iTnews
  • Home
  • News
  • Technology
  • Security

Militaries scramble for cyber skills

By Peter Apps, Political Risk Correspondent
Feb 13 2012 11:16AM
Follow google news

Nations recruit computer specialists for cyberwar era.

With growing worries about the threat of "cyber warfare", militaries around the world are racing to recruit the computer specialists they believe may be central to the conflicts of the 21st century.

Militaries scramble for cyber skills

But while money is plentiful for new forces of "cyber warriors", attracting often individualistic technical specialists and hackers into military hierarchies is another matter.

Finding the people to command them is also tough. After a decade of messy and relatively low-tech ground wars in Iraq and Afghanistan, some senior western officers are if anything less confident with technology such as smartphones and tablet computers than their civilian contemporaries.

But with the Pentagon saying its computers are being attacked millions of times every day, time is short.

"We are busy and we are getting busier every day," Lt Gen Rhett Hernandez, a former artillery officer who now heads US Cyber Command, told a cyber security conference in London last month organised by British firm Defence IQ.

"Cyberspace requires a world-class cyber warrior ... we must develop, recruit and retain in a different way to today."

Even in an era of shrinking western military budgets, funding for cyber security is ratcheting up fast. The Pentagon's 2012 budget allocated $US2.5 million ($A2.3 million) to improve cyber capabilities.

In December, the US Army announced its first "cyber brigade" was operational, whilst the US Navy and Air Force have their own cyber "fleets" and "wings".

Not only are they tasked with protecting key US military systems and networks, but they are also working to build offensive skills that US commanders hope will give them an edge in any future conflict.

These, insiders say, include developing the ability to hack and destroy industrial and military systems such as traffic and electricity controls.

"For better or worse, it is American military thought that is leading American societal thought (in) how to think about things cyber," former CIA director and Air Force Gen Michael Hayden told a security conference in Munich this month.

European, Latin American, Asian and Middle Eastern and other nations are seen following suit. Militaries had barely considered the Internet only a few years ago are building new centres and training hundreds or even thousands of uniformed personnel.

Russia and China are believed to put even greater emphasis on a field in which they hope to counter the conventional military dominance of the US.

In Australia, the Defence Signals Directorate has established a cyber operations arm to digitally pursue the directorate's mantra: "

But some worry much investment may be wasted.

"My theory is that huge defence agencies - having little clue of what cyber warfare is all about - follow traditional approaches and try to train as many hacking skills as possible," says Ralph Langner, the civilian German cyber security expert who first identified the Stuxnet computer worm in 2010.

"(The) idea could be to demonstrate hypothetical cyber power by sheer numbers, i.e. headcount."

Spy agencies better?

Many experts say the key to successful operations in cyberspace - such as the Stuxnet attack believed to have targeted Iran's nuclear program by reprogramming centrifuges to destroy themselves - is quality rather than quantity of technical specialists.

"Only a very small number of people are the top notch that you would want to employ for a high-profile operation like Stuxnet," says Langner, saying that there might be as few as 10 world-class cyber specialists. "These people will probably not be covered with a military environment."

Commanders say they are trying to change that, relaxing rules on issues such as hair length or fitness. But there are limits on how far such loosening can go.

While the US Air Force and Navy have significantly eased entry requirements for cyber specialists and removed some of the more arduous elements from basic training, the US Army still requires its "cyber warriors" to endure regular basic training.

Speaking on condition of anonymity, one senior European officer with responsibility for cyber complained of struggling to find suitable recruits in part because of competition from the private sector.

Agencies such as the US National Security Agency and Britain's GCHQ say they lose some of their best talent to Microsoft and Google.

But such agencies also pride themselves on their ability to find and retain the kind of eccentric expertise that would struggle to find their place in armies, navies, air forces or regular government departments.

"Higher end capability isn't principally about spending large amounts of money and having large numbers of people," says John Bassett, a former senior GCHQ official and now senior fellow at London's Royal United Services Institute.

"It's about having a small but sustainable number of very good people with imagination and will as well a technical know-how and we may be more likely to find them in an organisation like GCHQ than in the military."

Just another form of warfare

Many experts say offensive cyber warfare capability - particularly anything potentially lethal such as the ability to paralyse essential networks - should be kept in the hands of the directly accountable military, not shadowy spy agencies.

But most suspect the NSA, GCHQ and similar organisations will retain a considerable lead in technology and sophistication over their military counterparts.

The U.S. NSA and military Cyber Command are both located at Fort Meade outside Washington DC, and intelligence experts say working closely together is already the norm - with the former providing much support and expertise to the latter.

Some other countries now appear keen to avoid ploughing too much money into uniformed military cyber specialists at all.

Britain's Royal Corps of Signals and Royal Air Force in particular have been keen to get their hands on a share of Britain's newly expanded £650 million ($A960 million) cyber budget, but much of it is seen going straight to GCHQ.

What militaries in general and top commanders in particular need to focus on most, specialists argue, is learning to integrate the new tools and threats into their broader conflict-related understanding and training.

At the US Naval War College in Rhode Island, mid-career military officers conducting "wargaming" exercises are now regularly confronted with the new cyber dimension. Systems malfunction, supply chains are attacked, and information corrupted or deleted.

Israel's raid on a suspected Syrian nuclear weapons site in 2007, when a cyber attack was believed used to disable Syria's air defence radar, is seen a guide of how cyber can work alongside more conventional military operations.

"It's a new form of warfare and it has to be appreciated, just as in the past you had new developments - siege warfare, trench warfare and air warfare" says Dick Crowell, associate professor of military operations at the college.

Understanding of cyber warfare in military circles is roughly analogous to the understanding of air power in the 1930s, he said, clearly important in any future conflict, but with the shape of its role still largely unclear.

In new conflicts, those in charge may need to learn on their feet.

"What's really important is that you have senior commanders - three and four-star (general) level - who have a good enough understanding of it is to be able to integrate cyber into wider military campaigns," says former GCHQ official Bassett.

"Cyber fits into the wider picture of warfare now, and they have to understand that."

(Additional reporting by William Maclean in Munich; editing by Andrew Roche)

Add iTnews as your trusted source

Add iTnews As Your Trusted Source Add iTnews As Your Trusted Source
Got a news tip for our journalists? Share it with us anonymously here.
Copyright Reuters
© 2019 Thomson Reuters. Click for Restrictions.
Tags:
defencesecurity

Related Articles

  • Anthropic pulls Mythos-class models globally Anthropic pulls Mythos-class models globally
  • AudiA6 crypto launderers arrested, network taken down by police AudiA6 crypto launderers arrested, network taken down by police
  • US charges suspected Russian hacker with facilitating cyber campaign US charges suspected Russian hacker with facilitating cyber campaign
  • Gov looks for upstream threat blocking by telcos, cloud operators Gov looks for upstream threat blocking by telcos, cloud operators
Join our WhatsApp Channel

Partner Content

AI is delivering business value today
Partner Content AI is delivering business value today
You meet the security standard. Shame no one can see it
Promoted Content You meet the security standard. Shame no one can see it
Agile isn’t the problem: why projects still fail, and what’s missing
Partner Content Agile isn’t the problem: why projects still fail, and what’s missing
Scalable AI solutions: secure delivery
Scalable AI solutions: secure delivery

Sponsored Whitepapers

Are Australian organisations as cyber-ready as they think?
Are Australian organisations as cyber-ready as they think?
Are New Zealand organisations as cyber-ready as they think?
Are New Zealand organisations as cyber-ready as they think?
From visibility to execution:  Fixing the SaaS management gap
From visibility to execution: Fixing the SaaS management gap
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
Agile in the AI Era: why projects still fail
Agile in the AI Era: why projects still fail

Events

  • iTnews State of Security Breakfast iTnews State of Security Breakfast
  • iTnews State of Data & AI Breakfast iTnews State of Data & AI Breakfast
  • Forrester's AI Forum Sydney Forrester's AI Forum Sydney
  • The 2026 iAwards The 2026 iAwards
  • Security Exhibition & Conference Security Exhibition & Conference
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Anthropic releases Mythos-class model for public use

Anthropic releases Mythos-class model for public use

Apple bumps up security in fresh operating system releases

Apple bumps up security in fresh operating system releases

Anthropic opens Claude Mythos Preview AI program to Australia

Anthropic opens Claude Mythos Preview AI program to Australia

techpartner.news logo
Sydney-based AI-cloud waste startup raises $3m
Sydney-based AI-cloud waste startup raises $3m
Brennan uses NiCE to modernise its contact centre
Brennan uses NiCE to modernise its contact centre
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Interactive introduces private cloud platform
Interactive introduces private cloud platform
Digital61 expands cybersecurity portfolio
Digital61 expands cybersecurity portfolio
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.