The European View of Cyber Conflict: The “Cyberwar” Books by Sandro Gaycken

Book of the Month, Due Diligence, Employee Fraud, Employee Training, External Threats, Financial Investigations, Global Business, Hacking, Industrial Espionage, Intelligence, International Trade, People, Phishing, Risk Management, Security

October 1, 2025

A note before we start: both volumes are in German. If you or your German-speaking colleagues read the language, they are worth the effort — and if you do not, the argument is available in Gaycken's substantial English-language work. Details below.

Most writing on cyber conflict is American, and it carries American assumptions: that offence and defence are conducted by the same agencies, that the private sector is a partner to the state, and that the strategic frame is great-power competition.

Sandro Gaycken writes from Berlin, has advised the German government and the country's largest listed companies, and starts somewhere else entirely. His subject is a Europe that is industrially exposed, institutionally cautious, and dependent on infrastructure it does not control.

For any organisation operating across the Atlantic, that second perspective is the one usually missing.

What the books actually cover

The two volumes work together. Cyberwar: Das Internet als Kriegsschauplatz establishes the domain — how digital conflict actually functions as a military and strategic problem, rather than as the catastrophist scenario the popular coverage favours. Cyberwar: Das Wettrüsten hat längst begonnen takes the argument forward into the arms-race dynamic and its consequences for states that are not the largest players.

Gaycken's training is in the philosophy of science and technology, and it shows in the most useful way: he is unusually careful about what is actually demonstrated versus what is asserted. He is sceptical of the more theatrical claims made in this field, and equally sceptical of the reassurance offered by vendors selling the remedy.

Three arguments matter commercially.

Industrial espionage is the primary European exposure. Not infrastructure attack, not spectacular disruption — the patient extraction of technical intellectual property from companies whose engineering is their entire competitive position. For German industry specifically, that is the threat that has actually materialised.

Attribution and escalation are unresolved. A state that cannot confidently identify an attacker cannot respond proportionately, and Gaycken is clear-eyed about how much strategic doctrine rests on a problem nobody has solved.

Complexity is itself the vulnerability. His recurring structural point is that systems have been built to a level of interdependence that no one fully understands, and that security added afterwards cannot compensate for architecture chosen without it.

Cyberwar book cover

Why it matters for your risk posture

Read them for the industrial-espionage framing, which is the correct primary threat model for most European businesses and is consistently underweighted in Anglo-American analysis. If your value sits in engineering, formulations, process knowledge or customer relationships rather than in consumer data, your exposure profile is the one Gaycken describes.

Read them for the transatlantic difference. Regulatory posture, disclosure obligations, the relationship between state and industry, and the acceptable role of intelligence services all differ meaningfully between the United States and Germany. An organisation operating in both is subject to both sets of assumptions, and reading only the American literature leaves half the picture missing.

And read them for the scepticism. Gaycken is an academic rather than a vendor, and he is unimpressed by both the threat inflation that sells services and the complacency that follows a quiet year. That is a useful register for anyone assessing security claims commercially.

Key takeaways

  • For European industry, the threat is extraction, not disruption. Patient theft of technical intellectual property is what has actually happened, and it is quiet by design.
  • Attribution is unsolved, and doctrine depends on it. Response strategies that assume you will know who did it are resting on an unresolved problem.
  • Complexity is the vulnerability. Security bolted onto an architecture chosen without it cannot fully compensate. That is a design finding, not an operations one.
  • The American literature is not the whole picture. If you operate transatlantically, the European institutional and regulatory frame is a separate body of knowledge.

About the author

Dr Sandro Gaycken founded the Digital Society Institute at ESMT Berlin — a strategic research institute working on digital questions for Germany's largest listed companies — and works on the intersection of technology, security and strategy. He was previously a senior researcher at the Freie Universität Berlin.

His institutional reach has been unusually broad: he has held roles including Oxford Martin School Fellow, Senior Advisor to the AI Initiative at the Harvard Kennedy School, programme committee member of the Harvard-MIT conference series on cyber defence and cyber norms, Senior Fellow of the German Council on Foreign Relations, and a directing role within NATO's Science for Peace and Security cyberdefence programme.

As an adviser to the German government he contributed to the country's foreign cyber policy strategy, has testified repeatedly in the Bundestag, and participated in the Ministry of Defence's cyber defence white book process. He has published five scientific monographs, three of them on cyberwarfare, alongside more than sixty other publications.

Beyond the Book

Dr Sandro Gaycken — founder, Digital Society Institute, ESMT Berlin

  • The English-language work is extensive. If the German volumes are not accessible to you, Gaycken has published widely in English on cyberwarfare, attribution and industrial cyber risk. That is the route into the same argument.
  • The Institute is in Berlin and works with industry. The Digital Society Institute at ESMT operates on digital and security questions for major German companies, and publishes its research. For a firm with German industrial clients, that is a directly relevant body of work.
  • He has spoken and testified frequently at European security conferences and in parliamentary settings.
  • Read alongside: Dark Territory by Fred Kaplan, covered here — the American institutional history, which is precisely the perspective Gaycken is writing against.

Get your copy

Get your copy

Order Cyberwar on Amazon: find it here.

Discover more Insights from Falcone International

In “On Intelligence,” John Hughes-Wilson offers an insightful journey through the clandestine world of intelligence and espionage. Covering historical events to modern dilemmas, the book illuminates the inner workings of intelligence agencies and their impact on world history. This exploration encourages critical thinking about the role of intelligence in society and the ethical issues it presents.

This weekend read delves into the various risks businesses face during economic downturns, with a particular focus on the rise of fraud and malfeasance. It outlines several strategies to recession-proof a business, including fostering a culture of integrity, investing in human capital, leveraging technology, creating a robust crisis management plan, and implementing strong internal controls. By taking proactive measures, businesses can effectively manage risks, enhance resilience, and weather the economic storm.

In “Glass Houses,” author Joel Brenner dissects the paradox of privacy, secrecy, and cyber insecurity within our increasingly transparent digital age. Brenner presents a thorough exploration of the delicate balance between the need for secrecy and the demand for transparency in modern societies. Through his detailed examination of current cybersecurity issues, Brenner provides valuable insights into navigating the complex dynamics of privacy in a world where every action can be monitored and tracked.

In the world’s complex network of business transactions, counterparty risk stands out as an invisible game-changer. Frequently under-appreciated and easily overlooked, this element can silently sway a company’s fortune. This comprehensive guide seeks to demystify counterparty risk, illuminate its significance, and offer an efficient path toward its management.

Discover how we use our integrated capabilities for our clients

Case Studies and Client Stories