The New DoD Cyber Strategy with Deputy Assistant Secretary Mieke Eoyang
Sep 12, 2023
auto_awesome
Mieke Eoyang, the Deputy Assistant Secretary of Defense for Cyber Policy, offers an inside look at the 2023 DoD Cyber Strategy. She discusses the complexities surrounding international cybercrime treaties, highlighting the clash between democratic and authoritarian views. Insights from her DEF CON experience reveal how cybersecurity is reshaping military strategy, with a focus on the urgency of collaboration. Eoyang also dives into threat intelligence nuances in defense, emphasizing the challenges of rapid response versus control.
The podcast highlights significant international disagreements on cybercrime definitions, complicating efforts to finalize a unified convention among UN member states.
It emphasizes the Department of Defense's shift in cyber warfare strategy, integrating cyber capabilities with traditional military operations while enhancing collaboration with allies.
Deep dives
UN Cybercrime Convention Negotiations
Recent discussions among UN member countries focused on finalizing a convention on cybercrime, marking a critical step in international cyber policy. The process was described as bureaucratic, with conflicting perspectives among nations leading to an increase in unresolved issues in the treaty drafts. Concerns were raised about inadequate protections for cybersecurity researchers, emphasizing the need to define criminal intent clearly in the treaty. This ambiguity could allow governments to pursue security researchers, highlighting a potential legal loophole that needs to be addressed.
Differences in Cybercrime Perspectives
A significant divide exists between nations regarding definitions and approaches to cybercrime, particularly between those who have adopted the Budapest Convention and those who have not. Authoritarian regimes view cybercrime through the lens of state control and censorship, which differs from the more traditional perspectives of democratic nations that focus on hacking and cyber threats. This disparity complicates negotiations, as different values and priorities hinder progress toward a unified understanding of cybercrime on an international level. The challenge lies in aligning these divergent viewpoints to create an effective and comprehensive treaty by the 2024 General Assembly.
Changes to UK's Investigatory Powers Act
The UK government is amending its Investigatory Powers Act, creating potential challenges for cybersecurity and civil liberties. Key concerns include encryption backdoors and potential restrictions on company patching processes, which could have serious implications for the technology sector. However, there is a belief that fears surrounding these changes might be exaggerated, given the existing vulnerabilities equity processes intended to balance national security with societal protections. Continued scrutiny and public engagement are encouraged to ensure accountability and transparency in any legislative changes.
Evolving Cyber Warfare Strategies
The Department of Defense is revising its approach to cyber warfare, recognizing the need to integrate cyber capabilities within traditional military operational strategies. Historical perspectives that equated cyber actions with nuclear deterrence are being reassessed in light of practical experiences, particularly during the Russia-Ukraine conflict. This conflict highlighted the limitations of cyber warfare and underscored the importance of maintaining communication and data integrity for civilian populations during military actions. Moving forward, the focus will be on enhancing collaboration with allies and improving defensive measures while preparing for potential conflicts in the Indo-Pacific region.
In our latest episode, Alex Botting and Jen Ellis from the Center for Cybersecurity Policy & Law are joined by Mieke Eoyang, the Deputy Assistant Secretary of Defense for Cyber Policy. As the highest ranking civilian at the U.S. Department of Defense (DoD), tasked with thinking exclusively about cyber policy, Ms. Eoyang was able to provide valuable insights around the recently released unclassified 2023 DoD Cyber Strategy summary.