Research Themes
State-Backed Cyber Operations
Technology, Firms & Economic Risk
Governing Frontier Technologies
Democracy Innovation Lab
Governing Frontier Technologies
State-Sponsored Cyber Operations
At CSINT, we are committed to exploring the dynamics of state behavior in cyberspace, with a focus on how and why nation-states employ cyber instruments. We investigate the deployment of hackers as proxies by states to project power and examine the complex interactions and motivations behind these actions. Our current work centers on the dynamics of interstate cyber conflict and how states leverage cyber capabilities in the pursuit of national security goals. Through this research, we aim to uncover the strategies, tactics and implications of state-sponsored cyber operations, providing critical insights into the evolving landscape of global cybersecurity and digital diplomacy.
The draft principles represent a necessary effort to translate the series’ analytical findings into policy-ready language. However, the current draft requires substantial revision to narrow the principles.
Cyber espionage encompasses a broad range of intelligence-gathering activities conducted through digital networks, spanning multiple domains. While these various forms share technological methods, they differ significantly in targets, perpetrators, and strategic objectives.
NATO is no longer tiptoeing around its enemies. The alliance now speaks and acts with a clear and distinct intention.
States spend a lot of time worrying about spies, and a lot of money trying to protect themselves from espionage. They construct multilayered personnel policies to keep untrustworthy individuals from government jobs that involve handling classified information. They invest heavily in complex information systems to block access to sensitive communications.
What are the costs of cyber espionage? And how do they differ from those of operations designed to prepare for attack?
In 2010, Stuxnet, a stealthy, sophisticated computer worm widely attributed to the United States and Israel, infiltrated Iran’s Natanz uranium enrichment facility and sabotaged its industrial controls, delaying Iran’s nuclear program without a single bombing raid or overt military strike. A few years later, Russian operatives hacked into U.S. political organizations in 2016, stealing and leaking emails in an effort to sway the presidential election. At the same time, Chinese state-sponsored groups quietly penetrated foreign government and corporate networks to siphon off military technology and industrial secrets over many years. These incidents, though bloodless and often deniable, had clear strategic stakes.
Russia has been repeatedly accused of employing non-state cyber proxies to conduct sophisticated cyber-attacks and information operations aimed at influencing US elections. These allegations, notably around the contentious 2016 US presidential election, have attracted substantial global attention, underscoring critical vulnerabilities within democratic institutions.
Economic cyber espionage represents an ongoing threat to both nations and markets, yet unlike other cyber threats, it remains largely uninsured. This does not have to be the case. The underinsurance for economic cyber espionage is more of a mechanical problem, with coverage gaps hinging on proving damage to intangible assets. In fact, this protection gap persists even when attackers are “incompetent” (i.e., unable to use the IP they steal), since victims still incur measurable, indemnifiable costs.
The security of open source software (OSS) has morphed from a niche technical concern to a central cybersecurity policy challenge. High-profile incidents have led to suggestions for governments to help strengthen the OSS ecosystem, including calls for funds built to support open source projects and their maintainers, such as a proposal for an EU Sovereign Tech Fund. This research examines the argument that unconditional funding—namely, financial support without specific requirements for the recipient—causally improves the security posture of OSS projects.
Supply-chain decoupling doesn’t stop rival nations from hacking each other and can make it worse. A cyber-espionage expert explains what does work.
Cyber espionage is the use of cyber tools and techniques to gather intelligence or steal sensitive information from targeted entities. This form of espionage poses significant risks to national security, economic stability and corporate integrity. Given the complex and often hidden nature of cyber espionage activities, accurately measuring their costs presents a significant challenge.
As cyber threats become increasingly central to international politics, state-sponsored cyber attacks have become an instrument of geopolitical leverage.
The Mythical Beasts project addresses this meaningful gap in contemporary public analysis on spyware proliferation, pulling back the curtain on the connections between 435 entities across forty-two countries in the global spyware market. These vendors exist in a web of relationships with investors, holding companies, partners, and individuals often domiciled in different jurisdictions.
In September 2001, operatives for Procter & Gamble were caught diving in dumpsters outside a Unilever facility in Chicago in search of documents and other discarded items containing confidential information about Unilever’s hair care products business. To avoid litigation and the negative publicity that often accompanies such disputes, the companies quietly reached a negotiated settlement where Procter & Gamble agreed to not use any of the information obtained. This early example illustrates the ongoing vulnerability companies face regarding data security. In today’s corporate environment where digital data storage is the norm, companies now have to be wary of not only paper documents but also discarded storage devices like hard drives, USBs, and even old office equipment that might store digital data.
Traditional conceptions of state-sponsored cyber economic espionage suggest that countries with different product profiles should experience high levels of espionage between them. However, this is not what we observe empirically. This article offers new insights into the strategic calculations that underpin state-sponsored cyber espionage and challenges scholars and policymakers to rethink the dynamics of international economic competition and security in the digital age.
Governing Frontier Technologies
The rapid advancement of fields like quantum computing, artificial intelligence, biotechnology, and other cutting-edge innovations is radically transforming the technological landscape. While these developments hold immense promise for addressing global challenges and driving human progress, they also introduce complex geopolitical, economic, and social implications that require careful examination. The Frontier Technologies research stream explores the political dimensions of these transformative technological shifts. Through interdisciplinary collaboration aimed at building bridges between academic theory and public policy, this program investigates how the development and deployment of novel technologies are shaping the global balance of power, national security concerns, economic competitiveness, and the very fabric of society.
This paper examines whether orbital data centers could offer a viable alternative to the increasingly resource-intensive computing infrastructure supporting artificial intelligence. It evaluates the technical, economic, environmental, and governance challenges of moving computation into space, arguing that policymakers should address questions of orbital debris, liability, market concentration, and data sovereignty before commercial development outpaces regulation.
The infrastructure of artificial intelligence (AI) depends on critical minerals and rare earth elements, making their supply chains a central factor in national security, economic stability, and global technology competition and governance. Overreliance on supply chains characterized by limited geographic diversification exposes AI commercial and defense industries to trade disruptions, cyber sabotage and strategic leverage. This paper explores these issues.
The United Nations Educational Scientific and Cultural Organization (UNESCO) has designated 2022-2032 the International Decade of Indigenous Languages. This initiative comes at a time when endangered language speakers, linguists, and other groups are concerned about language extinction and the rapid spread of artificial intelligence (AI). Some researchers are optimistic that AI can be leveraged to help document, preserve, and revitalize at-risk languages, while others are concerned that the technology will accelerate the homogenization of human language.
In a given month, more than 100 million people open Pokémon Go—the app that allows users to superimpose the world’s most profitable media franchise onto reality using only their smartphone. Using their phone camera and a flick of the wrist, they captured tiny digital monsters at the park, at the office, sometimes in active minefields, and, yes, in the bathroom.
Who else was watching?
While social media disinformation has received significant academic and policy attention, more consequential forms of intentional manipulation target the underlying digital infrastructures upon which society depends.
A seasoned scholar, strategist, and expert in space policy and strategy, Dr. John J. Klein is well-versed in applying strategic theory to the space domain. In his new book, Fight for the Final Frontier: Irregular Warfare in Space (2023), Klein argues that irregular warfare, in both its military and nonmilitary forms, is a vital and underutilized concept for understanding malicious activities in space and the nature of space warfare. His argument draws on a diverse list of strategic theorists, historians, and contemporary policy analyses. Klein weaves these sources together persuasively, providing an accessible overview of a technologically demanding subject. Policy generalists and students, along with veteran analysts of space policy, will benefit from his account.
As the world’s infrastructure becomes increasingly interconnected, more critical systems are exposed to cyber threats. A cyber threat is a malicious act intended to steal, damage, or disrupt digital data. Cyber threats seek to turn potential security vulnerabilities into attacks on systems and networks.
Orbiting satellites perform many tasks: communications, broadcasting, weather forecasting, earth observation, intelligence-gathering, and scientific research. The first satellite, launched in 1957, was a modest metal sphere containing a simple radio transmitter. Since then, satellites have grown in size and complexity. Many are visible to anyone with a reasonably powerful backyard telescope.
In 2006, two leading scholars of the nuclear era warned that the age of mutually assured destruction (MAD) was ending. Seventeen years later, the authors are doubling down on these claims, arguing that the outbreak of new conventional conflicts has changed nuclear decision making, increasing the threat of coercive nuclear escalation. In an age of new technology, this warning is more pertinent than ever. The rapid introduction of emerging technologies and their weaponization raises concerns about maintaining strategic stability.
Last month, SpaceX became the operator of the world’s largest active satellite constellation. As of the end of January, the company had 242 satellites orbiting the planet with plans to launch 42,000 over the next decade. This is part of its ambitious project to provide internet access across the globe. The race to put satellites in space is on, with Amazon, U.K.-based OneWeb and other companies chomping at the bit to place thousands of satellites in orbit in the coming months.
Technology, Firms and Economic Risk
States have a strategic interest in adopting emerging technologies. This is especially true of digital technologies as battlefields become more ambiguously defined across civilian infrastructure and awash in data. This adoption relies on an often-contested relationship with technology firms, including some of the largest corporations assembled since the French Revolution. The nature of this contest, and the choice of strategies by states, and firms, to compete more effectively, has significant implications for the design and adoption of digital technologies, the political power of non-state groups, and the security of the United States and its allies.
This collection of applied research projects works to understand the mechanics of contestation between firms and the state, the strategies states use to influence the security of digital technologies, how the adoption of different kinds of technologies by states influences public-private political dynamics, and the diffusion of offensive digital technologies developed or employed by non-state groups. This work takes an explicitly interdisciplinary approach and works to translate findings into practical recommendations for different policymaking communities.
States spend a lot of time worrying about spies, and a lot of money trying to protect themselves from espionage. They construct multilayered personnel policies to keep untrustworthy individuals from government jobs that involve handling classified information. They invest heavily in complex information systems to block access to sensitive communications.
What are the costs of cyber espionage? And how do they differ from those of operations designed to prepare for attack?
Insecure software is a national security risk, costs the U.S. billions of dollars annually, and exposes users’ information to malicious actors. Software developers (vendors) who fail to securely develop their products currently face few legal repercussions, even if they engage in industry-agreed bad practices.
Cyber espionage is the use of cyber tools and techniques to gather intelligence or steal sensitive information from targeted entities. This form of espionage poses significant risks to national security, economic stability and corporate integrity. Given the complex and often hidden nature of cyber espionage activities, accurately measuring their costs presents a significant challenge.
As cyber threats become increasingly central to international politics, state-sponsored cyber attacks have become an instrument of geopolitical leverage.
The Mythical Beasts project addresses this meaningful gap in contemporary public analysis on spyware proliferation, pulling back the curtain on the connections between 435 entities across forty-two countries in the global spyware market. These vendors exist in a web of relationships with investors, holding companies, partners, and individuals often domiciled in different jurisdictions.
The Intellexa Consortium, a complex web of holding companies and vendors for spyware and related services, have been the subject of recent, extensive sanctions by the US Department of the Treasury and the focus of reporting by the European Investigative Collaborations among others. The Consortium represents a compelling example of spyware vendors in the context of the market in which they operate—one which helps facilitate the commercial sale of software driving both human rights and national security risk. This paper addresses an international policy effort among US partners and allies, led by the French and British governments, as well as a surge of US policy attention to address the proliferation of this spyware.
The Democracy Innovation Lab
The Democracy Innovation Lab is dedicated to exploring the complex relationship between technology and the health of democratic institutions. As digital platforms and new technologies become increasingly embedded in our daily lives, they also present new vulnerabilities and challenges for maintaining free, fair, and secure democratic processes. Through interdisciplinary research and collaboration, the Democracy Innovation Lab investigates how digital and emerging technologies can both be exploited to undermine democratic norms and institutions, as well as be leveraged to strengthen democratic resilience around the globe.
Between 2010 and 2022, 80 countries enacted new legislation or amended existing laws in an attempt to curb the spread of misinformation online. This sharp and global adoption of misinformation laws, however, cannot be explained by the sudden emergence of false or misleading information, as these problems have existed for a very long time.
In recent years, countries in the Sahel region of Africa have faced widespread insecurity and instability. Stretching across the northern tier of sub-Saharan Africa, Sahel countries Niger, Mali, and Burkina Faso have all experienced a series of military coups and rising levels of right-wing extremism.
Disinformation spread via digital technologies is accelerating and exacerbating violence globally. There is an urgency to understand how coordinated disinformation campaigns rely on identity-based disinformation that weaponizes racism, sexism, and xenophobia to incite violence against individuals and marginalized communities, stifle social movements, and silence the press.
What impact do foreign authoritarian influence operations (FIOs) have on democracy? Through an examination of democratic attitudes in 15 African countries between 2009 and 2023, we present preliminary but compelling evidence that autocrats export authoritarianism.
For almost a decade, the study of misinformation has taken priority among policy circles, political elites, academic institutions, non-profit organizations, and the media.