Changing China’s Cyber Calculus

The U.S. needs a strategy to counter China’s leverage in cyberspace. 

Changing China’s Cyber Calculus
A photo of the flag of the People’s Republic of China. (radiowood, https://flic.kr/p/7asMfM; CC BY-NC 2.0, https://creativecommons.org/licenses/by-nc/2.0/)

Over the past several months, a wave of stories has emerged about cyber operations from Iran-backed hackers targeting critical infrastructure. In July, at least 12 states reported that attacks exploited vulnerabilities in industrial controllers used by water and wastewater utilities; operators across several states reportedly lost control of monitoring and control functions, leading to a loss of pressure. In August, The Telegraph reported that Iranian cyber operators managed to shut down a British power plant for four days. The same month, the Cybersecurity and Infrastructure Security Agency (CISA) released an advisory warning that hackers were using an artificial intelligence (AI)-generated script to target programmable logic controllers. In September, Iranian hackers reportedly expanded their campaign to electric and telecommunication networks.

On their own, these attacks demonstrate the widespread vulnerability of American networks. Yet they fail to capture the true scope of the threat to U.S. critical infrastructure. These were relatively simple attacks from a capable but not especially technologically sophisticated adversary that exploited outdated systems, weak passwords, unnecessary internet-connected devices, and other basic cybersecurity weaknesses.

The longer term, more strategic threat comes from the People’s Republic of China, an actor the U.S. intelligence community has called “the most active and persistent threat” to U.S. networks. Chinese hackers known as Volt Typhoon sat in U.S. critical infrastructure for at least five years before they were discovered by Microsoft in May 2023. The goal was to pre-position malware and maintain dormant access to critical systems. The result is strategic asymmetry; China can threaten systems the United States depends on to fight and govern while Washington lacks the defenses that would give Chinese planners pause.

In the wake of the Iranian attacks, the Trump administration has announced several measures to strengthen the defense of critical infrastructure. These efforts, however, do not go far enough. In a new report for the Council on Foreign Relations (CFR), “Closing the Cyber Gap,” co-authored with Rush Doshi, we offer recommendations to address the systemic deficiencies in critical infrastructure cybersecurity and provide greater resilience no matter the source of the threat. We also propose a strategy for confronting Beijing that combines disruption of Chinese operations and political, diplomatic, and economic pressure.

How we got Here

The Iranian attacks revealed long-standing vulnerabilities across the U.S. technology landscape as well as issues specific to water, electric, and other critical infrastructure operators. Hardware and software is often shipped to consumers with insecure default settings and unpatched vulnerabilities. In a 2023 hack of a Pittsburgh-area water system, for example, Unitronics Vision Series programmable logic controllers were exposed to the internet with the default password “1111.” For the seller, speed to market is more important than security, and there are few penalties for shipping vulnerability-ridden software. Shared products and services are vulnerable and can cause cascading and hard-to-detect supply chain compromises.

Critical infrastructure operators are under-resourced yet on the front lines of nation-state attacks, as evidenced by the Iranian compromises of U.S. water systems. Water, electricity, transportation, and other utilities often fail to implement multifactor authentication, access management, segmentation between information technology (IT) and operational technology (OT), and other best practices. Systems are often unknowingly connected to the open internet. Located in small towns spread across the United States, operators lack the capital and human resources needed to patch vulnerabilities and ensure business continuity. As former Deputy Executive Assistant Director for Cybersecurity at CISA Matt Harman put it, “Many smaller water and wastewater systems operate legacy OT environments with limited security resources, where exposed controllers, weak credentials and insufficient segmentation can turn fairly basic techniques into meaningful operational risks.”

What to do at Home

While short of concrete operational details, the fourth pillar of President Trump’s Cybersecurity Strategy for America is to “secure critical infrastructure.” It declares that the United States must move away from “adversary vendors and products,” replacing them with American technology. The Trump administration has rejected most efforts to establish broad cybersecurity standards for critical infrastructure and has instead relied on executive action. In June 2026, the White House issued an executive order on AI and cybersecurity programs that directs the secretary of Homeland Security to use CISA to accelerate the use of AI-enabled defensive tools and facilitate access to cybersecurity services for critical infrastructure operators. After the Iranian attacks, the Office of the National Cyber Director and the state of Texas—to date the only state with a Cyber Command organization—announced Project Watershed 250, a six-month pilot designed to find vulnerabilities in water systems and give utilities access to private-sector cybersecurity services and AI tools. The expectation is that the model will be expanded nationally. 

These actions are well-intentioned and may prove helpful but will likely be insufficient given the scale of current cyber defense shortfalls. A first-order challenge is the comprehensive lack of visibility across the cyber defense community into adversary campaigns needed to inform disruptive or defensive actions. Cloud providers, telecoms, and private security firms often have segments of useful data, but the information is not combined in operationally relevant ways. In response, Congress should impose information sharing requirements, with appropriate liability and legal protections, on cloud providers, large internet service providers, mobile and satellite communications companies, and security providers. Providers should be required to report, on a machine-readable and near real-time basis, indicators of compromise, attack infrastructure, and observed tactics, techniques, and procedures (TTPs) to a government entity that would fuse the intelligence and share actionable insights to defenders.

Compounding this visibility challenge is the inherent opacity of OT networks. Programmable logic controllers, remote terminal units, and supervisory systems that run the physical layer of critical infrastructure generate little telemetry—data gathered automatically from software and hardware. While the United States already has a few programs to monitor critical infrastructure systems, including CISA’s CyberSentry Program and the Department of Energy’s Cybersecurity Risk Information Sharing Program, these should be strengthened and expanded.

Congress should authorize and fund a cross-sector cyber sensing program to detect attacks on priority networks in the energy, communications, transportation, and water and wastewater sectors. The program would fund the installation and integration of passive network sensors at designated assets, capturing indicators of compromise. A national laboratory would build and operate the infrastructure for transmitting, analyzing, and storing sensor-derived telemetry. CISA, working with the sector risk management agencies, would aggregate the resulting data with commercial information, conduct campaign-level analysis, and provide strategic warning to the defender community.

A third line of effort would build a defensive shield against foreign cyberattacks, preventing them from reaching their intended targets. The U.S. cannot and should not re-create China’s Great Firewall, which though built for censorship conveys defensive advantage by providing the ability to monitor and block cross-border traffic. But Washington already has privacy-preserving methods of blocking data flows, such as CISA’s protective DNS (domain name system, a security layer that checks web requests to block malicious sites) and the NSA Cybersecurity Collaboration Center’s signature-sharing services for the defense industrial base. Working together, Congress and the executive branch could establish a defensive shield for critical infrastructure operators in the communications, energy, transportation, and water and wastewater sectors.

The China Problem

The systemic vulnerabilities of U.S. critical infrastructure are compounded by the rising threat from China. Over the past decade, China has emerged as a peer competitor to the United States in cyberspace. China has built a sophisticated hacking apparatus that allows it to pre-position malware on critical infrastructure. During a conflict across the Taiwan Strait or in the South China Sea, Beijing might disrupt essential services, creating chaos and reducing American officials’ room to maneuver. They would also want to degrade military networks and support infrastructure used to project power and coordinate with allies. In scenarios short of conflict, pre-positioned accesses give China options to escalate in deniable and reversible ways, and could make them more inclined to do so.

Given the strategic and political advantages pre-positioning creates for Beijing, restoring balance in the cyber domain is an urgent national security and foreign policy priority. In the short term, U.S. policymakers should revisit the potential for diplomatic measures, economic sanctions, declaratory statements, or some combination of the three to shape Chinese behavior and limit Beijing’s willingness to fully weaponize its capabilities.

To be sure, the history of the United States’ engagement with China on cyber issues is not encouraging. China quickly returned to hacking after the two sides agreed in 2015 that neither “will conduct or knowingly support cyber-enabled theft of intellectual property, including trade secrets or other confidential business information for commercial advantage.” The agreement between Chinese President Xi Jinping and President Obama failed in part, however, because of a lack of pressure and consistency from successive U.S. governments. The United States and its allies continued attributing hacks to China-linked groups, indicting individual hackers, and sanctioning technology firms that provided support to the Chinese Ministry of State Security, yet in reality cyber was only briefly on the top of the agenda from 2013 to 2015. Successive White Houses quickly moved on to trade, technology, military, and other issues in the bilateral relationship. Beijing therefore learned that the United States would make some noise but do very little about Chinese cyber operations. 

In recent years, both sides have shown a newfound willingness to use seemingly disconnected points of leverage—rare earths, semiconductors, soybeans, military exercises—to gain advantage and constrain behavior elsewhere. It is now time to fully integrate cyber into this approach to cross-domain dealmaking and competition. Our CFR report calls for preemptively building a menu of options that would allow U.S. policymakers to credibly threaten to impose consequences on China outside of cyberspace. This would require clearly communicating to Beijing that certain categories of cyber behavior, particularly pre-positioning on civilian infrastructure, would result in sanctions and punishments in “non cyber” areas. These could include more restrictive export controls on U.S. advanced technologies, visa restrictions on Chinese leaders or their relatives, additional tariffs on imports of Chinese goods, or coordinated allied sanction and trade measures.

Actions outside of cyberspace would need to be reinforced and supplemented by measures to disrupt China’s ongoing campaigns. The first pillar of the Trump cyber strategy is “Shape Adversary Behavior,” and the White House says it “will deploy the full suite of U.S. government defensive and offensive cyber operations.” In addition, it adds, “We will unleash the private sector by creating incentives to identify and disrupt adversary networks.” There is no other public detail. 

In support of these goals, the Cyber Mission Force (the operational arm of U.S. Cyber Command) should concentrate its resources on China, whose cyber activities pose the greatest strategic threat relative to other nation-state threats. Operations should prioritize measurable degradation of Chinese campaigns and infrastructure over short-lived shows of digital force. In addition, the report calls on the administration to scale takedowns of the infrastructure used by Chinese actors. In August, the Department of Justice disrupted botnets used to target NASA, the Federal Reserve, and the National Institutes of Health as well as telecommunications providers, power companies, banks, and defense contractors. While takedowns generate positive headlines, they are under-resourced and ad hoc. The FBI lacks the funds and workforce to conduct takedowns at scale, and private-sector firms cannot effectively support them without clear legal pathways. In August, President Trump issued a National Security Memorandum under which vetted private-sector actors can disrupt cyber operations, but the target is transnational crime organizations, not the state actors responsible for Volt Typhoon or the attacks on Michigan’s water systems.

Conclusion

While directed at similar targets, Tehran’s attacks and Beijing’s pre-positioned presence on U.S. critical infrastructure are threats of different magnitudes and timescales. Hardening and making critical infrastructure more resilient addresses both, but neutralizing China’s strategic advantage requires economic, diplomatic, and operational measures that go well beyond technical defense.

A successful policy toward China must seamlessly combine competition in cyberspace with political, economic, and diplomatic responses. Building this menu of cross-domain options, however, is not the same as supplying the political willpower to employ them. So far, such willpower has been in short supply. There has been no reporting that President Trump raised Chinese pre-positioning with President Xi, and no mention of cyberspace in either country’s official readouts of the September summit. At past meetings, President Trump has equated American and Chinese actions, undermining any deterrence signal the United States might try to send. When asked by the press if he had confronted Xi about hacking during his May 2026 visit to Beijing, Trump answered, “I told them, ‘We do a lot of stuff to you that you don’t know about, and you are doing stuff to us that we probably do know about. But we do plenty. It’s a double-edged sword.’”

Cyber issues in the United States have long been confined to their own silo, receiving comparatively little attention from policymakers in other spheres, which in turn constrains the list of tools to defend, deter, or coerce. Recent events suggest this dynamic could change. The emergence of AI models with advanced cyber capabilities, heralded by Anthropic’s announcement of its Mythos model in early 2026, has suddenly made cyber issues a top West Wing priority. The Trump administration has shown a willingness to act quickly and decisively to address what it judges to be unacceptable cyber risks, for example, ordering Anthropic to suspend foreign national access to Fable 5 and Mythos 5. Whether AI ultimately emerges as a tool of offensive or defensive advantage, or whether the United States or China derives greater cyber benefits from AI, remains to be determined. We are, however, at an inflection point, where radical technological change will shake loose political and institutional constraints and expand the range of realistic policy options to address China’s cyber threat.

There are no simple solutions to this current state of affairs. U.S. critical infrastructure networks must be made more secure and resilient against all attackers, from the most sophisticated Chinese hackers to those who do just enough, like Iran-backed hackers. Doing so will take time and resources. In the meantime, defenders must develop a more comprehensive and effective approach to detecting and evicting cyber campaigns.

– Adam Segal, Matt Ferren, published courtesy of Lawfare. 

No Comments Yet

Leave a Reply

Your email address will not be published.

©2026 Global Cyber Security Report. Use Our Intel. All Rights Reserved. Washington, D.C.