Monday

25th May 2020

Opinion

EU cyber diplomacy requires more commitment

  • Europe needs to join together in "cyber solidarity" to deter cyberattacks. (Photo: European Commission)

The awareness of the damaging impact of cyber-attacks is growing globally, due to a quickly expanding list of actual examples – from cyberattacks on the Ukrainian electricity grid and the digital manipulation of the presidential elections in the US, to the global ransomware attacks in the past few months.

The recently published European Commission reflection paper – on the future of European defence – summaries the current challenge very well: Europe must have a stronger deterrent against cyberattacks.

Read and decide

Join EUobserver today

Support quality EU news

Get instant access to all articles — and 20 years of archives. 14-day free trial.

... or subscribe as a group

How to prevent fast-evolving and ever more damaging cyberattacks is, as yet, an unanswered question.

Of course, prevention starts with basic "cyber-hygiene", such as by updating software and installing appropriate security tools in ICT networks, but that is not enough. Hackers will always find ways to exploit computer codes, circumventing security measures.

It is important to take into account that cyber security is not only a matter of technical measures, but also of high politics – closely linked to the international political and strategic context.

The current “political cyber playbook” is still a slim volume, but it expands daily as parts of the world move towards greater strategic use of cyber weapons to persuade their adversaries to change their behaviour.

Recent history shows that cyber criminals are a big global problem, but that states are responsible for developing the most powerful cyber weapons (or exploiting bugs in computer codes).

Recent failures

Only state actors (or state-supported ones) have enough financial and human capacity to invest in developing the most powerful cyber weapons. Unfortunately, however, efforts to contain aggressive behaviour of states in cyberspace, by developing international norm-setting through the United Nations, have recently failed.

Without any common rules of behaviour, states can also rely on the deterrence of cyber-attacks. This can be done by promising military retaliation, like the United Kingdom threatened with air strikes against cyber-attackers, or by more peaceful diplomatic instruments.

Resilience is also emphasised when strengthening cyber deterrence.

The EU launched an interesting initiative in this context on 19 June. It announced that it would start developing what is called a "Cyber Diplomatic Toolbox" – a framework for joint EU diplomatic responses to malicious cyber activities.

Although it is not specified what exactly the instruments in this diplomatic toolbox will be, the decision refers to "measures within the Common Foreign and Security Policy" (CFSP) and the wording "restrictive measures" being used.

Next to the common diplomatic tools, such as making statements of condemnation, summoning ambassadors, or declaring diplomats persona-non-grata, this means that there can be serious a consideration of political and economic sanctions against any adversary attacking EU member states in cyberspace.

These kinds of diplomatic retaliation tools may function as a deterrent, making malicious cyber operations less anonymous and risk-free, while also bringing with them little danger of immediate escalation.

Five questions

The initiative is a valuable development and it should be supported in EU member states. But it also raises five questions which have to considered.

First, a big problem is that EU countries differ in their level of cyber-readiness. This makes it difficult to carry out the principle of operational solidarity – that the member states would really be willing to support each other and, in particular, be able to execute a joint EU diplomatic response.

Stronger political commitment on improving the level of cyber-readiness is needed in several EU member states. Otherwise, “the cyber solidarity” is weakened and the joint response is harder to carry out – and the deterrent effect does not work.

Second, diplomatic means to respond are important, but it should not be forgotten that there are many other options to respond too.

It is said that a state can respond using at least four instruments: diplomatic, informational, military, and economic. Policymakers need to consider the full range of responses at their disposal: from a quiet, diplomatic rebuke, to a full military strike.

Sometimes the diplomatic response is not enough, especially if the impacts of cyberattacks are severe. An EU comprehensive framework, with different ways to respond (more than just diplomatic tools), is needed.

Third, even if the EU member states agree with the content of the “Cyber Diplomatic Toolbox”, there have to be political processes and decisiveness to implement it concretely when a member state is hit by a cyber-attack. Joint political will to respond needs to be discussed thoroughly in advance and it is good to exercise it too.

Fourth, countering hybrid threats is a European priority, and the role of cyber operations in hybrid warfare is increasing.

However, there usually are no “cyber-only” operations and hybrid warfare is characterised by the tailored use of all instruments of power (including cyber) against the vulnerabilities of the opponent’s systems. Therefore, only creating diplomatic response tools against cyber-attacks is not enough.

Most probably, there will be other influencing instruments used simultaneously, and they must be taken into consideration when deciding on the response as well. Cyber hostilities should not be separated from the hybrid warfare context.

Fifth, in order to succeed in using the Cyber Diplomatic Toolbox, the EU must strengthen its capabilities to be able to attribute the attacker better, improve the European cybersecurity industry and increase the multidisciplinary cybersecurity research in Europe.

If the EU does not possess strong cyber capabilities and understanding, then the diplomatic toolbox is likely to be relatively useless.

The cyber threats that Europe faces can only be tackled by working together.

The initiative of the Cyber Diplomatic Toolbox may open a new and important page in European cyber deterrence, but only if it is supported by a strong political commitment, and if the broader context is understood.

Jarno Limnéll is a professor of cybersecurity at the Aalto University, Finland. Sico van der Meer is a Research Fellow at the Netherlands Institute of International Relations ‘Clingendael’.

Disclaimer

The views expressed in this opinion piece are the author's, not those of EUobserver.

Investigation

French election faces high cyber threat

French president Francois Hollande has called for "all necessary means" to be used to fend off cyber attacks ahead of the presidential election in April and May. But political parties are still vulnerable.

Interview

Greece keen to keep EU cybersecurity agency

Greek official welcomed proposal to give the agency a bigger role, downplayed its kitchen sink problems, and said he was himself the victim of a computer virus.

How coronavirus might hit EU defence spending

Among the casualties of coronavirus - worldwide and in the EU - is the defence sector. However, the Covid-19 pandemic has not made the world a less dangerous place and there is no alternative to having a functioning defence system.

Column

Saving Europe from corona's nasty geopolitics

Four months into the corona crisis and one month into the social and economic shutdown, it seems the big geopolitical loser of the pandemic is likely going to be Europe.

Coronavirus: A test of the West

We are experiencing the first global pandemic unfolding in the 24/7 news cycle and taking its toll, in real time, on our daily lives, our financial security and the global economy.

Stakeholders' Highlights

  1. European Sustainable Energy WeekThis year’s EU Sustainable Energy Week (EUSEW) will be held digitally!
  2. Nordic Council of MinistersNordic states are fighting to protect gender equality during corona crisis
  3. UNESDACircularity works, let’s all give it a chance
  4. Nordic Council of MinistersNordic ministers call for post-corona synergies between economic recovery and green transition
  5. Nordic Council of MinistersNordic co-operation on COVID-19
  6. Nordic Council of MinistersNordic research collaboration on pandemics

Stakeholders' Highlights

  1. UNESDAMaking Europe’s Economy Circular – the time is now
  2. Nordic Council of MinistersScottish parliament seeks closer collaboration with the Nordic Council
  3. UNESDAFrom Linear to Circular – check out UNESDA's new blog
  4. Nordic Council of Ministers40 years of experience have proven its point: Sustainable financing actually works
  5. Nordic Council of MinistersNordic and Baltic ministers paving the way for 5G in the region
  6. Nordic Council of MinistersEarmarked paternity leave – an effective way to change norms

Join EUobserver

Support quality EU news

Join us