Latest Stories

Welcome! Log in to stay connected and make the most of your experience.
Your membership has expired. Renew now to continue enjoying exclusive benefits and uninterrupted access.
Couldn’t find an account with that email address, please sign up.
United States
Popular
The Human Cost of War: My Own Failure and Our Military's Mental Health Crisis
The U.S. Needs a Stronger Cyber Defense Against Russia
Paul Kolbe, Director, Intelligence Project, Harvard University's Belfer Center for Science and International Affairs
Paul Kolbe is Director of The Intelligence Project at Harvard University’s Belfer Center for Science and International Affairs. He previously served 25 years as an operations officer in the CIA and was a member of the Senior Intelligence Service, serving in Russia, the Balkans, Indonesia, East Germany, Zimbabwe, and Austria.
This piece was first published by our friends at Russia Matters, from Harvard Kennedy School’s Belfer Center for Science and International Affairs.
According to U.S. officials, Russia is the likely perpetrator of the SolarWinds cyber compromise of federal agencies, private sector firms, NGOs and academic institutions. The scale and impact brought accusations of a reckless and indiscriminate operation. Some politicians labeled this an act of war, while other commentators dismissed the SolarWinds compromise as espionage. Calls for retribution were widespread.
We know few details about the breadth, depth and impact of the SolarWinds cyber operation, though the scale was clearly massive with over 18,000 SolarWinds customers uploading malware-laden tools. But we do not know which companies and agencies have been affected, what information was compromised or whether damage occurred to any information systems. This lack of public disclosure likely represents caution in revealing what is known and not known, but also signals the difficulty of assessing just how bad we’ve been had.
So how should the U.S. respond?
A natural inclination will be to strike back in order to modify future Russian behavior and to introduce stronger cyber deterrence for other potential actors. Responses might include declaring Russian intelligence personnel persona non grata, indictment of perpetrators, targeted sanctions and execution of similar operations against select Russian systems. The aim would not just be punishment, but to change the risk-gain calculation for Russia, and others, when considering new cyber operations.
But frankly, all of these actions have been tried in the past and have not slowed the cyber onslaught. Russia does appreciate and adhere to reciprocity, and a specific and carefully calibrated shot across the bow is appropriate in response to SolarWinds. But we should not kid ourselves and think that such responses will stop cyber espionage or assaults. We are simply too fat and easy a target.
For this reason, retaliation is neither the most urgent nor the most important task at hand. Our most critical mission is to relentlessly and comprehensively improve our cyber defense.
SolarWinds dramatically exposed what many cyber experts have known and warned of: that the United States is pervasively, systemically vulnerable. Our attack surface—the systems, networks and devices that can be targeted and compromised—is stupendously large. The skill and number of U.S. adversaries—the states, criminal organizations and individuals who would exploit those vulnerabilities—is proliferating. Russia is but one wolf in an evolving and growing pack of cyber predators.
Read The 2021 Cyber Threat Will Drive Stronger Alliances by former Homeland Security Secretary Michael Chertoff exclusively in The Cipher Brief
The Latest
'Havana Syndrome' - and a Possible Russia Connection
SUBSCRIBER+ INTERVIEW — Who – or what – is to blame for the debilitating symptoms known as “Havana Syndrome”? The question has been asked repeatedly [...] More
FISA Amendments Must Acknowledge Critical Role of OSINT
OPINION — As we approach the April 2024 expiration of Section 702 of the Foreign Intelligence Surveillance Act (FISA), it is heartening to see a [...] More
Where Are Bipartisan Congressional Leaders on National Security When You Need Them?
OPINION — “In order to allow Congress more time to reach consensus on how best to reform FISA (Foreign Intelligence Surveillance Act) and Section 702 [...] More
The Munich Dispatches: In Europe, a Focus on Russia and the United States
The Cipher Brief interviewed a number of national security experts on the sidelines of this year’s Munich Security Conference. Here are key takeaways [...] More
The West's Weapons Problem: Growing Threats, Dwindling Stockpiles
SUBSCRIBER+EXCLUSIVE REPORTING — As the U.S. and NATO deepen their involvement in a pair of major global conflicts, western nations face a critical [...] More
What Might a CIA-tasked 'Red Cell' on China Tell us?
OPINION / EXPERT PERSPECTIVE — After 9/11, the Directorate of Intelligence (DI) at CIA created a ‘Red Cell’ that was given the mission of truly [...] More
For general inquiries please email info@thecipherbrief.com






















