A note before we start: both volumes are in German. If you or your German-speaking colleagues read the language, they are worth the effort — and if you do not, be aware that the full argument exists at book length only in German, though Gaycken has published a number of English-language papers on attribution and industrial cyber risk.

Most writing on cyber conflict is American, and it carries American assumptions: that offense and defense are conducted by the same agencies, that the private sector is a partner to the state, and that the strategic frame is great-power competition.

Sandro Gaycken wrote from Berlin, has advised the German government and German industry, and starts somewhere else entirely. His subject is a Europe that is industrially exposed, institutionally cautious, and dependent on infrastructure it does not control.

For any organization operating across the Atlantic, that second perspective is the one usually missing.

What the books actually cover

The two volumes are designed to work together. Cyberwar: Das Internet als Kriegsschauplatz (Open Source Press, 2011) establishes the domain — how digital conflict actually functions as a military and strategic problem, rather than as the catastrophist scenario the popular coverage favors. Cyberwar: Das Wettrüsten hat längst begonnen (Goldmann, 2012) takes the argument forward into the arms-race dynamic and its consequences for states that are not the largest players.

Gaycken's training is in the philosophy of science and technology, and it shows in the most useful way: he is unusually careful about what is actually demonstrated versus what is asserted. He is skeptical of the more theatrical claims made in this field, and equally skeptical of the reassurance offered by vendors selling the remedy.

Three arguments matter commercially.

Industrial espionage is the primary European exposure. Not infrastructure attack, not spectacular disruption — the patient extraction of technical intellectual property from companies whose engineering is their entire competitive position. For German industry specifically, that is the threat that has actually materialized.

Attribution and escalation are unresolved. A state that cannot confidently identify an attacker cannot respond proportionately, and Gaycken is clear-eyed about how much strategic doctrine rests on a problem nobody has solved.

Complexity is itself the vulnerability. His recurring structural point is that systems have been built to a level of interdependence that no one fully understands, and that security added afterwards cannot compensate for architecture chosen without it.

Cyberwar book cover

Why it matters for your risk posture

Read them for the industrial-espionage framing, which is the correct primary threat model for most European businesses and is consistently underweighted in Anglo-American analysis. If your value sits in engineering, formulations, process knowledge or customer relationships rather than in consumer data, your exposure profile is the one Gaycken describes.

Read them for the transatlantic difference. Regulatory posture, disclosure obligations, the relationship between state and industry, and the acceptable role of intelligence services all differ meaningfully between the United States and Germany. An organization operating in both is subject to both sets of assumptions, and reading only the American literature leaves half the picture missing.

And read them for the skepticism. Gaycken is an academic rather than a vendor, and he is unimpressed by both the threat inflation that sells services and the complacency that follows a quiet year. That is a useful register for anyone assessing security claims commercially.

Key takeaways

  • For European industry, the threat is extraction, not disruption. Patient theft of technical intellectual property is what has actually happened, and it is quiet by design.
  • Attribution is unsolved, and doctrine depends on it. Response strategies that assume you will know who did it are resting on an unresolved problem.
  • Complexity is the vulnerability. Security bolted onto an architecture chosen without it cannot fully compensate. That is a design finding, not an operations one.
  • The American literature is not the whole picture. If you operate transatlantically, the European institutional and regulatory frame is a separate body of knowledge.

About the author

Dr. Sandro Gaycken founded the Digital Society Institute at ESMT Berlin — a strategic research institute set up with backing from German industry — and directed it until 2021; his work has centered on the intersection of technology, security and strategy. He was previously a senior researcher at the Freie Universität Berlin.

His ESMT faculty biography lists roles including Oxford Martin School Fellow, Senior Advisor to the AI Initiative at the Harvard Kennedy School, program committee member of the Harvard-MIT conference series on cyber defense and cyber norms, Senior Fellow of the German Council on Foreign Relations, and a directing role within NATO's Science for Peace and Security cyber defense program.

The same biography records that, as an adviser to the German government, he contributed to the country's foreign cyber policy strategy, testified as an expert witness in Bundestag hearings, and took part in the Ministry of Defence's cyber defense white book process, and that he has published five scientific monographs, three of them on cyberwarfare, alongside more than sixty other publications.

Beyond the Book

Dr. Sandro Gaycken — founder and former director, Digital Society Institute, ESMT Berlin

  • The English-language work is scattered. If the German volumes are not accessible to you, Gaycken has published a number of English-language papers on attribution and industrial cyber risk, though the full argument exists at book length only in German.
  • The Institute is based in Berlin and works with industry. The Digital Society Institute at ESMT operates on digital and security questions for major German companies, and publishes its research. For a firm with German industrial clients, that is a directly relevant body of work.
  • He has spoken and testified frequently at European security conferences and in parliamentary settings.
  • Read alongside: Dark Territory by Fred Kaplan, covered here — the American institutional history, which is precisely the perspective Gaycken is writing against.

Cyberwar book cover

Get the book

Cyberwar

Sandro Gaycken

Find it on Amazon

Also on Amazon UK · Amazon DE

Where the proceeds go

We donate 100% of what we earn to Children of Fallen Heroes

If you buy through the link above we may earn a small commission, at no extra cost to you. Every penny of it goes to Children of Fallen Heroes, a registered 501(c)(3). We keep none of it.

They run an 82-acre campus for the children of military families, first responders and foster youth — STEAM education in aviation, robotics and drones, alongside leadership and healing programs. More than 15,000 young people and families have been through it in eleven years.

See their work

We participate in the Amazon Services LLC Associates Program and similar affiliate programs; these relationships do not influence our recommendations. Cookies and similar technologies record interactions with affiliate links — see our Privacy Policy to disable them, or reach us via Contact.

Discover more Insights from Falcone International

In “On Intelligence,” John Hughes-Wilson offers an insightful journey through the clandestine world of intelligence and espionage. Covering historical events to modern dilemmas, the book illuminates the inner workings of intelligence agencies and their impact on world history. This exploration encourages critical thinking about the role of intelligence in society and the ethical issues it presents.

Fraud rises when budgets tighten. Pressure goes up, headcount comes down, and controls that quietly depended on someone having spare time stop working. This weekend read sets out where exposure concentrates during a downturn and which defenses actually hold: strong internal controls, systems that flag the patterns people miss, a crisis plan written before it is needed, and a culture in which raising an anomaly is not a career risk.

Joel Brenner sets the demand for transparency against the need for secrecy and finds that most institutions have no coherent answer to the collision. “Glass Houses” is less a privacy book than an account of what secrecy now costs, who can still maintain it, and how little of it survives in a world where nearly every action leaves a record somewhere.

Counterparty risk is the exposure you take on from the people you transact with — their solvency, their conduct, and their own counterparties. It rarely announces itself, and it is usually priced at zero until it is not. This guide sets out what counterparty risk actually covers, where it hides in ordinary commercial relationships, and how to assess it without stalling the deal.

Discover how we use our integrated capabilities for our clients

Case Studies and Client Stories