In 1983, Ronald Reagan watched the film WarGames — in which a teenager accidentally accesses a military computer — and asked his Joint Chiefs whether such a thing could actually happen.
The answer came back some weeks later: yes, and worse than that.
Fred Kaplan's history of cyber warfare begins there and runs forward three decades, and its central finding is not that the threat was unforeseen. It was foreseen almost immediately, described accurately, and repeatedly deprioritised. For anyone assessing organisational risk, that pattern is the more useful lesson.
What the book actually covers
Kaplan traces the institutional history: the early NSA work on information warfare, the 1997 Eligible Receiver exercise in which a small internal team demonstrated that critical American systems could be penetrated with commercially available tools, the Moonlight Maze intrusions, the establishment of Cyber Command, Stuxnet, and the progression from espionage to disruption to the contemplation of physical destruction.
The strategic material is what earns its place on a corporate shelf. Kaplan is clear-eyed about the structural problem at the heart of state cyber policy: the same agencies charged with defending national networks have an operational interest in the vulnerabilities remaining exploitable. A flaw disclosed and patched is a flaw no longer available for intelligence collection. That tension has never been resolved, and it explains a great deal about why defence has consistently lagged offence.
He is equally good on attribution, which is the practical difficulty that shapes everything else. Establishing who conducted an intrusion is slow, uncertain and frequently political, and a response cannot be proportionate to an actor you cannot confidently name.
The organisational pattern recurs throughout: capable people identify a vulnerability, write it up accurately, and are heard politely. Action follows an incident rather than a warning, and by then the cost has been paid.

Why it matters for your risk posture
Read it because your organisation almost certainly has its own Eligible Receiver — an internal assessment that identified a genuine exposure and was noted rather than funded. Kaplan's history is the large-scale version of a pattern that recurs at every size, and reading it makes the pattern easier to recognise in your own reporting.
Read it for the offence-defence tension, which has a direct commercial analogue. Wherever an organisation benefits from a gap remaining open — a control that would slow a revenue process, a disclosure that would embarrass a partner — the incentive to leave it open is real and rarely stated aloud. Naming that dynamic is the first step to overriding it.
And read it for the attribution problem. Boards routinely ask who was responsible after an incident, and the honest answer is usually slower and less certain than anyone wants. Understanding why is what allows a sensible conversation about response.
Key takeaways
- The warning is rarely the missing piece. Vulnerabilities are typically identified early, accurately, and by people who are then not resourced. Look at what your own assessments already say.
- Offence and defence compete for the same flaw. Wherever someone benefits from a gap staying open, it stays open. That incentive exists inside companies too.
- Attribution is slow, uncertain and political. Plan a response process that does not depend on knowing who did it.
- Incidents move budgets; reports do not. A structural fact worth knowing before you write the report.
About the author
Fred Kaplan writes the “War Stories” column for Slate and has spent a career covering national security, defence policy and the strategy community. He holds a doctorate in political science from MIT and previously reported for the Boston Globe, where he was part of a team awarded the Pulitzer Prize.
His books include The Wizards of Armageddon, on the civilian strategists who shaped American nuclear doctrine, The Insurgents, on David Petraeus and the counterinsurgency debate, and The Bomb, on presidential nuclear decision-making.
Dark Territory: The Secret History of Cyber War was published in 2016 and remains the standard narrative account of how state cyber capability developed.
Beyond the Book
Fred Kaplan — national security columnist, Slate
- Read him weekly, free: the “War Stories” column at Slate is ongoing and covers defence, intelligence and security policy as it happens. The book is a decade old; the column is the update.
- His other books: The Wizards of Armageddon is the one strategists cite, and The Bomb covers nuclear command decisions. Both apply the same institutional-history method.
- The primary sources are public. Much of the material Kaplan works from — commission reports, declassified assessments, congressional testimony — is freely available, and the book functions as a guide to where to look.
- Read alongside: The Cuckoo's Egg by Clifford Stoll, covered here — the first documented intrusion investigation, conducted while the institutions in Kaplan's book were still deciding whether any of this mattered.
Get your copy
Get your copy
Order Dark Territory on Amazon: find it here.
