Why the US can’t build a cyber grand strategy

Photo by Axel Houmadi on Unsplash Memorial World Trade Center, New York, United States

Memorial World Trade Center, New York, United States. Photo: Axel Houmadi/Unsplash

11 August 2026

In the weeks after the terrorist attacks of 11 September 2001, the United States remade its foreign policy almost overnight. Practices it had long pursued selectively were declared doctrine: preventive war, regime change, democracy promotion. It fought wars in Afghanistan and Iraq and reshaped its military and intelligence services for a generation

Yet this doctrine was not invented in those weeks. Preventive war and the ambition to maintain the US’ unchallengeable military position were first committed to paper in the 1992 Defense Planning Guidance, a decade before the attacks. What 9/11 supplied was not a new strategy but the speed and will to execute an existing one. 

In cyber, however, no attack has generated comparable urgency, and there is no settled doctrine waiting to meet one. What passes for strategy – wiping malware, imposing sanctions, even suing victims – is improvisation, a haphazard assemblage of tactics  scattered across agencies and dependent on a private sector that owns the terrain but has never been compelled into genuine partnership. 

The failures compound one another: responses disrupt tools, not incentives; the threat stays invisible to the public until the moment it is triggered; and deterrence (whose inadequacy after 9/11 was the very argument for acting preventively) is failing again in cyberspace. That is why America still has no coherent cyber strategy.

The wrong targets

In 2024, US officials disclosed that Volt Typhoon, a Chinese military cyber unit, had spent years planting digital booby traps across American manufacturing, utilities, and transportation. The aim is not to spy, but to detonate them in a future confrontation, likely one relating to Taiwan. 

Washington reached for a lever it rarely uses: a court-authorised FBI operation to wipe the group’s botnet malware from hundreds of routers. Within weeks, the botnet had been rebuilt on new hardware. No one has faced sanctions or charges for the intrusion itself. The operation disrupted the tool, not the actor.

The recurring failure is not the absence of a response, but the gap between disrupting an attack and making anyone pay for it. In 2020, after Russian intelligence planted a backdoor in SolarWinds software reaching some 18,000 organisations, the US accused Moscow and answered with sanctions and expulsions. The same group was operating months later. One penalty targeted the victim: the Securities and Exchange Commission sued SolarWinds itself, unsuccessfully

When the 2021 Colonial Pipeline ransomware attack drained pumps across the Southeastern United States, the federal answer was to keep fuel moving and claw back part of the ransom, leaving the business model intact. 

Whether it wipes the tool, sanctions the actor, or sues a victim, each response is the work of a different agency, and none has successfully dissuaded the attacker; the sanctioned services kept operating, and the wiped botnet was rebuilt within weeks.

A new strategy, the same gap

The Trump administration’s March 2026 cyber strategy is unusually blunt about offensive capability, declaring that the US will ‘act swiftly, deliberately, and proactively to disable cyber threats’ and that responses will not be confined to the cyber domain. But its four pages of ‘we will’ statements contain little on resources, implementation, or even named adversaries. 

The deeper problem is legibility – how visibly a danger can be attributed, narrated, and rallied around. Volt Typhoon scores poorly on legibility, because there is nothing yet to point to. The implants sit dormant, ‘living off the land’ until a crisis arrives. There is no visible damage, only the prospect of harm, confirmed by intelligence rather than experienced.

Colonial Pipeline was the exception at the time: when pumps ran dry, an abstract risk briefly became tangible (notably, the company turned off the tap – they could technically have kept the gas flowing). 

The July 2026 attacks on more than 30 Minnesota water systems, part of activity reported across a dozen states, show that tangible disruption is no longer the exception. Attackers locked operators out of internet-exposed controls, disconnecting services and provoking boil-water notices, yet no attribution followed. CISA declined to name a culprit, some officials suspected Iran-linked hackers, and the US President declared Iran not responsible. Visible harm alone is no guarantee for strategy – with authorities unable or unwilling to declare a clear culprit, it is  difficult to create a narrative and response to rally around. 

Volt Typhoon deepens the problem further; it is engineered to cause disruption at scale, but only once triggered, providing the US with no warning at all.

Why deterrence keeps falling short

For a decade, US cyber deterrence rested on a logic borrowed from the nuclear era: mutually assured disruption. Beijing would not disable US infrastructure because Washington could do the same to China’s. Pre-positioning alone does not break that logic; the Cold War powers deployed missiles to each other’s doorsteps precisely to make the mutual threat credible. 

But a deterrent has to be seen to deter. Volt Typhoon was built in secret, discovered rather than declared, and denied even after Washington raised it directly with Beijing. A capability hidden inside civilian infrastructure is not a signal; it is preparation. China, by acting as though it plans to use these disruptive abilities rather than advertising them, raises doubts about mutually assured disruption.

The fallback, ‘deterrence by denial’ (hardening networks until intrusion ceases to pay) has been pushed past its limits. A cyberattack differs from a physical one in that failure costs the attacker almost nothing, and a successful defence often reveals how the target is protected. 

The alternative, pairing denial with accountability, fares no better. In April 2024, US officials raised the topic of Volt Typhoon with Beijing, which denied involvement. No sanctions or indictments followed. With no completed act to attach consequences to, accountability is challenging.

Resilience as the fallback

If deterrence is structurally elusive, perhaps imposing costs on the attacker is the wrong measure of success. Many strategists make the case for resilience as the grand strategy itself; since no defence is perfect, the priority shifts to absorbing disruption and recovering quickly, denying the rival any payoff. 

Beijing’s implants are only worth something if disrupting US infrastructure would change Washington’s decisions in a Taiwan crisis. A resilient United States makes the investment less useful. Resilience is a form of deterrence that requires no retaliation at all.

Yet resilience is not a policy the federal government can enact alone. The infrastructure Volt Typhoon has seeded is overwhelmingly privately owned and operated. A strategy of absorption therefore depends on thousands of firms investing against a threat their customers cannot see and coordinating with  authorities divided among the FBI, CISA, the NSA, and sectoral regulators. The US has never compelled that sort of alignment in peacetime; the Defense Production Act, which lets Washington direct private industry, was born of the Korean War. Resilience thus inherits the same structural obstacles that defeat deterrence: fragmented authority and an unforced public-private compact.

Grand strategy was once formulated among governments and largely accepted by publics with limited access to unmediated information. Networked technology ended that deference, as officials have less and less control over accounts of events, and their claims now compete in real time with rival narratives online. 

The War on Terror was an easy sell – it was triggered by a wound the whole country had witnessed in real time. Taking dormant code in a power grid seriously, on the other hand, requires a great deal of convincing. Until the threat produces disruption more severe than a few low-pressure water taps, it asks a sceptical public to fear something based on an intelligence assessment alone. Further, trust in the federal government ‘to do what is right’, which surged to its highest level in decades in the weeks after 9/11, now sits near a seventy-year low.

The threshold question

What would it take to close the gap between the threat Volt Typhoon represents and the strategy the US has failed to produce? Perhaps only what everyone hopes to avoid: the disruption the implants were designed to deliver, in whatever form and at whatever moment Beijing chooses. But the lesson of 9/11 cuts against even that grim hope. The attacks produced sweeping strategic change because a doctrine already existed for the shock to activate. In cyber, no such doctrine exists. 

A catastrophe would supply urgency, but not the strategy, unified authorities, or public-private compact required to act; improvising all three mid-crisis is the worst conceivable way to acquire them. The alternative is the harder path the 2026 strategy gestures toward but does not take: building resilience, allocating resources, and forging government-industry alignment before the moment of need arrives. 

Declaring resolve is a beginning. Until it is matched by implementation, accountability, and a threat the public can see, adversaries who understand the distance between US ambitions and capacities will continue to exploit it.