Cyber threats do not respect the Atlantic. This capstone reads U.S. and EU cyber cooperation through three schools of international relations theory and asks what a genuinely unified transatlantic defense would take.
The argument
The paper works through the same institutions three times. A realist reading sees NATO's cyber posture as states pooling capability against a shared adversary. A liberal reading emphasises the rules and agencies that make cooperation routine: the U.S. Cybersecurity and Infrastructure Security Agency on one side, the EU Cybersecurity Act on the other. A constructivist reading asks whether the two sides actually share a definition of the threat, and finds the answer less settled than the treaties suggest.
Each frame explains part of the record and misses part of it, which is the point: a durable transatlantic cyber regime has to work at all three levels, capability, institutions, and shared norms.
What the paper recommends
- Expand threat-intelligence sharing. Widen the channels through which indicators and attributions move between CISA, NATO's cyber bodies, and EU member-state agencies, so that a threat seen on one side is acted on by both.
- Build capacity in partner nations. Fund training and infrastructure in the alliance's weaker members, since a unified defense is only as strong as its least defended network.
- Set standards through public-private partnership. Most of the attack surface is privately owned. The paper argues for joint standards developed with industry rather than imposed on it.