Security / Resilience / Autonomous Systems

The Paradigm Shift in Cyber Warfare: Strategic Defense, Persistent Engagement, and the Architecture of Denial

Report summary

For decades, the dominant theoretical paradigm governing conflict in cyberspace has been overwhelmingly offense-centric. Driven by the inherent asymmetries of the digital domain—where an attacker theoretically needs only one successful exploit to compromise a network, while a defender must flawlessl

Status
Research archive item
Category
Security / Resilience / Autonomous Systems
Length
6,636 words
Reading time
31 minutes
Report type
evaluation

Key topics

  • Security / Resilience / Autonomous Systems
  • Security
  • Resilience
  • Autonomous Systems
  • AI
  • Agentic Web
  • .NET
  • Physics
  • Semantic Systems

Research provenance

Archive status
Research archive item
Content identity
sha256:207725492d8f463843435125cd532212dbf82bc052fa374cf7661d35fc62cda3

For citation, use the report title and canonical URL. Archival presence does not establish authorship or promote report statements into portfolio evidence.

This page renders the archived Markdown as safe, formatted HTML. It is background research and does not become a portfolio claim without evidence review.

Full report

On this page

1. Introduction to the Cyber Strategic Environment

For decades, the dominant theoretical paradigm governing conflict in cyberspace has been overwhelmingly offense-centric. Driven by the inherent asymmetries of the digital domain—where an attacker theoretically needs only one successful exploit to compromise a network, while a defender must flawlessly secure every node—policymakers and military strategists have long operated under the assumption that cyberspace structurally favors the offense1. This assumption fostered a strategic culture that prioritized the accumulation of zero-day vulnerabilities, the development of sophisticated malware, and the pursuit of offensive cyber superiority over the tedious, complex work of hardening critical infrastructure. However, a fundamental reassessment of this strategic posture is currently underway across the international community. Empirical evidence, refined academic theory, and the escalating complexity of state-sponsored cyber operations indicate that the most effective offense in the digital age is, in fact, a powerful, dynamic, and unyielding defense. The assertion that "the best offense is a good defense" in cyber warfare is not merely a rhetorical inversion; it is a profound strategic reality grounded in the economics of exploitation, the limitations of offensive kinetic effects, and the psychological attrition of adversaries. The strategic power of the digital domain no longer belongs exclusively to those who can breach perimeters, but to those who can sustain operational resilience under constant, low-level siege. This comprehensive analysis explores the multifaceted dimensions of this paradigm shift. It deconstructs the myth of offense dominance by examining the true costs of executing complex, physically destructive cyber operations, viewing cyber conflict through the lens of an intelligence contest that occasionally escalates into physical degradation. It evaluates the evolution of cyber strategic thought—from the fraught application of Cold War-era deterrence theory to the contemporary embrace of "Cyber Persistence Theory," "Defend Forward," and "Persistent Engagement"4. Furthermore, it investigates the geopolitical application of these strategies by major cyber powers, notably the United States, the People's Republic of China, and the Russian Federation, alongside the acute challenges faced by flashpoint actors such as Taiwan. Finally, this report details the technical bedrock required to actualize deterrence by denial—specifically the implementation of Zero Trust Architecture (ZTA) in critical Operational Technology (OT) environments, the emergence of Assured Positioning, Navigation, and Timing (PNT) markets, and the indispensable role of international legal frameworks in enforcing normative boundaries. Through this multi-disciplinary lens, the analysis demonstrates that by institutionalizing robust resilience, implementing granular access controls, and continuously contesting adversaries in the gray zone, defending states can radically alter the cost-benefit calculus of attackers. In cyberspace, strategic victory is rarely achieved through a decisive disarming strike; rather, it is secured by denying the adversary their operational objectives, forcing them into a state of continuous, resource-depleting tactical friction.

2. Deconstructing the Offense-Defense Balance

The foundation of the "offense-dominant" consensus rests on a superficial understanding of network infiltration. While it is true that finding a single flaw in a software perimeter is often easier than patching all vulnerabilities, defining the offense-defense balance solely by the ease of initial access conflates espionage or simple disruption with strategic, physically destructive warfare.

2.1 The Complexity and Cost of Kinetic Cyber Effects

A rigorous assessment of the cyber offense-defense balance requires measuring the value and costs of an operation to both the attacker and the defender, contingent upon the specific organizational skills and technologies involved2. When the objective of a cyber operation shifts from data exfiltration (espionage) or simple denial-of-service to the degradation or destruction of physical infrastructure, the costs and complexities for the offense rise exponentially8. As defensive organizations improve their capability to manage complex information technology, the relative ease of offense declines dramatically. The widely cited Stuxnet operation against Iran's Natanz nuclear enrichment facility serves as the premier empirical case study for evaluating the true cost of offense. While Stuxnet successfully destroyed numerous centrifuges, the operation required immense resources: prolonged intelligence gathering, the procurement of multiple zero-day exploits, intricate knowledge of specific Siemens programmable logic controllers (PLCs), and a highly sophisticated delivery mechanism capable of bridging an air-gapped network. Detailed analyses suggest that the organizational and financial costs borne by the attackers vastly exceeded the routine costs of defense2.

VariableOffensive Cost DriversDefensive Cost DriversStrategic Impact of Enhanced Defense
Initial AccessZero-day procurement, bespoke phishing campaigns, extended reconnaissance.Continuous monitoring, user training, multi-factor authentication (MFA).Forces attackers to rely on highly sophisticated, expensive zero-days rather than cheap social engineering vectors.
Lateral MovementCustom tool development to bypass internal sensors and evade behavioral detection.Microsegmentation, internal firewalls, Zero Trust policy enforcement.Traps attackers in limited enclaves, preventing access to high-value data or critical control systems.
Kinetic/Physical EffectsDeep engineering knowledge of proprietary Operational Technology (OT), air-gap bridging.System Behavior Analytics (SBA), hardware fail-safes, network segregation.Makes physical sabotage prohibitively expensive and highly likely to be detected before execution.
PersistenceCommand and Control (C\&C) infrastructure maintenance, evading threat hunting algorithms.Active threat hunting, dynamic reconfiguration, rapid incident response.Drastically shortens the lifespan of an intrusion, minimizing the adversary's return on investment.

The success of offensive operations that result in kinetic or deeply disruptive effects is rarely the result of an insurmountable structural advantage of the domain itself. Instead, it is almost exclusively the byproduct of poor defensive management and the creation of unnecessary vulnerabilities2. Furthermore, the historical convergence of traditional human intelligence (HUMINT) and cyber operations reveals that major cyber powers frequently rely on human assets to bridge air gaps and deploy malware, demonstrating that purely digital offensive superiority is often a myth10. Therefore, a properly resourced and managed defense inherently shifts the balance, transforming cyberspace from a domain of easy offensive victories into a grueling environment of attrition for the attacker.

2.2 Historical Analogies and the Economics of Exploitation

The strategic logic of prioritizing defensive attrition over offensive maneuvering has historical analogues in traditional domains. For instance, the conceptualization of homeland missile defense rests heavily on the premise of deterrence by denial. By introducing location uncertainty and deploying mobile intercontinental ballistic missiles (ICBMs) alongside active defenses, a defending state can force an attacker to double or triple their strike force to ensure destruction11. This logic translates directly into the cyber domain: a robust, continuously shifting network architecture forces an adversary to expend disproportionate resources to achieve a high probability of success. Similarly, states with limited offensive capabilities have historically relied on intense active defense and isolationism. Albania's Cold War-era policy of "bunkerization" and terrain denial, while economically straining, effectively created a posture of defensive deterrence that made external invasion too costly to contemplate13. Japan's modern integration of ballistic missile defense (BMD) capabilities represents a contemporary effort to enhance deterrence by denial, forcing adversaries to reconsider the efficacy of coercive strikes14. In cyberspace, applying this logic means that by forcing adversaries to constantly re-tool and burn their capabilities without achieving strategic milestones, a powerful defense acts as a mechanism of economic warfare, steadily degrading the adversary's capacity to project power.

3. The Reconceptualization of Cyber Deterrence

As the limitations of an exclusively offensive posture have become apparent, the strategic discourse has evolved to address how states can prevent cyber aggression. For years, policymakers attempted to map Cold War-era nuclear deterrence frameworks onto cyberspace, a conceptual misalignment that has generated significant strategic confusion and operational failure.

3.1 The Illusion of the Nuclear Analogy and the Four Mechanisms of Dissuasion

Traditional deterrence theory relies heavily on the threat of massive retaliation (deterrence by punishment) to dissuade an adversary from taking a proscribed action15. In the nuclear realm, the attribution of an attack is immediate, the effects are catastrophic, and the threshold for response is universally understood. Cyberspace violates nearly all of these foundational conditions. Cyber operations are characterized by plausible deniability, routed through proxy servers, compromised third-party infrastructure, and non-state actors, making rapid and definitive attribution highly difficult16. Furthermore, the vast majority of state-sponsored cyber activities—such as intellectual property theft, election interference, and low-level disruptive attacks—occur in the "gray zone" below the threshold of armed conflict (jus ad bellum)4. Threatening kinetic military retaliation for a non-kinetic data breach lacks credibility and violates the international legal principle of proportionality20. Consequently, scholars such as Joseph Nye have argued that deterrence in cyberspace must be fundamentally broadened beyond punishment. Dissuasion in the digital domain relies equally on three other mechanisms: deterrence by denial (hardening defenses so the attack fails), entanglement (leveraging economic and systemic interdependence so an attack inadvertently harms the attacker), and norms (creating reputational costs for violating international standards)16.

Deterrence MechanismStrategic Application in CyberspaceOperational Efficacy and Limitations
Deterrence by PunishmentThreatening cross-domain retaliation (sanctions, kinetic strikes) or devastating counter-cyber attacks.Highly limited. Lacks credibility for gray-zone operations. Hindered by attribution challenges and escalation risks.
Deterrence by DenialImplementing Zero Trust Architecture, rapid patching, and network resilience.Highly effective. Alters the attacker's cost-benefit calculus regardless of attribution or adversary intent.
EntanglementExploiting mutual dependencies on global financial systems, supply chains, or shared digital infrastructure.Moderately effective against rational state actors, but completely ineffective against rogue states or non-state proxies.
Norms and TaboosEstablishing multilateral agreements and publicly attributing and shaming violators.Aims to establish long-term stability but suffers from severe enforcement and accountability gaps.

Of these mechanisms, deterrence by denial emerges as the most reliable and unilaterally controllable capability, as it does not rely on the adversary's rationality or the immediate resolution of the attribution problem16. In the pursuit of this, the concept of "transparent cyber deterrence" has gained traction. This strategy involves the deliberate, public disclosure of a nation's targeted offensive and defensive capabilities to actively influence the cost-benefit decisions of malicious actors, shaping global behavior by demonstrating that aggression will be met with immediate, proportional consequences24.

3.2 The Efficacy of Small State Cyber Diplomacy

The reliance on deterrence by denial and norm-building is particularly critical for smaller states, which cannot realistically field the offensive cyber forces required for deterrence by punishment. Analysis of small state cyber postures reveals that these nations must compensate for their inherent weaknesses through international cooperation, agile decision-making, and specialization17. Cyber diplomacy forms the bedrock of their defense, allowing them to leverage the collective security of broader alliances. Estonia stands as the paramount example of a small state mastering deterrence by denial through digital resilience. Following the devastating 2007 cyberattacks, Estonia fundamentally reimagined state continuity. Drawing on profound ontological insecurities, Estonia established the world's first "Data Embassy" in Luxembourg, utilizing KSI blockchain technology to back up critical government databases beyond its physical sovereign borders26. This model of extreme resilience ensures that even in the event of a total physical occupation or catastrophic cyber degradation of the homeland, the digital state continues to function, effectively denying the adversary their ultimate strategic objective.

4. Strategic Postures: Persistent Engagement, Defend Forward, and Their Discontents

Recognizing the failure of traditional deterrence to halt the steady bleed of intellectual property and the constant probing of critical infrastructure, strategic thought in the United States and allied nations has shifted toward a more proactive paradigm. This shift, however, has triggered a fierce academic and policy debate regarding the stability of cyberspace.

4.1 The Ascendancy of Cyber Persistence Theory

Theorists Michael Fischerkeller and Richard Harknett have pioneered "Cyber Persistence Theory," arguing that the structural features of cyberspace—specifically its absolute interconnectedness and the condition of constant contact—render traditional, episodic deterrence obsolete5. They argue that applying coercion theory to an environment of constant exploitation defies the core axioms of deterrence theory6. Because states are already in continuous, low-level conflict, Cyber Persistence Theory asserts that the primary strategic goal is not to deter action entirely, but to seize and maintain the initiative6. This theory advocates for an approach where defense is not a static wall, but a dynamic, continuous engagement that precludes, mitigates, and counters adversary actions before they cumulate into strategic losses6. By operating seamlessly between defense and offense, the defending state can dictate the tempo of operations, compelling adversaries to shift resources away from attacks and toward securing their own vulnerabilities5.

4.2 "Defend Forward" and the Execution of Active Defense

This theoretical framework was institutionalized by the United States Department of Defense and U.S. Cyber Command under the doctrines of "Persistent Engagement" and "Defend Forward"4. Rather than waiting for attacks to strike domestic networks, these strategies dictate that cyber forces must operate globally and continuously, maneuvering in foreign cyberspace to intercept and halt threats at their source4. Defend Forward represents the aggressive operationalization of deterrence by denial. By actively hunting adversaries in neutral or third-party networks, dismantling their infrastructure (such as taking down botnets or C\&C servers), and exposing their proprietary tools, the defending state introduces severe tactical friction29. The intended second-order effect of this continuous contact is "tacit bargaining": through repeated, non-escalatory disruptions, the adversary is compelled to acknowledge mutually understood boundaries of acceptable behavior, establishing norms through action rather than diplomacy3.

4.3 Escalation Inversion and the Security Dilemma

While Defend Forward provides a highly active defensive posture, it introduces profound third-order risks that threaten global strategic stability. Scholars such as Jason Healey and Robert Jervis warn that the assumptions underpinning Persistent Engagement may lead to "escalation inversion" and exacerbate the cyber security dilemma3. The core risk is that persistent engagement might not lead to tacit stability, but rather to an accelerated, chaotic arms race. If an adversary anticipates that their C\&C servers will be routinely dismantled by forward-defending forces, they are incentivized to bypass traditional operational control. To ensure mission success, adversaries may increasingly rely on fully autonomous, self-propagating malware that requires no external command infrastructure30. This adaptation drastically increases the risk of untargeted collateral damage and accidental escalation, as autonomous agents are far more difficult to recall or control once deployed30. Furthermore, the very act of maneuvering in foreign cyberspace to conduct defensive disruptions can be indistinguishable from the preparatory phases of a severe offensive attack. An adversary observing foreign forces in their networks cannot know if the intent is merely to disrupt an ongoing campaign (defense) or to lay the groundwork for a crippling strike on their critical infrastructure (offense)3. This ambiguity inherently threatens crisis stability. Consequently, critics argue for an alternative framework termed "stability-enhancing engagement," which begins with the desired end-state of strategic stability and works backward, prioritizing resilience, diplomatic signaling, and coalition-building over unilateral offensive maneuvering31.

5. Global Geopolitical Dynamics and Statecraft

The application of defensive and offensive cyber strategies varies significantly among major geopolitical actors, shaped by distinct national security doctrines and technological capacities. The strategic competition between the United States, China, and Russia, alongside the existential pressures faced by Taiwan and the collective response of NATO, illustrates the practical realities of modern cyber warfare.

5.1 China: Cyber Sovereignty and Information Dominance

The People's Republic of China (PRC) approaches cyberspace through the lens of "cyber sovereignty," a doctrine that fundamentally opposes the U.S.-led multi-stakeholder model of an open, unregulated global internet34. Chinese strategy fuses strict domestic information control with aggressive external technological expansion, viewing cyberspace as a critical domain for maintaining internal regime stability while projecting global influence34. Recognizing the strategic value of information dominance, the People's Liberation Army (PLA) recently executed a massive restructuring of its cyber capabilities. In April 2024, the PLA dissolved the Strategic Support Force (SSF), replacing it with distinct branches under the Central Military Commission (CMC): the Information Support Force (ISF), the Cyberspace Force (CSF), and the Aerospace Force (ASF)34. This reorganization signals a highly centralized, integrated approach to multi-domain warfare, mirroring the U.S. combatant command structure but tailored to China's unique strategic imperatives34. China's offensive cyber operations, deeply rooted in Sun Tzu's concepts of asymmetric and intelligentized warfare, have historically focused on massive campaigns of intellectual property theft and espionage aimed at achieving technological supremacy in fields like Artificial Intelligence (AI) and 5G10. Domestically, the PRC's "Xinchuang" policy mandates the replacement of foreign IT infrastructure with indigenous technology, a massive undertaking designed to eliminate supply chain vulnerabilities and insulate the nation from Western digital embargoes36. China's strategy demonstrates a profound understanding of the "stability-instability paradox": by maintaining an impenetrable domestic defense, China creates a secure base from which to confidently project offensive power globally, leveraging cyber operations as a primary tool of economic statecraft without fear of catastrophic retaliation10.

5.2 Russia: Information Confrontation and Hybrid Warfare

Russian military doctrine views cyberspace not as a distinct technological domain, but as one facet of a broader concept known as informatsionnoye protivoborstvo (information confrontation)38. This doctrine seamlessly integrates informational-technical operations (network hacking, denial-of-service, data destruction) with informational-psychological operations (disinformation, election interference, subversion)38. Operationalized by highly capable state-sponsored units within the GRU (military intelligence), FSB (domestic security), and SVR (foreign intelligence)—such as Sandworm, APT28 (Fancy Bear), APT29 (Cozy Bear), and Star Blizzard—Russia employs cyber operations as an instrument of continuous hybrid warfare38. The 2016 Russian Information Security Doctrine formally linked internal stability with external influence, positioning all foreign entities as potential threats to Russian information sovereignty38. Russia's approach highlights a critical vulnerability in Western defenses: while Western nations may excel at technical defense (securing networks via zero trust), they often struggle to defend against the psychological and cognitive manipulation that Russia deploys via the same digital infrastructure. The fusion of state-directed bot networks disseminating pro-Russian narratives with targeted spear-phishing campaigns creates a holistic offensive capability designed to degrade societal trust rather than merely destroy physical servers38.

5.3 Taiwan: The Frontlines of AI-Assisted Cyber Warfare

Nowhere is the necessity of a powerful cyber defense more acute than in Taiwan. Viewed by Beijing as a breakaway province, Taiwan is subjected to an unprecedented volume of cyber coercion designed to test its resilience, intimidate its political leadership, and steal critical semiconductor intellectual property40. In 2025, Taiwan's National Security Bureau reported that the island's critical infrastructure faced a staggering daily average of 2.63 million cyberattacks, a figure that surges concurrently with PLA kinetic military drills and key political speeches by Taiwanese leadership40. Crucially, the nature of these attacks is evolving rapidly due to artificial intelligence. In July 2026, Taiwan detected highly sophisticated, AI-assisted cyberattacks originating overseas targeting government agencies, the nuclear safety agency, and at least seven major energy companies41. Utilizing open-source AI agent frameworks like "OpenClaw" and "Hermes," attackers deployed coordinated, autonomous hacking teams capable of independently evaluating attack vectors, reprioritizing targets in real-time, and rapidly adjusting tactics when blocked by standard defenses43. This represents a terrifying inflection point in cyber warfare: the advent of fully autonomous, end-to-end AI cyberattacks capable of operating at a speed and scale that overwhelms traditional, human-in-the-loop Security Operations Centers (SOCs)43. Despite allocating NT$8.8 billion (approximately USD 300 million) toward its national cybersecurity development program from 2025 to 2028, Taiwan's expenditure remains vastly insufficient compared to global top spenders40. In response to the autonomous threat, defense analysts have urgently called for the development of a national AI "Cyber Shield"—a federated, autonomous defensive network capable of preemptively triaging vulnerabilities, integrating real-time threat intelligence, and executing remediation at machine speed45. Taiwan's experience proves that as offensive tools achieve autonomy, defensive architectures must equally evolve to leverage AI for rapid, predictive resilience45.

5.4 NATO and the Institutionalization of Collective Defense

Recognizing that disjointed national defenses are easily exploited, the North Atlantic Treaty Organization (NATO) has aggressively institutionalized collective cyber defense. At the 2024 Washington Summit, NATO significantly expanded its Cyber Defense Pledge, transitioning from voluntary guidelines to mandatory cybersecurity maturity assessments and stringent 24-hour incident reporting requirements for critical infrastructure across all member states46. This formalized compliance mechanism ensures that the weakest link in the alliance's digital supply chain does not compromise collective security. To resource these mandates, the 2025 Hague Summit saw the alliance commit to raising total defense and security-related spending to 5% of GDP by 2035, funneling unprecedented capital into secure cloud infrastructures and multi-domain defense networks46. The global defense cybersecurity market, valued at USD 39.15 billion in 2024, is consequently projected to reach USD 61.93 billion by 2032, expanding at a CAGR of 5.9%48. The broader cyber warfare market is expected to scale even faster, reaching USD 122.3 billion by 2032 at a 14.3% CAGR46. NATO is also actively integrating advanced technologies into its deterrence posture to counter hybrid and AI-enabled threats. Initiatives like the Defence Innovation Accelerator for the North Atlantic (DIANA) and the €1 billion NATO Innovation Fund provide the capital for dual-use tech integration49. The deployment of AI tools such as AI FELIX (automating communication processing during attacks) and AI AIDA (accelerating intelligence analysis) demonstrate a commitment to utilizing machine learning for rapid incident response49. Furthermore, NATO has pledged a minimum baseline funding of €40 billion within the next year to support Ukraine, establishing the NATO Security Assistance and Training for Ukraine (NSATU) to coordinate equipment and interoperability, directly linking cyber capacity building with conventional warfare support47.

Technical defenses alone are insufficient without a framework to shape international norms, attribute malicious behavior, and impose collective consequences. The strategic defense of cyberspace requires the integration of robust international law and cohesive multilateral alliances to hold rogue actors accountable.

6.1 The UN Norms of Responsible State Behavior

At the global diplomatic level, the United Nations Group of Governmental Experts (UN GGE) and the Open-Ended Working Group (OEWG) have labored for nearly two decades to establish boundaries for acceptable state conduct. The adoption of consensus reports in 2015 and 2021 established 11 voluntary, non-binding norms of responsible state behavior in cyberspace50. Key among these are Norm 13(f), which dictates that states should not intentionally damage critical infrastructure that provides services to the public, and Norm 13(c), which states that nations should not knowingly allow their territory to be used for internationally wrongful acts using Information and Communication Technologies (ICTs)52. The framework also explicitly protects Computer Emergency Response Teams (CERTs) under Norm 11, prohibiting activity that harms authorized emergency responders, and demands that states implement a Vulnerabilities Equities Process to responsibly manage zero-day exploits53. However, the primary vulnerability of the UN framework is the glaring accountability gap. Despite Russia's role in drafting these norms, its actions in Ukraine—including attacks on the power grid and the deployment of destructive wiper malware—constitute severe violations of the very framework it helped establish52. Norms are only effective as a defensive mechanism if they are backed by the willingness of the international community to impose severe political, economic, and diplomatic consequences on violators18. The failure to consistently enforce these norms reduces them to rhetorical aspirations rather than tangible deterrents56. Furthermore, international law struggles to address the actions of non-state actors operating in the legal void. Scholars point out that traditional international law, designed for state-to-state interactions, lacks the "teeth" to penalize individual hackers or technology firms acting as proxies57. Consequently, states are increasingly leveraging domestic criminal law to combat foreign malevolent cyber activity, focusing on pragmatic defenses against the daily barrage of ransomware and corporate espionage rather than waiting for an elusive international consensus on "cyber doomsday" scenarios58.

6.2 The Tallinn Manual and the Boundaries of International Law

Because the UN norms are voluntary, the definitive academic effort to map existing, binding international law onto cyberspace is the Tallinn Manual process, spearheaded by the NATO Cooperative Cyber Defence Centre of Excellence (CCDCOE)60. The original Tallinn Manual (2013) focused heavily on jus ad bellum and jus in bello, determining the conditions under which a cyber operation constitutes a "use of force" or an "armed attack" justifying a kinetic self-defense response60. Tallinn Manual 2.0 (2017) expanded this scope to the gray zone, analyzing how international law governs operations below the threshold of armed conflict, establishing guidelines for sovereignty, non-intervention, and the legality of countermeasures60. Recognizing the rapid evolution of state practice and the weaponization of new technologies, the CCDCOE launched the Tallinn Manual 3.0 project in 2021, directed by Professor Michael N. Schmitt alongside co-editors Liis Vihul and Marko Milanović, with an anticipated release in 202660. This update is critical for defensive strategy, as it directly addresses unresolved legal ambiguities that adversaries currently exploit. Tallinn Manual 3.0 will tackle the highly contested concept of sovereignty in cyberspace, the due diligence obligation of states to stop hackers operating within their borders, the legality of remotely conducted espionage, and the classification of election meddling as an internationally wrongful act59. Crucially, it will examine whether the weaponization of information—such as AI-driven disinformation campaigns that foreseeably cause injury or death—crosses the threshold into an armed attack63. By clearly delineating what constitutes an internationally wrongful act, the Tallinn Manual provides government legal advisors with the jurisprudential foundation required to authorize Defend Forward operations. If an adversary's action is legally classified as a violation of sovereignty, the defending state is empowered under international law to execute proportional countermeasures, legitimizing the active defense posture4.

7. Technological Architectures of Denial: Zero Trust, PNT, and Autonomous Defense

For deterrence by denial to function as a viable strategic offense, the underlying architecture of a nation's critical infrastructure must be inherently hostile to exploitation. The traditional model of cybersecurity—a hardened perimeter protecting a soft, implicitly trusted internal network—has failed decisively against modern threat actors.

7.1 The Demise of Perimeter Defense and the Rise of ZTA

In response to this systemic vulnerability, the global cybersecurity consensus has shifted toward Zero Trust Architecture (ZTA), formally codified in standards such as NIST SP 800-20765. ZTA operates on the foundational principle of "never trust, always verify"67. It abolishes the concept of implicit trust based on network location. Instead, every access request must be explicitly authenticated, authorized, and continuously validated based on identity, device posture, and contextual behavioral analytics66. Implementing ZTA is a complex, iterative process typically divided into six phases:

1. Foundations & Inventory (4-8 weeks): Mapping all assets, identities, and data flows.

2. Identity Verification (4-10 weeks): Implementing MFA and Identity Providers (IdP).

3. Device Trust (6-12 weeks): Validating the security posture of accessing endpoints.

4. Network Microsegmentation (8-16 weeks): Dividing the network into granular, isolated zones to prevent lateral movement.

5. Applications & Data (8-20 weeks): Implementing Data Loss Prevention (DLP) and API security.

6. Maturity & Automation (12-24 weeks): Integrating User and Entity Behavior Analytics (UEBA) and Security Orchestration, Automation, and Response (SOAR)67.

By implementing microsegmentation and enforcing the principle of least privilege, ZTA drastically minimizes the blast radius of a compromised account66. In a mature Zero Trust environment, an adversary who successfully phishes an employee's credentials will find themselves isolated in a micro-segment, unable to traverse the network or access critical data without triggering automated behavioral alarms67.

7.2 The Brownfield Challenge: ZTA in OT and SCADA Systems

While ZTA is highly effective in modern IT environments, implementing it within Critical Infrastructure—specifically Operational Technology (OT) and Supervisory Control and Data Acquisition (SCADA) systems—presents monumental engineering challenges66. OT environments are often "brownfield" deployments, consisting of legacy equipment and Programmable Logic Controllers (PLCs) designed decades before modern cybersecurity concepts existed66. These systems possess unique constraints: a lack of identity awareness (PLCs cannot process MFA requests), strict Size, Weight, and Power (SWaP) limitations, and a severe intolerance for latency, as industrial processes require deterministic, real-time communication66. Most critically, unlike IT systems that can safely block access during an anomaly, OT systems must prioritize human safety and physical availability, requiring fail-secure or hardware bypass designs66. To bridge this gap, defensive strategy has evolved to employ software-defined overlay architectures. Rather than attempting to force a legacy PLC to authenticate, an overlay network acts as a protective shield in front of the device, strongly verifying every inbound connection using available identity factors before allowing the traffic to proceed via industrial protocols66. Furthermore, the Electric Power Research Institute (EPRI) has introduced the ZT4OT framework, which utilizes System Behavior Analytics (SBA) and OT-tuned User and Entity Behavior Analytics (OT-UEBA)68. By establishing a design-derived behavioral baseline for how a SCADA system should operate, AI-enabled monitoring can instantly detect anomalous physics-based commands even if the command originates from a fully authenticated user account68.

Architecture ParadigmImplicit Trust ModelSegmentation StrategyIncident Response Capacity
Traditional IT/OTHigh (Internal networks trusted by default).Macro (IT separated from OT via single firewall).Reactive, manual, slow isolation leading to broad system compromise.
Enterprise ZTA (NIST 800-207)Zero (Continuous verification).Micro (Application/workload level).Automated isolation via SOAR, highly restricted blast radius.
OT/SCADA ZTA OverlayZero (Proxy-based identity enforcement).Protocol-aware Microsegmentation (Zones and Conduits).Fail-safe/Fail-open prioritization, isolation without disrupting physical safety controls.

7.3 Emerging Architectures: Assured PNT, Post-Quantum, and AI

As foundational architectures harden, adversaries target auxiliary vulnerabilities. The reliance of critical infrastructure on Global Positioning System (GPS) signals for precise timing and synchronization creates a massive vulnerability to electronic warfare (EW) and signal jamming. Consequently, the Assured Positioning, Navigation, and Timing (A-PNT) market has become a critical defensive priority, projected to grow at a 28.4% CAGR to reach USD 8.52 billion by 203577. NATO's 2024 Cyber Defense Pledge explicitly includes PNT signal authentication—utilizing blockchain-based timing attestation and real-time spoofing detection—blurring the line between hardware navigation and cyber defense77. Looking forward, the advent of quantum computing threatens the cryptographic foundations of existing OT networks. The migration to Post-Quantum Cryptography (PQC) is becoming an urgent requirement to secure SCADA communications, such as DNP3 traffic, against future decryption capabilities70. Simultaneously, while AI and Large Language Models (LLMs) offer unprecedented capabilities for autonomous cyber defense (such as rapid path planning for UAVs and machine-speed anomaly detection), researchers caution that these systems must be governed by strict ethical guidelines and accountability frameworks. The risk of false positives generated by autonomous AI defenses could inadvertently trigger cascading failures within critical infrastructure, highlighting the delicate balance between automation and human oversight33.

8. Conclusion

The architecture of modern cyber warfare dictates that offensive dominance is a precarious and transient illusion. As the kinetic impact of cyber operations requires increasingly specific engineering, vast financial resources, and deep systemic access, the advantage tilts fundamentally toward a well-resourced, technologically advanced defense. The doctrine that "the best offense is a powerful defense" is not a passive resignation, but an active, aggressive strategy of denial, attrition, and continuous engagement. To achieve strategic superiority, nations must integrate multiple layers of defense. Operationally, doctrines like Persistent Engagement and Defend Forward allow military forces to seize the initiative, introducing tactical friction into adversary networks and precluding attacks before they manifest domestically. However, this active posture must be tempered by precise diplomatic signaling and stringent legal frameworks to prevent rapid escalation inversion and the uncontrolled proliferation of autonomous malware. Technologically, the mandate is clear: the implementation of Zero Trust Architecture across both IT and legacy OT/SCADA environments is no longer optional; it is a national security imperative. By stripping away implicit trust, enforcing microsegmentation, deploying Assured PNT, and leveraging AI-driven System Behavior Analytics, defending organizations ensure that even when perimeters are breached, the adversary's operational objectives remain violently out of reach. Ultimately, cyber defense is an exercise in strategic deterrence by denial. By hardening critical infrastructure, codifying international legal thresholds through instruments like the Tallinn Manual, and enforcing compliance through powerful multilateral alliances such as NATO, defending states destroy the adversary's return on investment. In the continuous, gray-zone conflict of the digital age, victory belongs to the actor who can sustain operations, absorb impact, and endlessly deny their opponent the fruits of exploitation.

Works cited

1. Rebecca Slayton, Ph.D. \- College of Science & Engineering, https://cse.umn.edu/cbi/rebecca-slayton-phd

2. What Is the Cyber Offense-Defense Balance?: Conceptions, Causes, and Assessment, https://muse.jhu.edu/article/648308/summary

3. Cybersecurity Threat Answers \- DebateUS, https://debateus.org/cybersecurity-threat-answers/

4. Defend Forward & Sovereignty: How America's Cyberwar Strategy Upholds International Law, https://repository.law.miami.edu/cgi/viewcontent.cgi?article=2614\&context=umialr

5. Persistent Engagement: Foundation, Evolution and Evaluation of a Strategy | Lawfare, https://www.lawfaremedia.org/article/persistent-engagement-foundation-evolution-and-evaluation-strategy

6. Initiative Persistence as the Central Approach for US Cyber Strategy \- College of Arts and Sciences, https://www.artsci.uc.edu/content/dam/refresh/artsandsciences-62/departments/political-science/ccsp/pdf\_downloadableflyers/Kybernao\_PaperSeries\_Issue1\_Final.pdf

7. What Is the Cyber Offense-Defense Balance? Conceptions, Causes, and Assessment, https://www.belfercenter.org/publication/what-cyber-offense-defense-balance-conceptions-causes-and-assessment

8. Cult of the Cyber Offensive: Misperceptions of the Cyber Offense/Defense Balance (Volume 15, Issue 1\) \- Yale Journal of International Affairs, https://www.yalejournal.org/publications/cult-of-the-cyber-offensive-misperceptions-of-the-cyber-offensedefense-balance

9. Why Cyber Operations Do Not Always Favor the Offense \- Belfer Center, https://www.belfercenter.org/publication/why-cyber-operations-do-not-always-favor-offense

10. The Impact of China on Cybersecurity: Fiction and Friction \- ResearchGate, https://www.researchgate.net/publication/273513462\_The\_Impact\_of\_China\_on\_Cybersecurity\_Fiction\_and\_Friction

11. 'First, we will defend the homeland': The case for homeland missile defense, https://www.atlanticcouncil.org/in-depth-research-reports/report/first-we-will-defend-the-homeland-the-case-for-homeland-missile-defense/

12. ʻFirst, we will defend the homeland': \- Atlantic Council, https://www.atlanticcouncil.org/wp-content/uploads/2025/02/First-We-Will-Defend-the-Homeland-2024-FINAL-1.pdf

13. Albanian Land Forces \- Grokipedia, https://grokipedia.com/page/Albanian\_Land\_Forces

14. "Japan's Missile Defense: Diplomatic and Security Policies in a Changing Strategic Environment"., https://www2.jiia.or.jp/en/pdf/polcy\_report/pr200703-jmd.pdf

15. The Sheathed Sword: From Nuclear Brink to No First Use 9789354359590, 9789354355806, https://dokumen.pub/the-sheathed-sword-from-nuclear-brink-to-no-first-use-9789354359590-9789354355806.html

16. Deterrence and Dissuasion in Cyberspace \- ResearchGate, https://www.researchgate.net/publication/313268473\_Deterrence\_and\_Dissuasion\_in\_Cyberspace

17. \[PDF\] Deterrence and Dissuasion in Cyberspace \- Semantic Scholar, https://www.semanticscholar.org/paper/Deterrence-and-Dissuasion-in-Cyberspace-Nye/bffc9f4c3d6867b0e425cdcba247cca2d26f778c

18. Creating Accountability for Global Cyber Norms \- CSIS, https://www.csis.org/analysis/creating-accountability-global-cyber-norms

19. A Comparative Study of Domestic Laws Constraining Private Sector Active Defense Measures in Cyberspace, https://journals.law.harvard.edu/nsj/wp-content/uploads/sites/82/2020/01/CORCORAN\_Vol.-11.1.pdf

20. Chapter 3: Governance of Information Technology and Cyber Weapons, https://www.amacad.org/publication/governance-dual-use-technologies-theory-and-practice/section/6

21. A/76/136\* General Assembly \- United Nations Digital Library System, https://digitallibrary.un.org/record/3933543/files/A\_76\_136-EN.pdf

22. Integrated Deterrence and Cyberspace \- NDU Press, https://ndupress.ndu.edu/Portals/68/Documents/strat-monograph/Integrated-Deterrence-and-Cyberspace.pdf

23. What is the Future of Cyber Deterrence? \- FDD, https://www.fdd.org/analysis/2022/04/18/what-is-the-future-of-cyber-deterrence/

24. Transparent Cyber Deterrence \- NDU Press \- National Defense University, https://ndupress.ndu.edu/Joint-Force-Quarterly/Joint-Force-Quarterly-107/Article/Article/3197215/transparent-cyber-deterrence/

25. Deterrence by denial in cyberspace | Request PDF \- ResearchGate, https://www.researchgate.net/publication/367957765\_Deterrence\_by\_denial\_in\_cyberspace

26. Distributed Denial-of-Government: \- Royal Holloway Research Portal, https://pure.royalholloway.ac.uk/files/44682853/2020\_Robinson\_N\_PhD.pdf

27. Policy Roundtable: Cyber Conflict as an Intelligence Contest, https://tnsr.org/roundtable/policy-roundtable-cyber-conflict-as-an-intelligence-contest/

28. Choosing between Persistent Engagement and Deterrence in the American Cyber security Strategy | Request PDF \- ResearchGate, https://www.researchgate.net/publication/367997165\_Choosing\_between\_Persistent\_Engagement\_and\_Deterrence\_in\_the\_American\_Cyber\_security\_Strategy

29. The Escalation Inversion and Other Oddities of Situational Cyber Stability \- Texas National Security Review, https://tnsr.org/wp-content/uploads/2020/09/TNSR-Vol3-Iss4-Healey-and-Jervis.pdf

30. Preparing the next phase of US cyber strategy \- Atlantic Council, https://www.atlanticcouncil.org/in-depth-research-reports/issue-brief/preparing-the-next-phase-of-us-cyber-strategy/

31. The implications of persistent (and permanent) engagement in cyberspace, https://academic.oup.com/cybersecurity/article/5/1/tyz008/5554878

32. Cyber as statecraft, not war \- Defense Priorities, https://www.defensepriorities.org/briefs/cyber-as-statecraft-not-war/

33. (PDF) Systematic review of machine and deep learning models for unmanned aerial vehicles cyber threat defense \- ResearchGate, https://www.researchgate.net/publication/400761748\_Systematic\_review\_of\_machine\_and\_deep\_learning\_models\_for\_unmanned\_aerial\_vehicles\_cyber\_threat\_defense

34. Full article: Navigating the nexus: geopolitical, international relations and technical dimensions of US-China cyber strategic competition \- Taylor & Francis, https://www.tandfonline.com/doi/full/10.1080/23311886.2025.2499171

35. geopolitical, international relations and technical dimensions of US-China cyber strategic competition \- Taylor & Francis, https://www.tandfonline.com/doi/pdf/10.1080/23311886.2025.2499171

36. A secretive Chinese committee draws up list to replace US tech \- Taipei Times, https://www.taipeitimes.com/News/editorials/archives/2021/11/21/2003768216

37. (PDF) Navigating the nexus: geopolitical, international relations and technical dimensions of US-China cyber strategic competition \- ResearchGate, https://www.researchgate.net/publication/391347610\_Navigating\_the\_nexus\_geopolitical\_international\_relations\_and\_technical\_dimensions\_of\_US-China\_cyber\_strategic\_competition

38. Cyberwarfare by Russia \- Wikipedia, https://en.wikipedia.org/wiki/Cyberwarfare\_by\_Russia

39. \#GIDSresearch 2/2020 \- Army University Press, https://www.armyupress.army.mil/Portals/7/Hot-Spots/docs/Russia/GIDSresearch2020\_02\_McDermott\_Bartles%20(2).pdf

40. China's Escalating Cyberattacks Threaten Taiwan's National Security, https://globaltaiwan.org/2026/08/chinas-cyberattacks-taiwans-national-security/

41. Taiwan says it was targeted last month in AI-driven hacking campaign \- WKZO, https://wkzo.com/2026/08/12/taiwan-says-it-was-targeted-last-month-in-ai-driven-hacking-campaign/

42. Taiwan says it was hit by ‘abnormal’ AI-assisted cyber-attack, https://www.theguardian.com/technology/2026/aug/13/taiwan-ai-assisted-cyber-attacks-overseas

43. Taiwan Reports AI-Agent Cyberattacks on Government Networks \- eSecurity Planet, https://www.esecurityplanet.com/threats/news-ai-assisted-government-cyberattacks-apac-taiwan/

44. Transcript: US asks Ukraine to stop strikes on tankers using Russian port, https://www.ft.com/content/4b54db5c-c97f-477c-afec-b624c1b10fa5?syn-25a6b1a6=1

45. Taiwan Needs an AI Cyber Shield Now to Defend Against Invasion \- CSIS, https://www.csis.org/analysis/taiwan-needs-ai-cyber-shield-now-defend-against-invasion

46. Cyber Warfare Market Revenue Trends and Growth Drivers | MarketsandMarkets, https://www.marketsandmarkets.com/Market-Reports/cyber-warfare-market-149757137.html

47. FACT SHEET: The 2024 NATO Summit in Washington | The American Presidency Project, https://www.presidency.ucsb.edu/documents/fact-sheet-the-2024-nato-summit-washington

48. Defense Cybersecurity Market Trends | Future Outlook & Opportunities 2032, https://www.congruencemarketinsights.com/report/defense-cybersecurity-market

49. Cyber Deterrence in the Age of AI: How NATO is Adapting to Intelligent Threats from Russia and China \- New Geopolitics Research Network, https://www.newgeopolitics.org/2025/05/28/cyber-deterrence-in-the-age-of-ai-how-nato-is-adapting-to-intelligent-threats-from-russia-and-china/

50. A UN Effect? How the EU Implements the Norms of Responsible State Behavior in Cyberspace, https://www.interface-eu.org/publications/how-the-eu-implements-the-un-cyber-norms

51. PUTTING CYBER NORMS IN PRACTICE: \- Cybil Portal, https://cybilportal.org/wp-content/uploads/2021/11/Putting-Cyber-Norms-in-Practice.pdf

52. Open-Ended Working Group (OEWG) on security of and in the use of information and communications technologies 2021-2025 28March, https://documents.unoda.org/wp-content/uploads/2022/04/2022\_03\_30-Key-messages\_Agenda-item-5\_Rules-norms-and-principles-final.pdf

53. Full article: Cybersecurity capacities for the application of UN cyber norms \- Taylor & Francis, https://www.tandfonline.com/doi/full/10.1080/23738871.2026.2649932

54. The UN's New Global Mechanism on Cybersecurity \- Interface-eu.org, https://www.interface-eu.org/publications/the-new-united-nations-mechanism-on-cybersecurity

55. Global Commission on the Stability of Cyberspace \- Norms \- HCSS, https://hcss.nl/gcsc-norms/

56. ICT4Peace Commentary on final UN GGE 2021 Report, https://ict4peace.org/activities/ict4peace-commentary-on-final-un-gge-2021-report/

57. Why international law and norms do little in preventing non-state cyber attacks | Journal of Cybersecurity | Oxford Academic, https://academic.oup.com/cybersecurity/article/7/1/tyab009/6168044

58. Leveraging Domestic Law Against Cyberattacks, https://digitalcommons.wcl.american.edu/cgi/viewcontent.cgi?article=1122\&context=nslb

59. "Virtual" Disenfranchisement: Cyber Election Meddling in the Grey Zones of International Law \- Chicago Unbound, https://chicagounbound.uchicago.edu/cgi/viewcontent.cgi?article=1736\&context=cjil

60. Tallinn Manual \- Wikipedia, https://en.wikipedia.org/wiki/Tallinn\_Manual

61. The Tallinn Manual \- NATO Cooperative Cyber Defence Centre of Excellence, https://ccdcoe.org/research/tallinn-manual/

62. NATO Centres of Excellence – Cooperative Cyber Defence (CCD COE), https://www.act.nato.int/article/nato-centres-of-excellence-cooperative-cyber-defence-ccd-coe/

63. International law and cyber ops: Q & A with Mike Schmitt about the status of Tallinn 3.0, https://sites.duke.edu/lawfire/2021/10/03/international-law-and-cyber-ops-q-a-with-mike-schmitt-about-the-status-of-tallinn-3-0/

64. The CCDCOE Invites Experts to Contribute to the Tallinn Manual 3.0, https://ccdcoe.org/news/2021/the-ccdcoe-invites-experts-to-contribute-to-the-tallinn-manual-3-0/

65. Zero Trust for SCADA: A Practical Implementation Guide \- Merobix, https://www.merobix.com/blog/zero-trust-scada-architecture

66. Zero Trust for Legacy OT: How Federal Agencies Can Secure Brownfield ICS Without Disruption \- Zentera Systems, https://www.zentera.net/blog/zero-trust-ot-brownfield-legacy-ics

67. Zero Trust · Guide and implementation | Fortgale, https://fortgale.com/en/zero-trust/

68. ZT4OT Zero Trust for Operational Technology \- EPRI, https://restservice.epri.com/publicattachment/98631

69. FRAMEWORK FOR INTEGRATING ZERO TRUST IN CLOUD-BASED ENDPOINT SECURITY FOR CRITICAL INFRASTRUCTURE \- arXiv, https://arxiv.org/pdf/2602.09078

70. A National Cyber Defense Framework: Architecting Federated, AI-Powered, Zero-Trust Security at Scale | TechRxiv, https://www.techrxiv.org/doi/10.36227/techrxiv.175321961.11008476

71. Zero Trust Architecture for Critical Infrastructure: A Practical Adoption Roadmap \- JFL Consulting, https://www.jflconsulting.com/zero-trust-architecture-for-critical-infrastructure-a-practical-adoption-roadmap/

72. Zero Trust Guidance for Achieving Operational Resilience \- Cloud Security Alliance (CSA), https://cloudsecurityalliance.org/artifacts/zero-trust-guidance-for-achieving-operational-resilience

73. Implementing Zero Trust in Operational Technology: A Practical Case Study, https://www.sei.cmu.edu/blog/implementing-zero-trust-in-operational-technology-a-practical-case-study/

74. Cyber security of OT networks: A tutorial and survey \- arXiv, https://arxiv.org/html/2502.14017v2

75. (PDF) Adaptive Zero-Trust Cybersecurity Architectures for Protecting Distributed Critical Infrastructure Against Evolving Advanced Persistent Threats and Global Digital Risks \- ResearchGate, https://www.researchgate.net/publication/398918452\_Adaptive\_Zero-Trust\_Cybersecurity\_Architectures\_for\_Protecting\_Distributed\_Critical\_Infrastructure\_Against\_Evolving\_Advanced\_Persistent\_Threats\_and\_Global\_Digital\_Risks

76. Cybersecurity of energy systems \- ScienceDirect \- DOI, https://doi.org/10.1016/bs.mcps.2025.06.003

77. Assured PNT Market Size, Share, Growth, and Forecast by 2035 \- Market Research Future, https://www.marketresearchfuture.com/reports/assured-pnt-market-14009

78. Post-Quantum Cryptography for OT and ICS: Sovereign Migration, https://qsentinel.com/knowledge-base/post-quantum/post-quantum-cryptography-for-ot-and-ics-sovereign-migration-guide/