Preemptive Cyber Operations Fuel Escalation Risk
US High Threshold for Sovereignty Violations
The Lieber Institute, the Texas Law Review, and the NATO Cooperative Cyber Defence Centre of Excellence (CCDCOE) assert that the United States maintains a high threshold, considering cyber operations a violation of sovereignty only if they cause physical damage, injury, loss of functionality requiring repair, or interfere with inherently governmental functions. The UN Group of Governmental Experts (GGE) consistently affirmed the application of state sovereignty to information and communication technology (ICT) activities in reports from 2013, 2015, and 2021, though these reports did not resolve definitional divergence. "The US Department of Defense views sovereignty as a 'baseline principle' rather than a primary rule that automatically triggers international legal responsibility for every intrusion," the Texas Law Review explains. The Texas Law Review and the Texas National Security Review argue that this interpretation allows the US to conduct persistent, low-intensity operations, such as planting malware, without immediately breaching international law regarding territorial inviolability.
African Union Rejects De Minimis Bar
The NATO Cooperative Cyber Defence Centre of Excellence (CCDCOE) reports that the African Union explicitly rejects a de minimis bar for unauthorized access. Conversely, WICInternet and the NATO Cooperative Cyber Defence Centre of Excellence (CCDCOE) document that France, Iran, and the African Union advocate for a lower threshold, considering any unauthorized penetration or unlawful intrusion into foreign information and communication technology (ICT) infrastructure a sovereignty violation. The Cato Institute and the Miami Law Review discuss how this divergence creates a "liability gap," where US preemptive intrusions, permissible under US doctrine, may be interpreted as hostile acts by states adhering to a lower threshold, exacerbating the security dilemma. The Naval War College and WICInternet point out that this unilateral enforcement challenges the "sovereignty-as-rule" view held by many states, which considers any unauthorized penetration a violation.
US Defend Forward Plants Malware
The Cato Institute observes that US "Defend Forward" strategies routinely involve planting malware and maintaining non-destructive access in foreign systems. The persistent blending of espionage and pre-positioned malware in foreign networks systematically raises the risk of uncontrolled escalation, particularly in critical infrastructure. Adversaries face significant difficulty distinguishing between routine intelligence gathering and preparatory operations for a disabling strike on critical infrastructure because these persistent intrusions are structurally identical, the Cato Institute argues. The Cato Institute warns that detecting US malware in their power grids or military networks may lead adversaries to interpret all persistent cyber operations as escalatory, intensifying the security dilemma and increasing the likelihood of inadvertent escalation. The U.S. Department of State and the Texas National Security Review demonstrate that critical infrastructure sectors, such as energy grids, are highly interdependent and vulnerable, meaning a misinterpreted cyber operation could quickly trigger kinetic responses or broader conflict.
No Treaty Defines Cyber Damage Threshold
The Lieber Institute and Völkerrechtsblog note that no single, universally agreed-upon international legal consensus or formal treaty defines the precise threshold for cyber-induced physical damage versus mere functional disruption. The Lieber Institute and the American Journal of International Law point out that while broad agreement exists that cyber operations causing physical damage, injury, or a loss of functionality requiring repair or replacement constitute a sovereignty violation, most states, including the US, apply a consequence-based approach using a "scale and effects test" to determine if impacts are comparable to traditional uses of force.
US Defend Forward Creates Grey Zone
The Lieber Institute and Völkerrechtsblog observe that a unilateral assertion of operational freedom, while intended to deter, risks fostering a less predictable and more volatile international environment where states operate under conflicting legal frameworks. This unilateral assertion of operational freedom, as the Lieber Institute and Völkerrechtsblog also highlight, risks fostering a less predictable and more volatile international environment where states operate under conflicting legal frameworks, despite its deterrent intent. The persistent blending of espionage and pre-positioning malware in critical infrastructure networks means adversaries are systematically forced to assume the worst, increasing the likelihood of miscalculation, the Cato Institute warns. The U.S. Department of State and the Cato Institute explain that this operational ambiguity, combined with the lack of universal norms, heightens the long-term risk of uncontrolled escalation, potentially leading to kinetic responses or broader conflict triggered by cyber incidents.
Comments ()