Cyber Espionage as Acceptable State Behavior: A Case Study
This qualitative case study examines the proposition that cyber espionage constitutes acceptable state behavior for intelligence gathering, even though it is a form of cyberattack generally regarded as unacceptable. Drawing on thematic analysis of existing scholarly and policy literature, the paper investigates how cyber espionage functions within modern cyber warfare, what norms international law has developed to govern it, and why nation-states such as the United States, China, and Russia continue to employ it. Three major themes emerge from the analysis: cyber espionage is a key component of cyber warfare, it provides a framework for appropriate countermeasures, and it enhances intelligence gathering capabilities. The study applies Just War Theory as its theoretical lens and identifies gaps in international legal frameworks that leave cyber espionage in a normative grey zone.
- Introduction: Background, problem statement, and research purpose
- Literature Review: Proliferation and Debates Around Cyber Espionage: Scholarly perspectives on cyber espionage acceptability
- Gap in Existing Literature and Theoretical Framework: Just War Theory applied to fill research gap
- Research Design and Methodology: Qualitative case study design and thematic analysis
- Analysis and Findings: Three themes justifying cyber espionage as state behavior
- Conclusion: Findings summary and future research recommendations
✍️ How to write this paper — guide, tools & examples ▾
What makes this paper effective
- The paper establishes a clear and focused research question early on and returns to it consistently throughout, giving the argument strong structural coherence.
- The literature review is well-organized, presenting multiple competing perspectives—from scholars who support normative frameworks for cyber espionage to those who reject the proposition entirely—before synthesizing them into an identifiable gap.
- The use of Just War Theory as an explicit theoretical lens adds analytical rigor and situates the empirical question within a recognized ethical framework, which is appropriate given the morally contested subject matter.
Key academic technique demonstrated
The paper demonstrates effective use of thematic analysis in a qualitative case study design. By deriving three emergent themes from secondary literature rather than imposing categories in advance, the author shows how pattern recognition across diverse sources can generate meaningful analytical conclusions without primary data collection. The paper also models transparent acknowledgment of methodological limitations, noting that reliance on secondary data may affect generalizability.
Structure breakdown
The paper follows a conventional research-paper structure: abstract, introduction with background and problem statement, literature review organized by subtopic, a gap-and-theory section bridging review to method, a methodology section, thematic findings, and a conclusion with recommendations. This logical progression makes the argument easy to follow and each section builds directly on the one before it.
Introduction
Cyberspace has become an important element in the operations of any given country in today's information age. Countries across the globe use cyberspace for various purposes, including commerce and modern warfare. Cyberspace has developed into a crucial component of modern warfare as adversaries continue to exploit the potential of the Internet to carry out their activities. It is used at both the operational and strategic levels of modern conflict. At the strategic level, cyberspace is used to deter adversaries and influence the strategic balance of power in relation to the strengths and weaknesses of a state.1 As cyberspace has come to dominate modern warfare, the concept and practice of cyber espionage has emerged. Cyber espionage refers to the practice of obtaining secrets without the permission of the owner or possessor of the information.2 As a form of cyberattack, cyber espionage is one of the most complex international problems in today's world, despite being seen by some as an acceptable state behavior.
Cyber espionage has become one of the most important and complex international problems in today's world. It can generate numerous risks and threats to security and other critical operations because it involves the illegitimate possession of personal, sensitive, classified, or proprietary information. Cyber espionage is carried out through various exploitation methods and techniques targeting individual computers, networks, or the Internet. It incorporates intentional activities to infiltrate or penetrate computer systems and networks used by a rival in order to obtain information stored within or transmitted through those systems.3 Cyber espionage is used by different nations across the globe — including the United States, China, and Russia — despite ongoing concerns regarding its legitimacy and its status as an acceptable state behavior.
Cyber espionage involves practices that result in information theft that could be used to attack an adversary. It poses threats and risks to relations between states and has become a complex international problem in the modern world. Cyber espionage is largely viewed as a new intelligence-gathering approach and strategy for national security decision-making. However, it remains a form of cyberattack, which is legally and ethically contested.
How is cyber espionage an acceptable state behavior for intelligence gathering, even though it potentially damages relations between nation-states?
The purpose of this study is to examine the proposition that cyber espionage is an acceptable state behavior despite being a form of cyberattack, which is generally deemed unacceptable. The evaluation includes an exploration of norms established to promote the acceptability of cyber espionage despite its potential damaging impacts on relations between states.
This study helps address existing concerns regarding the acceptability of cyber espionage, even though it seemingly promotes information theft. It is important to study this issue because cyber espionage has generated numerous concerns regarding its legitimacy and acceptability vis-à-vis cyberattack, as well as broader global security concerns.
Literature Review: Proliferation and Debates Around Cyber Espionage
The issue of cyber espionage has attracted considerable attention in existing literature because of the challenges it poses to international relations. Existing studies examine different aspects of cyber espionage and its increased use in the modern international relations framework as well as in cyber warfare.
Banks (2017) defines cyber espionage as intentional activities used by an adversary to collect information resident on or transmitted through computer systems or networks.4 Cyber espionage has become common in the modern international relations framework due to the widespread use of cyberspace and the emergence of cyber warfare. In addition, the rise of cyber espionage is attributable to the long-standing practice of intelligence gathering and espionage in the national security apparatus of every nation. Cyber espionage involves electronic surveillance of computer systems or networks to intercept communication between two or more parties. Using electronic surveillance, adversaries intercept what is said and planned. Such surveillance invariably results in the processing and exploitation of huge volumes of communications transmitted over the Internet. Therefore, electronic surveillance has provided an avenue for the transformation of conventional state-sponsored surveillance and espionage.
Lotrionte (2015) offers a different perspective regarding the proliferation of cyber espionage. While the proliferation is attributable to the transformation of conventional surveillance and espionage, there are additional contributing factors. According to Lotrionte (2015), cyber espionage — particularly economic espionage — is driven by the failure of international law to provide public order.5 Prescriptive norms of international law are not strong enough to deter cyber espionage, especially economic espionage. Similarly, Libicki (2017) contends that despite objections to certain types of cyber espionage by the United States, such practices remain rampant due to the lack of suitable and effective norms.6 The absence of such norms or policies contributes to the widespread use of cyber espionage to promote cyberattacks on a nation's critical infrastructure.
Jasper (2015) contends that the spread of cyber espionage in the modern world is attributable to the struggle for control of world affairs. This struggle incorporates efforts by various actors including criminals, hackers, terrorists, non-state actors, and foreign powers.7 Foreign powers are employing tactics similar to those of criminals by carrying out malicious activities to intercept communications in computer systems and networks. The digital battlefield has become increasingly contested as nations seek to intercept the communications of their adversaries. For example, China has hacked numerous major American companies seeking useful information, as well as the computer systems of private transportation firms working for the U.S. Army.
According to Libicki (2017), there is a growing proposition that cyber espionage is an acceptable state behavior in the modern international framework. Based on this view, there have been calls for the establishment of norms in international law to promote the use of cyber espionage as an intelligence-gathering strategy. Proponents contend that cyber espionage can serve as a new strategy for traditional intelligence gathering and national security decision-making. This proposition is nonetheless contested, since cyber espionage is itself a form of cyberattack, which is generally deemed unacceptable.8 The debate has intensified at a time when the United States has rejected certain forms of cyber espionage, such as China's financially motivated cyber espionage and Russian doxing attacks.
Hjortdal (2011) states that over the past few years, China has shown a greater interest in offensive cyberspace operations than most other state actors. Cyber espionage — that is, espionage to gain military knowledge — is one of three key strategies employed by China to advance its position in the international system. This has generated significant concern as China uses cyber espionage to spy on and deter the United States.9 The National Counterintelligence and Security Center (2018) reports that cyber espionage poses significant threats to the security, prosperity, and competitive advantage of the United States.10 As a result, cyber espionage affects political and economic relationships between countries while transforming the modern warfare landscape.11 China's increased use of cyber espionage against the United States thus poses threats not only to U.S. homeland security but also to the political and economic relations between the two countries.
Libicki (2017) argues that, despite these threats, cyber espionage should be an acceptable state behavior — but only within specific normative constraints.12 Norms should be established to ensure that the results of cyber espionage are used for traditional intelligence purposes and national security decisions, and their use for cyberattacks on critical infrastructure should be prohibited. Georgieva concurs, arguing that intelligence agencies should collaborate to generate norms to guide cyber espionage for the international community.13 Kessler (2017) adds that the United States has led efforts toward establishing such norms by convening several Groups of Government Experts.14 These groups are charged with reporting on how information and communication technology affects national security. Through such reports, the United States and other nations can determine how to address cybersecurity, particularly with respect to cyber espionage. This is critical because cybersecurity continues to be a persistent and growing challenge as criminals and foreign powers exploit data obtained through cyber espionage.15
Brown (2017) contends that states have come to accept cyber espionage as part of international relations. This acceptance has contributed to a general tolerance of cyber espionage, given its utility in obtaining large volumes of data stored in or transmitted through computer systems and networks.16 However, the international legal system has failed to clearly distinguish cyber activities in relation to cyber espionage. Consequently, cyber espionage activities are neither clearly legal nor clearly illegal under international law, owing to the absence of well-defined norms.
Weissbrodt (2013) seemingly rejects this proposition by contending that cyber espionage creates new threats to national security and should be prohibited.17 Countries like the United States should focus on addressing flaws in existing legal structures that enable cyber espionage in order to deal with the threat it poses to computer systems and network operations. Smith (2018) supports this view by arguing that international law cannot meaningfully differentiate between economic espionage and cyber espionage conducted for national security reasons.18 Therefore, the proposition that establishing norms in international law can define acceptable cyber espionage is problematic, because international law may not fully distinguish between espionage for intelligence gathering or national security and espionage for economic gain. According to Yoo (2015), recent incidents of cyber espionage have demonstrated that it can inflict significant damage to another state's cyber infrastructure when employed as an armed attack.19 Efforts to establish norms in international law to determine the acceptability of cyber espionage could therefore be counterproductive, as they risk legitimizing its use for cyberattacks.
Gap in Existing Literature and Theoretical Framework
As shown in the literature review, existing scholarship presents divergent perspectives on the acceptability of cyber espionage as an intelligence-gathering framework. Existing studies tend to focus on the establishment of norms to define acceptable cyber espionage by governments. These studies do not explicitly state whether cyber espionage should be deemed an acceptable state behavior. Some explain the concept on the basis of its probable benefits to intelligence gathering and national security. On the other hand, some studies cite the lack of norms in international law as grounds for rejecting the proposition entirely. These studies therefore fail to reach consensus and provide contradictory opinions on the acceptability of cyber espionage as an intelligence-gathering framework. Additionally, they do not explicitly address how cyber espionage can be regarded as acceptable state behavior for intelligence gathering despite being a form of cyberattack. Consequently, a gap exists in the literature regarding whether cyber espionage should be regarded as an acceptable new intelligence-gathering approach.
This study seeks to address these gaps through the use of the Just War Theory, which addresses justifications for why and how wars are fought. The theory has played a major role in assessing and understanding the moral and ethical use of new weapons, and it can be applied to cyberspace with respect to cyber warfare.20 Using this theory, the acceptability of cyber espionage as an intelligence-gathering tool was examined in the context of it being a form of ethically and legally contested cyberattack. The Just War Theory was applied in the analysis to understand the implications of accepting cyber espionage as a state behavior for intelligence gathering in relation to cyberattacks.
Using this theoretical framework, the gap in existing literature was addressed based on acceptable justifications for why and how cyber wars are fought. These justifications in turn serve as the premise for determining the acceptability of cyber espionage as a state behavior for intelligence gathering and national security decision-making. The research focused on examining whether cyber espionage is legally and morally justified as an acceptable state behavior in relation to the Just War Theory. During this process, factors contributing to the proposition that cyber espionage is acceptable were critically analyzed in the context of the general unacceptability of cyberattack, which is the primary basis of cyber espionage.
Conclusion
Cyber espionage has become a major and complex international problem in today's world. Even though a proposition for cyber espionage to be viewed as an acceptable state behavior exists, the practice poses significant national security risks and threats. This qualitative case study examined existing data on this issue through a set of documents, which was then analyzed using thematic analysis to identify emerging themes and patterns. The study demonstrates that cyber espionage is an acceptable state behavior because it plays a key role in cyber warfare, improves intelligence-gathering capabilities, and helps establish appropriate countermeasures against cyberattacks and potential threats in cyberspace. Through these findings, the study addresses the existing gap in literature on the acceptability of cyber espionage and provides insights into the reasons for establishing cyber espionage norms in international relations.
However, the study's findings are based on secondary research since it employed a qualitative case study design. The lack of empirical data to support the broader themes identified in existing literature could negatively affect the generalizability of the findings. Future studies should therefore be conducted to further explore the topic and enhance understanding of cyber espionage. One recommendation for future research is to incorporate empirical or primary data. While qualitative methodology may still be appropriate, primary data should be collected and analyzed to improve understanding of the topic. Additionally, future research should incorporate alternative data analysis techniques in order to generate findings that can be more broadly generalized.
Ablon, L. "Data Thieves: The Motivations of Cyber Threat Actors and Their Use and Monetization of Stolen Data." RAND Corporation, March 2018.
Agarwal, A. & CERT-IN. "Cyber Espionage, Infiltration and Combating Techniques." Indian Computer Emergency Response Team, 2013.
Banks, W.C. "Cyber Espionage and Electronic Surveillance: Beyond the Media Coverage." Emory Law Journal 66 (2017).
Baxter, P. & Jack, S. "Qualitative Case Study Methodology: Study Design and Implementation for Novice Researchers." The Qualitative Report 13, no. 4 (2008).
Brown, G. "Spying and Fighting in Cyberspace: What is Which?" Journal of National Security Law & Policy 8 (2017).
Connell, M. & Vogler, S. "Russia's Approach to Cyber Warfare." CNA Analysis and Solutions, 2017.
Creswell, J.W. Research Design: Qualitative, Quantitative, and Mixed Methods Approaches, 4th ed. Thousand Oaks, CA: Sage Publications Inc.
Diplomacy Data. "Cyber Security and Cyber Espionage in International Relations." Diplomacy Data, 2015.
Deoliveira, J. "SWJ Primer: Chinese Cyber Espionage and Information Warfare." Small Wars Journal, 2019.
Georgieva, I. "The Unexpected Norm-Setters: Intelligence Agencies in Cyberspace." Contemporary Security Policy (2019).
Hjortdal, M. "China's Use of Cyber Warfare: Espionage Meets Strategic Deterrence." Journal of Strategic Security 4, no. 2 (2011).
Jasper, S. "Deterring Malicious Behavior in Cyberspace." Strategic Studies Quarterly 9, no. 1 (2015).
Jinghua, L. "What Are China's Cyber Capabilities and Intentions." Carnegie Endowment for International Peace, 2019.
Kessler, S. "Cyberespionage, and the Need for Norms." Harvard Political Review, March 2017.
Libicki, M. "The Coming of Cyber Espionage Norms." 9th International Conference on Cyber Conflict, 2017.
Lotrionte, C. "Countering State-Sponsored Cyber Economic Espionage Under International Law." North Carolina Journal of International Law and Commercial Regulation 40 (2015).
National Counterintelligence and Security Center. "Foreign Economic Espionage in Cyberspace." Office of the Director of National Intelligence, 2018.
Rubenstein, D. "Nation State Cyber Espionage and its Impacts." Washington University in St. Louis, December 2014.
Smith, J.M. "The Cyber Espionage Predominant Purpose Test." Small Wars Journal, 2018.
Warrell, H. & Foy, H. "Russian Cyberattack Unit 'Masqueraded' as Iranian Hackers, UK Says." Financial Times, 2019.
Weissbrodt, D. "Cyber-Conflict, Cyber-Crime, and Cyber-Espionage." Minnesota Journal of International Law 22, no. 2 (2013).
Yates, J.A. "Cyber Warfare: An Evolution in Warfare not Just War Theory." Marine Corps University, April 2013.
Yoo, C.S. "Cyber Espionage or Cyberwar?: International Law, Domestic Law, and Self-Protective Measures." University of Pennsylvania Law School, 2015.
Create your account
Always verify citation format against your institution’s current style guide requirements.