EXERCISE OBJECTIVES AND TRAINING AUDIENCE
Figure 3: Illustration of the whole-of nation approach.
To demonstrate the point, the following is
presented as an example of an incident which
escalates and impacts various domains.
„Several regions across country X suffer power
outages. These outages affect several major
industrial areas and even a military base
experiences a partial power outage. Due to
unexpected technical difficulties, back-up
generators are unable to begin providing the
military facility with electricity directly after the
blackout occurs. Best estimates suggest that
recovery will take at least 10 hours. The current
situation affects the everyday life of country X’s
population. The mood worsens as the blackout
leaves millions of people without electricity.
The outages induce public unrest, with protests
in the streets. According to investigators, the
loss of functionality was caused by a malware
attack that might have been conducted by a
group of attackers linked to a nation state.“
Domains that might be affected by such an
incident (the following questions can also steer
the process of formulating the exercise
objectives):
GOVERNMENT – The government faces a
crisis with a national impact, due to the limited
distribution of energy and outages.
What governmental department should
be the lead in dealing with this situation to
coordinate the responses of multiple
governmental entities?
Is there an option to legally and
operationally prioritize electricity supply to
critical services such as military and
national security installations, healthcare
systems and emergency services?
Are necessary policies, personnel, and
recovery plans in place for large scale
cyberattacks that affect the whole
population?
MILITARY – Since there are partial electricity
shortages at the military base, military
capability is affected as well.
Would a cyberattack on the electricity grid
be considered legitimate grounds for use
of force it such an attack compromises the
defensive capacities of the state? On what
basis?
Is the military legally and operationally
able to conduct active defense operations
in peacetime conditions (according to
IHL)?
INTELLIGENCE – To defend against such an
attack, the role of cyber threat intelligence
analysts is critical.
Is the malfunction considered an intended
attack?
Are the attackers linked to a nation state?
How can the attack be attributed to the
attackers?
What else is known about the attackers
and their motivation?
Are tools in place to gain sufficient insight?
10/29