The Cyber Defense Review is an open-access, peer-reviewed, scholarly journal that serves as a forum for current and emerging research on cyber operations. Its focus is on strategy, operations, tactics, history, ethics, law, and policy in the cyber domain.

The Cyber Defense Review positions itself as a leading venue for interdisciplinary work at the intersection of cyber and defense, welcoming contributions from the military, industry, professional, and academic communities.

The journal is committed to publishing original, previously unpublished, and intellectually rigorous research that advances the body of knowledge in this rapidly evolving field. We invite timely and relevant submissions that reflect both theoretical insight and practical application, with the goal of informing cyber-related decision-making, operations, and scholarship.

The Cyber Defense Review (ISSN 2474-2120) is published quarterly by West Point Press and hosted by the Army Cyber Institute.

The Cyber Defense Review

The Battlefield is not ‘Over There’ – It is Here, 24/7

Lieutenant General Jeth B. Rey

A Conversation with the U.S. Army Chief Information Officer

Mr. Leonel Garciga,

interviewed by Deborah S. Karagosian

The Sword of Damocles: A Cybersecurity Paradigm Shift for the Defense of Critical Infrastructure

Scott C. Fogarty

Southeast Asia: Where Facebook is the Internet

Cadet Brandon Tran

Toward Clarity in Cyber’s “Fog of Law”
Prof. Scott Sullivan
Lights Out: What Hurricanes Reveal about Cyberattacks and Blackouts

Tom Johansmeyer

Fighting Through Disruption: Reframing Cyber Resilience for Power Projection and Strategic Credibility

Dr. Karen Guttieri

INTRODUCTION Forging the Future of Cyber Defense in an Era of Change and Uncertainty

The Sword of Damocles: A Cybersecurity Paradigm Shift for the Defense of Critical Infrastructure

THE CYBER DEFENSE REVIEW S. C. Fogarty 2025, VOL. 10, NO. 1, 29-39

PROFESSIONAL COMMENTARY

The Sword of Damocles: A Cybersecurity Paradigm Shift for the Defense of Critical Infrastructure

Scott C. Fogarty

Ridgeback Network Defense, Baltimore, MD, USA

The decentralized nature of U.S. critical infrastructure, while an engine and source of enormous societal wealth, creates significant vulnerabilities. Systems and their defenders are unknowingly operating underneath a modern Sword of Damocles—a constant and catastrophic threat of disruption from sophisticated and persistent adversaries. Drawing a parallel to the defensive failures of the October 7th Attacks, this article demonstrates how current cybersecurity strategies, heavily reliant on probabilistic, detect-and-respond tools, have proven insufficient to secure the complex Operational Technology (OT) systems and vast supply chains at the core of this infrastructure. This article argues that the fundamental asymmetry between attacker and defender can only be redressed by a new defensive paradigm. By integrating scalable, deterministic, and fact-based security methods with existing tools, defenders can enable automated, offense-for-defense capabilities. This approach, grounded in game theory, is the key to imposing tangible costs on adversaries in real time, finally allowing defenders to step out from under the sword and instead wield it.

Keywords: cybersecurity, critical infrastructure, operating technology, offense-for-defense, deterministic security, probabilistic security.

Disclaimer: The views expressed in this work are those of the author(s) and do not reflect the official policy or position of the United States Military Academy, the Department of the Army, or the Department of Defense. Corresponding author: scott@ridgebacknet.com

INTRODUCTION

More than our nation’s isolation by two massive oceans that have protected us since its birth, America’s greatest gift to its citizens is our constitutional republic — the system of government designed by our forebears to preserve individual freedom. These rights have underpinned the greatest system of free enterprise ever, delivering unprecedented levels of innovation, social progress, and wealth creation. In today’s tech-connected world, however, our freedoms and the thriving economy they have created are vulnerable and exposed...

SECURITY IMPLICATIONS OF DATA SCIENCE INNOVATION

Over the past 40 years, innovators have advanced cybersecurity tools and techniques from basic firewall and antivirus solutions to increasingly sophisticated and intelligent capabilities...

THE CHALLENGE OF SECURING CRITICAL INFRASTRUCTURE

Securing critical infrastructure effectively is a complex undertaking. While sources of vulnerability are innumerable, the challenge can be understood through three high-level, interconnected themes...

WIELDING THE LETHAL SWORD OF DEFENSE

The fundamental asymmetry between cyber attackers and defenders cannot be redressed as long as resources are allocated to reactive detect-and-respond strategies...

CONCLUSION

This strategic shift transforms the defensive cybersecurity paradigm into a true Sword of Damocles over the heads of attackers. No longer a passive observer, the defender now wields a real and ever-present threat. The adversary must operate knowing the defensive response is not a probabilistic maybe but a deterministic certainty, held only by the single, fragile thread of the attacker’s own behavioral choices...

REFERENCES

  1. App, Peter. 2023. "Hamas Assault on Israel shows Surprise Still Possible in AI Era." Reuters, October 9.
  2. Borgeaud, Alexandra. 2024. "Spending on Cybersecurity Worldwide from 2017 to 2024.” Stats, June 18.
  3. Carchidi, Vincent. 2023. “The October 7 Hamas Attack: An Israeli Overreliance on Technology?” Middle East Institute, October 23.
  4. Gady, Franz-Stefan. 2023. “Israel’s Military Tech Fetish is a Failed Strategy.” Foreign Policy, October 26.
  5. Gosselin-Malo, Elisabeth. 2023. “Hamas Drones Helped Catch Israel Off Guard, Experts Say.” C4ISRNET, October 18.
  6. Granados, Samuel, et al. 2023. “How Hamas Breached Israel’s ‘Iron Wall’.” The Washington Post, October 10.
  7. Heiser, Jay. 2023. “Stop Performing Cybersecurity Theater: It is No Longer Scaling,” Gartner, January 5.
  8. IBM Security. 2024. “Cost of a Data Breach Report.” IBM Corporation.
  9. ISACA. 2025. “Cybersecurity in 2025: AI powered Threats, Supply Chain Vulnerabilities, and Regulatory Pressures Take Center Stage.” ISACA, February 20.
  10. Nash, John. 1951. “Non-Cooperative Games.” Annals of Mathematics.