Diplomatic Analysis: Despite inherent challenges, cyber operations *can* be deterred, but states appear reluctant to utilise deterrent threats effectively.
Overview
The application of deterrence theory to cyberspace presents unique difficulties. Unlike traditional domains of conflict, cyber operations are often obscured, attribution is problematic, and the potential for escalation is ambiguous. This analysis examines recent research utilising wargaming – specifically the “Tantalus” game developed by researchers at Sandia National Laboratories and UC Berkeley – to explore the efficacy of cyber deterrence. The study offers novel insights into how actors perceive and respond to deterrent threats in the cyber domain, challenging conventional wisdom and revealing a potential paradox: while cyber operations can be deterred, states are less likely to attempt deterrence in cyberspace than in the kinetic realm. This has significant implications for strategic planning and the broader landscape of international security.
Historical Context
Deterrence theory, foundational to Cold War strategy, relies on the credible threat of retaliation to dissuade an adversary from initiating hostile action. This traditionally involved visible, readily attributable capabilities – like nuclear arsenals – and clear red lines. However, the emergence of cyberspace as a theatre of conflict has complicated this model. The inherent characteristics of cyber warfare – its low cost of entry, deniability, and the difficulty in attributing attacks – challenge traditional deterrence mechanisms.
For years, analysts have debated whether existing deterrence frameworks can be effectively applied to cyberspace. Concerns have centred on the challenge of establishing credible threats given these ambiguities, and the likelihood that cyberattacks would be perceived as ‘less severe’ than conventional military action. Early debate focused on ‘cyber norms’, attempting to create a shared understanding of acceptable behaviour – a concept which has largely stalled. More recently, policy has emphasized resilience and defence, complemented by a focus on offensive capabilities, often tacitly seeking to create a deterrent through a ‘threat of retaliation’ without overtly articulating clear red lines. The difficulty stemming from the lack of empirical evidence of successful deterrence has fueled academic research into new methods of evaluating cyber deterrence, like the wargaming approach analysed here.
Key Actors & Positions
The research detailed in the War on the Rocks article focuses on the dynamics between hypothetical “Nation of Purple” and “Republic of Green”, used as variables within the Tantalus wargame. However, the underlying implications relate to real-world actors.
* The United States: Has consistently articulated a policy of retaining the option for response to significant cyberattacks, but stops short of clearly defining thresholds or promising specific retaliation. Department of Defence strategy increasingly highlights resilience.
* China: Views cyberspace as a key domain for asserting its interests and has demonstrated sophisticated cyber capabilities. While it has publicly professed a commitment to responsible state behaviour, evidence suggests continued engagement in espionage and potentially disruptive cyber activities.
* Russia: Has actively employed cyber operations as part of its geopolitical strategy, including interference in elections and attacks on critical infrastructure. Its approach is characterised by a willingness to test boundaries and exploit vulnerabilities.
* Iran: Displays growing cyber capabilities, utilised for both offensive and defensive purposes, and presents a significant, if asymmetric, challenge.
* Israel: A sophisticated actor in the cyber domain, with both offensive and defensive capabilities. It operates in a complex regional environment and views cyber as a crucial element of national security.
These actors, and others, grapple with the same challenges highlighted in the research: how to deter cyberattacks without escalating conflicts or inadvertently triggering unintended consequences.
Analysis
The Tantalus wargames reveal two key findings. First, and perhaps counter to prevailing scepticism, cyber operations can be effectively deterred. The research demonstrates that a threat of punishment is as likely to deter a cyberattack as it is a conventional kinetic attack. This suggests the inherent limitations of cyber as a means to exert pressure aren’t necessarily decreasing willingness to be deterred by a strong response.
However, the study reveals a significant paradox. Players were demonstrably less likely to issue deterrent threats in anticipation of cyberattacks compared to conventional attacks. This suggests a broad assumption, consistent with the US DoD’s 2023 Cyber Strategy, that cyber operations are an inevitable, background feature of the contemporary security landscape – a constant level of ‘noise’ to be managed through defensive measures rather than prevented through deterrence.
This reluctance to deploy deterrent threats is potentially problematic. The study implies that states may be leaving a valuable tool ‘on the table,’ potentially accepting cyberattacks that could have been prevented simply by articulating a credible threat of retaliation. The lower perceived destructiveness and attribution difficulties of cyber operations may contribute to this reluctance, with decision-makers potentially dismissing cyberattacks as “cost-effective coercion” or attributing them to non-state actors.
The use of wargaming as a research methodology is crucial. The Tantalus game successfully captured a snapshot of deterrence “in action” – the moment a player altered their planned action after receiving a deterrent threat. This is a data point almost impossible to observe in the real world, where success appears as the non-occurrence of an event.
Outlook
Given these findings, a recalibration of cyber strategy may be warranted. While investing in resilience and defensive capabilities remains vital, policymakers should reconsider the role of deterrence. More proactive articulation of red lines, along with a willingness to demonstrably respond to significant cyberattacks, could prove effective in shaping adversary behaviour. However, this must be approached cautiously, given the risk of escalation and the complexities of attribution.
We can anticipate further research utilizing similar wargaming methodologies to refine our understanding of cyber deterrence. The development of AI and increasingly sophisticated cyber tools will likely exacerbate the challenges of attribution and escalation, necessitating ongoing adaptation of strategies.
It is unlikely we will see a radical shift in state behaviour immediately. The entrenched belief that cyber operations are an inevitable reality will be difficult to overcome. However, as the costs of cyberattacks increase and the potential for significant disruption mounts, the incentive to explore more effective deterrent strategies will grow. Ultimately, a more credible and consistently applied deterrent posture – even in the inherently ambiguous realm of cyberspace – may prove essential to managing the risks of future conflict.
Sources
Booth, Ruby, and Andrew W. Reddie. “Can Cyber Operations Be Deterred? What Wargames Reveal.” War on the Rocks, 30 July 2026, [https://warontherocks.com/2026/07/can-cyber-operations-be-deterred-what-wargames-reveal/](https://warontherocks.com/2026/07/can-cyber-operations-be-deterred-what-wargames-reveal/).
U.S. Department of Defense. 2023 Cyber Strategy. Washington D.C., 2023.