This foreword introduces the issue by setting out how quickly cyber-war and cyber-crime events were escalating against corporate targets. The authors — Chris Colvin, Daniel Garrie and Siddartha Rao — point to the sophisticated intrusions on American banks reported in early 2013, and to the disruptive attacks that knocked out systems at American Express and JP Morgan Chase, as evidence that incident rate and threat level were rising together for the private sector. They note that some governments were responding with aggressive risk-management measures, citing the Israel Defense Forces.
Turning to the legal position, the authors describe an absence of legal and regulatory norms. Although there is consensus that the international law of armed conflict applies generally to cyber warfare, how far that application extends — and whether it extends at all in particular cases — remains unsettled, and attempts to bring cyber warfare within international-legal norms, among them the International Information Security Agreement, have been inconsistent.