Caught in the crossfire: Why CISOs need a cyber-security Geneva convention
It’s been around three decades since governments first began testing their offensive cyber capabilities. But to date, there has been no attempt by nation states to create a Geneva Convention that would establish globally recognised rules of cyber warfare.
Why? Partly because cyber-operations are by their very nature hard to define. They often fall below the threshold of armed conflict, making it challenging to discern when international humanitarian law (IHL) protections should apply. And attribution can be fiendishly difficult.
Yet these are not good enough reasons not to try.
In fact, calls to create internationally agreed norms are mounting. The boundaries between digital and physical worlds are blurring. Military objectives increasingly rely on cyber-capabilities. And digital attacks can on rare occasions cause loss of life. The case for a cyber-Geneva Convention has never been stronger: for civilian victims, governments unsure of their red lines, and businesses and their CISOs caught in the middle.
Why cyber?
The modern Geneva Conventions were born out of kinetic conflict. Ratified by 196 countries, they established globally agreed rules for protecting victims and combatants, including prisoners of war. Proponents of a digital version argue that its time is long overdue. They are right to do so.
Cyber-campaigns are increasingly a fallback for governments keen to advance their geopolitical aims. They’re cheaper than putting boots on the ground and crucially maintain an element of plausible deniability. That creates doubt in the minds of the attacked nation, which usually limits the response.
Some of the most egregious examples of recent years include the infamous Stuxnet worm, which helped to disrupt Iran’s nuclear ambitions by targeting industrial control systems at the Natanz nuclear plant. By physically destroying centrifuges in the plant, its creators avoided a presumed Plan B: to drop bombs on the facility. In a similar manner, the destructive Russian NotPetya worm wreaked havoc among Ukrainian energy, financial and government organisations in 2017
Russia continues to push the boundaries with cyber-attacks that just fall below the threshold of a formal military response. Most recently, it launched a coordinated attack on Polish energy infrastructure, which caused outages at some plants.
On the other hand, cyber-attacks are also being deployed in a growing number to support military action. Russia has launched coordinated cyber-attacks against Ukrainian government websites, energy grids, and communications infrastructure. Ukraine, supported by Western allies, has responded with defensive and retaliatory cyber-measures.
Cyber-attacks can also provide smaller s with a chance to level the playing field. Israel, Iran and North Korea have sophisticated offensive capabilities which allow them to wage asymmetric attacks on potentially larger geopolitical rivals. However, it is China, with the “largest state intelligence apparatus in the world,” that arguably poses the biggest cyber-threat to the West.
The case for a convention
The direction of travel is clear. Acts of cyber-warfare, or near misses, will only increase in frequency as geopolitical rivalries escalate and AI advances continue. That makes an even stronger case for a cyber-Geneva Convention.
The arguments in favour are solid. An international agreement could help ringfence critical civilian infrastructure as off-limits for deliberate attacks. It could help governments by establishing clearer boundaries about what constitutes unacceptable behaviour. And by creating new procedures for investigating and attributing incidents. These could force aggressor states to become more accountable and make plausible deniability harder to maintain.
Nobody is suggesting that such an agreement would be perfect. After all, states do contravene the Geneva Conventions in the heat of conflict. But it would create a standard by which the international community could judge behaviour. Those nations seen to continuously flout its rules may find themselves ostracised on the world stage – a political cost that even autocracies might calculate is not worth paying.
While NATO governments delay, the public is in no mood to compromise. A Politico study recently found that most citizens in the US, UK, Canada, France and Germany believe that attacks which disrupt critical infrastructure should be considered acts of war. It’s about time the alliance at least firmed up its definitionof what kind of cyber-attack would trigger the Article 5 mutual defence clause.
Why governments are dragging their heels
Western powers often say a cyber-Geneva Convention is unnecessary because laws already exist in this area. One NATO-aligned think tank suggests that the Council of Europe’sConvention on Cybercrime and the International Law Commission’s Draft Articles on Responsibility of States for Internationally Wrongful Acts are useful foundational texts.
Perhaps more convincing is the argument that enforcement would be devilishly difficult. That criminal and hacktivist groups would likely continue to enable plausible deniability for attacks. Then there’s the UN Security Council, which seems incapable of making coherent decisions about serious global issues; so opposed are the views of its members. This kind of gridlock may make an ambitious cyber-agreement beyond the ability of the five permanent members.
Stuck in the middle
Yet such arguments are defeatist. Microsoft has done a lot of work in this area over recent years, and made some sensible proposals which could form the basis of a new international agreement. The hardening views of citizens may well force governments to be more proactive. And the clamour will continue to grow from the businesses so often caught in the crossfire.
CISOs are increasingly placed in an impossible situation. They face both sophisticated nation states bent on projecting power and the financially motivated cyber-criminals they shelter. Sometimes these actors are one and the same. AI will continue to increase the corporate attack surface and enable actors at all levels to upskill and improve the speed and scale of their campaigns.
Now, a cyber-Geneva Convention wouldn’t eliminate the things that keep security leaders awake at night, like ransomware. But it could provide a deterrent for some attacks, and reduce the chance of businesses becoming collateral damage in NotPetya-like campaigns. It could also encourage governments to work more closely with the private sector, especially on information sharing. And it may indirectly strengthen the CISO’s hand when they next go to the board asking for investment.
But these are all hypotheticals, and CISOs must deal in realities. A cyber-Geneva Convention is an aspiration for the future. But cyber-resilience is a goal every business should be working towards today.
Simon Hodgkinson is a strategic adviser at Semperis. Semperis’ feature-length documentary Midnight in the War Room chronicles the escalating cyber-conflict among nation states, criminal groups, and the defenders on the front lines and shines a light on the people whose expertise, vigilance, and refusal to back down underpin the nations’ collective resilience. Through the voices of intelligence leaders, CISOs, journalists, victims, and reformed hackers, it shows what’s really at stake – the human toll, the pressure, and the responsibility.
Main image courtesy of iStockPhoto.com and stuartmiles99
Please take 30 seconds to register
Already have an account? Sign in
