Visualização de leitura

Cyble and DRONA Launch New Push to Close India’s Cybersecurity Gap

Cyber Yodha Campaign

AHMEDABAD (INDIA) — Cyble, the global AI-native cybersecurity company, and DRONA Cyber Solutions, the Ahmedabad-headquartered security operations firm, have launched an AI-powered cyber defense initiative in Ahmedabad, combining threat intelligence, investigation and endpoint enforcement through a joint managed security model.

The AI-Powered Intelligence for Cyber Defense initiative was formally launched Tuesday at DRONA Cyber Solutions' Command and Control Centre, where the companies presented a live technical demonstration showing how an intrusion attempt can be detected, investigated and contained.

The launch comes as India faces a growing cybercrime burden. India recorded 28.15 lakh cybercrime cases in 2025, a 24 percent increase over the previous year, with reported losses reaching ₹22,495 crore. The government's 1930 cybercrime helpline received 32.4 million calls during the year. Of the complaints filed, 55,484 were converted into FIRs. AI-powered cyber defense While large enterprises and banks increasingly have dedicated security teams, budgets and incident response capabilities, many manufacturers, hospital chains, schools and mid-sized businesses, particularly across Tier-2 and Tier-3 cities, continue to operate without comparable security resources.

AI-Powered Cyber Defense Takes Center Stage in Ahmedabad

Rather than focusing solely on formal remarks, Cyble and DRONA used the launch to demonstrate the initiative through a live technical exercise for the media. The demonstration began with material recovered from infostealer logs circulating on a criminal forum, alongside a lookalike domain registered to impersonate a target organisation. Analysts traced the infrastructure, established a pattern of previous activity associated with the same actor and demonstrated the detection and containment of an intrusion attempt on an endpoint.

The final containment action was authorised by a human analyst rather than executed automatically. The demonstration brought together multiple capabilities. Cyble Vision provided the initial detection through continuous monitoring of criminal marketplaces and leak sites.

Cyble Hawk supported the investigative process and attribution, while Cyble Titan handled endpoint enforcement, using hardware-level integrity checks to support its assessment. DRONA analysts remained at the centre of the process, making decisions that the system was deliberately not permitted to make independently. Cybersecurity Collaboration Mandar Patil, Executive Vice President at Cyble, said the initiative was designed to address a longstanding gap between threat detection and action for mid-sized businesses.
"India is not short of alerts. It is short of what happens next," Patil said. "We have spent a long time in this industry watching mid-sized businesses get told about a threat and then having nowhere to take that information. What we are launching today is not another alert. It is a complete chain — intelligence before the attack, investigation that would stand up to scrutiny, enforcement on the device, and a person accountable for the decision at the end of it."
Dhruv Pandit, Co-Founder and CEO of DRONA Cyber Solutions, said the initiative reflects the operational needs of organisations that require immediate action rather than another security dashboard.
"A factory owner calling us at two in the morning does not want to be shown a dashboard," Pandit said. "He wants to know what happened, he wants it contained, and he wants someone to take responsibility for what happens next."

From the Command Centre to Gujarat University, India

The Gujarat University engagement was not simply a conventional cybersecurity student session. It was a technical session titled “Kavach: Beyond the Surface — Threat Intelligence from the Dark Web Depths,” hosted by the Department of Biochemistry and Forensic Science, Gujarat University, in collaboration with Cyble.

The session brought together speakers from Cyble and DRONA Cyber Solutions to examine areas including dark web threat intelligence, government and PSU cybersecurity projects, digital forensics and incident response (DFIR), and the transition of threat intelligence from information to action.

Mandar Patil and Augustin Kurian of Cyble discussed the dark web threat intelligence landscape. Prathmesh Pawar spoke about government and PSU cybersecurity projects, while Brijesh Kapadiya addressed DFIR and Vijay Mali discussed moving threat intelligence from information to action. The keynote was delivered by Prof. Dr. Kapil Kumar, Coordinator, Department of Biochemistry and Forensic Science. AI-powered cyber defense

The session highlighted several practical aspects of cybersecurity work. The dark web was discussed not simply as a hidden part of the internet, but as a structured ecosystem requiring dedicated intelligence-gathering and threat-discovery methods. DFIR was presented as an area where speed and process are as important as technical expertise.

Another key takeaway was the importance of turning threat intelligence into action. Rather than treating intelligence as information alone, the session focused on how it can inform practical security decisions.

Patil told students that the cybersecurity industry faces a shortage of professionals with practical skills in analysing and validating threat intelligence.
"The gap this industry has is not a gap of ideas. It is a gap of people who know how to do the work," Patil said. "What separates a useful analyst from an alert-reader is the ability to ask whether a piece of intelligence is actually true before you act on it."
Augustin Kurian, Editor-in-Chief of The Cyber Express, told students that threat intelligence and journalism share an emphasis on verification.
Every story we publish about a breach, a ransomware group or a leaked database starts exactly where today's demonstration started — with intelligence somebody had to go and find, verify, and decide was worth acting on," Kurian said. The instinct we have tried to build at The Cyber Express is the same instinct a good analyst needs: do not report, and do not act on, what you have not verified.
The programme also involved technical and production teams supporting the session. Screen, sound and lighting were handled by the technical team under the guidance and supervision of Aditya More, while Misha Alagiya, Kavya Maharaja, Pathak Ami, Omi and Nandini supported stage management and photography.

A Broader Cybersecurity Collaboration

Both companies emphasised that the partnership is not intended to represent a single solution to India's cybersecurity deficit. Cyble and DRONA maintain relationships with other partners, service providers and government bodies.
"India's exposure is too large for any single partnership to take credit for solving," Patil said. "What matters is whether more of these collaborations exist a year from now, and whether the businesses we are talking about today — the ones without a security team — actually have somewhere to turn."

The AI-Powered Intelligence for Cyber Defense initiative will be delivered through DRONA's Ahmedabad command centre, with the companies indicating an intent to extend the service model to customers elsewhere in India over time.

The initiative also folds into DRONA's existing Cyber Yodha Campaign, a national programme aimed at building 50 integrated cybersecurity command centre labs and training more than 100,000 defenders.

US Telecom Giants Launch Private ISAC to Counter AI-Powered Cyberattacks

private ISAC

The U.S. telecom sector is strengthening its cybersecurity coordination efforts with the launch of a new private ISAC designed to help major communications companies respond more effectively to AI-powered cyberattacks, state-backed espionage campaigns, and emerging threats targeting national communications infrastructure.  The Communications Cybersecurity Information Sharing and Analysis Center, known as the C2 ISAC, was created by some of the country’s largest telecommunications providers to establish a more confidential environment for exchanging cybersecurity intelligence. The founding members include AT&T, Charter, Comcast, Cox, Lumen, T-Mobile, Verizon, and Zayo. The chief information security officers from these companies will serve on the organization’s board.  The newly formed private ISAC will be led by Valerie Moon, a former senior official with both the Cybersecurity and Infrastructure Security Agency (CISA) and the FBI’s Cyber Division, who has been appointed executive director.  According to Mark Clancy, chief security officer at T-Mobile and a board member of the C2 ISAC, the evolving threat landscape was a major factor behind the creation of the private ISAC.  “The main driver for us is our recognition that the threat environment has evolved, and we as a sector and private entities need to evolve and really keep up with the pace and velocity [at which] that’s happening,” Clancy said in an interview with Cybersecurity Dive.  Clancy explained that telecom companies recognized the need for more direct collaboration during the industry’s response to Salt Typhoon. “The need for us to collaborate on a private-to-private basis really became amplified,” he added. 

Telecom Sector Pushes for Faster Intelligence

Although the telecom sector already participates in information-sharing initiatives through the Communications ISAC, also referred to as the National Coordinating Center for Communications, that organization differs from most ISACs because it operates within the federal government under CISA rather than as an independent private entity.  According to Clancy, that government affiliation created hesitation among some telecom companies when it came to sharing sensitive cybersecurity intelligence.  “There’s been concerns and hesitations about it,” he said.  The new private ISAC aims to address those concerns by limiting participation to industry members and excluding government agencies from its internal discussion channels. Organizers believe this structure will encourage companies to exchange threat intelligence more openly and at earlier stages of investigations.  “When you have public-sector entities involved, there’s more review and deliberation about what gets put into that channel,” Clancy explained, adding that the new arrangement allows companies to be “a little more raw and early in sharing information.”  Over time, telecom providers realized they had become overly cautious in the information they shared through the existing Communications ISAC. Clancy acknowledged that companies often withheld lower-level threat indicators that later turned out to be connected to broader malicious campaigns.  “We were being too restrictive in what we were sharing,” he said, noting that some seemingly isolated activities were “actually tethered to bigger activity.”  Moon emphasized that the private ISAC is not intended to replace the existing Communications ISAC. Instead, both organizations are expected to operate alongside each other, with the older structure continuing to focus on broader operational concerns such as physical infrastructure threats.  “We really see this as a complementary effort,” Moon said. “When you think about each of these companies and their adherence to ensuring that the privacy of their data is very much at the forefront of their minds, they see this as a trusted space.” 

Private ISAC May Expand Beyond Threat Sharing

Information-sharing efforts within the telecom sector have already proven valuable in combating cybercrime and network abuse. One example involved the detection of SIM boxes — devices commonly used by cybercriminals to generate large volumes of difficult-to-block spam calls and text messages.  After T-Mobile identified indicators connected to SIM box activity, the company shared those findings with other telecom providers, enabling them to locate and block similar operations on their own networks.  Clancy noted that addressing such threats requires coordinated action because malicious infrastructure often spans multiple providers. “In order to figure out what’s happening, you’ve got to look at both sides,” he said.  Beyond direct threat intelligence, telecom companies have also exchanged operational strategies and defensive techniques through existing partnerships. Clancy recalled learning an effective method for handling residential proxy networks from another telecom operator.  “I learned a technique for dealing with some of the residential proxy networks from another operator that was really clever,” he said. “And I’m, like, ‘Yeah, we’re going to go do that.’”  While the immediate focus of the private ISAC is improving information sharing related to AI-powered cyberattacks and network threats, its leaders are also considering broader future capabilities. Clancy suggested the group could eventually develop shared automation platforms and collaborative technologies that would be easier to coordinate privately than through government-led regulatory frameworks.  The organization may also explore involvement in coordinated cybersecurity operations such as botnet disruptions, though Moon said those discussions are still in early stages.  “It just depends on what the operation is and where the authorities lie and what we are trying to accomplish,” she said.  Moon described the private ISAC as being “in its nascent stages,” adding that several long-term objectives remain under discussion.  Membership expansion is another unresolved issue. Although the current founding members represent some of the largest companies in the telecom sector, Clancy acknowledged that broader participation will be necessary for maximum effectiveness.  “There are more than eight companies in the communications sector, and so we won’t be fully effective until we increase that membership base,” he said.  The launch of the private ISAC also coincides with significant uncertainty surrounding federal cybersecurity programs. Budget reductions, staffing cuts, and shifting priorities across government agencies have forced many private-sector organizations to reconsider how they coordinate cybersecurity defense efforts.  “Obviously, what’s happening in the public sector informs what we need to do,” Clancy said, referencing challenges involving government funding, agencies, and legislative processes.  He also encouraged the Department of Homeland Security to accelerate efforts to replace the now-defunct Critical Infrastructure Partnership Advisory Council framework, which previously supported confidential discussions between industry and government stakeholders. Despite operating independently, the private ISAC still plans to maintain communication with federal agencies. According to Clancy, the group intends to share relevant intelligence either directly with government partners or through the existing Communications ISAC framework. “We could have a more freewheeling private-to-private conversation [and] we could distill the useful, important bits and push them … over to the government side,” he said.

OpenAI Introduces AI Security Platform as Cyber Defense Race Heats Up

OpenAI Daybreak

OpenAI has officially entered the AI cybersecurity race with the launch of OpenAI Daybreak, a new initiative focused on helping security teams identify, validate, and fix software vulnerabilities faster using artificial intelligence. Announced through the company’s LinkedIn post, OpenAI described Daybreak as its vision for “a new era of cyber defense,” where AI systems can assist defenders across secure code reviews, vulnerability analysis, remediation, and threat investigation workflows. The launch reflects a growing industry trend in which AI companies are positioning advanced language models as cybersecurity tools capable of reducing the time between vulnerability discovery and remediation. While AI-generated coding tools have often raised concerns around insecure code generation, companies are now increasingly focusing on using AI defensively to strengthen software security practices. According to OpenAI, AI models are already changing how security teams operate by enabling them to reason across large codebases, identify subtle vulnerabilities, validate fixes, and analyze unfamiliar systems more efficiently. However, the company also acknowledged that advanced AI cybersecurity capabilities require “trust, verification, safeguards, and accountability,” particularly as AI systems become more capable of handling sensitive defensive workflows.

What Is OpenAI Daybreak?

At the center of the announcement is OpenAI Daybreak, a cybersecurity-focused platform powered by GPT-5.5 and Codex, OpenAI’s coding-focused agentic system. OpenAI said the platform is designed to help organizations move from vulnerability discovery to remediation faster while improving visibility into the entire security workflow. The system combines AI reasoning with coding automation to support several defensive security functions, including:
  • Secure code reviews
  • Threat modeling
  • Patch validation
  • Malware analysis
  • Dependency risk analysis
  • Remediation guidance
  • Vulnerability triage
  • Detection engineering
One of the more notable capabilities highlighted by OpenAI is the platform’s ability to generate and test patches directly within repositories. According to the company, these workflows operate under monitored and controlled access models while also producing audit-ready reports that help security teams verify remediation activity. The emphasis on auditability suggests OpenAI is attempting to address one of the biggest concerns surrounding AI in cybersecurity: the need for accountability and human oversight in automated decision-making.

OpenAI Introduces Tiered Cybersecurity Access

OpenAI is rolling out Daybreak through three different access levels depending on the sensitivity and complexity of cybersecurity operations. The first layer uses GPT-5.5 for broader security assistance and general workflows. The second tier, GPT-5.5 with Trusted Access for Cyber, is aimed at defensive cybersecurity tasks such as secure code review, malware analysis, vulnerability triage, detection engineering, and patch validation. The highest tier is powered by GPT-5.5-Cyber, which OpenAI says is intended for specialised and authorised workflows including penetration testing, red teaming, and controlled validation exercises. The structured access model indicates OpenAI is taking a cautious approach toward releasing advanced cyber capabilities, especially as concerns grow around dual-use AI systems that can potentially be misused by threat actors.

AI Cybersecurity Competition Continues to Grow

The launch of OpenAI Daybreak also comes at a time when AI companies are increasingly competing to establish themselves in cybersecurity operations. Recently, Anthropic introduced Claude Mythos, a cybersecurity-focused AI system that the company claimed could identify software vulnerabilities at a scale beyond what human experts can typically achieve. However, Anthropic stated that Claude Mythos would not be released publicly due to risks associated with its advanced cyber capabilities. That contrast highlights a broader debate currently shaping the AI cybersecurity sector. While companies see AI as a major force multiplier for defenders, there are ongoing concerns about how powerful cyber-focused AI models should be deployed, monitored, and restricted. For OpenAI, Daybreak appears to position the company toward enterprise-controlled and monitored security environments rather than open public access.

AI’s Role in Cyber Defense Is Expanding

The launch of OpenAI Daybreak reflects how rapidly AI is becoming embedded into cybersecurity workflows. Security teams are increasingly under pressure to manage growing attack surfaces, software complexity, and faster-moving threats, making automation and AI-assisted analysis more attractive. At the same time, the rollout of advanced cyber-focused AI systems is likely to intensify discussions around governance, oversight, and responsible deployment. With companies like OpenAI and Anthropic now building specialised cybersecurity AI platforms, the next phase of cyber defense may increasingly depend on how effectively organizations balance AI-driven speed with security safeguards and human verification.

Why Traditional Security Tools Fail-and How Unified AI Platforms Solve the Problem

When More Tools Create More Problems For years, organizations have approached cybersecurity with a simple mindset-add more tools to strengthen defenses. Firewalls, endpoint solutions, intrusion detection systems, and monitoring platforms have all been layered together to create what appears to be a comprehensive security posture. Yet, despite this growing investment, security outcomes have not improved

The post Why Traditional Security Tools Fail-and How Unified AI Platforms Solve the Problem appeared first on Seceon Inc.

The post Why Traditional Security Tools Fail-and How Unified AI Platforms Solve the Problem appeared first on Security Boulevard.

Kuwait Banks Deploy Real-Time War Room to Fight Growing Cyber Fraud Threats

Kuwait cyber fraud threats

Kuwait’s banking sector is strengthening its defenses against rising Kuwait cyber fraud threats with the deployment of an advanced virtual operations system designed to detect and respond to financial crimes in real time. The initiative, led by the Kuwait Banking Association, comes under the direction of the Central Bank of Kuwait as part of a broader effort to counter increasing fraud targeting bank customers.

Virtual War Room Enhances Financial Cybercrime Response

Officials say the newly enhanced platform, often described as a virtual war room banking system, has evolved into a centralized national mechanism to tackle Kuwait cyber fraud threats more effectively. According to Abdulwahab Al-Duaij, head of the Anti-Fraud Committee at the association, the system enables banks and authorities to act quickly when fraud is detected. It connects directly with government bodies, including the Ministry of Interior and the Public Prosecution, allowing coordinated action without delays. This level of integration is seen as a critical step in addressing financial cybercrime Kuwait, where speed often determines whether stolen funds can be recovered.

Real-Time Action to Stop Fraudulent Transactions

One of the key features of the system is its ability to respond immediately to incidents. Once suspicious activity is identified, the platform allows authorities to halt transactions, trace the movement of funds, and begin legal proceedings. This rapid response capability is central to tackling Kuwait cyber fraud threats, which increasingly involve fast-moving digital transactions that can be difficult to track after the fact. Officials say the banking fraud detection system has already improved the efficiency of handling fraud cases, reducing response times and limiting financial losses for customers.

Shift From Reactive to Proactive Monitoring

The upgraded system marks a shift in how Kuwait cyber fraud threats are managed. Instead of reacting only after fraud occurs, the platform now actively monitors patterns and emerging tactics used by attackers. Authorities have identified a range of common scams, including fake bank communications, fraudulent links requesting data updates, misleading advertisements, and false prize claims. These tactics are designed to trick users into sharing sensitive information. By tracking these patterns, the system aims to detect suspicious activity earlier and prevent fraud attempts before they succeed.

Coordination Strengthens National Cyber Defense

The collaboration between banks, law enforcement, and regulatory bodies is a key part of the strategy. Officials say this coordinated approach improves visibility into threats and ensures that responses are aligned across institutions. As Kuwait cyber fraud threats continue to evolve, such coordination is becoming increasingly important. Financial fraud is no longer limited to isolated incidents but often involves organized networks using multiple channels to target victims. The virtual chamber serves as a central hub where information can be shared quickly, enabling faster and more informed decision-making.

Customers Urged to Stay Vigilant

While the system strengthens institutional defenses, officials stress that customer awareness remains essential in reducing Kuwait cyber fraud threats. Users are being warned not to share banking details, passwords, or one-time codes under any circumstances. Banks have reiterated that they do not request such information through phone calls, text messages, or online links. Many recent fraud cases have relied on social engineering techniques, where attackers impersonate trusted entities to gain access to sensitive data.

Ongoing Efforts to Address Emerging Threats

The Kuwait Banking Association says the virtual system will continue to evolve as new fraud techniques emerge. The goal is to maintain a high level of readiness and ensure that financial institutions can respond effectively to changing risks. As digital banking adoption grows, Kuwait cyber fraud threats are expected to remain a key concern for both regulators and financial institutions. Strengthening detection systems and improving response coordination are likely to remain central to the country’s cybersecurity strategy. Officials say the focus will remain on protecting customer assets, maintaining trust in the banking system, and ensuring that fraud cases are addressed quickly within legal frameworks.

CISA on Life Support

The latest shutdown may be temporary, but the damage at CISA is not. Staffing cuts, stalled leadership and political crossfire have hollowed out what was once a bright spot in federal cybersecurity. When institutions built on trust and coordination lose people and mission clarity, the risks extend far beyond Washington.

The post CISA on Life Support appeared first on Security Boulevard.

Navigate EclecticIQ Threat Intelligence Platform like a pro with our new ‘Getting Started’ module.

Effectively navigating and utilizing a Threat Intelligence Platform (TIP) can feel complex, particularly for those doing so for the first time. From triaging alerts to investigating threats and producing finished intelligence, the variety of features and workflows can be daunting. That’s why we’ve introduced the “Getting Started" module - an intuitive guide designed to walk users through each step, ensuring that both newcomers and experienced professionals can maximize the platform's capabilities with ease and efficiency. 

Taking the fight to the enemy: Cyber persistence strategy gains momentum

The nature of cyber warfare has evolved rapidly over the last decade, forcing the world’s governments and industries to reimagine their cybersecurity strategies. While deterrence and reactive defenses once dominated the conversation, the emergence of cyber persistence — actively hunting down threats before they materialize — has become the new frontier. This shift, spearheaded by the United States and rapidly adopted by its allies, highlights the realization that defense alone is no longer enough to secure cyberspace.

The momentum behind this proactive cyber strategy can be found in America’s Defend Forward initiative, the rise of cyber persistence among U.S. allies and the successful takedowns of infamous groups like LockBit ransomware. Meanwhile, the broader implications of this shift are revealed in the U.S. Department of State’s focus on digital solidarity in contrast to digital sovereignty.

Cyber persistence: A strategic pivot

The idea of cyber persistence, as opposed to cyber deterrence, is reshaping global cybersecurity efforts. Traditional deterrence theory, which aims to dissuade adversaries through the promise of retaliation, has failed to address the complexities of cyber criminal behavior. Malicious cyber actors, including state-sponsored entities and organized crime groups, continue to exploit vulnerabilities, which leads to critical infrastructure compromise, sensitive data theft and government or corporate network disruption.

In response, the U.S. Department of Defense 2023 Cyber Strategy reinforced the country’s commitment to “Defend Forward,” a proactive approach designed to directly disrupt adversaries’ operations. This strategy empowers cybersecurity forces to identify malicious activities before they escalate, track adversaries and take action to prevent or mitigate attacks. U.S. allies like the United Kingdom, Japan, Canada and the Netherlands have subsequently adopted similar strategies. They’ve all come to realize that cyberspace requires constant vigilance and operational persistence to stay ahead of evolving threats.

As the U.S. DoD outlines, engaging adversaries early in planning is essential to creating a more secure cyberspace. This involves tracking the capabilities and intentions of malicious actors and degrading their ability to act. Such a proactive stance requires cooperation, coordination and trust among allies. This is especially true since cyber campaigns often involve joint operations where one nation may invite another into its networks to assist in defense.

The shift from deterrence to persistent engagement

Increasingly, nations like the UK and the Netherlands are taking proactive measures to combat cyber threats by operationalizing cyber persistence. For example, the UK’s National Cyber Strategy highlights the importance of actively tackling adversaries’ cyber dependencies and emphasizing the need for persistent engagement in cyberspace. Further examples of this shift include Japan’s efforts to introduce active cyber defense and Canada’s participation in “Hunt Forward” operations. Both aim to actively search for and disarm malicious actors.

NATO has also acknowledged the necessity of a more proactive cyber stance. The 2022 NATO Strategic Concept recognizes that cyberspace is “contested at all times.” The document explicitly states that the cumulative effect of cyber activities could reach the level of an armed attack, potentially triggering NATO’s mutual defense obligations under Article 5. This signals the acceptance of cyber persistence as a critical aspect of national and collective security.

While deterrence remains a core strategy for nuclear and conventional warfare, it is becoming clear that in cyberspace, persistence — constantly identifying, mitigating and neutralizing threats — is critical to preventing large-scale cyber incidents.

Explore IBM X-Force Red offensive security services

The LockBit ransomware takedown: A case study in persistence

The February 2024 takedown of the LockBit ransomware group under Operation Cronos serves as a prime example of how persistent cyber strategies can effectively neutralize significant threats. LockBit, one of the most prolific Ransomware-as-a-Service (RaaS) groups, was responsible for approximately a quarter of all ransomware attacks in 2023. This included attacks on hospitals and other critical services during the COVID-19 pandemic.

Operation Cronos, a coordinated international effort, resulted in significant arrests, sanctions and the seizure of LockBit’s operational infrastructure. This was not just a technical takedown but a broader effort to undermine the group’s viability. Law enforcement agencies managed to access LockBit’s internal communications, expose its affiliates and disrupt its financial networks. This cumulative disruption severely damaged the group’s reputation, making it difficult for them to regain support within the cyber crime community.

While LockBit’s ringleader, known as “LockBitSupp,” has tried to claim the group’s resurgence, analysis shows that the law enforcement operation has had lasting effects. The exposure of the group’s inner workings has sowed distrust among affiliates, with many distancing themselves from the group. The takedown’s success demonstrates the power of cyber persistence, as it involved not only technical measures but also strategic psychological operations aimed at eroding the group’s support base.

Digital solidarity vs. digital sovereignty

At the heart of the United States’ international cyber strategy lies the concept of digital solidarity, which stands in stark contrast to the protectionist policies of digital sovereignty. Digital solidarity promotes collaboration and mutual support among nations, emphasizing the need for a secure, inclusive and resilient digital ecosystem. This strategy, unveiled in the U.S. Department of State’s 2024 International Cyberspace and Digital Policy Strategy, advocates for building international coalitions, aligning regulatory frameworks and fostering a free flow of data across borders.

The key pillars of digital solidarity include promoting an inclusive digital ecosystem, aligning governance approaches to data and advancing responsible state behavior in cyberspace. These efforts aim to ensure that all nations, especially emerging economies, have access to secure digital infrastructure and that global cooperation can thwart cyber threats through shared intelligence and mutual defense efforts.

In contrast, digital sovereignty emphasizes national control over digital infrastructure and data. Countries that adopt this stance seek to protect their digital assets by restricting foreign access to their markets and mandating data localization. While proponents argue that this approach can reduce dependence on foreign technology and enhance security, critics warn that it fragments the global digital ecosystem and makes it harder to respond collectively to cyber threats.

The tension between digital solidarity and digital sovereignty has significant implications for global cybersecurity. As the world’s digital infrastructure becomes more interconnected, the U.S. and its allies argue that collaboration, not isolation, is the key to addressing the complex cyber challenges of the future.

The future of proactive cyber defense

The shift from deterrence to persistence in cyberspace represents a new era of proactive cyber defense. By identifying vulnerabilities, disrupting adversaries’ operations and engaging in continuous cyber campaigns, the U.S. and its allies are reshaping the way nations approach cybersecurity.

Operations like the LockBit takedown underscore the effectiveness of this strategy. Plus, the emphasis on digital solidarity highlights the importance of international cooperation in creating a safer and more resilient digital ecosystem. As cyber threats continue to evolve, the persistence approach will likely become a cornerstone of modern cybersecurity. The goal is to ensure that nations can stay ahead of their adversaries and secure the future of cyberspace.

The post Taking the fight to the enemy: Cyber persistence strategy gains momentum appeared first on Security Intelligence.

❌