Civic / Privacy / Digital Rights
The Strategic and Legal Dimensions of Preemptive Cyber Operations Against Known Threat Groups: A Global Perspective
Report summary
The evolution of cyberspace from a decentralized domain of information exchange to a primary theater of geopolitical and strategic conflict has fundamentally altered the calculus of national security. In traditional military domains—land, sea, air, and space—the principles of deterrence, defense, an
Key topics
- Civic / Privacy / Digital Rights
- Civic
- Privacy
- Digital Rights
- .NET
- Research Archive
- Strategy
- Audit
- Architecture
Research provenance
For citation, use the report title and canonical URL. Archival presence does not establish authorship or promote report statements into portfolio evidence.
This page renders the archived Markdown as safe, formatted HTML. It is background research and does not become a portfolio claim without evidence review.
Full report
On this page
Introduction to Proactive Cyber Operations
The evolution of cyberspace from a decentralized domain of information exchange to a primary theater of geopolitical and strategic conflict has fundamentally altered the calculus of national security. In traditional military domains—land, sea, air, and space—the principles of deterrence, defense, and response rely on physical distance, early warning systems, and observable force buildup. Cyberspace, however, possesses structural characteristics that inherently favor the attacker. The barrier to entry is extremely low, attribution is notoriously difficult, and the speed at which a digital payload can compromise critical infrastructure renders reactive defense mechanisms frequently inadequate. Consequently, a growing number of sovereign states are concluding that leaving cyberspace uncontested allows malicious actors to operate with impunity. This structural reality has catalyzed a shift toward proactive, active, and preemptive cyber postures. Preemptive cyber operations involve the deployment of technical capabilities to disrupt, degrade, or dismantle an adversary’s digital infrastructure before a malicious act can be successfully executed against the defending state. These operations shift the paradigm from perimeter defense—waiting for the adversary to strike a network firewall—to forward-leaning engagement, wherein threats are neutralized at their point of origin, often deep within foreign networks. The strategic argument for preemptive cyber strikes rests on the premise that continuous, low-intensity disruption is the only viable method to prevent known threat groups from accumulating the capabilities required to execute catastrophic breaches. These "known groups" represent a spectrum of actors, ranging from highly resourced state intelligence apparatuses and Advanced Persistent Threats (APTs) to state-sponsored proxies, hacktivist collectives, and transnational cybercriminal syndicates operating Ransomware-as-a-Service (RaaS) models. Because these groups continuously probe vulnerabilities, the necessity for preemptive action is increasingly recognized not merely as an aggressive military tactic, but as a mandatory component of national resilience. However, the shift toward preemption introduces profound legal and normative complexities. The international legal order, anchored by the United Nations Charter, strictly regulates the use of force and the right to self-defense. Striking an adversary’s infrastructure before an attack has fully materialized challenges traditional interpretations of sovereignty and imminent threat. Furthermore, when the target is a non-state actor operating from within the borders of a third-party state, preemptive operations test the boundaries of international law. This exhaustive report provides a comprehensive analysis of the arguments justifying preemptive cyber operations against known threat groups. By examining the international legal frameworks governing anticipatory self-defense and exploring the distinct cyber doctrines of the United Kingdom, France, South Korea, Australia, Israel, China, and the European Union, the analysis illustrates how sovereign nations globally conceptualize, justify, and operationalize preemptive cyber capabilities to safeguard their national interests.
The Evolving Threat Landscape: The Rise of Non-State Actors and Known Groups
To understand the justification for preemptive cyber operations, it is necessary to examine the nature of the adversaries targeted by these actions. Historically, national security doctrines were designed to manage state-on-state conflict. Today, however, the most persistent threats in cyberspace frequently emanate from non-state actors or semi-autonomous groups operating with varying degrees of state sponsorship or tolerance.
The Blurring of State and Non-State Actors
Known threat groups often operate in a gray zone of attribution and affiliation. Cybercriminal syndicates, such as REvil or DarkSide, execute crippling ransomware attacks against critical infrastructure, healthcare systems, and energy pipelines1. While financially motivated, these groups often operate from jurisdictions that provide safe harbor, creating a scenario where the host state is either unable or unwilling to curb their activities. Similarly, state-sponsored APTs frequently utilize proxy groups to maintain plausible deniability. These proxies execute disruptive campaigns, steal intellectual property, and position malware within the critical infrastructure of adversary nations. Because these known groups operate continuously, traditional reactive defense—patching vulnerabilities after they are discovered or attempting to block incoming traffic during an active breach—is fundamentally asymmetrical. The attacker only needs to succeed once, while the defender must succeed every time.
The Inadequacy of Perimeter Defense
The inadequacy of perimeter defense is the primary operational driver for preemption. A cyber weapon, such as a sophisticated logic bomb or a dormant ransomware payload, may be implanted in a nation's critical infrastructure months or even years before it is activated2. The execution of the attack occurs at the speed of light, leaving the defending state absolutely no time to deliberate or deploy countermeasures once the activation command is sent. For national security apparatuses, waiting for a known group to initiate an attack on a power grid or a financial system is an unacceptable risk. If intelligence agencies identify a known group assembling the digital architecture required for a catastrophic attack—such as establishing command-and-control (C2) servers, acquiring zero-day exploits, or moving laterally within a targeted network—the strategic imperative dictates that this infrastructure must be dismantled before the attack sequence is finalized.
The International Legal Framework: Anticipatory Self-Defense in Cyberspace
The legality of preemptive military action, whether kinetic or digital, remains one of the most rigorously debated subjects in international jurisprudence. The foundational framework governing international conflict is established by the United Nations (UN) Charter. Article 2(4) of the Charter mandates that all member states refrain from the threat or use of force against the territorial integrity or political independence of any state4. The primary exception to this prohibition is Article 51, which preserves the "inherent right of individual or collective self-defence if an armed attack occurs"4. Applying these mid-twentieth-century principles to modern digital operations against known threat groups requires navigating three critical legal thresholds: the definition of an "armed attack," the standard for attributing acts to a state or navigating non-state actor threats, and the temporal boundaries of self-defense—specifically, when a state may act in anticipation of an attack.
The Threshold of an "Armed Attack"
For a state to lawfully invoke Article 51 and use force—including military-grade cyber force—in self-defense, the prospective cyber operation it seeks to preempt must reach the threshold of an "armed attack"2. The international community largely adheres to the "scale and effects" doctrine, prominently featured in the Tallinn Manual on the International Law Applicable to Cyber Warfare. According to this standard, a cyber operation constitutes a use of force or an armed attack if its scale and effects are comparable to those resulting from the use of conventional kinetic weapons6. Operations that result in significant physical destruction, severe economic paralysis, or loss of life unambiguously meet this threshold6. For instance, penetrating military systems to compromise defense capabilities, manipulating a dam's control systems to cause flooding, or triggering a technological disaster that paralyses whole swathes of a country's activity would legally justify a robust self-defense response6. Conversely, cyber espionage, data theft, and periodic denial-of-service (DoS) attacks on non-essential government networks generally do not rise to the level of an armed attack, thus falling short of triggering the right to self-defense under Article 518. However, the calculation is complicated by the concept of cumulative effects. Some nations argue that a sustained, coordinated campaign of low-level disruptions orchestrated by a known threat group can cumulatively cross the threshold into an armed attack6. If an APT continuously degrades a nation's critical infrastructure without causing immediate physical destruction, the targeted state may legally argue that the aggregate impact justifies a preemptive cyber operation to halt the campaign6.
**The Caroline Doctrine and Anticipatory Self-Defense**
If a prospective cyber operation is deemed to meet the criteria of an armed attack, the next legal hurdle is determining whether a state can act before the attack physically strikes. Article 51 explicitly states "if an armed attack occurs," which restrictivists argue precludes any preemptive action; under a strict textual reading, the defending state must absorb the first blow4. However, customary international law has long recognized a more permissive standard based on the Caroline incident of 1837\. Following the British destruction of an American steamboat utilized by Canadian rebels, US Secretary of State Daniel Webster articulated the standard for anticipatory self-defense. He stated that preemptive force is justified only when the necessity of self-defense is "instant, overwhelming, and leaving no choice of means, and no moment for deliberation"2. This doctrine requires the threat to be imminent, real, and immediate, distinguishing lawful anticipatory self-defense from unlawful preventive war. Preventive war, which involves attacking an adversary to neutralize a long-term, non-imminent threat, remains broadly illegal under international law7.
Redefining Imminence: The "Last Possible Window of Opportunity"
Translating the Caroline standard of "imminence" to cyberspace is profoundly challenging. In the conventional domain, imminence is largely temporal. A state can observe an adversary massing troops at a border; the attack is imminent because the physical invasion is chronologically immediate. In cyberspace, the concept of temporal imminence is functionally obsolete2. To resolve this dilemma, legal scholars, state attorneys-general, and the drafters of the Tallinn Manual 2.0 have advanced the concept of "contextual imminence" and the "last possible window of opportunity" to act2. Under this framework, an attack is deemed legally imminent not necessarily because it is about to occur chronologically, but because the defending state has reached the final moment in which it can effectively act to prevent the attack from succeeding7. If an intelligence agency detects that a known state-sponsored hacking group has compromised a national power grid and possesses both the capability and the verified intent to trigger a blackout, the attack is contextually imminent10. The defending state is not required to wait until the adversary initiates the final command sequence. If neutralizing the adversary's C2 server today is the only guarantee of preventing the blackout tomorrow, the last window of opportunity is closing now. A preemptive cyber strike against the adversary's infrastructure to sever their access is therefore justified under international law, as waiting further would result in the state being unable to defend itself effectively13. This "last window of opportunity" standard—heavily influenced by the Bethlehem Principles—requires three stringent conditions to avoid sliding into illegal preventive war:
1. Capability: The adversary must possess the technical means and digital architecture to launch the attack10.
2. Intent: There must be verifiable intelligence indicating the adversary is irrevocably committed to the attack, moving beyond mere contingency planning10.
3. Exhaustion of Alternatives: The preemptive strike must occur during the last feasible window where peaceful alternatives, such as diplomatic démarches, economic sanctions, or law enforcement actions, are either impossible or would fail to mitigate the threat in time8.
| Legal Concept | Traditional Kinetic Interpretation | Cyber Domain Interpretation (Contextual Imminence) |
|---|---|---|
| Armed Attack | Physical invasion, bombardment, large-scale loss of life. | Cyber operation yielding scale/effects equivalent to kinetic damage (e.g., destruction of critical infrastructure). |
| Imminence | Attack is temporally immediate (e.g., troops crossing a border). | The "Last Possible Window of Opportunity" to thwart an attack before the defender loses the capacity to prevent it. |
| Anticipatory Self-Defense | Striking an incoming bomber before it releases its payload. | Neutralizing a foreign C2 server that is preparing to activate a dormant logic bomb within domestic infrastructure. |
| Preventive War (Illegal) | Attacking a rival state to prevent them from building an army over the next decade. | Hacking and destroying a foreign research facility simply because it might develop cyber weapons in the future. |
Preempting Non-State Actors and the Sovereignty Dilemma
When the known group posing the threat is a non-state actor—such as a cybercriminal syndicate or a terrorist organization—justifying preemptive strikes introduces the sovereignty dilemma. A state is generally responsible for cyberattacks perpetrated by non-state actors only if those actors act de facto on the state's instructions, orders, or under its direct control6. However, what occurs when a ransomware gang operates from a neutral or adversarial state that is not directly directing the attacks, but is turning a blind eye? International counter-terrorism practice following the September 11 attacks, reflected in UN Security Council Resolutions 1368 and 1373, established that states have a right of self-defense against non-state actors2. If the host state is "unable or unwilling" to halt the malicious cyber activities emanating from its territory, the victim state may argue it has the right to preemptively strike the non-state actor's digital infrastructure within that host state's borders3. While highly controversial and heavily scrutinized for potential sovereignty violations, this justification is increasingly invoked by advanced cyber powers to legitimize the disruption of transnational cyber syndicates.
Strategic Rationales: Moving Beyond Deterrence by Punishment
The global push toward preemptive and active cyber defense is driven not solely by the evolution of legal theory, but by urgent strategic necessity. During the Cold War, international security was heavily predicated on deterrence by punishment—the threat of overwhelming kinetic or nuclear retaliation if an adversary attacked. This model translates exceptionally poorly to cyberspace15. First, the attribution problem fundamentally undermines the certainty of punishment8. Malicious groups routinely use proxy servers, false flags, and third-party infrastructure to mask their origins, making swift, decisive retaliation politically and technically perilous. If a state cannot definitively prove who launched an attack in real-time, threats of retaliation lose their coercive power. Second, the structural asymmetry of cyberspace means that non-state actors can wield strategic influence without possessing targetable state assets9. Threatening to impose economic sanctions or launch military strikes against a loosely affiliated hacking collective operating across multiple jurisdictions lacks credibility. Furthermore, inaction following the attribution of a cyberattack creates a negative precedent, undermining both retaliatory threats and the credibility of a nation's cyber capabilities16. Because deterrence by punishment frequently fails to alter the risk calculus of cyber attackers, states are shifting toward deterrence by denial and disruption, a concept heavily influenced by Cyber Persistence Theory15. This theory posits that security in cyberspace is achieved not by drawing red lines, but by continuously seizing and sustaining the initiative18. Preemptive cyber strikes are the operational embodiment of this strategy. By persistently engaging the adversary, degrading their infrastructure, and introducing friction into their networks, a defending nation imposes continuous operational costs on threat groups. This active, continuous campaigning aims to make attacks so resource-intensive, technically difficult, and consistently frustrated that the adversary is denied the operational freedom necessary to achieve their strategic objectives15.
Global Doctrines and Case Studies: The Framing of Preemption
While the United States’ adoption of "Defend Forward" and "Persistent Engagement" is widely documented, numerous other global powers have evolved highly sophisticated doctrines for preemptive, active, and offensive cyber operations. Examining the strategic frameworks of the United Kingdom, France, South Korea, Australia, Israel, China, and the European Union reveals a diverse spectrum of approaches to managing offshore cyber threats from known groups.
United Kingdom: Responsible Cyber Power and Cognitive Effects
The United Kingdom has emerged as a leading proponent of integrating offensive cyber capabilities into continuous national security campaigns, guided by an explicit doctrine of responsibility and transparency. Established in 2020 by drawing on personnel from the Government Communications Headquarters (GCHQ), the Ministry of Defence, the Defence Science and Technology Laboratory (Dstl), and the Secret Intelligence Service (SIS), the UK's National Cyber Force (NCF) is tasked with operating continuously in and through cyberspace to counter threats proactively15. In 2023, the NCF published a landmark doctrine titled "Responsible Cyber Power in Practice," which firmly rejects the notion of cyberspace as a sanctuary for malicious actors. The UK government’s strategy asserts that leaving cyberspace uncontested allows adversaries to operate with impunity18. Consequently, the NCF engages in continuous, proactive campaigns to disrupt the capacity of specific adversaries, seizing opportunities to advance security while managing the risk of escalation18. A defining feature of the UK’s preemptive approach is its emphasis on "cognitive effects." The UK recognizes that purely destructive cyber operations are often ephemeral; an adversary can swiftly replace destroyed hardware or migrate to new server infrastructure18. Instead, the UK employs a "bend-but-do-not-break" philosophy. By preemptively infiltrating an adversary's operating environment and introducing precise, calibrated technical friction, the NCF aims to degrade the functionality and reliability of the threat group's systems over a prolonged period18. The resulting cognitive effect is profound. When a threat group’s customized malware intermittently fails, their stolen data is subtly corrupted, or their internal communications are disrupted, the group loses confidence in its own technology and intelligence. The inherent ambiguity of the operation—whether a system crash is the result of a software bug, poor coding, or a deliberate British cyber strike—creates intense organizational friction18. This slows the adversary's decision-making process, diverts their resources toward internal audits and system rebuilding, and ultimately degrades their capacity to launch attacks against the UK. The UK meticulously aligns this proactive disruption with legal and ethical frameworks, ensuring operations are accountable (complying with domestic and international law), precise (carefully timed and targeted), and calibrated (assessed for their intended impact)18. By publicly releasing this doctrine, the UK seeks to establish a normative "license to operate," demonstrating to the international community that preemptive offensive cyber capabilities can be wielded responsibly to stabilize the strategic environment rather than escalate it21.
**France: Doctrinal Restraint and *Lutte Informatique Offensive***
France offers a highly nuanced approach, balancing a formal, diplomatic rejection of sweeping preemptive self-defense paradigms with the maintenance of formidable offensive cyber capabilities for use in defined military contexts. French cyber strategy rigorously separates Lutte Informatique Défensive (LID \- Defensive Cyber Warfare) from Lutte Informatique Offensive (LIO \- Offensive Cyber Warfare), tasking different bureaucratic entities to ensure the protection of civil liberties and clear chains of command22. The ANSSI (National Cybersecurity Agency) oversees civilian and defensive aspects, while the military’s Commandement de la Cyberdéfense (COMCYBER) handles offensive operations23. France’s official diplomatic posture is highly legalistic. It has explicitly criticized the broad American concept of "preemptive self-defense" as a legal oxymoron, arguing that attacking a state based merely on early signs of hostility without an imminent, verifiable threat threshold risks eroding the stability of international law6. Under French interpretation, an armed attack must reach the severity of physical force, and attribution to a sovereign state requires strict proof of de facto control over the non-state actors executing the attack6. However, this rhetorical restraint does not translate into operational passivity. France's military doctrine fully integrates LIO into its strategic planning. Driven by consecutive Military Programming Laws (LPM), France aims to deploy over 5,000 "cyber combatants" by 2025 and has declared that, in response to cyber threats, it is not afraid to deploy its offensive cyber power24. French military doctrine views cyber weapons as a means of combination, utilized alongside traditional kinetic weapons for intelligence gathering, deception, and the neutralization of adversary systems27. In practice, if France detects a highly sophisticated foreign capability preparing to target its critical military infrastructure during a state of armed conflict, COMCYBER is authorized to execute operations to neutralize the threat, provided the action strictly adheres to International Humanitarian Law (IHL)—specifically the principles of distinction, proportionality, and precaution27. Thus, while France rejects the political rhetoric of unchecked preemptive war, it actively cultivates and employs the technical means to preemptively dismantle adversarial systems when legally and militarily justified, demonstrating a pragmatic synthesis of stringent legalism and active defense26.
South Korea: Active Cyber Defense and Extraterritorial Neutralization
The geopolitical reality of the Korean Peninsula profoundly shapes the cyber strategy of the Republic of Korea (ROK). Facing persistent, asymmetrical, and highly aggressive cyber operations from the Democratic People's Republic of Korea (DPRK)—operations ranging from widespread intelligence gathering to cryptocurrency theft designed to fund nuclear proliferation—South Korea has recognized that a purely defensive posture is strategically untenable28. The volume of attacks, estimated by the National Intelligence Service (NIS) to exceed a million attempts daily, dictates a forward-leaning response28. In its 2024 National Cybersecurity Strategy, South Korea formalized a pivot from reactive defense toward a doctrine of Active Cyber Defense (ACD) and proactive disruption16. This shift acknowledges that traditional deterrence has failed to alter Pyongyang's calculus. ACD in the South Korean context involves synchronized, real-time capabilities to detect, analyze, mitigate, and proactively block threats before they breach domestic networks16. A cornerstone of this preemptive capability is legislative. In 2024, the South Korean government amended the Regulation on Cybersecurity Duty, introducing Article 6 bis. This article provides the NIS with the explicit legal authority to take necessary steps to proactively identify, deter, and block activities that threaten national security and interests29. Crucially, paragraph three of this article legally authorizes the tracking and "neutralization" of foreign and North Korean bases29. This legal provision effectively sanctions state-directed, preemptive cyber operations targeting the physical and digital infrastructure adversaries use to launch attacks, even when those assets are located in foreign jurisdictions. If South Korean intelligence identifies a DPRK server staging a massive ransomware deployment against South Korean financial institutions, the NIS or the military's Cyber Command is empowered to proactively dismantle that staging ground. This integration of intelligence, active defense, and extraterritorial neutralization exemplifies a state utilizing preemptive cyber strikes to manage an otherwise uncontainable, persistent threat actor16.
Australia: Blurring the Lines of Intelligence and Law Enforcement
Australia's approach to proactive cyber operations highlights a rapid evolution in threat perception, driven heavily by devastating attacks on critical civilian infrastructure by known cybercriminal groups. In late 2022, Australia suffered unprecedented data breaches targeting Optus, a major telecommunications provider, and Medibank, the country's largest health insurer. These breaches, orchestrated by offshore hackers, compromised the sensitive personal and medical data of roughly 40 percent of the Australian population30. In response to these incursions, which demonstrated that offshore cybercriminal syndicates pose a national security threat equivalent to state-sponsored espionage, the Australian government initiated a paradigm shift in how it combats digital threats. The government announced a tripling of its investment in offensive cyber defense capabilities and established a Joint Standing Operation (JSO) comprising the Australian Federal Police (AFP) and the Australian Signals Directorate (ASD)30. The JSO represents a fundamental departure from traditional policing and defense models. Historically, law enforcement reacted after a crime occurred, while signals intelligence agencies monitored foreign state actors. The JSO, however, focuses explicitly on preemptive disruption of known non-state groups30. Its mandate is not merely to investigate cybercrimes post-facto, but to proactively target, hack, and dismantle the infrastructure of foreign cybercriminals before they can extort Australian targets31. Operating offshore, the ASD utilizes its offensive cyber capabilities to disable botnets, divert harmful data traffic, and strip attackers of their control over digital infrastructure31. By officially avowing these actions, Australia is establishing a norm that sovereign states possess the right and responsibility to preemptively neutralize offshore criminal threats that target their domestic populations. The strategic rationale is clear: to ensure Australia is not perceived as a "soft target" on the global stage. By imposing continuous operational costs on ransomware groups, Australia aims to force adversaries to shift their efforts elsewhere, achieving a localized form of deterrence by denial31.
Israel: The "Campaign Between Wars" in Cyberspace
Israel’s unique strategic environment requires it to manage simultaneous existential threats from state actors (e.g., Iran) and heavily armed, state-sponsored proxy groups (e.g., Hezbollah, Hamas) encircling its borders. To address this complex threat matrix, the Israel Defense Forces (IDF) developed a distinct operational doctrine known as the **"Campaign Between Wars" (CBW or Mabam)**34. The CBW is a doctrine of integrated, continuous, low-intensity preemptive warfare. Instead of oscillating between absolute peace and total war, Israel operates under the assumption of continuous conflict. The primary objective of the CBW is to delay major wars and weaken enemy forces by proactively and preemptively degrading their force buildup, specifically preventing the transfer of strategic, equilibrium-breaking weapons35. As cyberspace emerged as a critical domain of conflict, the principles of the CBW were seamlessly integrated into Israel's cyber strategy37. For Israel, cyber weapons are highly attractive tools for the CBW because they allow for the preemptive degradation of enemy capabilities with a lower risk of triggering a full-scale kinetic escalation. The most prominent example of this strategy was the deployment of the Stuxnet worm34. By infiltrating Iranian nuclear facilities and causing uranium-enrichment centrifuges to physically self-destruct, the operation preemptively degraded a strategic threat while operating below the threshold of conventional armed conflict2. The IDF’s strategy relies heavily on high-quality intelligence to identify enemy intentions and capabilities early, allowing for precise, preemptive strikes35. This applies to both kinetic strikes on weapons convoys in Syria and digital strikes against Iranian command-and-control networks or maritime infrastructure38. By continuously pruning the adversary's capabilities through proactive cyber and physical engagement, Israel maintains an active defense posture designed to continuously disrupt the "Ring of Fire" strategy orchestrated by its adversaries40.
**China: The Ambiguity of Jiji Fangyu (Active Defense)**
The People's Republic of China approaches the concept of cyber preemption through its overarching strategic military concept of jiji fangyu, translated as "active defense"41. The Chinese conceptualization of active defense contains inherent ambiguities that blur the lines between defensive posturing and preemptive offensive action, leading to divergent interpretations between Chinese strategists and Western analysts. From the perspective of the Chinese strategic community, jiji fangyu is fundamentally defensive in nature. It implies a posture of retaliatory self-defense, prioritizing defense first while maintaining the capability to counterattack vigorously once deterrence fails43. Chinese analysts often criticize the U.S. "Defend Forward" and preemptive doctrines as overtly offensive, arguing that American strategy actively seeks preemption and unilateral military advantage, thereby destabilizing international cyber norms43. However, Western military analysts view China's application of jiji fangyu in cyberspace quite differently. Because active defense incorporates the principle of "defense in an offensive posture," it allows for operations that function preemptively at the tactical and operational levels while remaining strategically "defensive" in the eyes of Beijing42. This means that if China perceives a strategic threat to its domestic stability or territorial core interests, the doctrine of active defense authorizes preemptive network penetrations, the prepositioning of malware in foreign critical infrastructure, and intelligence preparation of the battlefield. Thus, while China officially distances itself from the rhetoric of preemption, its operational capability and doctrine of active defense allow for preemptive cyber strikes justified under the broad umbrella of national self-preservation41.
The European Union and Germany: Due Diligence and Caution
In contrast to the highly proactive stances of the UK, Australia, and South Korea, the European Union—and specifically Germany—approaches active and preemptive cyber defense with profound caution, constrained by constitutional law, historical aversion to preemptive force, and strict adherence to international norms. Cyber defense considerations within the EU are transitioning from purely reactive approaches to proactive defense concepts to protect civil-military infrastructure, as highlighted by the 2022 Communication on an EU Cyber Defence Policy31. However, European policymakers are deeply concerned about the "militarization" of the cyber domain. A review of emerging state practice identifies key questions that Europe needs to work through as close partners like the US and UK engage in disruptive defense17. European states emphasize that any active defense must comply with peacetime "due diligence" obligations, ensuring that activities emanating from their territory do not unlawfully violate the rights of other states31. Germany exemplifies this cautious approach. Germany's first National Security Strategy, presented in 2023, commits to reviewing cyber defense powers, but government officials explicitly rule out "hackbacks" (retaliatory or preemptive cyber strikes against civilian or criminal infrastructure) as a lawful means of cyber defense31. Furthermore, to proactively disrupt threats beyond its borders, Germany would require an amendment to its Basic Law (constitution)31. German officials emphasize that proactive disruption poses exceedingly high legal hurdles and strictly requires a reliable and robust technical, political, and legal attribution of attacks beforehand—a standard that is notoriously difficult to achieve in the rapid timeframe required for preemptive action31. Thus, the European perspective serves as a counterweight to the trend of active defense, prioritizing norm formulation, resilience, and strict legalism over preemptive tactical advantage.
| Nation | Strategic Cyber Doctrine | Stance on Preemptive / Active Cyber Defense | Primary Targets / Justifications |
|---|---|---|---|
| United Kingdom | Responsible Cyber Power / Persistent Engagement | Highly proactive. Conducts continuous campaigns to introduce "cognitive friction" and degrade adversary capabilities. | State adversaries, terrorists, cybercriminals. Justified via accountable, precise, and calibrated application of national power. |
| France | Lutte Informatique Offensive (LIO) | Rhetorically rejects preemptive self-defense, but maintains robust offensive capabilities for integration with military operations during conflict. | Foreign military and state intelligence apparatuses. Justified under strict adherence to International Humanitarian Law. |
| South Korea | Active Cyber Defense (ACD) | Highly proactive. Law explicitly authorizes tracking and neutralizing offshore digital and physical bases. | DPRK state-sponsored hackers. Justified by the sheer volume of daily attacks and existential national security threats. |
| Australia | Joint Standing Operation (JSO) | Proactive and disruptive. Merges intelligence (ASD) and law enforcement (AFP) to dismantle offshore infrastructure. | Transnational cybercriminal syndicates (e.g., ransomware gangs). Justified to prevent extortion and protect domestic civilian data. |
| Israel | Campaign Between Wars (CBW) | Continuous, low-intensity preemptive warfare. Seeks to delay war by disrupting enemy force buildup digitally and physically. | Iran and state-sponsored proxy groups (Hezbollah, Hamas). Justified as necessary active defense against the "Ring of Fire." |
| China | Jiji Fangyu (Active Defense) | Officially claims a defensive/retaliatory posture, but operationalizes "defense in an offensive posture" allowing tactical preemption. | Broad geopolitical rivals. Justified as strategic self-preservation and safeguarding of core national interests. |
| Germany / EU | Norm-Based Resilience | Highly restrictive. Rejects "hackbacks" and faces steep constitutional hurdles for proactive extraterritorial disruption. | Focuses on defensive resilience. Any proactive measures demand absolute attribution and strict adherence to due diligence. |
Operationalizing Preemptive Cyber Defense: Challenges and Escalation Risks
While the case for preemptive cyber operations is supported by urgent national security imperatives and sophisticated legal interpretations of imminence, operationalizing these strikes carries inherent, severe risks.
Intelligence Requirements and the Attribution Dilemma
The success and legal legitimacy of any preemptive strike rely entirely on the absolute certainty of intelligence. To satisfy the "last possible window" criteria, a state must not only identify a vulnerability in an adversary's system but confidently attribute that system to a specific threat group with verifiable hostile intent7. Erroneous attribution could result in an unprovoked cyber attack against an innocent third-party state, violating their sovereignty and potentially triggering an international diplomatic or military crisis. States attempt to mitigate this by investing heavily in Cyber Threat Intelligence (CTI) and establishing multilateral intelligence-sharing partnerships. For example, the strategic cyber partnership between the UK and South Korea facilitates the sharing of highly relevant CTI regarding North Korean state-linked actors, allowing both nations to cross-verify threat indicators before authorizing proactive defense measures45.
Sovereignty and "Hunt Forward" Operations
Executing active cyber defense often requires operating on infrastructure located in third-party countries. Malicious actors, particularly ransomware gangs, routinely lease servers in neutral or unaligned jurisdictions to mask their location. When a state executes a preemptive operation to neutralize a C2 server located in an unaligned nation, it risks violating the territorial sovereignty of that host state9. To navigate this sovereignty dilemma legally, nations are increasingly utilizing "Hunt Forward" operations. Pioneered by U.S. Cyber Command and adopted by allies like the UK, Hunt Forward involves cyber specialists deploying physically or digitally into the networks of partner nations—with their explicit consent—to proactively hunt for, identify, and dismantle adversary staging grounds before they can be used to launch attacks globally16. By operating with host-nation consent, the intervening state preserves international legal norms regarding sovereignty while still achieving preemptive disruption.
Escalation Management and Norm Formulation
A primary criticism of preemptive cyber operations is the risk of an unconstrained cyber arms race and uncontrollable escalation21. If every nation claims the right to proactively disrupt perceived threats, cyberspace could descend into perpetual, unstructured conflict. Opponents of preemptive doctrines argue that normalizing anticipatory self-defense in cyberspace lowers the threshold for the use of force, increasing global instability. However, proponents of active defense argue that persistent engagement does not lead to uncontrollable escalation; rather, strategic advantage is gained through continuous, calibrated, competitive interactions carefully maintained below the threshold of armed conflict15. By focusing on non-destructive cognitive effects, disrupting criminal infrastructure, and adhering strictly to legal frameworks, states can exert power responsibly. To prevent norm erosion, it is imperative that capable cyber powers articulate clear boundaries for their operations. Public doctrinal transparency, such as the UK’s publication of its NCF principles or South Korea’s open declaration of Active Cyber Defense, serves as a vital diplomatic tool, communicating to adversaries and allies alike that preemptive actions are deliberate, proportionate, and legally grounded15.
Conclusion
The argument for preemptive cyber operations against known threat groups rests on the stark, structural reality that reactive defense is fundamentally insufficient in the digital age. A posture of static resilience guarantees that malicious actors—whether hostile state military units, state-sponsored proxies, or offshore cybercriminal syndicates—can continuously probe critical infrastructure for vulnerabilities with near-zero risk, eventually achieving catastrophic success. To counter this asymmetry, nations across the globe are redefining the legal, strategic, and operational boundaries of self-defense. International legal frameworks are adapting through concepts like "contextual imminence" and the "last possible window of opportunity," providing a legal architecture that permits states to neutralize digital threats before they are irretrievably launched. Strategically, global powers have moved beyond the outdated paradigm of deterrence by punishment, embracing deterrence by denial and continuous disruption. As demonstrated by international case studies, there is no monolithic approach to cyber preemption. The United Kingdom utilizes continuous campaigns to impose cognitive friction on adversaries. France balances strict legal restraint with the integration of robust offensive capabilities into its military apparatus. South Korea has enacted legislation to proactively track and neutralize North Korean cyber bases to survive a daily onslaught of digital aggression. Australia has merged signals intelligence with federal law enforcement to preemptively dismantle criminal infrastructure offshore, while Israel incorporates cyber preemption into a holistic, permanent campaign to stall adversarial force buildup. Conversely, the European Union and China approach preemption through lenses of strict due diligence and ambiguous active defense, respectively. Ultimately, preemptive cyber attacks are increasingly justified by the international community not as punitive acts of aggression or illegal preventive wars, but as necessary, calibrated mechanisms for threat management. By actively engaging known adversaries, degrading their infrastructure, and seizing the operational initiative, sovereign nations ensure that the cost of initiating a cyber attack remains prohibitively high, thereby preserving national security and contributing to a more stable, albeit fiercely contested, international digital order.
Works cited
1. Domestic and international approaches to combating ransomware: between contradiction and coherence \- Oxford Academic, https://academic.oup.com/ijlit/article/doi/10.1093/ijlit/eaag004/8465022
2. EVALUATING THE “IMMINENCE” OF A CYBER ATTACK FOR PURPOSES OF ANTICIPATORY SELF-DEFENSE \- Columbia Law Review, https://columbialawreview.org/content/evaluating-the-imminence-of-a-cyber-attack-for-purposes-of-anticipatory-self-defense/
3. Evaluating the "imminence" of a cyber attack for purposes of anticipatory self-defense, https://www.researchgate.net/publication/320413303\_Evaluating\_the\_imminence\_of\_a\_cyber\_attack\_for\_purposes\_of\_anticipatory\_self-defense
4. The Legality of Preemptive Strike in International Law \- Modern Diplomacy, https://moderndiplomacy.eu/2025/06/29/the-legality-of-preemptive-strike-in-international-law/
5. Cyber Attacks as "Force" Under UN Charter Article 2(4) \- Scholarship Archive, https://scholarship.law.columbia.edu/cgi/viewcontent.cgi?article=1882\&context=faculty\_scholarship
6. Self-defence \- International cyber law: interactive toolkit, https://cyberlaw.ccdcoe.org/wiki/Self-defence
7. Full article: Reconceptualising the right of self-defence against 'imminent' armed attacks, https://www.tandfonline.com/doi/full/10.1080/20531702.2022.2097618
8. Cyber Espionage and International Law: Legal Boundaries and Strategic Ambiguities, https://www.cyber-espionage.ch/Law.html
9. Active Cyber Defense in the Korean Context \- CSIS, https://www.csis.org/analysis/active-cyber-defense-korean-context
10. When did the Armed Attack against Ukraine become 'Imminent'? \- EJIL: Talk\!, https://www.ejiltalk.org/when-did-the-armed-attack-against-ukraine-become-imminent/
11. Preemptive Strikes: Overview | Military History and Science | Research Starters \- EBSCO, https://www.ebsco.com/research-starters/military-history-and-science/preemptive-strikes-overview
12. Cyber Attacks as Armed Attacks? : The Right of Self-Defence When a Cyber Attack Occurs \- DiVA portal, http://su.diva-portal.org/smash/record.jsf?pid=diva2:1754047
13. Beyond Self-Defense and Countermeasures \- Texas Law Review, https://texaslawreview.org/beyond-self-defense-countermeasures/
14. Israel's Operation Rising Lion and the Right of Self-Defense \- Lieber Institute \- West Point, https://lieber.westpoint.edu/israels-operation-rising-lion-right-of-self-defense/
15. Evaluating the National Cyber Force's 'Responsible Cyber Power in Practice' \- RUSI, https://www.rusi.org/explore-our-research/publications/commentary/evaluating-national-cyber-forces-responsible-cyber-power-practice
16. South Korea's Integrated Cyber Defense Framework: Active Cyber Defense and Reactive Responses \- CSIS, https://www.csis.org/analysis/south-koreas-integrated-cyber-defense-framework-active-cyber-defense-and-reactive
17. Hardening Norms and Networks: Europe's Cyber Defence Posture \- Intereconomics, https://www.intereconomics.eu/contents/year/2024/number/4/article/hardening-norms-and-networks-europe-s-cyber-defence-posture.html
18. U.K. National Cyber Force, Responsible Cyber Power, and Cyber Persistence Theory | Lawfare, https://www.lawfaremedia.org/article/uk-national-cyber-force-responsible-cyber-power-and-cyber-persistence-theory
19. Responsible Cyber Power in Practice (HTML) \- GOV.UK, https://www.gov.uk/government/publications/responsible-cyber-power-in-practice/responsible-cyber-power-in-practice-html
20. The Offense Death Cycle: Proactive Environmental Control as a Method of Persistent Cyber Defense, https://cyberdefensereview.army.mil/Portals/6/Documents/2026-vol11-iss1/CDR\_V11\_N1\_A5\_Styran.pdf
21. Licence to Operate: Transparency and Responsibility in UK Offensive Cyber Power \- RUSI, https://www.rusi.org/explore-our-research/publications/cyber-effects-perspectives/licence-operate-transparency-and-responsibility-uk-offensive-cyber-power
22. Cyber security in the French Republic, https://ebrary.net/173495/political\_science/cyber\_security\_french\_republic
23. La cyberdéfense, nouvelle arme géopolitique \- La Jaune et la Rouge, https://www.lajauneetlarouge.com/la-cyberdefense-nouvelle-arme-geopolitique/
24. Et la cyberdéfense devint une priorité nationale \- Ministère des Armées, http://www.defense.gouv.fr/actualites/cyberdefense-devint-priorite-nationale
25. cyberdéfense \- Assemblée nationale, https://www.assemblee-nationale.fr/dyn/opendata/RINFANR5L15B1141.html
26. Full article: Cyber conflict short of war: a European strategic vacuum \- Taylor & Francis, https://www.tandfonline.com/doi/full/10.1080/09662839.2022.2031991
27. DROIT INTERNATIONAL APPLIQUÉ AUX OPÉRATIONS DANS LE CYBERESPACE | Just Security, https://www.justsecurity.org/wp-content/uploads/2019/09/droit-internat-appliqu%C3%A9-aux-op%C3%A9rations-cyberespace-france.pdf
28. DPRK and Russian Collaboration in Cyberspace as a Driver for UK-ROK Cyber Cooperation \- 38 North: Informed Analysis of North Korea, https://www.38north.org/2026/03/dprk-and-russian-collaboration-in-cyberspace-as-a-driver-for-uk-rok-cyber-cooperation/
29. Forging Forward: South Korea's Proactive Cyber Defense and Strategic Cooperation with the United States \- CSIS, https://www.csis.org/analysis/forging-forward-south-koreas-proactive-cyber-defense-and-strategic-cooperation-united
30. Shifting Paradigms in Europe's Approach to Cyber Defence, https://www.swp-berlin.org/publikation/shifting-paradigms-in-europes-approach-to-cyber-defence
31. Shifting Paradigms in Europe's Approach to Cyber Defence, https://www.swp-berlin.org/en/publication/shifting-paradigms-in-europes-approach-to-cyber-defence
32. Key Activity: Offensive Cyber Operations \- Transparency Portal, https://www.transparency.gov.au/publications/defence/australian-signals-directorate/australian-signals-directorate-annual-report-2024-25/chapter-3.-report-on-performance/key-activity%3A-offensive-cyber-operations
33. Key Activity 3: Offensive cyber operations \- Transparency Portal, https://www.transparency.gov.au/publications/defence/australian-signals-directorate/australian-signals-directorate-annual-report-2021-22/chapter-3%3A-report-on-performance/key-activity-3%3A-offensive-cyber-operations
34. Israel – Hamas 2023 Symposium – Strategy and Self-Defence: Israel and its War with Iran, https://lieber.westpoint.edu/strategy-self-defence-israel-its-war-with-iran/
35. The Campaign Between Wars: How Israel Rethought Its Strategy to Counter Iran's Malign Regional Influence | The Washington Institute, https://www.washingtoninstitute.org/policy-analysis/campaign-between-wars-how-israel-rethought-its-strategy-counter-irans-malign
36. “The IDF Strategy”: A Focused Action Approach \- INSS, https://www.inss.org.il/publication/the-idf-strategy-a-focused-action-approach/
37. FIRST PRIZE: The Theory, Pursuit, and Practice of Cyber power in Israel, https://jmss.org/article/view/73312
38. Cyber Power – Tier Two \- The International Institute for Strategic Studies, https://www.iiss.org/research-paper/2021/06/cyber-power---tier-two/
39. The Evolution of Israel's Security Doctrine from Jabotinsky to the Present \- ICGS, https://icgs.org.il/en/publications/from-jabotinsky-to-today/
40. Two Years Into the War: Israel's Strategic Reckoning \- JINSA, https://jinsa.org/two-years-into-the-war-israels-strategic-reckoning/
41. Red Wings Ascendant \- NDU Press \- National Defense University, https://ndupress.ndu.edu/Portals/68/Documents/jfq/jfq-60/jfq-60\_95-101\_Flaherty.pdf?ver=gpxBZMLKL-k8dL7oKQGbgQ%3D%3D
42. Red Wings Ascendant: China's Air Force Contribution to ... \- DTIC, https://apps.dtic.mil/sti/tr/pdf/AD1018566.pdf
43. A Chinese Perspective on the Pentagon's Cyber Strategy: From 'Active Cyber Defense' to 'Defending Forward' | Lawfare, https://www.lawfaremedia.org/article/chinese-perspective-pentagons-cyber-strategy-active-cyber-defense-defending-forward
44. A Chinese Perspective on the Pentagon's Cyber Strategy: From, https://gssd.mit.edu/search-gssd/site/chinese-perspective-pentagon%E2%80%99s-cyber-61704-thu-03-28-2019-2120
45. RUSI Report: Strengthening UK–South Korea Cyber Security Cooperation, https://www.comparethecloud.net/news/rusi-report-strengthening-uk-south-korea-cyber-security-cooperation
46. Strengthening UK–South Korea Cyber Security Cooperation \- RUSI, https://my.rusi.org/resource/strengthening-uksouth-korea-cyber-security-cooperation.html
47. Integrating Hunt Forward Operations for Enhanced UK Cyber Campaigning \- RUSI, https://www.rusi.org/explore-our-research/publications/cyber-effects-perspectives/integrating-hunt-forward-operations-enhanced-uk-cyber-campaigning