A note before we start: both volumes are in German. If you or your German-speaking colleagues read the language, they are worth the effort — and if you do not, be aware that the full argument exists at book length only in German, though Gaycken has published a number of English-language papers on attribution and industrial cyber risk.
Most writing on cyber conflict is American, and it carries American assumptions: that offense and defense are conducted by the same agencies, that the private sector is a partner to the state, and that the strategic frame is great-power competition.
Sandro Gaycken wrote from Berlin, has advised the German government and German industry, and starts somewhere else entirely. His subject is a Europe that is industrially exposed, institutionally cautious, and dependent on infrastructure it does not control.
For any organization operating across the Atlantic, that second perspective is the one usually missing.
What the books actually cover
The two volumes work together. Cyberwar: Das Internet als Kriegsschauplatz (Open Source Press, 2011) establishes the domain — how digital conflict actually functions as a military and strategic problem, rather than as the catastrophist scenario the popular coverage favors. Cyberwar: Das Wettrüsten hat längst begonnen (Goldmann, 2012) takes the argument forward into the arms-race dynamic and its consequences for states that are not the largest players.
Gaycken's training is in the philosophy of science and technology, and it shows in the most useful way: he is unusually careful about what is actually demonstrated versus what is asserted. He is skeptical of the more theatrical claims made in this field, and equally skeptical of the reassurance offered by vendors selling the remedy.
Three arguments matter commercially.
Industrial espionage is the primary European exposure. Not infrastructure attack, not spectacular disruption — the patient extraction of technical intellectual property from companies whose engineering is their entire competitive position. For German industry specifically, that is the threat that has actually materialized.
Attribution and escalation are unresolved. A state that cannot confidently identify an attacker cannot respond proportionately, and Gaycken is clear-eyed about how much strategic doctrine rests on a problem nobody has solved.
Complexity is itself the vulnerability. His recurring structural point is that systems have been built to a level of interdependence that no one fully understands, and that security added afterwards cannot compensate for architecture chosen without it.

Why it matters for your risk posture
Read them for the industrial-espionage framing, which is the correct primary threat model for most European businesses and is consistently underweighted in Anglo-American analysis. If your value sits in engineering, formulations, process knowledge or customer relationships rather than in consumer data, your exposure profile is the one Gaycken describes.
Read them for the transatlantic difference. Regulatory posture, disclosure obligations, the relationship between state and industry, and the acceptable role of intelligence services all differ meaningfully between the United States and Germany. An organization operating in both is subject to both sets of assumptions, and reading only the American literature leaves half the picture missing.
And read them for the skepticism. Gaycken is an academic rather than a vendor, and he is unimpressed by both the threat inflation that sells services and the complacency that follows a quiet year. That is a useful register for anyone assessing security claims commercially.
Key takeaways
- For European industry, the threat is extraction, not disruption. Patient theft of technical intellectual property is what has actually happened, and it is quiet by design.
- Attribution is unsolved, and doctrine depends on it. Response strategies that assume you will know who did it are resting on an unresolved problem.
- Complexity is the vulnerability. Security bolted onto an architecture chosen without it cannot fully compensate. That is a design finding, not an operations one.
- The American literature is not the whole picture. If you operate transatlantically, the European institutional and regulatory frame is a separate body of knowledge.
About the author
Dr. Sandro Gaycken founded the Digital Society Institute at ESMT Berlin — a strategic research institute set up with backing from German industry — and directed it until 2021; his work has centered on the intersection of technology, security and strategy. He was previously a senior researcher at the Freie Universität Berlin.
His ESMT faculty biography lists roles including Oxford Martin School Fellow, Senior Advisor to the AI Initiative at the Harvard Kennedy School, program committee member of the Harvard-MIT conference series on cyber defense and cyber norms, Senior Fellow of the German Council on Foreign Relations, and a directing role within NATO's Science for Peace and Security cyber defense program.
The same biography records that, as an adviser to the German government, he contributed to the country's foreign cyber policy strategy, testified as an expert witness in Bundestag hearings, and took part in the Ministry of Defence's cyber defense white book process, and that he has published five scientific monographs, three of them on cyberwarfare, alongside more than sixty other publications.
Beyond the Book
Dr. Sandro Gaycken — founder and former director, Digital Society Institute, ESMT Berlin
- The English-language work is scattered. If the German volumes are not accessible to you, Gaycken has published a number of English-language papers on attribution and industrial cyber risk, though the full argument exists at book length only in German.
- The Institute is based in Berlin and works with industry. The Digital Society Institute at ESMT operates on digital and security questions for major German companies, and publishes its research. For a firm with German industrial clients, that is a directly relevant body of work.
- He has spoken and testified frequently at European security conferences and in parliamentary settings.
- Read alongside: Dark Territory by Fred Kaplan, covered here — the American institutional history, which is precisely the perspective Gaycken is writing against.

Where the proceeds go
We donate 100% of what we earn to Children of Fallen Heroes
If you buy through the link above we may earn a small commission, at no extra cost to you. Every penny of it goes to Children of Fallen Heroes, a registered 501(c)(3). We keep none of it.
They run an 82-acre campus for the children of military families, first responders and foster youth — STEAM education in aviation, robotics and drones, alongside leadership and healing programs. More than 15,000 young people and families have been through it in eleven years.
We participate in the Amazon Services LLC Associates Program and similar affiliate programs; these relationships do not influence our recommendations. Cookies and similar technologies record interactions with affiliate links — see our Privacy Policy to disable them, or reach us via Contact.
