A cyber operation can disrupt services or expose sensitive information without producing the kind of visible damage associated with an airstrike. If a serious incident happens during a tense standoff, governments may face pressure to respond before the source is clear.
What evidence would decision-makers need before publicly blaming another state? And if attribution remains uncertain, could a response be aimed at the suspected actor without crossing into conventional military action? I’d like to hear how others think about the threshold between a cyber incident and an act of war.