June 3, 2011 11:05AM 

# Cyberphobia 

By [Benjamin H. Friedman](https://www.cato.org/people/benjamin-friedman) 

---

<a class="js-popover-trigger cursor-pointer popover-trigger" data-bs-placement="bottom" data-bs-trigger="click" id="popover-trigger"> 

SHARE 

</a> 

The *Wall Street Journal* [reports](http://online.wsj.com/article/SB10001424052702304563104576355623135782718.html) that the Pentagon will soon release a policy document explaining what cyberattacks it will consider acts of war meriting military response. Christoper Preble and I warn against this policy in an [op-ed](http://blogs.reuters.com/great-debate/2011/06/02/a-military-response-to-cyberattacks-is-preposterous/) up at *Reuters​.com*:

> The policy threatens to repeat the overreaction and needless conflict that plagued American foreign policy in the past decade. It builds on national hysteria about threats to cybersecurity, the latest bogeyman to justify our bloated national security state. A wiser approach would put the threat in context to calm public fears and avoid threats that diminish future flexibility.

*Reuters* headlined our piece: “A military response to cyberattacks is preposterous.” Actually, our claim is not that we should never use military means to respond to cyberattacks. Our point instead is that the vast majority of events given that name have nothing to do with national security. Most “cyberattackers” are criminals: thieves looking to steal credit card numbers or corporate data, extortionists threatening denial of service attacks, or vandals altering websites to grind personal or political axes. These acts require police, not aircraft carriers.

Even the cyberattacks that have affected our national security do not justify war, we argue. There is little evidence that online spying has ever done grievous harm to national security, [thinly sourced](http://www.slate.com/id/2216795/) [reports](http://online.wsj.com/article/SB124027491029837401.html) to the contrary notwithstanding. In any case, we do not threaten war in response to traditional espionage and should not do so merely because it occurs online.

Moreover, despite [panicked](http://www.wired.com/threatlevel/2010/04/cyberwar-richard-clarke/) [reports](../cyber-alarm/) claiming that hackers are poised to sabotage our “critical infrastructure” — downing planes, flooding dams, crippling Wall Street — hackers have accomplished nothing of the sort. We [prevent](http://www.bostonreview.net/BR34.4/morozov.php) these nightmares by decoupling the infrastructure management system from the public internet. But even these higher-end cyberattacks are only likely to damage commerce, not kill, so threatening to bomb in response to them seems belligerent.

The [Stuxnet](http://www.nytimes.com/2011/01/16/world/middleeast/16stuxnet.html) worm shows that cyberattacks may indeed do considerable harm, perhaps someday killing on a scale akin to small arms. Attacks like that might indeed merit military response. But they remain hypothetical here.

Vague terms like “cyberattack” and the alarmist rhetoric that surrounds them confuse common nuisance attacks with theoretical tragic ones. The danger is militarized responses to criminal acts, foolish regulation, wasteful spending, or even needless war.

To learn about the exaggeration of cyberthreats, read these [two](http://mercatus.org/publication/beyond-cyber-doom) [articles](http://mercatus.org/sites/default/files/publication/110421-cybersecurity.pdf) from the Mercatus Center. For a good discussion of the policy options for dealing with the various cyberharms, see this [2009 congressional testimony](https://www.cato.org/testimony/ct-jh-20090625.html) from Jim Harper.

##### Related Tags 

[Defense and Foreign Policy](https://www.cato.org/defense-foreign-policy) 

[![Creative Commons License](/build/cato_2020/images/creative-commons.svg)](http://creativecommons.org/licenses/by-nc-sa/4.0/) 
This work is licensed under a [Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License](https://creativecommons.org/licenses/by-nc-sa/4.0/).