CommentaryGuest Commentary

Cyber Campaigning: Mid-Tier States Can Leverage Civilian Cyber Power

A concept image of two people working at a computer, one in uniform and the other in a hooded sweater.

Cyber strategy: Private sector companies have capabilities that governments could introduce into their campaigns. Image: DC Studio / Adobe Stock


States lacking vast nuclear and conventional capabilities should team with the private sector via letters of marque and digital levée en masse.

States that lack nuclear arsenals and large conventional forces should make greater use of cyberspace as a strategic environment. Unlike the nuclear domain, cyberspace does not require enormous financial or technological investments to achieve strategic effects. It is accessible to states of different sizes and, importantly, to non-state actors and private companies. The war in Ukraine demonstrates this increasingly blurred boundary: not only states but cyber activists and technology companies such as Starlink, Amazon and Microsoft have impact on the conflict.

Cyberspace creates opportunities for mid-tier states. Rather than attempting to replicate the capabilities of major cyber powers they can exploit the distinctive logic of cyberspace and cooperation with civilian partners. Two mechanisms could operationalise this approach: Cyber letters of marque, whereby states authorise private technology companies to conduct specified cyber operations on their behalf; and a digital levée en masse, through which civilian cyber expertise is mobilised to strengthen national cyber resilience and, where appropriate, support operations during conflict.

Cyber Persistent Theory

For much of its development, academic thinking about cyber operations was framed through nuclear and conventional concepts, particularly deterrence and coercion. Cyber persistent theory offers a perspective away from the ‘deterrence default: cyberspace should be understood as a distinct strategic environment with its own logic and dynamics. After all, empirical evidence indicates that cyber operations frequently remain below the threshold of armed conflict, are seldom coercive and involve a wide range of non-state actors.

A defining characteristic of this environment is interconnectedness. Constant interaction is a condition rather than a choice. Strategic success therefore depends on persistent engagement or cyber campaigning. Rather than waiting for conflict or seeking a single decisive battle, actors should maintain the initiative, shape the cyber environment to their advantage and accumulate smaller gains over time. This requires a degree of (tacit) understanding among competing actors about the boundaries of acceptable behaviour.

quote
Private-sector activities authorised under a state strategy could therefore contribute to persistent engagement, provided that they remain coordinated and subject to clear legal constraints

Persistent campaigning is imperative in cyberspace if strategic gains are to be pursued. The question is how mid-tier states can develop sufficient capacity to create operation friction in cyberspace without building every capability themselves. In their RUSI comment, Kello and Harknett suggest that states with limited resources can concentrate their persistent campaigning on a relatively small number of targets that are critical to national interests. Complementing that, states can team up with civilian partners to achieve strategic effects.

Teaming up with civilian partners

Mid-tier states have three broad options. They can build national cyber commands, intelligence capabilities and supporting infrastructure from scratch to engage in cyber campaigning; cooperate with larger cyber powers’ campaigns, accepting a degree of dependency; or leverage domestic private-sector capabilities. In practice, a combination of these approaches may be appropriate.

This Commentary focuses on the third option of teaming up with private-sector companies as an extension of cyber campaigning. It is true that cooperation between governments and private companies in national security and defence raises significant legal and ethical questions. Yet, in the course of history, states often relied on civilian actors or privateers for military and security purposes, producing two aforementioned models that are particularly relevant to cyberspace: the letters of marque and the levée en masse.

Cyber Letters of Marque

Historically, letters of marque authorised private vessels to conduct operations against enemies on behalf of a sovereign. Even today, states still employ private actors in security and defence, including private military companies. The increasingly private ownership of digital infrastructure suggests a possible cyber equivalent: states could authorise (trusted) Information and Communications Technology (ICT) companies to conduct specified cyber operations in support of national objectives.

A US legislative proposal has already sought to create such a mechanism by allowing the President to issue ‘cyber letters of marque. Under such a framework, a private entity could be authorised to conduct operations against designated targets, subject to government-imposed conditions. Potential activities could include intelligence collection, seizure of digital assets and disruption of malicious infrastructure.

The concept aligns with the central principles of cyber campaigning: initiative, cumulative gains, and agreed competition. States need to shape the digital environment continuously, and authorised cooperation with trusted ICT firms could allow states lacking substantial indigenous capabilities to remain proactive while retaining governmental control over inherently governmental functions.

Enjoy our analysis and research? Ensure it shows up first on Google

Help your search results show more from RUSI. Adding RUSI as a preferred source on Google means our analysis appears more prominently.

Cyber operations can produce strategic effects through the accumulation of smaller actions (or gains) rather than a single decisive strike. Private-sector activities authorised under a state strategy could therefore contribute to persistent engagement, provided that they remain coordinated and subject to clear legal constraints.

Cyberspace is, finally, characterised by constant interaction among states and non-state actors via a system of tacitly agreed bargaining. Because the boundaries of acceptable behaviour are partly constructed through this interaction, uncontrolled or poorly understood activities can increase instability. Regulated cooperation between a mid-tier state and specific ICT firms could instead help reduce capability gaps and contribute to a more balanced cyber environment.

Digital Levée en Masse

A second model is digital Levée en Masse. In its strict legal sense, levée en masse refers to civilians spontaneously taking up arms against an invading force. The concept has historical roots in the French Revolution and was subsequently incorporated into the law of armed conflict. In a broader sense, however, it can describe the mobilisation of dormant civilian capabilities in response to a crisis, comparable to the stay-behind organisation that existed during the Cold War period. The Ukrainian IT Army similarly provides a contemporary cyber-related example.

For cyberspace, this concept could be adapted to mobilise the cyber expertise already present in critical sectors. Chief Information Security Officers (CISOs) and their teams possess detailed knowledge of the vulnerabilities, systems and dependencies within their organisations and sector. Relying on a network of firms, for instance leveraging the NIS2 framework, these CISO-communities could cooperate with national cyber security centres and intelligence agencies during peacetime, while becoming more closely integrated with national cyber commands as tensions rise.

The principal value of such a network could be defensive. A national CISO-community could improve threat intelligence, monitoring and resilience across critical sectors, while providing government and ICT companies with sector-specific expertise. The knowledge these communities possess (on architecture and vulnerabilities in specific industries) can, however, also contribute to planning and conducting offensive cyber operations. Unlike cyber letters of marque, the CISO-community would not necessarily conduct operations itself. Rather, it would strengthen the wider ecosystem on which state cyber power depends.

Subscribe to the Cyber & Tech Newsletter

Stay up to date with the latest publications and events from the Cyber and Tech Research Group

Subscribe to the RUSI Newsletter

Get a weekly round-up of the latest commentary and research straight into your inbox.

It may sound counterintuitive, but for this notion to work the existence and role of the civilian cyber network should be sufficiently transparent to avoid surprising other states and to reduce the risk of miscalculation and unwanted escalation.

The Strategic Opportunity and Risks

Cyber Campaigning offers mid-tier states a way to pursue strategic advantage without possessing the nuclear or conventional capabilities of major powers. The key is not to reproduce the capabilities of larger states but to exploit the distinctive characteristics of cyberspace: persistent interaction, interconnectedness, civilian participation and the possibility of accumulating effects over time.

Cyber letters of marque and a digital levée en masse provide complementary mechanisms especially for mid-tier states. The former could allow trusted ICT companies to perform specified functions on behalf of the state; the latter could mobilise existing civilian expertise to strengthen national cyber defence and resilience. Used together, they could enable mid-tier states to remain persistently engaged in cyberspace despite limited resources.

There are, however, important risks. First, greater reliance on civilian cyber capabilities could deepen rather than reduce asymmetries between states, particularly because authoritarian governments may find it easier to mobilise (or enforce the alignment of) private actors than democratic governments. Second, involving civilians in cyber operations raises serious questions under international law, particularly when civilian actors participate directly in activities associated with armed conflict.

These concerns do not invalidate the concept, but they demonstrate the need for clear legal mandates, political oversight and carefully defined roles. If these conditions can be met, civilian cyber capacity could become an important force multiplier for mid-tier states. Rather than waiting and hoping to acquire the capabilities of major cyber powers, they can begin to shape the cyber environment with the resources already available to them.

© B.M.J. Pijpers & Jelle van Haaster, 2026, published by RUSI with permission of the authors.

The views expressed in this Commentary are the authors', and do not represent those of RUSI or any other institution.

For terms of use, see Website Terms and Conditions of Use.

Have an idea for a Commentary you'd like to write for us? Send a short pitch to commentaries@rusi.org and we'll get back to you if it fits into our research interests. View full guidelines for contributors.


WRITTEN BY

Dr Peter B.M.J Pijpers

Guest Contributor

View profile

Dr Jelle van Haaster

Guest Contributor

View profile



Explore our related content