The Logic of Coercion in Cyberspace

Erica D. Borghard, Shawn W. Lonergan

Security Studies · 2017 · 175 citations · 0 references

Concepts

TL;DR

Coercion in cyberspace involves states using cyber means to influence adversaries, raising questions about how traditional coercion theory applies in this emerging domain. The study evaluates how six classic coercion strategies—attrition, denial, decapitation, intimidation, punishment, and risk—work in cyberspace. The authors review coercion theory’s core requisites and analyze their applicability to cyberspace, then assess the effectiveness of six traditional coercion strategies in that context. Cyber power alone is limited for coercion, but effective when combined with other national power; states can achieve objectives mainly through attrition, denial, or decapitation, and these constraints may lead to rethinking norms on civilian infrastructure.

Abstract

What are the dynamics of coercion in cyberspace? Can states use cyber means as independent tools of coercion to influence the behavior of adversaries? This article critically assesses traditional coercion theory in light of cyberspace's emergence as a domain in which states use force, or its threat, to achieve political objectives. First, we review the core tenets of coercion theory and identify the requisites of successful coercion: clearly communicated threats; a cost–benefit calculus; credibility; and reassurance. We subsequently explore the extent to which each of these is feasible for or applicable to the cyber domain, highlighting how the dynamics of coercion in cyberspace mimic versus diverge from traditional domains of warfare. We demonstrate that cyber power alone has limited effectiveness as a tool of coercion, although it has significant utility when coupled with other elements of national power. Second, this article assesses the viability and effectiveness of six prominent warfighting strategies in the traditional coercion literature as applied to the cyber domain: attrition, denial, decapitation, intimidation, punishment, and risk. We conclude that, based on the current technological state of the field, states are only likely to achieve desired objectives employing attrition, denial, or decapitation strategies. Our analysis also has unique implications for the conduct of warfare in cyberspace. Perhaps counterintuitively, the obstacles to coercion that our analysis identifies may prompt states to reevaluate norms against targeting civilian infrastructure.