The democratization of cyber warfare — and what it means for CISOs

The democratization of cyber warfare — and what it means for CISOs

For most of modern history, sophisticated and costly warfare had a high barrier to entry. In order to maintain a significant tactical advantage, you needed money, infrastructure and highly trained human resources. In the physical realm, you needed trained and capable warfighters along with relativel

For most of modern history, sophisticated and costly warfare had a high barrier to entry. In order to maintain a significant tactical advantage, you needed money, infrastructure and highly trained human resources. In the physical realm, you needed trained and capable warfighters along with relatively expensive and specialized weaponry, made by skilled tradesmen. In cyber, you needed operators who understood networks, vulnerabilities, exploitation and how to move through an environment without getting caught. Warfare was typically a whole-of-society contest that came down to who had the best and most vast resources at their disposal. Those barriers are coming down. They have always been, but now it is accelerating more rapidly than ever before in human history. This is called the democratization of warfare, and it is terrifying. Its ramifications in cyber are being felt throughout both the public and private sectors, on battlefields and in boardrooms. Warfare has been democratizing for centuries I’ve seen the democratization of warfare firsthand. In Ukraine, relatively inexpensive, commercially available technology has put capabilities into the hands of individuals that would have been unimaginable not long ago. Look at Moscow. In 2023, drones reached the Kremlin itself, marking the first attack on the Kremlin since Nazi Germany bombed it during Operation Barbarossa in World War II. A target that had gone untouched by an enemy for more than 80 years was suddenly within reach. Democratization of war is not a new trend. The firearm was itself a democratizing technology, dramatically reducing the skill and physical barriers required to inflict lethal force on an adversary — so was the crossbow before that, and others before that. Those technologies enabled new techniques and expanded existing ones, including forms of irregular warfare that allowed smaller forces to exploit the asymmetry they created. European armies arriving in North America brought a tradition built around disciplined formations and massed firepower, but quickly encountered Indigenous forces that emphasized mobility, concealment, surprise and intimate knowledge of terrain. Colonial forces began adapting to those tactics. Benjamin Church incorporated Native American tactics into his ranger force during King Philip’s War in the 1670s. Nearly a century later, Robert Rogers took those lessons further during the French and Indian War, building Rogers’ Rangers into a force designed to scout, raid and operate deep in terrain where conventional formations struggled. The technology mattered and so did the underlying lesson: you didn’t have to match a superior adversary soldier for soldier if you could change the conditions of the fight with the technology at your disposal. That lesson carried into the American Revolution, where commanders like Francis Marion and Daniel Morgan employed irregular approaches against the British, using mobility, surprise and targeted attacks to work around traditional advantages in equipment, training and manpower. Democratization has continued to iterate throughout human history. Today, a $1,000 drone bought online, altered with 3D-printed components and operated with relatively little training can destroy personnel or a weapons system that costs millions of dollars. That changes the economics of warfare. More importantly, it changes who is capable of creating a significant tactical effect on the battlefield. AI is collapsing the barriers to cyber warfare We are watching the same thing happen in cyber warfare — and it matters because the downstream effects are already reaching the private sector. Cyber has always offered an asymmetric return on investment compared with conventional warfare: a relatively small number of skilled operators can impose enormous costs on a much larger adversary. Thus, cyber has always been an especially favored weapon of choice for nation-states with constrained resources. AI pushes that asymmetry even further by driving down the cost of sophisticated cyber operations while simultaneously collapsing the skill gap required to conduct them. We’ve seen glimpses of this before. In 2015, a 15-year-old named Kane Gamble operated from his family home in England and compromised accounts belonging to some of the most senior intelligence officials in the United States, including then-CIA Director John Brennan and Director of National Intelligence James Clapper. He did it largely through social engineering, not some enormous state-sponsored cyber apparatus. AI is pouring gasoline on something that was already possible. It is putting increasingly sophisticated offensive capabilities in the hands of people who previously wouldn’t have had the skills, money or resources to use them. That is the democratization of cyber warfare. That brings us to what happened in Taiwan. In August, researchers disclosed what they described as the first largely autonomous AI-enabled cyberattack against government infrastructur

Source: CSO Online