• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
CommentaryThe Biden administration

The U.S. must do what it takes to achieve national security in the age of cyber conflict

By
Vince Stewart
Vince Stewart
and
Gary Corn
Down Arrow Button Icon
December 21, 2021, 7:19 AM ET
Paul Nakasone, director of the National Security Agency (NSA) and commander of the U.S. Cyber Command, recently acknowledged operations against ransomware groups.
Paul Nakasone, director of the National Security Agency (NSA) and commander of the U.S. Cyber Command, recently acknowledged operations against ransomware groups.

It’s been just over a year since cybersecurity firm FireEye disclosed what turned out to be the proverbial tip of the SolarWinds iceberg. As we now know, the breach of its network turned out to be part of a much broader Russian cyber espionage operation.

Exploiting vulnerabilities in the SolarWinds platform, Russia’s intelligence services gained access to the networks of thousands of customers, including a number of key federal government clients. A far smaller number of users were subsequently compromised by follow-up hacking. Microsoft President Brad Smith described it at the time as “the largest and most sophisticated attack the world has ever seen.” 

Unfortunately, just twelve months later, the SolarWinds hack faces some stiff competition for Smith’s superlative ranking. The steady drumbeat of hostile cyber operations that have unfolded since, from China’s Microsoft Exchange Server hack to increasingly costly and harmful ransomware attacks, have given the SolarWinds breach a run for its money. They demonstrate even more clearly what some of us already knew: As a nation, we remain unacceptably vulnerable to cyber threats, a circumstance our adversaries recognize and routinely exploit to our disadvantage in strategic competition.

With the digitization and interconnection of almost every facet of our lives, not to mention our homeland security and national defense systems, national cybersecurity is, as President Biden recently described it, “the core national security challenge we are facing.” Yet too often we have failed to keep pace with this persistent and evolving threat, hitting the snooze button in the face of one “wake up call” after another.

We have failed to fully embrace the strategic reality that our adversaries are committed to constant and unrelenting hostile cyber campaigns against us. Reversing this trend requires not only a recognition of the gravity of the threat, but a related commitment at all levels of the public and private sectors to more proactively confront it.

While the Biden Administration has yet to issue a comprehensive cyber strategy, it has taken a number of steps in the right direction. It has prioritized cybersecurity through both policy and action to push a more collaborative national effort to reduce vulnerabilities, enhance resiliency and drive down risk. Mandating improved cybersecurity standards across the Federal government, leveraging the weight of the government to improve supply chain security in the private sector, enhancing partnerships, establishing improved standards and expectations for critical infrastructure security, and taking steps to remove barriers to threat information sharing between government and the private sector are just a few of the efforts underway to improve overall security and deny our adversaries the benefits of their malign efforts.

As important as these efforts are, they are incipient; and even when fully realized they will not eliminate the incentive structures that motivate our adversaries to confront us through cyberspace. More persistent, proactive measures are needed to counter our adversaries and set the overall conditions of security in cyberspace.

The administration has also made cyber diplomacy a cornerstone of its approach, continuing its leadership role in United Nations processes, engaging a smaller group of states to more actively cooperate in the fight against ransomware, and enhancing key partnerships and alliances. The value of diplomacy and the advancement of international law and norms of responsible state behavior in cyberspace should not be understated. Ceding the field to determined moves from China and Russia to reset the rules-based order to fit their authoritarian goals would be a mistake. However, diplomatic efforts are characteristically reactive and slow. They are unlikely to alter our key adversaries’ calculus, and will not provide solutions to an immediate, ongoing, and urgent problem.

It is vital for the U.S. to take a leading role in international norms-setting efforts, but we will also need to persistently engage our adversaries, employing our cyber capabilities during day-to-day competition to disrupt or halt their malicious cyber operations at the source. Disruptive counter-cyber operations must play a role in achieving cybersecurity in depth.

Recently, NSA Director and Commander of the U.S. Cyber Command Gen. Paul Nakasone acknowledged operations to disrupt ransomware groups, taken in partnership with other elements of the federal government. These actions no doubt reflect valuable lessons learned during operations to defend our elections from foreign interference and other threats to the nation. These operations were made possible by key changes in strategy, policy, and legislation in 2018 that provided for more agile and responsive coordination and approval processes to confront emerging threats. Although not offering a panacea, these operations have made a successful contribution to national security–something we should build on.    

States, non-state actors, and criminals will not abandon cyber tools as means of statecraft, conflict, and crime. Our vulnerability to these threats will remain a core national security concern for the foreseeable future. Disruptive operations are an essential component to achieving better cybersecurity and can be done consistently with our international legal obligations, commitment to norms, and our goal of ensuring a free, open, and secure internet. 

Lieutenant General (Ret). Vince Stewart is the former Deputy Commander of U.S. Cyber Command and the Chief of Inclusion and Innovation for Ankura.

Colonel (Ret.) Gary Corn is former Staff Judge Advocate to U.S. Cyber Command and program director for American University Washington College of Law’s Tech, Law & Security Program and a senior fellow for the R Street Institute.

Editor’s Note: This article has been updated to reflect the number of users affected by the Sunburst breach, according to CISA findings.

More must-read commentary published by Fortune:

  • Extreme events are forcing corporations to think like insurers
  • To deliver the infrastructure boom, construction giants must open their doors to startups
  • Meet your new A.I. best friend
  • Can a community of basketball fanatics run an NBA team as a DAO?
  • If you’re not Elon Musk: Communication and compliance for fintech CEOs
Never miss a story: Follow your favorite topics and authors to get a personalized email with the journalism that matters most to you.
About the Authors
By Vince Stewart
See full bioRight Arrow Button Icon
By Gary Corn
See full bioRight Arrow Button Icon

Latest in Commentary

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Fortune Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map

© 2025 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.


Most Popular

placeholder alt text
Success
Marriott’s CEO spoke out about DEI. The next day, he had 40,000 emails from his associates
By Ashley LutzJanuary 1, 2026
1 day ago
placeholder alt text
Politics
Buddhist monks peace-walking from Texas to DC persist even after being run over on highway outside Houston
By The Associated PressDecember 30, 2025
3 days ago
placeholder alt text
Success
Melinda French Gates got her start at Microsoft because an IBM hiring manager told her to turn down its job offer—'It dumbfounded me'
By Emma BurleighDecember 31, 2025
2 days ago
placeholder alt text
Startups & Venture
Trump Mobile says its first-ever smartphone is delayed, and the government shutdown is to blame
By Dave SmithDecember 31, 2025
2 days ago
placeholder alt text
Health
Lay's drastically rebrands after disturbing finding: 42% of consumers didn't know their chips were made out of potatoes
By Matty Merritt and Morning BrewDecember 31, 2025
2 days ago
placeholder alt text
C-Suite
Exiting CEO left each employee at his family-owned company a $443,000 gift—but they have to stay 5 more years to get all of it
By Nick LichtenbergDecember 30, 2025
3 days ago

Latest in Commentary

Eric Simons
Commentarystart-ups
15 years after skipping college to launch 3 startups, I believe the taboo around questioning higher ed is holding an entire generation back
By Eric SimonsJanuary 2, 2026
4 hours ago
MGI
CommentaryProductivity
The world is awash in wealth but starved for productivity—and that imbalance is distorting growth, debt, and opportunity. We need AI to come through
By Jan Mischke, Olivia White and Rebecca J. AndersonDecember 31, 2025
2 days ago
Zohran, Trump
Commentarywork culture
Strange political bedfellows not that strange in the season of the new nihilism
By Ian ChaffeeDecember 31, 2025
2 days ago
Moreland
CommentaryRetirement
Retirement is changing. Here’s why companies need to change, too
By Mary MorelandDecember 31, 2025
2 days ago
worker
CommentaryJobs
Erased: what 2025 revealed about America’s real economic risk
By Katica RoyDecember 31, 2025
2 days ago
Wesley Yin is a Professor of economics at UCLA in the Luskin School of Public Affairs and Anderson School of Management
CommentaryIPOs
Privatizing Fannie Mae and Freddie Mac the wrong way risks a second Great Recession
By Wesley YinDecember 30, 2025
3 days ago