Cybersecurity expert Dmitri Alperovitch described the strategic role of cyber operations in modern nation-state conflict, contrasting Western and Eastern approaches during a public interview. Alperovitch, a co-founder of CrowdStrike and author of World on the Brink, outlined how cyberspace functions as the fourth domain of military conflict alongside land, air, and sea.
Modern warfare now includes kinetic war, cyberwar, and cyber-kinetic operations, according to Alperovitch. He stated that nation-state cyber activity is generally characterized as ideologically East versus West. The 'East' geopolitical bloc in cyber operations primarily includes China, Russia, Iran, and North Korea. The 'West' geopolitical bloc in cyber operations primarily includes North America, the U.K. the E.U. Australia, and New Zealand.
The three primary geopolitical motivations for nation-state cyber operations are espionage, regime change, and territorial disputes. Nation states use cyber espionage to monitor military capabilities, steal military secrets, and steal intellectual property from foreign enterprises. He noted that espionage is a universal practice among nations that does not typically trigger full-scale kinetic war. "We’re not going to go [full kinetic] war over espionage, because everyone does it," he said.
The two primary causes for kinetic war are regime change and territorial disputes. Kinetic activity is generally preceded by or concurrent with aggressive cyber activity. Recent examples of attempted regime change involving cyber operations include Venezuela and Iran. Recent examples of territorial disputes involving cyber operations include Russia with Ukraine and China with Taiwan.
He distinguished the operational methods of state actors from criminal groups. Criminal cyber activity is motivated by monetary gain and prioritizes speed and low cost. In contrast, nation-state cyber activity is characterized by stealth and continuous dwell time rather than speed. "If you detect nation state actors on your network, chances are they have already been there for weeks or months," he said.
Western nations adhere to rule of law and do not engage in intellectual property theft for industrial benefit or ransom operations, he stated. "We don’t steal intellectual property from private companies for the benefit of our own industries," he said. He added that Western alliances do not engage in financial theft similar to adversarial regimes. "We don’t engage in ransom operations or theft of currency and cryptocurrency as North Korea does," he said.
The Five Eyes alliance consists of the U.S. Canada, the U.K. Australia, and New Zealand. "It’s an intelligence alliance (US, Canada, UK, Australia and New Zealand) that evolved from the work of Alan Turing and Bletchley Park during the Second World War," he said. The Five Eyes alliance originally started as a signals intelligence alliance collecting from airwaves and detecting radio signals.
Five Eyes operations follow domestic and international rule of law. "NSA, GCHQ, and the other countries in the alliance are now using cyber to accomplish national security priorities – which is the collection of intelligence on our adversaries," he said.
The institutionalization of cyber capabilities in the United States followed a specific timeline. U.S. Cyber Command was ordered by Secretary of Defense Robert Gates in 2009. U.S. Cyber Command became operational within Strategic Command in 2010.
Cyber became an official military domain in the U.S. in 2011. The United States Cyber Command (USCYBERCOM) is one of the eleven unified combatant commands of the United States Department of Defense (DoD). USCYBERCOM unifies the direction of cyberspace operations, strengthens DoD cyberspace capabilities, and integrates and bolsters DoD's cyber expertise which focus on securing cyberspace. U.S. Cyber Command became an independent unified combatant command in 2018.
International recognition of the domain expanded beyond the United States in subsequent years. Cyber became an official military domain in NATO countries in 2016. Other nations have also established dedicated units, such as the Cyber Command of the Belgian Armed Forces, which was established in 2022.
The integration of cyber operations into military doctrine reflects a shift in how nations approach conflict and intelligence gathering. By defining cyberspace as a formal domain of warfare, governments have created structured commands to manage these capabilities alongside traditional forces. The distinction between Western adherence to legal frameworks and Eastern utilization of cyber tools for economic gain shows differing strategic priorities among major powers.
Understanding the motivations behind cyber activity allows for clearer differentiation between criminal enterprises seeking quick financial returns and state actors pursuing long-term strategic advantages through espionage or disruption. The convergence of cyber and kinetic operations in territorial disputes and regime change efforts demonstrates that digital activities are no longer isolated from physical conflict but are integral components of modern geopolitical strategy.
Why It Matters
Recognizing cyberspace as the fourth domain of military conflict alongside land, air, and sea establishes a framework where kinetic war is primarily triggered by regime change or territorial disputes rather than espionage. This distinction shapes global stability, as aggressive cyber activity often precedes or occurs concurrently with physical combat in conflicts involving Ukraine, Taiwan, Venezuela, and Iran. Furthermore, understanding that nation-state actors prioritize stealth over speed means detection often reveals intrusions that have persisted for weeks or months.
forum Comments (0)
No comments yet. Be the first to comment.