The Attack We Knew Was Coming
The Bulwark · C · trust 38/100

Effectively defending against cyber threats against critical infrastructure requires a long-term commitment of political will.
Mark Hertling August 4 Upgrade to listen 11 minutes 295 44 49 The East Bay Municipal Utility District Wastewater Treatment Plant in Oakland, California. (Photo by Justin Sullivan/Getty Images) WHEN REPORTS EMERGED LAST WEEK that hackers had penetrated water systems across multiple American states , public attention immediately turned to the question of responsibility. Was it Iran, Russia, China, or—as President Trump wildly suggested —Democrats within the affected states? While Iranian-affiliated cyber actors are widely considered the leading suspects, federal investigators have yet to make a formal attribution. More importantly, so far there is no evidence that drinking water has been contaminated or that public health has been endangered. What the attacks did demonstrate, however, was that malicious actors have the capacity and, at times, desire to compromise the operational systems that control essential public infrastructure.
Yet the greatest significance of these attacks lies not in their novelty but in their familiarity. For those who have spent careers in the military or national security space, the reports were unsurprising: The attacks represent precisely the kind of threat that American strategists and analysts have anticipated for more than two decades. Long before cyberwarfare entered the public vocabulary, successive administrations, military planners, and allied governments repeatedly warned that America’s greatest vulnerabilities would not necessarily be found on distant battlefields but at home, embedded within the civilian infrastructure that underpins modern society.
That conclusion has appeared consistently in a range of national security planning documents, in various threat assessments by all agencies, and within the National Cybersecurity Strategy. The specific language has evolved over the years, but the underlying assessment has remained strikingly consistent. America’s critical infrastructure—including energy grids, communications systems, transportation networks, financial institutions, health care ecosystems, pipelines, and water systems—would become targets for adversaries seeking strategic advantage while avoiding direct military confrontation. These systems support every other element of national power while often remaining lightly defended compared with traditional military targets, which makes them soft targets.
Within the military, recognizing this has fundamentally changed how campaigns are planned. Leaders no longer view cybersecurity as a technical specialty to be delegated to communications experts after operational plans have been completed. Instead, it has necessarily become an integral part of campaign design from the outset. While joint doctrine describes offensive cyberspace operations, defensive cyberspace operations, and the operation of the Defense Department’s own information networks as distinct missions, commanders tend to think about cyber in broader operational terms. More and more, however, the military integrates cyber capabilities into comprehensive campaigns in which diplomacy, intelligence, economic pressure, information operations, and military force are all synchronized to achieve strategic objectives. Cyber has become another asymmetric capability available and integrated into virtually every modern campaign plan rather than treated as a supporting specialty.
Some cyber operations are conducted independently to collect intelligence, penetrate networks, or create strategic effects without employing conventional military force. Others directly support combat operations by disrupting the enemy’s command-and-control systems, logistics networks, air defenses, or communications, thereby allowing friendly aircraft, ships, and ground forces to maneuver inside the disrupted space.
The strategic evolution of cyber operations reflects a broader truth about contemporary conflict: Adversaries no longer need to destroy a nation’s military to impose real strategic costs; they can instead undermine the systems upon which civil society itself depends. On the face of it, a water-treatment facility may appear to have little connection to national defense until one considers the cascading consequences of disabling it. Hospitals rely upon clean water. Fire departments rely upon water (and water pressure). Manufacturing plants depend upon reliable municipal systems. Citizens expect government to provide potable water every day without interruption. Even a temporary disruption to that confidence forces governments to divert resources, commands attention at the highest political levels, and reminds the public that essential services are more fragile than they are believed to be. The strategic objective is often less about physical destruction than about eroding confidence and trust in government and its institutions. A cyber attack that causes the public to question its drinking water, for example, becomes psychological as much as operational.
WHILE SERVING AS CHIEF OF OPERATIONS for U.S. Army Europe nearly twenty years ago, I was present as Estonia experienced what many military professionals now regard as the opening chapter of modern strategic cyberwarfare . In April 2007, the Estonian government decided to relocate a statue called the Bronze Soldier , a Soviet war memorial in central Tallinn that many ethnic Estonians viewed as a symbol of decades of Soviet occupation. The decision ignited protests and diplomatic outrage from Moscow, and, within days, a wave of coordinated cyber attacks unlike anything the world had previously witnessed.
The attacks targeted far more than government websites. The Estonian parliament, ministries, banks, newspapers, broadcasters, telecommunications providers, and other essential services found themselves overwhelmed by distributed denial-of-service (DDOS) attacks that flooded networks…
Read the original at The Bulwark →
Open in TruthVane →