Table of Contents
Executive Summary .......................................................................................1
1. Introduction .............................................................................................4
Objective of Belfer’s NCPI 2020 .......................................................................4
Contrasting the NCPI with Existing Cyber Indices ...........................................6
2. National Cyber Power Index 2020 ..........................................................11
Interpreting the National Cyber Power Index 2020 ..........................................13
Limitations .........................................................................................................16
Lack of Publicly Available Data on Cyber Capabilities .................................................16
Lack of Data Surrounding Proxies in Cyberspace ........................................17
Simplifications ...............................................................................................18
Capturing the Duality of Cyber Capabilities ................................................19
3. Conceptual Framework ........................................................................20
National Objectives ...........................................................................................20
4. Methodology and Discussion ..............................................................26
Scoring Intent and Sources ...............................................................................26
Scoring Capabilities and Sources .....................................................................37
Construction of the Aggregated NCPI .............................................................44
5. Conclusion ...........................................................................................49
Bibliography .............................................................................................................50
Annex A. NCPI Plot Charts by Objective ......................................................................53
Annex B. Detailed Explanation of Intent Indicators by Objective .................................57
Annex C. Detailed Explanation of Capability Indicators ..............................................61
Annex D. Radar Charts of All Capabilities by Country ................................................70
Executive Summary
The Belfer National Cyber Power Index (NCPI) measures 30 countries’
cyber capabilities in the context of seven national objectives, using 32
intent indicators and 27 capability indicators with evidence collected
from publicly available data.
In contrast to existing cyber related indices, we believe there is no
single measure of cyber power. Cyber Power is made up of multiple
components and should be considered in the context of a country’s
national objectives. We take an all-of-country approach to measuring
cyber power. By considering “all-of-country” we include all aspects
under the control of a government where Within the
NCPI we measure government strategies, capabilities for defense and
offense, resource allocation, the private sector, workforce, and inno-
vation. Our assessment is both a measurement of proven power and
potential, where the final score assumes that the government of that
country can wield these capabilities effectively.
The NCPI has identified seven national objectives that countries
pursue using cyber means. The seven objectives are:
1. Surveilling and Monitoring Domestic Groups;
2. Strengthening and Enhancing National Cyber Defenses;
3. Controlling and Manipulating the Information Environment;
4. Foreign Intelligence Collection for National Security;
5. Commercial Gain or Enhancing Domestic Industry Growth;
6. Destroying or Disabling an Adversary’s Infrastructure and
Capabilities; and,
7. Defining International Cyber Norms and Technical Standards.
In contrast to the broadly held view that cyber power means
destroying or disabling an adversary’s infrastructure (commonly
referred to as offensive cyber operations), offense is only one of these
seven objectives countries pursue using cyber means.
1 We do not include non-state actors in our ranking.
The overall NCPI assessment measures the “comprehensiveness” of a coun-
try as a cyber actor. Comprehensiveness, in the context of NCPI, refers to
a country’s use of cyber to achieve multiple objectives as opposed to a few.
The most comprehensive cyber power is the country that has (1) the intent
to pursue multiple national objectives using cyber means and (2) the capa-
bilities to achieves those objective(s).
The NCPI 2020’s Most Comprehensive Cyber Powers across all seven
objectives are, from 1st to 10th: US, China, UK, Russia, Netherlands,
France, Germany, Canada, Japan, Australia.
We present three different indices. The NCPI, the Cyber Intent Index (CII),
and the Cyber Capability Index (CCI). Both the CII and CCI are stand-
alone measures. The NCPI is a combination of CII and CCI.
We recognize that national cyber objectives are not composed in isolation:
cyber capabilities are just one of the suite of tools, . alongside tradi-
tional military means, diplomacy, public policy, punitive measures, and
trade policy, available for countries to employ to achieve their national
objectives.
The NCPI builds on existing databases that measure specific elements
of cyber power and collates this data with multiple indicators that were
sourced in-house. Our data analyses followed a rigorous methodology and
procedure, all of which are available upon request.
We verified our analysis of national cyber strategies using natural language
processing. We have correlated the NCPI composite indicator with relevant
measurable phenomena (similar composite indicators but also relevant
quantities . GDP/capita, International Telecommunications Union
Cybersecurity Index etc.) to identify similarities or differences.
The Cyber Intent Index reflects the different prioritization that some
countries place on developing specific objectives and are therefore more
important to their conceptualization of cyber power than others.
For the DPRK we could not find reliable measurements for many of the
capabilities listed in our index. We have therefore asked several experts to
provide us with their assessments of the different capabilities as they relate
to the DPRK to inform the NCPI. Researchers and practitioners should
bear in mind that the DPRK is a special case when referencing its NCPI
score in comparison to the other countries in this index.
We have used a Min-Max normalization technique to rescale the cyber
capability indicators because it: (1) best reflects our conceptual frame-
work; (2) is most appropriate for the data properties; and, (3) can be easily
interpreted by users. The intent part of our formula can be considered as
equivalent to a weight.
Researchers and practitioners should use the NCPI to gain a more compre-
hensive understanding of the components that comprise cyber power and how
cyber means can be employed to achieve a range of objectives. Users who are
interested in a specific national objective can analyze the NCPI by both intent
and capabilities by objective to better understand their country of interest.
In this paper we contrast the NCPI with existing cyber-related indices,
outline our conceptual framework, provide guidance on how to interpret
our findings, share the methodology for scoring intent, capabilities and the
composite indicator, list the sources we used, and provide an overview of
the limitations of our approach.
The purpose of the NCPI is to broaden the discussion on cyber power to
reflect that it can be applied to achieve more than destructive capabili-
ties and that it is an important tool for governments to achieve multiple
objectives. We believe that further transparency around national cyber
objectives and capabilities is needed to make more relevant and effective
policy and prevent dangerous escalation between countries. We hope that
the NCPI helps move the discussion on cyber power and the utility of
increased transparency around capabilities, forward.
1. Introduction
The public is informed of the cyber impacts of only a handful of countries:
notably ., Israel, Iran, China, Russia and DPRK. Most news coverage
reports on only the large-scale or dramatic offensive cyber-attacks. This is a
misrepresentation of the full schope of the capabilities, objectives, and the
range of actors in cyber space. Additionally, when reporting on these, there
is no systematic measure or comparison of even this narrow range of cyber
capability.
Objective of Belfer’s NCPI 2020
The objective of the Belfer 2020 National Cyber Power Index (NCPI) is to
provide a more complete measure of cyber power than existing indices.
We take an all-of-country approach to measuring cyber power. By con-
sidering “all-of-country” we include all aspects under the control of a
government where possible. 2 Within the NCPI we measure government
strategies, capabilities for defense and offense, resource allocation, the
private sector, workforce, and innovation. Our assessment is both a mea-
surement of proven power and potential, where the final score assumes
that the government of that country can wield these capabilities effectively.
In contrast to existing cyber power indices, we dispute the notion that
there is an absolute measure of cyber power and propose multiple compo-
nents of cyber power. Furthermore, any measure of cyber power should be
considered in relation to the national objectives of the country in question
and their decision to use cyber means to achieve those objectives.
We have identified seven national objectives that countries pursue using
cyber means. The NCPI considers cyber power within the context of these
seven national objectives. No other ranking of cyber power does this.
2 We do not include non-state actors in our ranking.
We measure a country’s intent to pursue each objective through an
assessment of national strategies, rhetoric, and attributed cyber opera-
tions. If a country’s intent to pursue an objective is low, we assess that the
objective is of less importance to that country.
We then measure a country’s capability within each objective. The indicators we
consider are in line with widely accepted definitions of cyber power within
national security. For example, a cyber power has been described as “a country
who is world class in safeguarding the cyber health of citizens, businesses and
institutions; has the legal, ethical and regulatory regimes to foster public trust;
and the ability to project cyber power to disrupt, deny or degrade adversaries”.3
However, we recognize that national objectives pursued using cyber means are
not composed in isolation. Cyber capabilities are just one of a country’s suite of
tools, . alongside traditional military means, diplomacy, sanctions, and tariffs,
that are available for countries to deploy to achieve their national objectives.
Cyber power in the context of the NCPI is when a country effectively
develops cyber capabilities to achieve its national To differen-
tiate between levels of intent and capability between countries across all
objectives we assign the term “comprehensiveness” to describe a country’s
use of cyber to achieve multiple objectives as opposed to a few.
Through combining both the intent and capability score across all seven
objectives, we are able to reflect a “Comprehensive Cyber Power Ranking”.
The most comprehensive cyber power is the country that:
• Has the intent to pursue multiple national objectives using cyber means
• Has the essential capabilities to pursue and achieve said objectives
The most comprehensive cyber power has the highest intent and highest
capability to achieve the most objectives using cyber means and the lowest
scoring country is pursuing the least objectives using cyber means with the
lowest level of intent and capability.
3 Jeremy Fleming, Director GCHQ, “Keynote Speech: The UK is a Global Cyber Power”. International
Institute of Strategic Studies, Singapore. Published February 25, 2019.
4 Voo, Julia., Irfan Hemani, Simon Jones, Winnona DeSombre, Dan Cassidy and Anina Schwarzen- bach.
“Reconceptualizing Cyber Power”. Belfer Policy Paper. Published April 2020.
The NCPI scores 30 countries5 against our unique framework. The
selection of these countries grew out of the teams’ original query of the
often-cited five cyber superpowers,6 countries with attributed APT
groups,7 and rumored rising cyber powers. Due to limited resources and
access to open source data we were unable to include many more coun-
tries. The countries included in the NCPI have indicated, either overtly or
covertly, their desire to be considered as a cyber power.
We opted for a transparent approach and provide a disaggregated measure that
builds on both publicly available data and expert assessments. In this paper
we contrast the NCPI with existing cyber power indices, outline our concep-
tual framework, provide guidance on how to interpret our findings, share the
methodology for scoring intent, capabilities and the composite indicator, list the
sources we used, and provide an overview of the limitations of our approach.
The NCPI provides a new conceptual framework and data to the discussion
on cyber power. A better-informed understanding of which countries are
and are not pursuing certain objectives and capabilities using cyber means
will contribute to relevant, and more effective long-term strategies.
Contrasting the NCPI with
Existing Cyber Indices
Over the past decade, several organizations have provided measures for an
aspect of national cyber power. In this section, we provide a high-level con-
ceptual comparison of the NCPI with three widely used frameworks for
measuring cyber power. These three widely used frameworks are listed below:
5 The 30 countries are: Australia, Brazil, Canada, China, Democratic People’s Republic of Korea (DPRK),
Egypt, Estonia, France, Germany, India, Iran, Israel, Italy, Japan, Lithuania, Malaysia, Neth- erlands, New
Zealand, South Korea, Russia, Saudi Arabia, Singapore, Spain, Sweden, Switzerland, Turkey, Ukraine, UK,
USA, and Vietnam.
6 US, UK, Israel, China, and Russia. As highlighted in Voo, Julia., Irfan Hemani, Simon Jones, Winnona
DeSombre, Dan Cassidy and Anina Schwarzenbach. “Reconceptualizing Cyber Power”. Belfer Policy Paper.
Published April 2020.
7 The Five Eyes is an intelligence (signals, human, military) alliance between Australia, Canada, New Zealand,
UK, and US
• The International Telecommunications Union (ITU)’s Global
Cybersecurity Index8 (GCI) has been released three times in the
past decade. The ITU is a body of the United Nations and it is the
oldest global international organization. The GCI is designed to
encourage the development of international cyber resilience among
ITU member states. It focuses on domestic cyber resilience and is
based on members states’ self-assessments.
• The Potomac Institute’s Cyber Readiness Index (CRI ) 9
is designed to evaluate a country’s maturity and commitment to
securing its national cyber infrastructure and services. CRI
examines 125 countries (including: the top 75 countries from the
ITU ICT Development Index and G20). Notably, the CRI does
not assign a score or a rank to the countries it analyses.
• The Economist Intelligence Unit & Booz Allen Hamilton (EIU & Booz)
developed a “cyber power index” (CPI) in 201110 ranking 19 of the G20
In contrast to the other two indices that exclusively measure
cyber security related capabilities, the CPI purports to provide a broader
measure of cyber power. However, it is worth noting that the CPI, in
contrast to Belfer’s NCPI, does not measure offensive capabilities, and
focuses largely on economic and resource indicators—which although
are important to understanding the potential for developing cyber
power does not provide the fullest picture of cyber capabilities.
Table 1 compares NCPI’s ranking of the top ten cyber powers with the
ranking provided by ITU (2018) and the Economist Intelligence Unit
(2011). The Potomac Institute’s ranking is not included because their index
does not score or rank countries.
Table 2 compares the high-level concepts that comprise the NCPI with the
three other indices.
8 International Telecommunications Union. 2018. Global Cybersecurity Index. Accessed May 6, 2020.
9 Potomac Institute for Policy Studies. 2015. Cyber Resilience Index. Accessed May 6, 2020. https://
10 Economist Intelligence Unit & Booz Allen Hamilton. 2011. Cyber Power Index. Accessed May 6, 2020.
htps://
Power%20Index%20Findings%20and%
11 The European Union is the 20th member of the G20 and excluded.
Table 1: Top-10 Comparison
#
Belfer Center:
National Cyber Power
Index 2020
International
Telecommunications Union:
Global Cyber Security
Index 2018
Economist Intelligence Unit &
Booz Allen Hamilton:
Cyber Power Index 2011
1 United States United Kingdom United Kingdom
2 China United States United States
3 United Kingdom France Australia
4 Russia Lithuania Germany
5 Netherlands Estonia Canada
6 France Singapore France
7 Germany Spain South Korea
8 Canada Malaysia Japan
9 Japan Canada Italy
10 Australia Norway Brazil
Table 2: Concept Comparison
Belfer Center:
National Cyber
Power Index 2020
International
Telecommunications
Union:
Global Cyber
Security Index
2018
Potomac Institute:
Cyber Readiness
Index
Economist Intelli-
gence Unit & Booz
Allen Hamilton:
Cyber Power Index
2011
Year(s) Published 2020 2018 2015 2011
Iterations 1 3 2 1
Objective
To measure the cyber
power of countries
against their stated
objectives
To measure the com-
mitment of countries
to increase their
domestic security
To measure a coun-
try’s commitment to
securing its national
cyber infrastructure
and services
To measure cyber
power by country
Countries
Assessed 30 193 (2018) 125 19
Indicators
27 Capability;
32 Intent 25 7 39
Score X X X
Ranking X X X
Themes:
National Objectives
Drive Capability
Development
X
Evidence of Attacks X
National Online
Content X
Domestic State
Cyber Structures X X X X
Cyber Vulnerability
Mitigation X X X X
Private Sector,
Trade and
Innovation
X X X X
Connectivity X X X X
Workforce X X X X
Domestic and
International
Legal and Policy
Frameworks
X X X X
This comparison demonstrates that the NCPI uniquely provides a rigorous
assessment of each country’s national objectives that they seek to carry out
with cyber means. Furthermore, that the NCPI considers both concepts
that have been traditionally linked to assessments of cyber power and con-
cepts that have so far been neglected by previous assessments.
2. National Cyber Power
Index 2020
As seen in Graph 1, the top ten most comprehensive countries with the
highest level of intent and capabilities across all seven objectives are as fol-
lows. Graph 2 shows a breakdown of the rankings by objective.
1. United States
2. China
3. United Kingdom
4. Russia
5. Netherlands
6. France
7. Germany
8. Canada
9. Japan
10. Australia
Graph 1: NCPI 2020: Most Comprehensive Cyber Powers
United States
China
United Kingdom
Russia
Netherlands
France
Germany
Canada
Japan
Australia
Israel
Spain
Sweden
Estonia
New Zealand
ROK
Switzerland
Singapore
Malaysia
Vietnam
India
Turkey Iran
Brazil
Ukraine Saudi
Arabia
Lithuania
Italy
Egypt
0
10 20 30 40 50 60 70 80 90 100
National Cyber Power Score
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
United States
China
United Kingdom
Russia
Netherlands
France
Germany
Canada Japan
Australia
Israel
Spain
Sweden
Estonia
New Zealand
ROK
Switzerland
Singapore
Malaysia
Vietnam
National Cyber Power Index
China
Russia United
States
United Kingdom
Canada
Germany New
Zealand
Netherlands
Australia
Estonia Saudi
Arabia
Switzerland
Sweden
Singapore
Spain
Vietnam
France
Malaysia
Turkey
Japan
Surveillance
China
France
Netherlands
United States
Canada Japan
Sweden
United Kingdom
Switzerland
Germany
Australia
Estonia
Singapore
Spain
New Zealand
ROK
Brazil
Russia
Malaysia
Lithuania
Defense
United States
Russia
China
Israel
Vietnam
United Kingdom
New Zealand
Iran
Australia
Germany
Canada Japan
France
Netherlands
Spain
Sweden
ROK
Italy
Brazil
Estonia
Information Control
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
India
Turkey
Iran
Brazil
Ukraine
Saudi Arabia
Lithuania
Italy
Egypt
0 20 40 60 80 100
ROK
Ukraine
Lithuania
Italy
Israel
India
Egypt
Brazil
Iran
0 20 40 60 80 100
Turkey
Ukraine
Israel
India
Saudi Arabia
Egypt
Italy
Vietnam
Iran
0 20 40 60 80 100
Switzerland ●
Ukraine ●
Lithuania ●
Singapore ●
Malaysia ●
Saudi Arabia ●
Turkey ●
Egypt ●
India ●
0 20 40 60 80 100
United States
United Kingdom
China
Israel
Netherlands
ROK
Canada
National Cyber Power Score
Intelligence
●
●
●
●
●
●
●
China
United States
United Kingdom
Japan
ROK
Netherlands
Switzerland
National Cyber Power Score
Commerce
●
●
●
●
●
●
●
United States
United Kingdom
Russia
China
Spain
Israel
Germany
Offense
●
National Cyber Power Score
●
●
●
●
●
●
United States
France
Japan
Germany
China
United Kingdom
Australia
Norms
National Cyber Power Score
New Zealand ●
Australia ●
Russia ●
Spain ●
France ●
Vietnam ●
Germany ●
India ●
Australia ●
Sweden ●
Singapore ●
Israel ●
Malaysia ●
New Zealand ●
Germany ●
Canada ●
Iran ●
Netherlands ●
France ●
Estonia ●
Canada ●
Sweden ●
Australia ●
ROK ●
ROK
Netherlands
Canada
Estonia
India
Malaysia
Singapore
Russia
Singapore ●
Switzerland ●
Japan ●
Sweden ●
France ●
Spain ●
Italy ●
India ●
Japan ●
Vietnam ●
Ukraine ●
Turkey ●
Switzerland
Israel
Sweden
Spain
Italy ●
Iran ●
Ukraine ●
Iran ●
Lithuania ●
Estonia ●
Switzerland ●
Singapore ●
Saudi Arabia ●
Turkey
New Zealand
Brazil
Estonia ●
Brazil ●
Lithuania ●
Turkey ●
Saudi Arabia
Malaysia
Egypt
0 20 40 60 80 100
Ukraine ●
Brazil ●
Vietnam ●
Russia ●
Saudi Arabia ●
Turkey ●
Egypt ●
0 20 40 60 80 100
New Zealand ●
Malaysia ●
Lithuania ●
Italy ● India
● Egypt ●
Brazil ●
0
20 40 60 80 100
Italy
Vietnam
Ukraine
Lithuania
Egypt
Saudi Arabia
Iran
0 20 40 60 80 100
National Cyber Power Score National Cyber Power Score National Cyber Power Score National Cyber Power Score
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
G
ra
ph
2
: N
C
P
I 2
0
20
B
y
N
at
io
na
l O
bj
ec
tiv
e
12
N
at
io
na
l C
yb
er
P
ow
er
In
de
x
20
20
: M
et
ho
do
lo
gy
a
nd
A
na
ly
ti
ca
l C
on
si
de
ra
ti
on
s
Interpreting the National
Cyber Power Index 2020
Researchers and practitioners may use the NCPI in different ways. First,
they might use the NCPI’s aggregated measure of cyber power across all
seven objectives to understand which country is the most comprehensive
cyber power, as seen in Graph 1. Graph 1 favors countries that had high
scores on both intent and capability for multiple cyber objectives, which
leads us to assess that these countries are effectively using cyber means to
achieve multiple policy goals. Each country has a different score based on
each objective.
Because our analysis of cyber power is the product of intent and capability,
we can plot countries within each objective into the following four quad-
rants seen in Graph 3. Note that we have drawn the quadrants on the mean
values of intent and capability (the maximum value achieved by any coun-
try in the dataset was an intent score of 100 and a capability score of 80).
Most of the countries cluster around the middle of the plot.
Graph 3: Plot of Cyber Power Rankings across Capability and Intent
0 20 40 60 80 100
Cyber Capability Index
China●●
●● United Kingdom
ia
Israel ●● N
Spain ●●
New Zealand
●●
●●●●
Germany
India
●●
Ukraine
●●
●● Italy
ability &
Intent
Higher Cap
Lower
ability &
Intent
Lower Cap
Lower
Egypt●●
Singapore
ia
●● Malaysia●●
●● Lithuan
a
●●
Turkey
●● Brazil●●
Saudi Arabi
●● ROK●●
Estonia
Japan
●●
●● Sweden
●● Switzerland
●● Vietnam
France
●● Canada
●●
Australia
●●
Iran●●
etherlands
States●● United
●● Russ
ability &
Intent
Higher Cap
Higher
ability &
Intent
Lower Cap
Higher
C
yb
er
In
te
nt
In
de
x
Higher Capability, Higher Intent
. US, UK, China, France, Germany
Countries with high levels of both intent and capability for a specific
objective (or for multiple objectives as seen in Graph 1), are among the
highest-ranking countries in the NCPI. These countries both signal in
strategies and in previously attributed cyber-attacks that they intend to use
cyber to achieve policy goals and have the capabilities to achieve them.
Higher Capability, Lower Intent
. South Korea
Countries with high levels of capability, but low levels of intent for a spe-
cific objective or set objectives fall under two possibilities. The country
in question may be trying to actively avoid a specific goal. For example,
because the United States is home to multiple large-scale social media
companies, passing legislation to better control online speech would be an
effective way for the US to control online content for domestic audiences.
However, because the United States strongly adheres to the right to free-
dom of speech enshrined in the First Amendment to its Constitution it
likely has little intention to do so. The other possibility is that the country
in question may be trying to use its cyber capabilities in secret, without
openly stating that they intend to use cyber capabilities for specific goals.
Higher Intent, Lower Capability
. Russia, Iran, Israel, Netherlands
These countries are actively signaling to other states that they intend to
develop their cyber capabilities but have either a) not publicly disclosed
their capabilities (through stated or demonstrated means), or b) do not
currently have the capabilities at hand to achieve their cyber goals.
As for the latter, while they may be openly signaling future plans, these coun-
tries do not have the capability to become a comprehensive cyber power at
present. For example, the Netherlands has stated their intent to “use... offen-
sive capabilities and a broader response in the cyber domain”,12 especially
against disruptive cyber actors, in their 2018 national cyber
In addition, Iran has been credited for conducting multiple cyber-attacks
which indicate that it has been aggressively pursuing some objectives
through cyberspace. However, it was one of the lowest scoring nations with
regards to its capabilities surrounding norms, cyber defenses, commercial
gain, and information control beyond its borders, which are all weighted
equally to offense in the NCPI.
Lower Intent, Lower Capability
. Egypt, Lithuania
Countries that fall into this category either are not actively developing the
capability and intent to project power in cyberspace, or have not published
(or had published about them) a sufficient amount of information on their
cyber strategy, cyber-attacks attributed to them, or capabilities used to
measure cyber power in this study.
Country-specific analysis has been displayed through use of radar charts in
the Annex. Individuals interested in a specific national objective within
NCPI can view the data sources we have selected for capability or intent
that contribute to the specific objectives in Chapters 3 and 4. In addition to
viewing the overall comprehensiveness score we recommend that policy
makers consider the capability and intent scores separately for any country
of interest, as well as its overall score.
12 Netherlands National Cyber Security Strategy 2014, see national-
cyber-security-strategies/ncss-map/national-cyber-security-strategies-interactive-map/
strategies/national-cyber-security-strategy-1
13 The Netherlands proved their capabilities not just by having well-staffed cyber military units, but also by
infiltrating Russian intelligence networks in 2015. These countries are likely currently projecting cyber
power, achieving policy goals by using cyber capabilities, and actively signaling to other states that they
intend to further develop their existing capabilities. See
nieuwsuur/artikel/2213767-dutch-intelligence-first-to-alert-u-s-about-russian-hack-of-democratic-
Limitations
The NCPI’s objective-oriented analysis of national cyber power suffers
from some limitations, which are mostly connected with the nature of
the subject of “Cyber Power” itself. Here we will briefly address the most
important limitations and challenges faced by the research team.
Lack of Publicly Available Data on
Cyber Capabilities
There were instances where information was available for some, but not
all countries. There were, understandably, difficulties in obtaining certain
information that is often considered classified, such as the number of cyber
military personnel or the number of people within intelligence services with
a cyber remit. There were, however, other areas where less sensitive informa-
tion was also unavailable, such as the number of skilled technology workers.
Similarly, countries may also deliberately shield their intent and capabilities
from public knowledge for strategic reasons. We recognize that countries’
deliberately choosing to be opaque will be vastly under-ranked in the index.
We suspect that Israel falls into this category. This highlights the challenge
of measuring cyber power, both to determine capabilities that would map
to certain objectives, and to find measurements of these capabilities in open
source. We also assert that, while a country may have intentions that are not
published externally, both political will and harnessing of national resources
are required for a country to pursue a particular objective, both of which can
be signaled through publishing of national strategies and doctrines.
We also strongly believe that “Amassing Wealth or Extracting Cryptocur-
rency” is a top objective of some countries and that they employ cyber
means to achieve Unfortunately, we were not able to collect suffi-
cient data for both intent and capability indicators that would allow us
to measure each country against this objective. We consider this to be
14 “Amassing Wealth or Extracting Cryptocurrency” is when a country has conducted either illegal or legal
wealth generation via cyber means. This includes the use of ransomware, attacking the digital infrastructure
of banks and financial institutions, and blackmail based on information obtained via data breaches. Legal
means include cryptocurrency generation and taxation.
an important objective that is pursued using cyber means and we hope
to measure this objective in future iterations of NCPI when more data
becomes available.
Other issues contributing to the relative lack of information on some coun-
tries as opposed to others is a combination of researchers and observers to
date focusing on wealthier Western countries and as a result there is gener-
ally more publicly available English-language information. Our assessment of
the national cyber strategies also relied on English translations when official
English versions were not available. These translations may not be entirely
accurate, where some words such as “informatization” are used in Russia and
China and not in English-speaking countries. For this reason, Israel, DPRK,
and Iran also likely appear lower on the NCPI than potentially expected.
Lack of Data Surrounding
Proxies in Cyberspace
To ensure comparability of information across countries—both liberal
democracies and not—we used proxy information on cyber opera-
tions, such as the existence of cyber military strategies and attribution of
state-sponsored attacks.
The NCPI also includes by proxy the power held by some non-state actors
such as technology companies. Where technology companies contrib-
ute to a country’s economic strength and contribute to their innovation
ecosystem, they have been included in the Digital Evolution index score.
However, this does not consider the awesome power that some technology
companies have independently of governments by virtue of their global
reach, computing power and technological development. Google, Face-
book, Baidu, or Huawei on their own may rank as highly as some of the
countries at the top of our index. The countries that they reside in will reap
benefits in terms of technical capability and access to information.
Another example would be one of the most prolific intelligence gathering
tools that was developed in Israel will no doubt be of benefit to the Israeli
government. The NCPI also does not include the power of mercenary
groups located within a country’s national borders, affiliated with the
government or not. Multiple devastating attacks that have originated in
China, Russia, and other countries have been attributed to mercenary
groups and other non-state actors.
Simplifications
Conventional military power, in comparison to cyber capabilities, has
more tangible metrics such as the number of schools, soldiers, tanks, and
nuclear arsenal a country has. It is more difficult to determine what consti-
tutes a “cyber weapon”.
We assume that the NCPI’s indicators are an accurate reflection of the poten-
tial and real capability a country has to achieve those objectives. In the NCPI,
each objective has between five to ten capability indicators. This simplifica-
tion is required to be able to quantify and compare countries’ capabilities
against one another. However, we recognize that a) these indicators may not
accurately and comprehensively measure the totality of a country’s capability,
and b) not all data available in the public domain are complete and accurate.
Where possible, we have used data that has been widely used by practi-
tioners and academia often sourced from recognized institutions, such as
the United Nations or World Bank, national governments, and other indi-
ces that have reliable methodologies for gathering data globally (such as
the Freedom House Index15).
We have also included some innovative and less well-known data which
help us to capture a broader range of cyber capabilities. For instance, to
measure a country’s strength to control the information environment we
have included data on take down requests from Google and statistics from
Amazon’s Alexa Top 100
15 See
16 Google operates a takedown request service where users can report content on a Google product that they
believe violates the law or their rights. Google then reviews the product and considers blocking, limiting, or
removing access to it. We accessed data on Government requests to remove content via Google’s
Transparency Report. See, ment-removals/overview?hl=en.
See for data gathered by Amazon on the top 100 websites visited by internet users using
various browser extensions.
Capturing the Duality of Cyber Capabilities
A challenge of measuring cyber power is to account for its duality. Some
capabilities add to cyber power in one national objective but are detri-
mental for another. For example, while a highly connected population
can benefit a country’s internet monitoring efforts, the potential impact of
attacks becomes more likely and more severe. Therefore, we count the per-
centage of users connected to the internet within a country positively for
internet monitoring and negatively for defense.
Moreover, within the open source data available, certain data can be both
a measure of intent and capability. For example, each operation within the
Council on Foreign Relations’ Cyber Operations Tracker represents both
a measure of intent and capability. By having an attributed state-spon-
sored operation, a state has revealed its intention to achieve an objective
in cyberspace, as well as its capability to do so. For example, when the
compromise of Sony Pictures Entertainment was attributed to DPRK, the
international community was able to determine that DPRK had both the
intent and capability to control the information environment, by hindering
viewership of the film.
Another example is national cyber legislation. National cyber legislation
reveals both the extent of a country’s intention to control cyber activities,
as well as the capabilities or funding that a government is allocating to do
so. To deconflict these two examples, we have created different measure-
ments from the same datasets. For the Cyber Operations Tracker, if a state
has conducted at least one operation that achieves a particular objective,
we have measured that as an intent We have then measured
the number of attributed operations achieving that objective as a measure
of capability. For cyber legislation, we measure intent by analyzing specific
laws and strategies, and to measure capability we consider the number of
different types of cyber legislation and the timeliness of their updates.
17 A limitation of our research is that we cannot account for non-attributed cyber operations that have
occurred.
3. Conceptual Framework
Countries use cyber capabilities to achieve their wider policy goals. In this
section, we highlight the national objectives countries have historically
pursued using cyber means. We then explain how a country’s intent to
pursue those objectives, and the capabilities required to achieve those
objectives, create our formula for cyber power.
National Objectives
While it seems accurate to assume that the most technically capable or
best equipped country is the most powerful, we argue that cyber power is
made of different components. We pursue a holistic approach and consider
all components to assess the overall cyber power. Cyber power should be
measured in relation to each country’s national objectives.
The most comprehensive cyber power is the country that most ably uses
cyber means to achieve the most objectives. We recognize that countries
have non-cyber means to achieve the same objective(s) and a country may
elect to do that instead. However, within the NCPI we do not consider
these other tools at a country’s disposal. For example, a country that seeks
to use surveillance to monitor domestic groups may use cyber means
to complement the traditional tools it has available, such as gathering
human intelligence and conducting physical surveillance. The focus of our
research is on how a country develops and uses its cyber capability to meet
national objectives.
To understand how capable a country is, we started by identifying the
range of national objectives that countries may try to achieve via cyber
means. International relations theory forms the basis of our under-
standing of how countries theorize national objectives. The Council on
Foreign Relations’ Cyber Operations database18 of publicly attributed
18 Most of the objectives were identified through analyzing the Council on Foreign Relation’s “Cyber
Operations Tracker”. See, We also mapped each cyber-
attack within the database (as of December 2019) to the objectives below, to use real histori- cal cyber-attacks
as a measure of cyber power capability.
state-sponsored incidents provided us with an insight of how some coun-
tries have deployed their cyber capabilities. Based on this research, we
identified seven cyber objectives that countries have broadly pursued
between 2005-2019 that we have explained in Table 3.
Table 3: Definitions of National Objectives19
Cyber Power Objectives
Common objectives states will attempt to acheive through cyberspace, as
determined by the Belfer Center Cyber Power Team.
1 Surveilling and Monitoring Domestic Groups
A country has taken steps to give itself the legal permissions and cyber surveillance capabilities to monitor, detect, and gather intelli- gence on domestic
threats and actors within its own borders. This may range from efforts to conduct surveillance of its citizens, monitor internet traffic, circumvent
encryption, or detect and disrupt foreign intelligence services, criminal organisations, and terrorist groups.
2 Strengthening and Enhancing National Cyber Defenses
A country has prioritized enhancement of the defense of government and national assets and systems, and improved national cyber hygiene and
resilience. This includes active defence of government assets, promoting cybersecurity and cyber hygiene to key industries and the general population,
and raising national awareness of cyber threats.
3 Controlling and Manipulating the Information Environment
Reflecting the duality of information controls, a country has prioritized using electronic means to control information and change narra- tives at home
and abroad, AND/OR attempted to protect the internet privacy and free speech of its citizens. The form includes spreading domestic propaganda, creating
and amplifying disinformation overseas, and using cyber capabilities to target and disrupt groups other- wise outside of its jurisdiction. The latter
includes taking down extremist material from social media, and refuting foreign propaganda.
4 Intelligence Gathering and Collection in other Countries for National Security
A country has extracted national secrets from a foreign adversary via cyber means. This objective is specifically focused on the collec- tion of
information that is not commercially sensitive, but instead the collection of information that informs diplomatic activities, military planning, treaty
monitoring, and other situations in which countries seek to improve their situational awareness and understanding of a foreign country. This includes
hacks and breaches of classified material, such as military plans, but it also includes stealing personnel records, and accessing the communications of
senior government figures, such as Members of Parliament.
5 Growing National Cyber and Technology Competence
A country has attempted to either grow its domestic technology industry, or used cyber means to develop other industries domestically. This could be
through legal and illegal means. Illegal means include by conducting industrial espionage against foreign companies and countries to facilitate
technology transfer. Legal means include investment in cybersecurity research and development and prioritizing cybersecurity workforce
development.
6 Destroying or Disabling an Adversary’s Infrastructure and Capabilities
A country has used destructive cyber techniques, tactics, and procedures to deter, erode, or degrade the ability for an adversary to fight in cyber or
conventional domains. This includes cyber attacks on critical infrastructure, and DDOS attacks on government communica- tions networks. It also
includes cyber attacks to demonstrate intent and capability to deter an adversary from acting.
7 Defining International Cyber Norms and Technical Standards
A country has actively participated in international legal, policy, and technical debates around cyber norms. This might include signing cyber treaties,
participating in technical working groups, and joining cyber partnerships and alliances to combat cyber crime and share technical expertise and
capabilities.
19 Table created by authors.
An Eighth Objective: Amassing Wealth
and Extracting Cryptocurrency
The 2020 NCPI assesses countries against seven objectives, however there
is one objective clearly missing. The missing objective, “Amassing Wealth
and Extracting Cryptocurrency”, is defined as follows:
A country has conducted either illegal or legal wealth generation
via cyber means. Illegal and legal wealth generation via cyber
means. This could include the use of ransomware, attacking
the cyber infrastructure of banks and financial institutions,
and blackmail based on information obtained via hacks and
data breaches. It could also include legal means, such as
incentivizing and encouraging domestic actors to develop
exportable cybersecurity products, and the development of
cryptocurrencies.
We attempted to collect our own data to demonstrate “Amassing Wealth
and Extracting Cryptocurrency” through exploring the availability of
data on Bitcoin cash withdrawals, mining statistics, and successful scams
attributed to criminal actors within a specific country. We recognize that
much of this activity is not state-sponsored
Unfortunately, for this years’ index we were unable to find the above data,
nor were we able to find measurements of capabilities that could serve as
proxies for the capabilities we wanted to measure. As a result, we excluded
this objective from this years’ study because the data that was available
would overly skew the results. We hope that relevant data to measure capa-
bility around “Amassing Wealth and Extracting Cryptocurrency becomes
available in coming years so that we can include it in future iterations of the
NCPI.
20 See gauge-of-
a-countrys-progress/
What Objective(s) are Countries’ Prioritizing,
and Can They Be Achieved?
To measure a country’s cyber power, we must answer the following
questions:
1. Which objective(s) does a country intend to pursue in cyberspace?
2. What capabilities does a country have that could achieve those
objective(s)?
The first question is a measure of intent, while the second is a measure of
capability. Both terms are used in the classic definition of national power
and the discussion of adversarial
Intent is a measurement of the quality and quantity of government plan-
ning initiatives (. national cyber security strategies, crisis plans, and other
related government planning documents). It is a subjective assessment of
the government’s “observed behavior” on cyber relevant
Capabilities are measurements of the quality and quantity of country output
related to one or more cyber objectives (. number of patents filed per
year, number of global top security firms, number of skilled workers).
The distinction between intent and capability is important for two reasons:
1. A government may have the capabilities to achieve an objective
using cyber means but not have the intent to do so.
2. A government may wish to pursue an objective through cyber means
but lacks the required capability or resources to actually do so.
21 See and
assets/
22
National Cyber Power Index Formula
For our NCPI Formula we draw on intelligence and national power litera-
ture. 23 There, intent and capability parameters are multiplied against each
other to obtain threat and power
There is a dynamic relationship between capability and intent. If capability is
taken as the base line ability to exercise cyber power, then a country’s intent
is its vector, . it establishes both the magnitude and direction of travel of its
cyber power. A strong intent magnifies the effect of cyber capability, whereas
lower intent score would hinder an otherwise strong capability.
We score each country based on their intent to pursue each of the seven
objectives and capability to achieve said objective. We compute the NCPI
intent scores by multiplying—for each national objective—a country’s
capabilities with its intent. The NCPI intent score reflects the different
prioritization that some countries place on leveraging specific cyber capa-
bilities, and therefore can be considered as a weight. This assumes that a
country can only fully deploy its cyber capabilities in a domain, such as
national surveillance, if it shows a 100 percent intent to do so.
Therefore, in the NCPI, a country scores highly in an objective only if it has
both strong intent and the necessary capabilities to achieve the objective,
as capabilities or intent alone are not sufficient. In formula form, national
cyber power of a country is the product of capability and intent:
where x represents one of the seven objectives:
23 Singer, J. D. (1958). Threat-perception and the armament-tension dilemma. Journal of Conflict
Resolution, 2(1), 90-105.
24 Cline, R. S. (1993). The power of nations in the 1990s: a strategic assessment. University Press of America.
1. Surveilling and Monitoring Domestic Groups
2. Strengthening and Enhancing National Cyber Defenses
3. Controlling and Manipulating the Information Environment
4. Intelligence Gathering and Collection in other Countries for
National Security Objectives
5. Growing National Cyber and Technology Competence
6. Destroying or Disabling an Adversary’s Infrastructure and
Capabilities
7. Defining International Cyber Norms and Technical Standards
4. Methodology and Discussion
Scoring Intent and Sources
To identify which objective(s) each country is pursuing we created a set of
unique 32 intent indicators, alongside additional assessments captured as
‘intent factors’, and attributed attack data, that together formulate an intent
score. Half of the intent score was formulated using indicators derived
from each country’s public cyber-related documents, public announce-
ments and national cyber strategies, including evidence of funding. Given
the importance that we placed on demonstrated intent, the other 50% of
the intent score was allocated to evidence of attributed attacks.
From this evidence of attributed attacks, together with the other indicators
that demonstrate preplanning and predisposition, it is possible to infer an
overall general intent; that “which is presumed from the act of commis-
sion” from the actions of a Therefore, the intentions of a country
can also be inferred from the cyber-attacks and activities it conducts.
We include demonstrated intent because a country may not publicly state
their intention to achieve a specific objective for strategic reasons. How-
ever, there may be evidence that said country has pursued these objectives
through attributed cyber operations. For example, the Chinese govern-
ment has denied its use of cyber espionage to steal US intellectual property
for multiple years, describing the accusations as “slanderous”.26 However,
analysis conducted by multiple private sector organizations have attributed
cyber operations targeting US organizations back to Chinese
We examined the entries in CFR’s Cyber Operations Tracker between 2015
to December 2019 to determine where a country has had a cyber operation
attributed to it that helped the country achieve one of the seven objectives.
If a country had one or more cyber operations attributed to it, we would
give the country full marks on demonstrated intent for that objective. Due
25 Riverside City Sheriff’s Department (1975). Element of Intent in Criminal Law. Mount San Jacinto College.
26 Philip Wen. (2018) “China Denies Slanderous Economic Espionage Charges from US allies”. Reuters.
27 Many of these attacks are captured in the Council on Foreign Relations’ Cyber Operations Tracker
to the covert nature of cyber operations, we assume that if a country had
one attributed cyber operation, the country likely had conducted other
cyber operations that achieved similar goals and would likely continue to
pursue these methods.
As for stated intent, we conducted a two-pronged approach: an assessment
of a country’s stated intent by objective in the public domain, as well as an
in-depth analysis of overall intent.
A number of international institutions, including the UN and EU recom-
mend that countries produce a national cyber strategy, with ITU noting
that “By developing and implementing a National Cybersecurity Strategy, a
nation can improve the security of its digital infrastructure and ultimately
contribute to its broader socio-economic aspirations. National leaders need
to be strategic about the opportunities offered and the risks posed to their
countries by the digital environment; they also need to establish a clear
vision of the digital future they wish to create.”28 On this basis, we looked at
several factors relating to each country’s cyber strategy, including:
1. How comprehensive is the country’s cyber strategy—does it include
specific actions, owners, and objectives?
2. How long has the country had a cyber strategy for?
3. How regularly has the country updated its cyber strategy?
4. How recently has the country updated its strategy?
5. Has the country announced increased cyber funding since it last
published its strategy?
We conducted textual analysis of each country’s cyber strategy, as well
as other similar documents, to determine what objectives were laid out
in each document. To verify the findings, we applied natural language
processing (NLP) to pull out the top words and trigrams (sets of three
consecutive words) within each strategy. If a word or trigram referring to
an objective was surfaced using NLP and not surfaced through the manual
28 International Telecommunications Union. (2018). “Guide to Developing a National Cybersecurity
Strategy—Strategic Engagement in Cybersecurity”
scan, we double checked our assessment. For example, the words “norms,
international, Interpol” would likely refer to international norms, while the
trigram “actively, punish, adversary” would likely refer to the destruction
of adversary infrastructure. Countries without a publicly available strategy,
such as Iran, were assessed using expert analysis and third-party docu-
ments to identify and score their intent to achieve objectives.
A country that has a long-standing, publicly available cyber strategy, which
is publicly funded, would have a more-established governance framework
facilitating delivery of the strategy29. A long standing publicly available
cyber strategy increased the score a country achieved for its intent. Given
the dynamic nature of cyberspace and the rapidly changing threats and
opportunities, a country that did not regularly review its strategy is less
likely to be a leader in cyber thinking.
A study of iterations of national cyber strategies demonstrated how the
application of cyber means has evolved over time. Looking at whether a
cyber operation that achieved one of the seven objectives had been
attributed to the country’s government proved a country’s resolve to
achieve the objective through cyber means. Countries that have consis-
tently pursued cyber objectives for a longer period received a higher score.
We extensively researched each country’s websites, online publications,
and comments made by senior government figures to the media. With the
exception of the DPRK, we only assessed attributed or official government
resources. We did not use third-party sources, or leaked or hacked infor-
mation, as we wanted to establish the specific message each country was
communicating on its objectives and intentions. Finally, we analyzed mem-
bership of and participation in international institutions and organizations.
Table 4 shows how these strategy-based indicator scores fit into the overall
intent score. Table 5 shows the full set of questions that the indicators and
intent factors sought to address. The scoring method of these intent indica-
tors is displayed by objective in Annex C.
29 We recognize that some anomalies are able to execute government policy and be effective without a public
strategy and dedicated resource.
Table 4: Key for Scoring Intent Factors in Cyber Strategies
Indicator Scoring Method
The total period over which the country has had a Cyber Strategy Number of years from first strategy to 2020
Frequency of Strategies Period from first to last strategy divided by the total number of strategies published
Years since strategy last updated Number of years from last strategy to 2020
Score based on how many of the following elements the strategy contains:
1 General overview of threats and priorities
2 Detailed analysis of threats and clearly articulated priorities
3 Division of responsibilities between government departments
4 Detailed timeline OR success critera
Strategy review score
5 Detailed timeline AND success critera
Table 5: Questions asked in Overall Intent Scoring (by Objective)
# Surveillance Defense Control Intelligence Financial Commercial Offense Norms
1
Does the country have at
least one policy or law
enforcement agency with
specialist cyber-crime
expertise or that encour-
ages citizens to report
cyber-crime?
Has the country published a
cyber security plan that
defines how it will protect
government systems and/or
critical national
infrastructure?
Data law protection
strength
Does the country's cyber
military planning or
strategy documents, or
wider military planning or
strategy documents,
acknowledge that the
country has cyber intelli-
gence-gathering capability?
Is the country a member of
the Common Criteria
Recognition Arrangement
(CCRA)?
What is the quality of
participation across all 22
ISO/IEC Joint Technical
Committees?
Does the country's cyber
military planning or
strategy documents, or
wider military planning or
strategy documents,
acknowledge that the
country has a destructive
cyber capability?
How many of the past five UN
Cyber Government Group of
Experts (GGE) consultations
has the coun- try participated
in?
2
Does the country’s domes- tic
intelligence agency
acknowledge surveillance
cyber capabilities?
Does the country under- take
cyber awareness and cyber
hygiene campaigns?
Does the country's cyber
military planning or
strategy documents, or
wider military planning or
strategy documents,
acknowledge that the
country has cyber
capabilities to control and
manipulate the information
environment ?
Does the country's military
cyber unit or command
acknowledge that the coun- try
has a cyber intelligence
gathering capability?
Is the country a member of
the IEC System for
Conformity Assessment
Schemes for Electro-
technical Equipment and
Components (IECEE)?
Does the country have a
public-private partnership
initiative to grow its domestic
cyber industry, workforce, and
raise aware- ness of cyber
issues?
Does the country's military
cyber unit or command
acknowledge that the country
has a destructive cyber
capability?
How many times has the
country sponsored UN
GGE related resolutions
between 2012-2016? Out of a
total of five.
3
Is cyber crime, cyber
terrorism, or domestic
surveillance via cyber means
referred to within the country's
domestic counter-terrorism or
home- land security strategy,
plan, or law?
Has the country stated it plans
to undertake national active
cyber defense-style effects?
Does the country's military
cyber unit or command
acknowledge that the
country has cyber
capabilities to control and
manipulate the information
environment?
Does the country's signals
intelligence agency or foreign
intelligence service
acknowledge that the coun- try
has a cyber intelligence
gathering capability?
Has the country published a
plan or strategy to attract
investment towards cyber
firms or growing its cyber
exports?
Is there evidence the country
has invested in or funded
cyber research?
Does the country's signals
intelligence agency or foreign
intelligence service
acknowledge that the country
has a destructive cyber
capability?
How many times has the
country participated in the
Internet Governance
Forum (IGF) between 2015-
2019?
4
Consistency of objective: is it
pursued in >1 strategy?
Consistency of objective: is it
pursued in >1 strategy?
Does the country's signals
intelligence agency or
foreign intelligence service
acknowledge that the
country has cyber
capabilities to control and
manipulate the information
environment?
Consistency of objective: is it
pursued in >1 strategy?
Consistency of objective: is it
pursued in >1 strategy?
Consistency of objective: is it
pursued in >1 strategy?
Consistency of objective: is it
pursued in >1 strategy?
Has the country partici- pated
in the Global Forum for
Cyber Expertise capac- ity
building activities?
5
If surveillance activity is
acknowledged in the
country's national cyber
strategy: include strat- egy
score
If strengthening and
enhancing national cyber
defenses activity is
acknowledged in the
country’s national cyber
strategy: include strategy
score.
Consistency of objective: is it
pursued in >1 strategy?
If intelligence activity is
acknowledged in the
country's national cyber
strategy: include strat- egy
score
If amassing wealth and/or
extracting cryptocurrency
activity is acknowledged in
the country's national cyber
strategy: include strategy
score
If growing national cyber
and technology
competence activity is
acknowledged in the
country's national cyber
strategy: include strat- egy
score
If destructive activity is
acknowledged in the
country's national cyber
strategy: include strat- egy
score
What is the quality of
participation across all 22
ISO/IEC Joint Technical
Committees?
6
If surveillance activity is
acknowledged in the
country's national cyber
strategy: include finan-
cial score
If strengthening and
enhancing national cyber
defenses activity is
acknowledged in the
country’s national cyber
strategy: include finan-
cial score
If controlling and manip-
ulating the information
environment activity
is acknowledged in the
country's national cyber
strategy: include strat- egy
score
If intelligence activity is
acknowledged in the
country's national cyber
strategy: include finan-
cial score
If amassing wealth and/or
extracting cryptocurrency
activity is acknowledged in
the country's national cyber
strategy: include financial
score
If growing national cyber
and technology
competence activity is
acknowledged in the
country's national cyber
strategy: include finan-
cial score
If destructive activity is
acknowledged in the
country's national cyber
strategy: include finan-
cial score
What is the quality of
participation across
the International
Telecommunication
Union’s Standardization
Study Groups 13 (Future
Networks), 17 (Security),
and 20 (IoT and Smart
Cities)?
7
Has the country been
attributed to a cyber attack
that assists this objective?
(50% of the score)
If controlling and manip-
ulating the information
environment activity
is acknowledged in the
country's national cyber
strategy: include finan-
cial score
Has the country been
attributed to a cyber attack
that assists this objective?
(50% of the score)
Has the country been
attributed to a cyber attack
that assists this objective?
(50% of the score)
Has the country been
attributed to a cyber attack
that assists this objective?
(50% of the score)
Has the country been
attributed to a cyber attack
that assists this objective?
(50% of the score)
Has the country par-
ticipated in bilateral or
multilateral cyber defense
exercises?
8
Has the country been
attributed to a cyber attack
that assists this objective?
(50% of the score)
Consistency of objective: is it
pursued in >1 strategy?
9
If defining international cyber
norms and technical
standards activity is
acknowledged in the
country's national cyber
strategy: include strategy
score.
10
If defining international cyber
norms and technical
standards activity is
acknowledged in the
country's national cyber
strategy: include financial
score.
Cyber Intent Index (CII)
The Cyber Intent Index is based on the ratings of 32 indicators which are
grouped under the seven national objectives: (1) surveillance, (2) defense,
(3) control, (4) intelligence, (5) commerce, (6) offence, and (7) norms.
These, combined with the score for intent factors within Cyber Strategies,
plus the score for attributed attacks make up the overall intent score.
A country’s overall rating is the average of the seven national objectives.
We used a combination of dichotomous (1 for a yes and 0 for a no answer);
three-point scoring system (the possibility of a score is introduced, to
capture “grey areas”); and a percentage (shown in decimal form, between
and ).30
A country’s overall rating is the average of the seven national objectives
converted to a scale of 0 to 100 percent.
Results
After scoring the 30 countries across the 7 objectives, the top ten highest scor-
ing countries for intent were:
1. China
2. United States
3. United Kingdom
4. Russia
5. Netherlands
6. Israel
7. Spain
8. Australia
9. Canada
10. Iran
30 A similar approach was taken by the Economist Intelligence Unit Democracy Index and by Freedom House’s
Freedom in the World Index.
Table 6 shows the top ten ranking for intent by each objective.
Table 6: Top 10 Intent Ranking by Objective
# Surveillance Defense Control Intelligence Commercial Offense Norms
1 Russia UK US UK China UK UK
2 China Netherlands China US Iran US Germany
3 Vietnam France Russia Spain UK Israel US
4 Saudi Arabia US Vietnam Netherlands Japan Spain Japan
5 UK China Israel Israel Switzerland Russia France
6 Estonia Japan Iran Russia Netherlands Iran Switzerland
7 Netherlands Canada UK
New
Zealand
Sweden China Netherlands
8 Australia Sweden Germany Canada Australia Netherlands China
9 US Estonia
New
Zealand
Australia US Estonia Canada
10 Switzerland Australia France China Russia Australia Australia
Analysis
Each of the countries in the CII top 10 have a comprehensive range of evi-
dence across all objectives. Unsurprisingly, these countries scored highly
in “strengthening and enhancing national cyber defenses”. Given the long-
term focus of these countries in securing themselves against cyber-attacks,
most of these countries have not only tried to increase the resilience of
their domestic populations, but also pursued active cyber defense mea-
sures, such as US CYBERCOM’s persistent engagement strategy.
The weighting given to demonstrated intent within the score using
attributed attack data propelled several countries’ up the rankings. This in
part explains why China achieved the highest score for intent, scoring
above other countries who were more explicit in strategic documentation
as to their intent, or were equally active in international fora.
The scores for destructive cyber intent were the most polarizing. Just under
half the countries in our index are either not actively pursuing this objec-
tive, have not publicly confirmed they are pursuing it, or have not been
observed pursuing it. We assess that this is for two main reasons: firstly,
the high level of technical competence needed to achieve these objectives,
and secondly, the international debate around how destructive cyber capa-
bilities comply with international law on armed conflict. The nations that
scored the highest in the destructive category were the UK and the US,
followed by Russia with the score gained by other nations quickly taper-
ing off. Few nations have been observed conducting a destructive act using
cyber capability. China, DPRK, the Netherlands, Iran, Israel, Russia, Spain,
UK, and the US were the only nations which received a score under this
objective. Many nations did not score highly or at all in this category
mainly because they are officially silent on whether they might undertake
destructive cyber operations. On this point, China’s intent score for offense
is particularly interesting as their official position is that they are against all
forms of cyber-attacks and advocate for the peaceful use of cyberspace.
15 countries demonstrated their intelligence intent by conducting cyber-at-
tacks that focused on the collection of information to improve their
situational awareness and understanding of a foreign country. Interest-
ingly, 21 countries acknowledged that they conduct intelligence activities
using cyber means, either through their military or through their signals
or foreign intelligence agency. Conversely, only three countries have been
observed conducting cyber-attacks for the purposes of industry espionage,
but 29 of the countries have also sought to grow their domestic cyber and
tech competence via legal means.
While 29 countries were observed pursuing legal wealth generation
via cyber means, only one country was observed pursuing it via illegal
means—DPRK. Only one country was assessed to have not demonstrated
its wealth generation intent at all—Egypt.
There are several limitations of this analysis that it is important to note.
Firstly, this project conducted searches in both English and the native
language of each country, using commercially available language transla-
tion software, and, where provided, English translations of non-English
documents. While our approach endeavored to be exhaustive, it is possible
that documents were missed, or the sentiment expressed was lost in transla-
tion. However, we also approached this analysis from the perspective that; for
a country to demonstrate specific intent it should be positively and actively
communicating its intentions to its domestic population and foreign observ-
ers. Therefore, documents that were difficult to locate on obscure websites
or behind firewalls do not communicate intent and we feel that the language
limitations did not fundamentally undermine our search process.
Secondly, some countries are clearly less willing to be transparent and
publicly share information, particularly around military and intelligence
matters. DPRK was the most secretive, For DPRK, we relied on credible,
non-state issued sources to allow us to offer scores for it across all objec-
tives. The only official DPRK sources we used were from its universities. It
was also very difficult to find information on the role and priorities of the
Egyptian military and intelligence community, as well as their counterparts
in a range of other countries.
Unsurprisingly, countries that had declared AND demonstrated their
intent scored highest in each objective. Largely due to its transparency on
cyber matters, as well as having conducted cyber intelligence and offensive
operations, the UK takes the top spot in four categories for intent.
Surveillance: Russia, China, Vietnam, and Saudi Arabia occupied the top
spots for the domestic surveillance objective. In addition to all four coun-
tries having been observed shutting down “illegal content”31 within their
domestic populace, all had law enforcement bodies and domestic intel-
ligence agencies with specific cyber capabilities, and all bar Saudi Arabia
referenced cyber threats within their homeland security or domestic ter-
rorism strategies or plans.
Control: This objective reflects the duality of cyber means. To score highly
in this objective a state has demonstrated control through either removing
extremist material and refuting foreign propaganda or through domestic
propaganda and creating and amplifying disinformation overseas. The
31 Russell, Jon. “Vietnam Threatens to Penalize Facebook for Breaking Its Draconian Cybersecurity Law.”
TechCrunch, TechCrunch, 9 Jan. 2019,
ens-to-penalize-facebook/.
United States topped this objective because of the former. The US scores
highly because of US military and intelligence agencies’ role in disrupting
the Islamic State’s ability to recruit and communicate with its fighters and
efforts to limit Tehran’s ability to spread propaganda post-9/11. In contrast,
China and Russia’s high rank is due in large part to the disinformation
campaigns that have been attributed to both countries since 2016.
Destructive: The cyber and military strategies of the UK, Israel, and the US
acknowledge that these countries have developed destructive cyber capa-
bilities. In addition, all three countries have demonstrated these capabilities
in offensive operations.
Intelligence: Given the information revealed in the Snowden leaks, it is
unsurprising that the UK and US top the intelligence objective. Spain
taking third place is possibly more interesting. Like the UK and the US,
Spain’s military and intelligence agencies have declared and demonstrated
their intent to use cyber means to gather intelligence.
Commercial: In-line with recent headlines in Western countries, China
tops the Growing National Cyber and Technology Competence objective.
Along with DPRK and Iran, China is one of only three countries assessed
to be pursuing this objective through both legal and illegal means. It
has been both observed conducting industrial espionage and sought to
incentivize and grow its domestic cyber expertise through research and
development, and public-private partnerships.
Norms: Of the 29 countries we found cyber strategies for, 27 of the coun-
tries noted their pursuit of Defining International Cyber Norms and
Technical Standards in their strategy. Only Egypt and India did not. Ger-
many came second in this indicator, which is consistent with Germany’s
wider support for international institutions and international capacity
building initiatives.
Defense: All the top five countries for the cyber defense objective have
pursued both increased cyber resilience and active cyber defense measures.
Graph 4 displays CII by Country across all seven objectives. Graph 5 dis-
plays the CII broken down by objectives.
Graph 4: CII 2020 by Country
100
Objectives
Surveillance
Defense
Control
Intelligence
Commerce
Offense
Norms
80
60
40
20
0
China
United States
United Kingdom
Russia
Netherlands
Israel
Spain
Australia
Canada
Iran
France
Germany
New Zealand
Japan
Sweden
Vietnam
Switzerland
ROK
Estonia
India
Ukraine
Italy
Turkey
Singapore
Malaysia
Brazil
Saudi Arabia
Lithuania
Egypt
Intent Index
Russia
China
Vietnam
Saudi Arabia
United Kingdom
Estonia
Netherlands
Australia
United States
Switzerland
New Zealand
Germany
Canada Turkey
Sweden Spain
Singapore
India
Ukraine
Malaysia
Japan
Italy
France
ROK
Lithuania
Israel
Egypt
Iran
Brazil
Surveillance
United Kingdom
Netherlands
France United
States
China
Japan
Canada
Sweden
Estonia
Australia
Switzerland
Spain
New Zealand
Germany
Malaysia
Brazil
Russia
Turkey
ROK
Israel
Italy
Singapore
Lithuania
Ukraine Saudi
Arabia
India
Iran
Egypt
Vietnam
Defense
United States
China
Russia
Vietnam
Israel
Iran
United Kingdom
Germany
New Zealand
France
Australia
Japan Canada
Netherlands
Spain
Sweden Italy
Ukraine
Brazil
Switzerland
ROK
Estonia
Lithuania
Singapore
Malaysia
Turkey
Saudi Arabia
Egypt
India
Information Control
Intent Score
Intelligence
Intent Score
Commerce
Intent Score
Offense
Intent Score
Norms
United Kingdom
United States
Spain
Netherlands
Israel
Russia
New Zealand
Canada
Australia
China
ROK
Iran
Vietnam
India France
Ukraine
Sweden
Japan
Germany
Switzerland
Italy
Singapore
Turkey
Estonia Brazil
Lithuania
Saudi Arabia
Malaysia
Egypt
China
Iran
United Kingdom
Japan
Switzerland
Netherlands
Sweden
Australia
United States
Russia
Spain India
Israel
Turkey
Singapore
Malaysia
ROK
New Zealand
Italy
Canada
Ukraine
Germany
France Saudi
Arabia
Brazil
Vietnam
Lithuania
Estonia
Egypt
United Kingdom
United States
Israel
Spain
Russia
Iran
China
Netherlands
Estonia
Australia
Germany
France
Canada
Sweden
ROK
Japan
Vietnam ●
Ukraine ●
Turkey ●
Switzerland ●
Singapore ●
Saudi Arabia ●
New Zealand ●
Malaysia ●
Lithuania ● Italy
●
India ●
Egypt ●
Brazil ●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
United Kingdom
Germany
United States
Japan
France
Switzerland
Netherlands
China
Canada
Australia
Estonia
Sweden
Spain
Russia
ROK
Turkey
Israel
India
Malaysia
Italy
New Zealand
Ukraine
Singapore
Brazil
Egypt
Vietnam
Lithuania
Iran
Saudi Arabia
Intent Score Intent Score Intent Score Intent Score
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
G
ra
ph
5
: C
II
2
0
20
b
y
O
bj
ec
tiv
e
an
d
C
ou
nt
ry
36
N
at
io
na
l C
yb
er
P
ow
er
In
de
x
20
20
: M
et
ho
do
lo
gy
a
nd
A
na
ly
ti
ca
l C
on
si
de
ra
ti
on
s
Scoring Capabilities and Sources
To become a cyber power, a country requires capabilities to achieve their
intended objectives. Cyber capabilities relate to the creation, control and
communication of electronic and computer-based information infra-
structure, networks, software, and human Therefore, countries
invest in a wide range of resources including areas such as military cyber
capabilities, cyber defense, and surveillance, but also in human capacity,
institutional strengthening, and domestic policy. In addition, being able
to influence the global context of cyberspace, be that through technical
standards, international norms, or exports, allows countries to cultivate an
environment in which they can protect their interests and exercise their
power to extend their zones of influence. Thus, countries will attempt to
control cyberspace not just within their own borders, but internationally as
well. We have considered all the above elements when assessing countries’
cyber capabilities by objective.
The complex source of cyber power is reflected in our mapping of each
national objective to indicators that reflect a country‘s capability to achieve
said objective. Many indicators contribute to more than one objective
and as a result some indicators have counted in multiple objectives to
reflect that overlap. Table 7 explains the mapping of indicators to national
objectives and a high-level overview of our approach to scoring. Annex B
provides a more in-depth description surrounding each capability indica-
tor’s scoring.
The 27 capability indicators included in the NCPI reflect a more compre-
hensive list of capabilities than what was previously available moving us
toward a more realistic and comparable understanding of cyber power
at the national level. The data collected on capabilities can be categorized
into eight themes: Evidence of Attacks; National Online Content; Domes-
tic State Cyber structures; Cyber Vulnerability Mitigation; Private Sector,
Trade, and Innovation; Connectivity; Workforce; and Legal and Policy
32 Daniel T. Kuehl. 2009. ‘From Cyberspace to Cyberpower: Defining the Problem’, In Franklin Kramer, Stuart
Starr and Larry K. Wentz (eds.) Cyberpower and National Security. Washington DC: National Defense
University Press. p24
33 These themes are purely for conceptual ease and do not affect our NCPI calculations.
Table 7: Capability Indicators Mapped to Objectives
Indicator
D
om
es
ti
c
Su
rv
ei
lla
nc
e/
M
on
ito
ri
ng
N
at
io
na
l C
yb
er
D
ef
en
se
In
fo
rm
at
io
n
C
on
tr
ol
In
te
lli
ge
nc
e
C
ol
le
ct
io
n
C
om
m
er
ci
al
G
ai
n
D
is
ab
lin
g
A
dv
er
sa
ry
In
fr
as
tr
uc
tu
re
In
te
rn
at
io
na
l C
yb
er
N
or
m
s
Objective(s) Mapping Explanation
Cyber Security Laws X X X
Cyber security laws allow a country to better control the data of its own population, interact with other countries, bolster defense, as well
as set precedent for how they will interact with foreign partnerships.
State-Sponsored Attacks X X X X X
State-sponsored cyber attacks allow a state to collect foreign intelligence, conduct corporate espionage, surveil dissidents,
spread disinformation, and disable adversary infrastructure.
Bilateral Cyber Agreements X
International cyber norm-setting can be measured by how active a state has been in creating informal and formal statements of
international collaboration.
Multilateral Cyber Agreements X
International cyber norm-setting can be measured by how active a state has been in creating informal and formal statements of
international collaboration. Multilateral agreements demonstrate consensus building between multiple states
Cyber Military Doctrine X
Cyber military doctrines facilitate cross-Goverment resources and direct them towards developing an offensive capability.
National Cyber Command X
Centralised Cyber Commands allow national governments to coordinate and harness multiple cyber capabilities to deploy
military cyber means when needed.
Global top 100 technology firms X X X
A state's technology firms grow its domestic industry and influences the industries of countries abroad, especially if the firm has a
large number of foreign users.
High-tech Exports X X X X
Exporting high-tech products to a foreign country can benefit a state's economy, and (depending on the state) may allow foreign
intelligence access to the data the products collect on foreign citizens. This can result in foreign dependence on the high tech export,
which could cause adversary capabilities to slow or halt if the exports stop.
Skilled employees in the technology
industry X X X
This capability is based on the question: “In your country, how easy is it for companies to find employees with the required skills for
their business needs? High availability of skilled employees allows for better recruitment into cyber security jobs (growing the
private sector), or better recruitment into government work (such as intelligence). A higher number of skilled employees within
cyber security and across a number of fields helpwith cyber defense.
Cyber Military Staffing X X
"It identifies the number of publicly acknowledged personnel assigned to military cyber roles.
this indicator reports absolute counts of individuals working in military cyber roles in a given country."
Global Top 500 Cybersecurity Firms X X
The greater number of cyber security ventures headquartered within a state, the greater the cyber security industry grows.
Computer Infection Rates X
The more computers that can be affected by non-state-sponsored malware, the more vulnerable national cyber defense likely
is.
Mobile infection Rates X
The more devices that can be affected by non-state-sponsored malware, the more vulnerable national cyber defense likely is.
Population % on Social Media X X
The greater number of citizens using social media, the more likely their data will be on the internet, causing more individuals to be
affected by domestic surveillance or data laws. However, more individuals on social media (in many cases) may result in a greater
amount of the domestic populace vulnerable to foreign disinformation campaigns.
Population % on the internet X X X
The greater number of citizens using the internet, the more likely their data will be on the internet, causing more individuals to be
affected by domestic surveillance or data laws. However, more individuals on the internet (in many cases) may result in a greater
amount of the domestic populace vulnerable to foreign disinformation campaigns, cybercrime or cyber espionage attempts.
Existence of Private Sector Surveillance
Technology X X
Greater number of surveillance companies within a state gives the state greater avenues and opportunities to monitor its own
citizens. The greater number of these companies, the more revenue the surveillance industry within the state pulls in.
Top Websites in Alexa top 50 X X
More internationally trafficked websites with corporations headquartered within a state gives the state more power to push common
narratives or ideals popular within a given state on the Internet, and also allow the corporation that owns the website to generate more ad
revenue or deliver more product to consumers.
Top News Sites in Alexa top 50 X
More internationally trafficked news sites headquartered within a state gives the state more power to push common narratives or
ideals popular within a given state on the Internet.
Successful Google Content Removal
Requests X
More successful Google content removal requests demonstrate that a country has effectively taken down information on the
internet, demonstrating an amount of control over the information space.
Freedom On The Net Score X
The less freedom on the net there is within a state, the more likely it is that the government is effectively able to surveil and monitor its
citizens, and the more likely it is that the state can effectively control information flow.
ICT Imports X X X
The more information and communication technology that is imported, the market need for domestic solutions may decrease, and
the state may incur higher supply chain risk within its domestic cyber infrastructure.
Patent Applications X The more patent applications exist within a country demonstrates innovation, which may lead to commercial gain.
Speed of broadband X
The faster the broadband speed, it is likely that more updated internet infrastructure exists, which ideally increases the likelihood of
better defensive mechanisms.
Speed of mobile X
The faster the mobile speed, it is likely that more updated internet infrastructure exists, which ideally increases the likelihood of
better defensive mechanisms.
Ecommerce economy X More e-commerce sales allow more revenue into the state's private sector retailers, growing the domestic economy.
Vulnerabilities listed in Shodan affecting
domestic machines X The more vulnerable a state's computers are in general, the more susceptable to attack a state may be.
Existence of Cyber Security Incident
Response Teams (CSIRTs) X
The existence of a CSIRT is an indicator that the country has provided resources to mitigating cyber vulnerabilities and related crises.
Global Soft Power X The more soft power a country has, the more it can influence others in adopting or maintaining international norms.
Cyber Capability Index (CCI)
The CCI is on a scale from 0 to 100 percent of the capabilities measured, and it is based on
the ratings of 27 indicators which are grouped by the seven national objectives.
The CCI can be broken down by objective and that score is based on the average value of
the normalized indicators that inform said objective. The overall rating of the CCI is the
average across all 7 objectives.
Before aggregating the indicators, we rescaled them using the Min-Max normalization
technique, which rescales data on different intervals based on minimum and maximum
values. Some of our indicators do not follow a Gaussian distribution, which prevents us
from using other normalization techniques (such as the z-standardization). The min-max
technique is widely applied for constructing composite It has the advantage of
setting the boundaries of all indicators between an identical range (a min of 0 and a max of
1). For every capability indicator, the minimum value gets transformed into a 0, the
maximum value gets transformed into a 1, and every other value gets transformed into a
decimal between 0 and 1.
One disadvantage is that the technique is based on the extreme values of a distribution
which strongly influence the final output. We have performed a series of sensitivity checks
using other normalization techniques to test for a potential bias resulting from extreme
values (see Section 4’s subsection on sensitivity analysis).
Results
The top ten countries per objective are listed in Table 8 below. Capabilities by country and
more specific rankings can be found in the Annex.
34 Patro, S., and Kishore Kumar Sahu. “Normalization: A preprocessing stage.” arXiv preprint arXiv: (2015).
Table 8: CCI 2020 by Objective
# Surveillance Defense Information
Control
Intelligence Commercial Offense Norms
1 US China US US US Russia US
2 UK Singapore Russia UK South Korea US France
3 France Canada China China China China Japan
4 China France South Korea Germany Japan Germany China
5 Japan Switzerland Sweden Singapore UK UK Germany
6 Sweden Netherlands Singapore Israel Singapore France Singapore
7 Canada US UK France Netherlands Netherlands UK
8 Germany Japan
New
Zealand
Malaysia Germany Spain Malaysia
9
New
Zealand
Germany Saudi Arabia Estonia France Estonia South Korea
10 Israel Sweden Canada Netherlands Switzerland Canada India
Analysis
The US scores highest on five out of seven objectives. Russia, which ranks
tenth overall in the CCI, tops the list for the offense35 objective. China leads
the ranking on cyber defense capabilities, Within its portfolio of cyber
capabilities, national cyber defense is the objective the US’ scored the
lowest where it ranked 7th out of 30 countries.
China is in the top 5 for every single objective. In recent years, China has
invested heavily in research and development of technologies that allow the
country to achieve multiple objectives in cyberspace. These results reflect
China’s increasingly dominant position in cyberspace but also highlight the
significant gap in capability between China and the US in most
The UK scores particularly high in two domains and comes third in the
overall ranking: intelligence and surveillance (in both cases the country is
35 Offense is short form for the destruction and disablement of adversary infrastructure objective.
36 Inkster, N., 2018. China’s Cyber Power. Routledge.
Cheung, ., 2018. The rise of China as a cybersecurity industrial power: balancing national secu- rity,
geopolitical, and development priorities. Journal of Cyber Policy, 3(3), -326.
topped only by the US). This is of no surprise: the country has tradition-
ally held strong positions in both the foreign intelligence collection for
national security purposes and the surveillance and monitoring of domes-
tic It has also devoted a substantial amount of public money to
strengthen its capabilities to achieve several of the assessed objectives.
Norms capabilities relied on a mix of international treaties and standards
bodies, as well as the norms defined by the technology a country exports.
Because of that, Japan and the US find themselves near the top of the list.
Russia is positioned at the forefront of the offense objective. The country
has an established cyber command and detailed cyber military doctrine, as
well as making headlines in this space over several Most notably,
the country has carried out a large amount of disruptive cyber-attacks over
the past This is a clear demonstration of its capability to destroy
and disrupt adversary infrastructure.
Singapore has focused heavily on national The country has not
taken any (known) disruptive actions in cyberspace, focusing its resources
on strengthening and enhancing its defense capabilities instead. Next to
Singapore, China, Canada, France, and Switzerland are all invested toward
promoting an environment that serves the same goal.
One area where the ranking is at odds with conventional thought is around
Israel. Israel is often put at the top of pseudo-rankings by commentators,
particularly highlighting its capabilities around offensive cyber and intelli-
gence gathering. We agree that this is an anomaly in this ranking, and this
could be down to several factors. Importantly, this index uses only open
source data. Much of Israel’s cyber program is coordinated and directed
covertly, and not in the public or business sectors. Secondly, this section
37 Kris, ., 2015. Trends and predictions in foreign intelligence surveillance: The FAA and beyond. J. Nat’l
Sec. L. & Poly, 8, .
Leigh, I., 2010. Intelligence and the Law in the United Kingdom. In The Oxford Handbook of National Security
Intelligence.
38 Giles, K., 2012, June. Russia’s public stance on cyberspace issues. In 2012 4th International Confer- ence on
Cyber Conflict (CYCON 2012) (pp. 1-13). IEEE.
39 Attacks are included in CFR’s Cyber Operations Tracker.
40 Ventre, D. ed., 2013. Cyber Conflict: competing national perspectives. John Wiley & Sons.
Ad’ha Aljunied, ., 2019. The securitization of cyberspace governance in Singapore. Asian Secu- rity,
-20.
of the NCPI measures capability. When looking at intent, Israel scored
highly for those two objectives. However, it does not necessarily have the
cyber-military industrial capacity, the economic power, or other key mea-
sures that have been considered to measure capability here.
The index also highlights several countries not normally associated with
being cyber powers, as having strong capabilities in certain areas. Malaysia
is in the top 10 four times for information control, intelligence, commer-
cial gain and norms and laws. Sweden is in the top 10 for three objectives:
surveillance, cyber defense, and information control. Switzerland made the
top 10 for cyber defense and commercial gain.
Estonia, often heralded as a beacon of cyber and digital capability, made
the top 10 for only two objectives: intelligence and offense. Whilst this is
impressive for a country of under million, it is perhaps not as impres-
sive as the team were expecting.
Germany, a country not often talked about when discussing cyber capabil-
ity, was ranked in the top 5 for intelligence, offense, and norms, being able
to draw on its strong industrial base and its well-organized military and
civilian capabilities.
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
●
Graph 6: CCI 2020 Across All Objectives
United States
China
United Kingdom
Germany
France
ROK
Singapore
Japan
Netherlands
Russia
Canada
Sweden
Estonia
Israel
Malaysia
Australia
Switzerland
Spain
New Zealand
Lithuania
Brazil
Vietnam
Italy
Turkey
Ukraine
India
Saudi Arabia
Iran
Egypt
0 10 20 30 40 50 60 70
Capability Score
80 90 100
Graph 7: CCI by Individual Objective
United States
China
United Kingdom
Germany
France
ROK
Singapore
Japan
Netherlands
Russia
Canada
Sweden
Estonia Israel
Malaysia
Australia
Switzerland
Spain
New Zealand
Lithuania
Brazil
Vietnam
Italy
Turkey
Ukraine
India
Saudi Arabia
Iran
Egypt
United States
United Kingdom
China
Germany
Singapore
Israel France
Malaysia
Estonia
Netherlands
ROK
Switzerland
Canada
New Zealand
Japan
Australia
Vietnam
Lithuania
Sweden
Italy
Russia
India
Spain
Brazil
Ukraine
Saudi Arabia
Egypt
Capability Index
0 20 40 60 80 100
Capability Score
Intelligence
United States
United Kingdom
France
China
Japan
Sweden
Canada
Germany
New Zealand
Israel
Netherlands
Australia
ROK
Singapore
Estonia
Malaysia
Spain
Switzerland
Lithuania
Russia
Brazil
Saudi Arabia
Italy
Turkey
Ukraine
Iran
Vietnam
Egypt
India
United States
ROK
China
Japan
United Kingdom
Singapore
Netherlands
Germany
France
Switzerland
Israel
Aust