Persistent Engagement and the Illusion of Cyber Equilibrium
Strategies built to disrupt cyber adversaries may impose costs but are unlikely to lead to long-term stability.
The United States is now eight years into a military strategy and academic theory built, in part, on a daring view of how to achieve stability in cyberspace.
The U.S. Cyber Command remains “persistently engaged in cyberspace operations against the world’s most dangerous foreign adversary threats [and] routinely denies or manipulates the most significant foreign cyber threats to the Nation.” The command’s goal “is to improve the security and stability of cyberspace.” The idea—stability through more military offensive cyber operations—is backed by substantial scholarship.
We are skeptical. Enthusiasm for this concept—and the accompanying “cyber persistence theory”—may be based more on its success in describing the past few years of cyber conflict than on any ability to stabilize cyberspace. Persistent engagement is one thing if it attempts to establish a balanced equilibrium, but quite another when one or both sides are seeking dominance over cyberspace, which they see as an increasingly existential necessity amid a period of rising international turmoil.
This article briefly examines constant contact and persistent engagement, then discusses concepts of strategic equilibria from other contexts, and proposes recommendations.
Three Decades of Constant (but Evolving) Contact
Because states are in “constant contact” with one another in cyberspace—their cyber forces continuously contesting for initiative and advantage—Michael Fischerkeller, Emily Goldman, and Richard Harknett argue that U.S. cyber strategy must reorient to embrace a cyber persistence theory. This theory entails U.S. personnel engaging with adversary cyber forces continuously as a “structurally and strategically driven imperative.” The theory argues such a strategy will “contribute to stability” by “clarify[ing] the distinction between acceptable and unacceptable behavior in cyberspace.”
The United States—or any interconnected state, according to theory—must persistently conduct operations to erode its rival’s national security, while simultaneously countering the rival’s operations to do the same. Initiative and action, not restraint, are what keep conflicts limited. Because “adversaries intending to limit the type of conflict can come to tacit understandings of constraints,” such contestation will lead to stability. Adversaries find the bounds by overstepping them.
The prescriptions of this academic theory were enacted quickly as an operating concept by the U.S. Cyber Command and later embraced, to varying degrees, by successive Pentagon and White House strategies.
Equilibrium in Cyber Rivalry
While these U.S. strategies might succeed in checking some adversary cyber operations, we find them unlikely to lead to any stable equilibrium, at least not one favorable to the United States.
A stable system is one in which a stimulus produces beneficial negative feedback, an automatic counteraction that reestablishes the equilibrium. Think of a thermostat or the Bismarckian balance of power system. In an unstable system, a stimulus takes the system farther away from equilibrium, which can lead to an overreaction, causing further positive feedback such as a runaway conflict spiral.
The best-known equilibrium for modern readers is mutually assured Destruction (MAD) during the Cold War, achieved through the deterrent capabilities of assured second-strike nuclear capabilities, as later codified by formal arms control agreements. A related equilibrium came about when
What determines whether systems are stable, and which type of system is persistent cyber engagement most like?
In the supporting theories, such as Robert Gilpin’s regarding imperial overstretch, an equilibrium represents the point at which neither strategic competitor can reap excess revenue over costs by pressing for further change in the status quo. In Gilpin’s model, equilibrium occurs because power projection becomes more costly the farther from an empire’s home base. In the alternative model of the security dilemma, equilibrium occurs when defensive operations and tactics are the best form of self-defense, and when a dollar spent on defensive capabilities can more than offset a dollar spent on attack capabilities.
There is nothing like such a self-enforcing equilibrium in the cyber realm, nor do we expect one anytime soon.
An equilibrium might occur in an environment where states use cyber capabilities as a pressure release to avoid broader conflict, blowing off inconsequential steam rather than resorting to more kinetic options. Many observers have argued that colonial competition and compensation served a similar safety valve in the three decades before World War I. But if so, the valve worked only until it didn’t. Nations may push too far again under the illusion that their behavior is far from triggering any tipping points.
In recent times, great power adversaries have been relatively restrained from direct cross-border armed attack in all its forms, not just cyber. Any seeming cyber stability or predictability may just reflect this overall geopolitical situation. As Graham Allison claimed, “the past eight decades have been the longest period without a war between great powers since the Roman Empire.” The ups and downs of cyber operations have always been tied to geopolitics. As crises multiply, cyber stability is likely to degrade as well. Cyber competition might soon be called upon to release more geopolitical pressure than it can handle.
What has held for the first three decades of constant contact may not hold for the fourth, fifth, sixth, or beyond.
Persistent Engagement and Instability
Another prominent proposal for cyber stability is persistent engagement.
Advocates for deterrence through persistent engagement might argue that cyber conflict suffers from destabilizing positive feedback because the United States has not responded actively enough to its rivals’ transgressions. Harknett and Fischerkeller embrace Thomas Schelling’s concept of agreed competition and tacit bargaining, arguing that repeated “action and interaction” in cyberspace between adversaries leads to “increased clarity and reduced uncertainty regarding boundaries or limits on behaviors,” engendering “predictability and potential stability.”
Disrupting adversaries might be a sound operating concept, but we question the theory’s prediction that this is leading to stability under recent, present, and likely future circumstances.
Such a disruptive approach to equilibrium would be easier if each side had narrow and compatible concerns, such as protecting critical infrastructure from attack. But nowadays, rival cyber powers are playing different games with different rules in pursuit of clashing interests. Russian President Vladimir Putin needs to conduct cyber disruption to destabilize the West to feel secure. To establish a regional autarky, Chinese Premier Xi Jinping believes he needs to steal technology and credibly threaten U.S. infrastructure. Meanwhile, the United States, wielding the most potent cyber panoply, is loath to give up any advantages with such dangerous rivals. All are used to easy gains from their cyber predation, with seemingly little risk.
For reasons as much situational and political as cyber-technological, the main rivals all consider cyber offense a vital tool, producing the classic spiral escalation of the security dilemma rather than a stable defensive equilibrium. Strategic interactions are unlikely to be stable under these conditions.
Persistent engagement, as conversation through counterattack, is likely to lead to destabilizing feedback loops in which emotion, cognitive biases, and organizational dynamics might encourage tit-for-tat responses. And there are few alternative communication channels to warn a rival that their tit-for-tat is swerving toward a disproportionate response.
Long-term cyber stability, the original stated goal of U.S. Cyber Command, might emerge if rivals decided to play the same game or if geopolitical tension drastically relaxed, reducing the existential angst. If Russia became unafraid of regime change or the U.S. acceded to China becoming a regional autarkic hegemon, the rivals would rely less on the riskiest cyber operations, allowing room for possible equilibrium. MAD, which helped deliver nuclear stability, has not been a likely candidate to do the same for cyber, despite some backers, as capabilities have never been sufficiently destructive. In the coming years, cyber MAD is slightly more plausible as artificial intelligence leads to worrying increases in vulnerability and improvements in offensive capabilities.
Other well-established theories that aim to achieve strategic stability through strictly defensive measures seem less risky in principle, but can they be applied to the cyber realm? In the past, these took the form of arms control agreements to eliminate first-strike weapons, bans on exercising or training forces in a provocative manner, or using radars and satellites to monitor each other’s nuclear delivery mechanisms. It seems hard to imagine how these models could be applied to cyber.
In the absence of a structurally induced strategic equilibrium through dominance of the defense, the concept of persistent engagement relies more on a tactically induced equilibrium of action and interaction. In standard theories of mixed-motive competitive-cooperative games such as the prisoner’s dilemma, the nearest analogue is the tactic of tit-for-tat. In a famous 1980 experiment, Robert Axelrod proved such equivalent retaliation as the winning strategy in an indefinitely repeated, symmetric game in which cooperation pays off more than mutual defection. Despite tit-for-tat leading to higher overall gains, each side often prefers, if possible, to defect while the other cooperates for larger relative gains.
But tit-for-tat in the prisoner’s dilemma is not a perfect fit with the theory of persistent engagement. Rather than coolly and rationally responding to defection with defection, the adversaries engaging in the gritty struggle of constant contact will perceive defections from cooperation regardless of intent.
Not only will emotions run high, but each believes its own moves are acceptable while viewing the other’s moves as treacherous defections. After all, the main rivals don’t agree on what game is being played or the rules.
For example, according to the U.S. intelligence community, Putin undermined the 2016 election in part because he assessed the “Panama Papers disclosure and the Olympic doping scandal as US-directed efforts to defame Russia.” His election interference in the U.S. presidential election led subsequently to U.S. outrage and intensification.
Even within one country, different bureaucracies can play different games, frustrating any subtle tit-for-tat strategies. In response to an incident seen as particularly egregious, the U.S. military might reserve some highly punishing attacks, such as disrupting the home network of Chinese intelligence headquarters, in line with persistent engagement, but forgo such intrusions that are in line with accepted norms and therefore acceptable. But other responses, troubling to the Chinese Communist Party, would continue because they are not seen as part of the same game. The State, Treasury, and Justice departments might sanction or indict those behind the “acceptable” intrusion. Meanwhile, the intelligence community gathers geopolitical intelligence, and other parts of the military gain access to critical Chinese infrastructure to prepare for warfare. China may even assess embarrassing stories about Chinese leaders in U.S. media as defection.
Two Models of Limited Competition
How this dynamic of limited cyber competition plays out is likely to depend on a crucial distinction—whether the rivals are engaging in a balanced competition or a competition for dominance:
- Balanced competition: A situation in which neither side wants nor envisions overall dominance in cyberspace, but simply wants to gain as much benefit as possible within a permanently delimited sphere of competition.
- Competition for dominance: A situation in which each side acts with restraint while attempting to decisively shift the balance of forces in its favor with a view toward supremacy and enforcing its preferred rules governing cyber competition and cooperation.
In the first model, balanced competition, nobody especially wants dominance, thinks it matters, or believes it is possible, such as legal economic competition among liberal democratic states, with each actor seeking to achieve a competitive position that leaves it as wealthy, prestigious, and successful as possible. Cyber persistence theory leans toward balanced competition, like an intelligence contest, to be managed and not won outright.
In these situations, agreement on rules regulating competition may not be necessary to stabilize persistent, limited engagement. Each actor makes its own prudent, unilateral calculation that escalation is disadvantageous, too costly to be worthwhile, and possibly unnecessary since key goals can probably be achieved without escalation.
In the second model, limited competition for dominance, each side may believe that the costs of escalation are likely to be so high that uncontrolled escalation should be avoided, while believing that one’s own side has good prospects for achieving partial dominance through persistent engagement in the future.
As with balanced competition, in principle the limits on escalation might be enforced by the individual prudence of one or both sides, without any agreement on explicit or even tacit rules. However, because submitting to the adversary’s dominance means accepting a high cost, opponents are likely to engage in a competition of risk taking before one decides to submit to the opponent. To avoid unintended costly escalation, the two sides have a significant incentive to agree on stabilizing rules to govern their competition. Because of these high risks and stakes, agreement on explicit or tacit rules is both more valuable and more difficult for the parties to achieve. Earlier generations of U.S. military leaders seemed favorably inclined to balanced competition.
Nowadays, though, military and political leaders often lean toward the objective of cyber dominance. The Trump administration’s cyber strategy in 2018 was particularly straightforward in its lament that “Americans sometimes took for granted that the supremacy of the United States in the cyber domain would remain unchallenged.” America should accordingly push for an overall “balance of power that favors the United States.” The newer Trump 2026 strategy is not quite so dramatic: The Pentagon’s assistant secretary for cyber has said the U.S. “must dominate the cyber domain, establishing a position of strength that deters our adversaries and protects our interests.”
Striving for dominance seems even more likely now that the head of U.S. Cyber Command is from the special operations community—not signals intelligence, as his predecessors were. The strategic culture of intelligence is traditionally more watchful and wary than the bias-for-action Delta Force.
There is an explicit analogy between cyber dominance and doctrines of nuclear escalation dominance. Colleen Larkin calls this idea “waging deterrence,” in which “the bomb was both an unusable, revolutionary deterrent and an essential tool for fighting and winning the next war.” Extended deterrence requires the ability to prevail in a nuclear counterforce exchange or in an open-ended nuclear counterforce arms race, as recently described by Vipin Narang and Pranay Vaddi.
These ideas are essentially the opposite of Glenn Snyder’s concept of the stability/instability paradox, which argues that it is safe to unleash a victorious conventional offensive because the absolute stability of MAD deters a nuclear response.
Fischerkeller and Harknett propose that “interaction in cyberspace is bounded by a strategic objective to advance national interests while avoiding war.” If so, then cyber competition might echo other historical conflict studies of agreed, limited competition for dominance. There is no shortage of such limited competitions—such as skirmishing on the turbulent frontier of empire, competition for resources and strategic positions of strength like the naval showdown between Britain and France during the 1898 Fashoda crisis, and other brinkmanship crises before World War I. More recently, there have been proxy wars and salami tactics in the Cold War; Kargil-style conventional battles between nuclear-armed India and Pakistan; and peacetime mercantilist commercial rivalry between great powers in all eras.
Different combinations of power, interest, and means of struggle led to differing outcomes in these contests. As exemplified by the differing patterns of escalation control in Kargil and World War I, not all of these conflicts remained stable for long periods, nor did they all resolve peacefully. Most were based largely on unilateral calculations about the dangers of escalation, lacking explicit agreement over the thresholds and rules of the competition. Some—such as Britain’s coercion of France over Fashoda—wound up with a (limited) winner and a (limited) loser, whereas in the most extreme case—the brinksmanship crises between the great powers between 1905 and 1914—the adversaries no longer cared about limits and escalated to world war.
This perspective should encourage great humility among cyber theorists and strategists of self-limiting rivalry.
Recommendation
Tellingly, the posture statements to Congress by cyber commanders brag about dozens of activities, but no actual victories, no successes in convincing adversaries to back down or establish any equilibrium. Perhaps the successes were top-secret disruptions of particular campaigns, but strings of tactical successes are not stability, the promised goal. It is covering fire to keep an adversary’s head down.
Any meaningful success should appear as reductions in the number or severity of nation-state attacks. Yet eight years since the introduction of persistent engagement, there have been no obvious reductions in adversary malicious activities, no sharp knee-in-the-curve of their depredations, and no stability. Although defenders are making it more difficult for adversaries, the consequences of cyber campaigns keep getting worse.
Because persistent engagement has only one vocabulary—that of offensive cyber operations—it has only one remedy on offer: “If adversaries do not reduce their attacks, for any reason, the theory offers little advice other than to defend forward harder.” Sport coaches warn their athletes about such blind spots: “If you’re too committed to your own system, the answer will always be to do the same thing better.”
The same may be true here. As one of us argued in 2018, the Pentagon (or the academic theorists) needed to offer clear criteria and timelines for persistent engagement’s success:
Cyber Command asserts more agility will increase adversary’s costs and bring them back towards global norms. Okay. How long will that take and how will we know it when we see it? If this cannot be answered, then it cannot be approved …. We likewise need to have specific criteria for measuring if more agility is definitely not working. This needs to be directly addressed, or [the Department of Defense] can continually come back and say “almost there” and “we just need to be a bit more agile and aggressive,” while ignoring clear indicators of failure.
Success in cyberspace seems as elusive as it was in Vietnam or Afghanistan. Victory, Americans are assured, is just around the corner if the military is unleashed just a bit more.
Since stability may not be attainable with a military solution, cyber conflict needs a new theory, one not predicated on successful military employment. Future research should explore stability-enhancing engagement, beginning with the desired end state of equilibrium and working backward through a more complete set of ways and means. After all, if constant contact between military cyber forces is enabled by a lack of defensible borders in cyberspace, then surely building such fortifications is a more natural imperative than striking back.
And even if formal diplomatic norms are elusive, one of the steepest drops in adversary activity was not from a military counteroperation but, rather, from sustained U.S. political pressure. In 2013, Tom Donilon, the national security adviser for President Obama, stressed that “[f]rom the President on down, [Chinese cyber espionage and theft of intellectual property] has become a key point of concern and discussion with China at all levels of our governments. [The United States needs from China] a recognition of the urgency and scope of this problem and the risk it poses … to our overall relations.” China later drastically reduced such operations, according to hard-nosed cyber leaders, such as Rob Joyce and John Carlin, and confirmed by cybersecurity company FireEye.
A more stability-forward theory must also explore feedback loops more deeply and how these loops may interact to create unintended consequences and their impact on enhancing or degrading both national power and crisis stability.
The world increasingly depends on stability in cyberspace to ensure the critical systems behind societies, economies, and militaries operate dependably. That stability must rely on more than a hopeful theory prescribing more offensive cyber operations.
