Przejdź do treści

Cyber Deterrence is Overrated – Analysis of the Deterrent Potential of the New US Cyber Doctrine and Lessons for Germany’s “Active Cyber Defence”

Proponents of active, offensive cyber operations argue that they could have a deter­rent effect on potential cyber attackers. The latter would think twice about attacking if a digital counter-attack might be the consequence. The idea that offensive cyber capabilities should have a deterrent effect was one reason why the new US cyber doctrine was adopted in 2018. The same assumption is implicit in the debate about cyber counterattacks (“hack backs”) in Germany. Yet these assessments are based on a superficial understanding of deterrence. Cyber deterrence by the threat of retaliation works differently than that of nuclear deterrence. Problems of attribution, displays of power, controllability and the credibility of digital capabilities increase the risk of deterrence failure. Thus, the German cyber security policy would be well advised to increase its “deterrence by denial”, cyber security and the resilience of its systems.

More external publications

  • Research and Analysis
Hand and Glove: How Authoritarian Cyber Operations Leverage Non-state Capabilities

26 June 2025
In this article, Jakob Bund examines how authoritarian states like Russia, China, and North Korea increasingly harness non-state cyber actors to expand their capabilities, blur attribution, and complicate global responses. He argues that this growing fusion of state and criminal or contractor activity demands integrated threat assessments and response tools that can operate independently of political attribution.

Welcome to our Cyber Incident Dashboard!

For best results, please view on a desktop device.