55 pages of footnotes), but it’s not always an easy one. The argument is rigorous and dense.
It’s also strikingly ambitious. The book claims to offer no less than a new paradigm for cyber security. It argues the unique features of networked computing and its digital interfaces have created a security environment completely unlike those of conventional or nuclear security. Concepts borrowed from those realms, such as coercion and deterrence, don’t help understanding the specific logic of cyber security. Cyber space is “macro-resilient (and thus stable) and micro-vulnerable (and thus inherently exploitable)”. It’s resilient partly because the internet was, after all, the product of an effort to eliminate single points of failure in US nuclear command and control. It’s vulnerable because the technology was designed, from the outset, to expedite rather than deny access.
States seeking to improve their security in cyberspace have an incentive to exploit its micro-vulnerabilities and the book records how they are doing so. But this constant competition to shape and reshape cyberspace only rarely involves direct engagement between states. Rather, it is taking place through a series of unilateral faits accomplis. Efforts at cyber deterrence have failed because cyberspace is an environment of exploitation rather than coercion. Attempts to categorise cyber operations as “defensive” or “offensive” are similarly missing the point, as the authors note:
If I track an active breach of my network and simultaneously protect aspects of that network, but allow access to other sectors of the network to understand … the opponents and then use information gained to enhance a prepositioned set of code and execute my own exploitation of the opponent’s system all in a simultaneous set of manoeuvres that take effect in a matter of minutes, if not seconds, at what point am I playing defence and at what point offence?
In this environment, states that take the initiative and act quickly to shape cyberspace in their favour will be rewarded. A purely defensive strategy won’t work because it cedes the initiative to other actors. Although states could, theoretically, simply disconnect from cyberspace, this would also preclude them from enjoying its many benefits and weaken overall security.
The authors are perhaps too sanguine about the risks of escalation and the corrosive effect of persistent competition. They argue that the absence, so far, of a cyberattack that has the effect of an armed attack is not just luck: the structure of cyberspace encourages competition below the threshold of armed conflict. But if the book is right to argue that “competition below the level of armed conflict is just as consequential strategically as war and territorial aggression” then perhaps we should be more worried about constant competition between keyboard warriors in the United States, China, the United Kingdom, Russia, Israel, Iran and North Korea.