The big idea: As societies run on digital systems, a new arena of conflict has opened up: cyber conflict. States and non-state actors can attack each other's networks, steal data, disrupt infrastructure and spread chaos — often without firing a shot. Cyber blurs the line between war and peace, and one problem sits at its heart: the attribution problem — it is genuinely hard to prove who did it, which makes deterrence and response much harder.
- Cyber attack — hacking, data theft, disruption of systems.
- Cyber warfare — state-level cyber operations, e.g. sabotaging infrastructure or military systems.
- Critical infrastructure attacks — hitting power grids, hospitals, banks or elections.
- Non-state actors — criminal gangs (ransomware), hacktivists, and groups acting for or alongside states.
Cyber blurs war and peace: Traditional conflict has clear markers — a declaration, uniforms, borders crossed. Cyber conflict has none of these. Attacks can be launched instantly from anywhere, hide their origin, and cause serious harm — shutting off power, crippling hospitals, stealing secrets — while falling below the threshold of open war. This 'grey zone' lets states pressure and damage each other without clear acts of war, making cyber a constant, ambiguous form of competition that is hard to deter, hard to answer, and hard even to define as war or peace.
Free preview
This is the free notes preview
You're reading the free notes. Aimnova Pro unlocks the full study experience — and you can try it free for 7 days:
- FlashcardsLock in vocabulary and key terms with spaced repetition.
- Practice questionsAnswer exam-style questions and get instant AI marking.
- Mock exams & past-paper vaultSit full mocks and see exactly how examiners award marks.
- Personalised study planA daily plan built around your exam date and weak areas.
The attribution problem is what makes cyber conflict so distinctive. Attackers can route through other countries, disguise their identity, and use non-state proxies — so a victim may be fairly sure who did it but rarely able to prove it beyond doubt, which undermines deterrence and accountability.
Why attribution is so hard
Cyber attackers hide their tracks: routing attacks through servers in other countries, disguising their tools, mimicking others' methods, and using criminal gangs or hacktivists as deniable proxies. So even when a victim strongly suspects a state, proving it to the standard needed for a public accusation or legal response is genuinely difficult.
Why it matters politically
Attribution matters because you cannot deter or punish an attacker you cannot name. If states can attack without being provably blamed, the usual logic of deterrence weakens, retaliation risks hitting the wrong target, and accountability collapses — so the attribution problem actively encourages cyber aggression and makes it hard to build clear rules.
Case study — an attack on critical infrastructure: Imagine a country's power grid or hospital network is knocked offline by a sophisticated cyber attack, causing real harm to civilians. Investigators trace the tools and methods and become fairly confident a particular state was behind it — but the attack was routed through servers in several other countries and may have used a criminal group as a proxy, so certain proof is elusive. The victim faces a dilemma: retaliate on strong suspicion and risk escalating with the wrong target, or hold back and let the aggression stand. It captures the HL lesson: cyber conflict combines real, serious harm with deniability, so the attribution problem is not a technical footnote — it is the core reason cyber blurs war and peace and is so hard to govern.
The key point: Cyber conflict lets states and non-state actors attack networks and infrastructure — causing serious harm below the threshold of open war, blurring war and peace. The attribution problem — the difficulty of proving who did it — sits at its heart, weakening deterrence, complicating retaliation, and undermining accountability. Non-state actors (criminals, hacktivists, proxies) add further ambiguity, making cyber a constant, hard-to-govern 'grey zone' of competition.
Practice with real exam questions
Answer exam-style questions and get AI feedback that shows you exactly what examiners want to see in a full-marks response.
Is cyber conflict a genuinely new kind of warfare, or just old rivalry by new means? Can it be deterred and governed by rules — or does the attribution problem make that impossible? Weigh it — and recommend.
The case that cyber is a game-changer
Cyber conflict is genuinely new: it can cause serious harm — crippling infrastructure, stealing secrets, disrupting elections — instantly, from anywhere, and with deniability, blurring the line between war and peace in ways traditional conflict never did. The attribution problem removes the deterrence that keeps other aggression in check, so cyber is a distinctive and destabilising new domain.
The case that cyber is not so new
Others argue cyber is old wine in new bottles: states have always spied, sabotaged and coerced, and cyber is simply another instrument of the same rivalry, pursued by the same actors for the same aims. On this view, the domain is new but the logic of power and competition is not, and it can be managed like other threats through defence, deterrence and diplomacy.
Two perspectives — weigh them: One view: cyber conflict is a game-changing new domain — borderless, deniable and destabilising because of the attribution problem. Another: it is old rivalry by new means, manageable like other threats. Strong HL answers judge that cyber is both: the underlying logic of power and competition is familiar, but the attribution problem and grey-zone character genuinely change the strategic picture — weakening deterrence and blurring war and peace — so it needs a mix of defence, deterrence, norms and diplomacy rather than either panic or complacency.
How cyber conflict comes up in Paper 3: Paper 3 stimulus might show a cyber attack on infrastructure, an election, or a company, with disputed responsibility. Analyse the attribution problem and how cyber blurs war and peace, then recommend — usually strong defence PLUS deterrence, international norms and cooperation, given that attribution is hard.
How Paper 3 rewards you (HL)
Understand
Show you understand the challenge and the stimulus material accurately.
base
Analyse
Break the challenge down — causes, actors, perspectives — using the material.
analyse
Recommend
Propose and justify a course of action — the Paper-3-specific skill.
recommend
Synthesise
Pull the material together into a judged, evaluated response.
top
Recommend how the international community could reduce the dangers of cyber conflict.
Model answer plan
See the mark-by-mark plan — for / against / judgement, with marking guidance — in study mode.
Common mistakes (Paper 3): 1. Ignoring the attribution problem. It is the core of why cyber is hard.
2. Treating cyber as identical to conventional war. It blurs war and peace.
3. Forgetting non-state actors. Criminals and proxies matter.
4. Only describing attacks. Analyse + recommend.
5. Relying on one tool. Defence, deterrence, norms and cooperation together.