Agenda
European Repository of Cyber Incidents + LIVE Q&A
Wed Nov 9 / 11:00 - 11:45 CEST
Jakob Bund (SWP Berlin)
Kim Schuck (Heidelberg University)
- The maturity of academic research on cyber conflict has been held back by a lack of quantifiable data about the phenomenon. For conventional war, numerous databases facilitate generalizable conclusions about the character of conventional armed conflicts, such as their intensity and temporal or regional distribution. For cyber conflict, we lack large-N datasets that compare cyber incidents based on theoretically founded categories. Consequently, our knowledge is often limited to individual case studies of famous incidents, such as Stuxnet or the DNC hack. The empirical analysis of well-known case-by-case studies is not only prone to selection biases, which severely limits the applicability of the results but also makes it hard to infer the larger impact of state policies regarding cyber conflict – an essential precondition for evaluating implemented measures.
To narrow this data gap, we have been developing a European Repository of Cyber Incidents, a dataset currently featuring over 1,500 cyber operations worldwide reaching back to 2000. In this paper, we present its methodology intending to invite academic and practitioner feedback to further strengthen this resource for the scientifically robust study of cyber conflict. Based on this significantly expanded empirical foundation, we explore opportunities to test conceptual frameworks for how states are using cyber capabilities the academic research community has developed. We highlight the strengths of an interdisciplinary approach built on over 60 political, legal and technical variables that embed analysis of cyber components in the wider reality of underlying conflict drivers. Political variables include characteristics of targets (targeted countries, sectors, damage and effects), attackers (states, proxies, and other non-state actors), attribution information (who attributed an attack to whom, when, and how), and policy responses to attacks, including diplomatic reactions. Additionally, we collect data on the legal dimension of cyber operations: what type of domestic legal response followed an attack (indictments, sanctions), what areas of international law were affected and invoked by responding states, and whether legal countermeasures could be warranted. Lastly, we assess technical variables derived from the MITRE ATT&CK framework, including details on the initial access vectors, the usage of 0-days, and the technical impact of an attack (disruption, destruction or physical effects).
Jakob Bund
Jakob Bund is an Associate at the German Institute for International and Security Affairs (SWP), where he is responsible for threat analysis in the build-up of a European Repository of Cyber Incidents (EuRepoC). His research focuses on the cumulative effects of cyber operations and measures for escalation control.
In collaboration with Microsoft and the German Marshall Fund, Jakob has been co-chairing the working group on “Enhancing Cross-sectorial Lines of Communication” for the European Cyber Agora. He currently is a Fellow for the European Cyber Conflict Research Initiative (ECCRI) and for the Transatlantic Digital Debates Initiative.
Until 2022, Jakob headed the Cyberdefense Project at the Center for Security Studies at ETH Zurich, advising the Office of Cyberdefense Policy in the Swiss Department of Defense and the Project Cyber Command of the Swiss Army. Previously, he worked as researcher at Oxford University and the EU Institute for Security Studies, assessing the inclusive development of cybersecurity strategies for the British Foreign Office and the World Bank and supporting the EU’s track-two dialogues with strategic partners.
Kim Schuck
Kim Nina Schuck is project manager in the EuRepoC project. She is also an academic assistant at the Chair of International Relations and Foreign Policy at the Institute of Political Science at Heidelberg University. Previously, she completed her bachelor degree in Political Science with a minor in Psychology at the University of Mannheim with a semester abroad in Exeter. She completed her master degree at the University of Heidelberg in Political Science with an accompanying subject in Public Law. Her master thesis focused on the weaponization of outer space and the variance in cooperative arms control of space-based weapon systems. Her research interests are in international relations, norm-building, and (cyber-)security of outer space systems.