The big idea: As societies run on digital systems, a new arena of conflict has opened up: cyber conflict.
What cyber conflict looks like
- States and non-state actors can attack each other's networks, steal data, disrupt infrastructure and spread chaos — often without firing a shot.
- Cyber blurs the line between war and peace.
The problem at its heart: One problem sits at its heart: the attribution problem — it is genuinely hard to prove who did it, which makes deterrence and response much harder.
- Cyber attack — hacking, data theft, disruption of systems.
- Cyber warfare — state-level cyber operations, e.g. sabotaging infrastructure or military systems.
- Critical infrastructure attacks — hitting power grids, hospitals, banks or elections.
- Non-state actors — criminal gangs (ransomware), hacktivists, and groups acting for or alongside states.
Traditional conflict
- Clear markers: a declaration, uniforms, borders crossed.
Cyber conflict
- None of these markers.
- Launched instantly from anywhere.
- Hides its origin.
- Causes serious harm — shutting off power, crippling hospitals, stealing secrets.
- Falls below the threshold of open war.
Cyber blurs war and peace: This 'grey zone' lets states pressure and damage each other without clear acts of war. It makes cyber a constant, ambiguous form of competition that is hard to deter, hard to answer, and hard even to define as war or peace.
Free preview
This is the free notes preview
You're reading the free notes. Aimnova Pro unlocks the full study experience — and you can try it with your first topic free to keep:
- FlashcardsLock in vocabulary and key terms with spaced repetition.
- Practice questionsAnswer exam-style questions and get instant AI marking.
- Mock exams & past-paper vaultSit full mocks and see exactly how examiners award marks.
- Personalised study planA daily plan built around your exam date and weak areas.
The attribution problem is what makes cyber conflict so distinctive. A victim may be fairly sure who did it but rarely able to prove it beyond doubt, which undermines deterrence and accountability.
How attackers hide
- They route through other countries.
- They disguise their identity.
- They use non-state proxies.
Why attribution is so hard
Cyber attackers hide their tracks: routing attacks through servers in other countries, disguising their tools, mimicking others' methods, and using criminal gangs or hacktivists as deniable proxies. So even when a victim strongly suspects a state, proving it to the standard needed for a public accusation or legal response is genuinely difficult.
Why it matters politically
Attribution matters because you cannot deter or punish an attacker you cannot name. If states can attack without being provably blamed, the usual logic of deterrence weakens, retaliation risks hitting the wrong target, and accountability collapses — so the attribution problem actively encourages cyber aggression and makes it hard to build clear rules.
Case study — an attack on critical infrastructure: Imagine a country's power grid or hospital network is knocked offline by a sophisticated cyber attack, causing real harm to civilians.
Why proof is elusive
Tracing
Investigators trace the tools and methods and become fairly confident a particular state was behind it.
Hiding
But the attack was routed through servers in several other countries and may have used a criminal group as a proxy.
No certainty
So certain proof is elusive.
Fairly sure is not proof.
The victim's dilemma: retaliate on strong suspicion
- Risk escalating with the wrong target.
Or hold back
- Let the aggression stand.
The HL lesson: Cyber conflict combines real, serious harm with deniability. So the attribution problem is not a technical footnote — it is the core reason cyber blurs war and peace and is so hard to govern.
The key point: Cyber conflict lets states and non-state actors attack networks and infrastructure — causing serious harm below the threshold of open war, blurring war and peace.
Why it is hard to govern
- The attribution problem — the difficulty of proving who did it — sits at its heart.
- It weakens deterrence, complicates retaliation, and undermines accountability.
- Non-state actors (criminals, hacktivists, proxies) add further ambiguity.
- That makes cyber a constant, hard-to-govern 'grey zone' of competition.
Practice with exam-style questions
Answer exam-style questions and get AI feedback that shows you exactly what examiners want to see in a full-marks response.
Is cyber conflict a genuinely new kind of warfare, or just old rivalry by new means? Can it be deterred and governed by rules — or does the attribution problem make that impossible? Weigh it — and recommend.
The case that cyber is a game-changer
Cyber conflict is genuinely new: it can cause serious harm — crippling infrastructure, stealing secrets, disrupting elections — instantly, from anywhere, and with deniability, blurring the line between war and peace in ways traditional conflict never did. The attribution problem removes the deterrence that keeps other aggression in check, so cyber is a distinctive and destabilising new domain.
The case that cyber is not so new
Others argue cyber is old wine in new bottles: states have always spied, sabotaged and coerced, and cyber is simply another instrument of the same rivalry, pursued by the same actors for the same aims. On this view, the domain is new but the logic of power and competition is not, and it can be managed like other threats through defence, deterrence and diplomacy.
One view: game-changing
- A new domain.
- Borderless, deniable and destabilising because of the attribution problem.
Another view: old rivalry by new means
- Manageable like other threats.
Two perspectives — weigh them: Strong HL answers judge that cyber is both. The underlying logic of power and competition is familiar, but the attribution problem and grey-zone character genuinely change the strategic picture — weakening deterrence and blurring war and peace.
What it needs: So it needs a mix of defence, deterrence, norms and diplomacy rather than either panic or complacency.
How cyber conflict comes up in Paper 3: Paper 3 stimulus might show a cyber attack on infrastructure, an election, or a company, with disputed responsibility.
Your three moves
Analyse attribution
Explain the attribution problem: it is hard to prove who did it.
Analyse war and peace
Show how cyber blurs war and peace.
Recommend
Usually strong defence PLUS deterrence, international norms and cooperation, given that attribution is hard.
How Paper 3 rewards you (HL)
Understand
Show you understand the challenge and the stimulus material accurately.
base
Analyse
Break the challenge down — causes, actors, perspectives — using the material.
analyse
Recommend
Propose and justify a course of action — the Paper-3-specific skill.
recommend
Synthesise
Pull the material together into a judged, evaluated response.
top
Recommend how the international community could reduce the dangers of cyber conflict.
Model answer plan
See the mark-by-mark plan — for / against / judgement, with marking guidance — in study mode.
Common mistakes (Paper 3): 1. Ignoring the attribution problem. It is the core of why cyber is hard.
2. Treating cyber as identical to conventional war. It blurs war and peace.
3. Forgetting non-state actors. Criminals and proxies matter.
4. Only describing attacks. Analyse + recommend.
5. Relying on one tool. Defence, deterrence, norms and cooperation together.