Individual Submission Summary
Share...

Direct link:

Nonstate Actors and Cyber Coercion

Fri, August 30, 4:00 to 5:30pm, Hilton, Columbia 5

Abstract

Terrorist organizations have become increasingly adept at utilizing social media, disseminating videos that display production savvy, and with online tools of communication. Terrorist organizations often use cyberspace as a tool of propaganda - they take credit for attacks, release information, and recruit to their cause. Terrorist groups utilize fear and the threat of loss of life to their advantage, and cyberspace offers a way to leverage this potential. However, it is frequently argued that non-state actors are unlikely to utilize offensive cyber capabilities and that cyberattacks are an ineffective way for terrorist groups to coerce their adversaries. This argument, that cyberattacks by terrorist organizations is an unlikely outcome, is based primarily on three assumptions. First, terrorist groups do not possess the capabilities necessary to effectively coerce state actors. Second, attribution is difficult in the cyber domain, and terrorism itself is often defined a demonstrative act – that terrorists want attention and credit for their attacks. The final assumption is that terrorist groups are only able to coerce a government to change its policies through killing civilians or the threat of future harm to civilians.

This paper will challenge these three assumptions to argue that terrorists could utilize cyber capabilities in order to compel or deter their adversaries, perhaps more effectively than through explicit violence. First, terrorist groups have a range of cyber capabilities available, including interfering with the functionality of a computer system, exfiltration of data, cyber espionage, financial and political intrusions, hacking, attacks on critical infrastructure, among others. While terrorist groups may not possess the ability to carry out as sophisticated offensive cyber operations as states, malicious cyber tools and misinformation campaigns are becoming increasingly commodified. Groups can purchase cyber tools from non-state actors, just as states have. Second, attribution is difficult in the cyber domain, and the covert nature of many cyber capabilities could be used to the terrorists’ advantage. Moreover, many terrorist attacks are unclaimed. Uncertain attribution makes it more difficult for states to retaliate, and this is even more of an issue against terrorist organizations that are transnational or lacking a home base. Finally, while terrorist groups have not carried out a major cyber-attack, there have been a number of cyber-attacks carried out by states and non-state actors such as hacktivist groups, commissioned by state actors. Attacks on critical infrastructure have the potential to result in loss of life – hospitals could lose power and networking capabilities or communication and emergency response services could be adversely impacted. Using qualitative analysis of available capabilities, past cyber-attacks, and the current behavior and goals of terrorist groups, this paper will make the case that non-state actors are likely to increase their use of cyber-attacks in order to generate fear and manipulate and coerce their adversaries.

Author