Skip to content
Search

Latest Stories

Welcome! Log in to stay connected and make the most of your experience.

Input clean

The U.S. Needs a Stronger Cyber Defense Against Russia

The U.S. Needs a Stronger Cyber Defense Against Russia

Paul Kolbe, Director, Intelligence Project, Harvard University's Belfer Center for Science and International Affairs

Kolbe

Paul Kolbe is Director of The Intelligence Project at Harvard University’s Belfer Center for Science and International Affairs. He previously served 25 years as an operations officer in the CIA and was a member of the Senior Intelligence Service, serving in Russia, the Balkans, Indonesia, East Germany, Zimbabwe, and Austria.

This piece was first published by our friends at Russia Matters, from Harvard Kennedy School’s Belfer Center for Science and International Affairs. 

According to U.S. officials, Russia is the likely perpetrator of the SolarWinds cyber compromise of federal agencies, private sector firms, NGOs and academic institutions. The scale and impact brought accusations of a reckless and indiscriminate operation. Some politicians labeled this an act of war, while other commentators dismissed the SolarWinds compromise as espionage. Calls for retribution were widespread.

We know few details about the breadth, depth and impact of the SolarWinds cyber operation, though the scale was clearly massive with over 18,000 SolarWinds customers uploading malware-laden tools. But we do not know which companies and agencies have been affected, what information was compromised or whether damage occurred to any information systems. This lack of public disclosure likely represents caution in revealing what is known and not known, but also signals the difficulty of assessing just how bad we’ve been had.

So how should the U.S. respond?

A natural inclination will be to strike back in order to modify future Russian behavior and to introduce stronger cyber deterrence for other potential actors. Responses might include declaring Russian intelligence personnel persona non grata, indictment of perpetrators, targeted sanctions and execution of similar operations against select Russian systems. The aim would not just be punishment, but to change the risk-gain calculation for Russia, and others, when considering new cyber operations.

But frankly, all of these actions have been tried in the past and have not slowed the cyber onslaught. Russia does appreciate and adhere to reciprocity, and a specific and carefully calibrated shot across the bow is appropriate in response to SolarWinds. But we should not kid ourselves and think that such responses will stop cyber espionage or assaults. We are simply too fat and easy a target.

For this reason, retaliation is neither the most urgent nor the most important task at hand. Our most critical mission is to relentlessly and comprehensively improve our cyber defense.

SolarWinds dramatically exposed what many cyber experts have known and warned of: that the United States is pervasively, systemically vulnerable. Our attack surface—the systems, networks and devices that can be targeted and compromised—is stupendously large. The skill and number of U.S. adversaries—the states, criminal organizations and individuals who would exploit those vulnerabilities—is proliferating. Russia is but one wolf in an evolving and growing pack of cyber predators.

Keep reading...Show less
Access all of The Cipher Brief’s national security-focused expert insight by becoming a Cipher Brief Subscriber+ Member.

Related Articles

Experts Assess Iran Strikes, Response and What Comes Next

Experts Assess Iran Strikes, Response and What Comes Next

EXPERT SUMMARY -- Given this weekend’s strikes on Iran’s nuclear facilities and the incredible fast pace at which events are unfolding, The Cipher [...] More

Dead Drop: June 20

IT ONLY TOOK 116 YEARS: The British Secret Intelligence Service better known as MI6 will soon be headed by its first-ever female chief when Blaise [...] More
How Resilient is the Energy Market in Midst of Middle East Crisis?

How Resilient is the Energy Market in Midst of Middle East Crisis?

EXCLUSIVE EXPERT PERSPECTIVE -- One would have thought that the outbreak of a major war between Iran and Israel with daily missile salvos, would have [...] More

Report for Friday, June 20, 2025

9:22 America/New York Friday, June 20 [...] More

Report for Thursday, June 19, 2025

9:51 America/New York Thursday, June 19 [...] More

The Rampant Leadership Corruption Plaguing China and Russia

OPINION — In March 2025 the Office of the Director of National Intelligence (ODNI) published an unclassified report on “Wealth and Corrupt Activities [...] More
Hitting the Panic Button on Rare Earth Minerals

Hitting the Panic Button on Rare Earth Minerals

Rare Earth minerals might not be at the top of your panic list today but when it comes to U.S. national security, it’s an issue that has the [...] More

Amid Crisis, A Lesser-Told Story of US-Iran Similarities Holds Some Hope

OPINION — As experts studiously debate what the latest Israel-Iran fighting will lead to, including a possible Iranian collapse, one enduring but [...] More

Report for Wednesday, June 18, 2025

9:04 America/New York Wednesday, June 18 [...] More