Abstract
The transnational nature of cyberspace alters the role of third-party countries (TPCs) in international conflict. In the conventional environment, military operations are primarily confined to the boundaries of the combatants or a designated war zone. However, during cyber conflicts, operations may occur on the digital infrastructure of states not otherwise involved in the dispute. Nevertheless, within the cyber conflict literature, little is said about TPCs who, by virtue of interconnectivity, may find themselves involved in a conflict not of their own making. Consequently, we examine the political and diplomatic hazards of cyber operations involving these actors. Through survey experiments involving participants from the United Kingdom and Canada, we assess the public opinion impact of an offensive cyber operation’s revelation on a TPC population. We find that while these incidents are viewed negatively, prior authorization and the involvement of an ally reduces this tendency. Such conditions lead the public to perceive these operations as corresponding with their national interest while suppressing fears of the possible consequences following their indirect involvement.
Introduction
In 2016 US Cyber Command launched Operation Glowing Symphony, a cyber operation intended to degrade and disrupt the digital infrastructure of the Islamic State of Iraq and Syria (ISIS) (Temple-Raston, 2019). However, before the first ISIS video could be deleted, the Obama administration was wracked by a bitter internal debate. Conventional military operations against ISIS principally occurred inside Iraq and Syria, but the group had a global digital footprint, and Glowing Symphony’s targets included 35 countries (Nance and Sampson, 2017). The question that confounded the Obama administration was not the use of offensive cyber operations but rather how the US should conduct operations against systems physically located within the sovereign territory of foreign governments – including US allies.
The diplomatic dilemma raised by Operation Glowing Symphony highlights the precarious position of third-party countries in the age of cyber conflict. In contrast to often physically constrained conventional uses of force, cyberspace’s transnationality and interconnectedness result in geographically dispersed operations that can cross multiple national borders and sovereign jurisdictions. Consequently, governments and populations who may not otherwise be parties to a dispute may nevertheless play unwitting hosts to digital dogfights waged across their networks. These states are defined as third-party countries (TPC) as they are not immediate parties to a conflict but are nonetheless involved as foreign actors conduct operations in or through their digital infrastructure.
This article explores the political and diplomatic hazards inherent in cyber operations involving TPCs and their implications for international politics. Building on recent public opinion scholarship in cybersecurity, 1 we employ survey experiments 2 to surface the reactions and consequences of cyber operations involving TPCs. 3 Utilizing the unique approach of treating participants as bystanders rather than targets, it illustrates the weight of host government approval, alliance status, and target identity on public perceptions. These conditions, in turn, shape sentiments toward threat perception and security partnerships in cyberspace.
While TPC populations respond negatively to cyber operations, prior authorization and an existing alliance temper this backlash. Such cooperative measures reduce the perceived consequences of the cyber operation and encourage participants to perceive an alignment with their underlying national interests. Furthermore, these conditions provide the foundation for future joint operations between the initiator and the TPC.
This article begins by examining the issue of conflict spillover into TPCs and how the transnationality of cyberspace constitutes a unique evolution of this phenomenon. We then outline our theoretical expectations and research design. Using a 2 × 2 × 2 research design, we test whether specific contexts like governmental approval influence the responses of the TPC population following the revelation of a cyber operation. For the United Kingdom and Canada, we find that while publics do not condone such operations, core characteristics like the perpetrator being an ally do matter.
Third-party countries in transnational conflicts
TPCs are states within whose borders a foreign cyber operation occurs but who are not a party to the operation as either an attacker or the intended target. For example, during Operation Glowing Symphony, US Cyber Command (attacker) conducted offensive cyber operations against ISIS (target). However, specific actions (e.g. deleting content) occurred on servers physically located within Germany (TPC).
The growth of cyber conflict as a theater of geopolitical competition (Fischerkeller et al., 2022; Valeriano and Maness, 2014) makes the situation of TPCs increasingly tenuous, but neither their contested status nor potential entanglement in foreign conflicts is novel. International conflicts are never wholly contained within the borders of combatants and may spill over into TPCs as a feature of militarized international disputes (Buhaug and Gleditsch, 2008; Salehyan, 2011; Siverson and Starr, 1991). Beyond the confines of combat, overfly privileges, transit agreements, and basing issues are emblematic of TPCs’ role in international disputes without being a party to the conflict (Mason, 2010; Pettyjohn and Kavanagh, 2016). However, the growth of transnational conflict in the 20th century featured TPCs as the loci for operations conducted on their soil between rival foreign factions. This trend gained prominence with the growth of transnational terrorism in the 1960s and 1970s. Groups like the Popular Front for the Liberation of Palestine and individuals like Carlos the Jackal pioneered tactics such as airplane hijackings that exploited a globalized environment and lax security conditions in TPCs to enable attacks against adversaries (Enders and Sandler, 2019; Hughes, 2014). Unsurprisingly, national governments like Israel also expanded their operations into TPCs in response (Klein, 2007; Reeve, 2011). Following the 9/11 terrorist attacks, the Bush Administration asserted a unilateral right to conduct counterterrorism operations against targets worldwide (Cronin, 2002; Patman, 2006). Consequently, TPCs became integral to the ‘Global War on Terror’, with friends and adversarial states integrated into US intelligence and counterterrorism operations (Clarke, 2004; Owen and Maurer, 2012; Schaller, 2015). This interventionist approach presented a unique challenge for US partners. While national governments might have supported combating international terrorism, how that conflict manifested within their borders or impinged on their sovereignty remained an open question (Acharya, 2007; Biswas, 2009; Jackson, 2007).
With transnational conflict and intelligence contests (Rovner, 2020) unfolding in cyberspace, TPCs have emerged as a critical facet of cyber conflict. This prospect is rooted in the transnational nature of the digital domain that is simultaneously dispersed yet geographically bound (Kello, 2013; Libicki, 2009). Cyberspace is a domain where information flows unimpeded by national boundaries yet relies on physical infrastructure like servers that exist in the terrestrial world and fall under the jurisdiction of sovereign states. Nevertheless, the ability to remotely create, access, or interact within cyberspace creates an enabling environment whereby actions are not limited by geographic proximity or national jurisdiction. This transnational environment muddies traditional notions of national sovereignty (Lambach, 2020; Mueller, 2020) and emphasizes the salience of TPCs since cyber operations can be conducted within the digital infrastructure of TPCs without either combatant being physically present. In the parlance of cyber operations, the entirety of the digital arena outside of one’s own networks (blue space) and those controlled by the enemy (red space) is known as gray space. However, rather than a digital no man’s land, gray space is populated by many users, companies, and governments who fill the digital domain and whose own systems might be ensnared in the crossfire of cyber conflicts waged across their networks (Smeets, 2019).
Operation Glowing Symphony exemplifies this dynamic. Although ISIS was based in Iraq and Syria, its digital operations included servers in the United States, Canada, Belgium, and the Netherlands (Nance and Sampson, 2017; Pop and Rasmussen, 2018). US Cyber Command created a list of ISIS targets, including 35 countries, as part of this operation. Declassified documents indicate the involvement of some foreign governments in planning the operation, but many others were not consulted (Department of Defense, 2016). Notably, whether to seek permission from the German government to conduct operations on their networks sparked a debate within the Obama administration (Nakashima, 2017). The administration eventually decided to notify the German government of the operation while purposefully not asking the Germans for either authorization or permission.
Operation Glowing Symphony heralded the growing role of TPCs in cyber conflict, but it was not an isolated occurrence. In March 2021, General Paul Nakasone, the head of US Cyber Command and the National Security Agency, testified that the US conducted over two dozen cyber operations to prevent interference in the 2020 US election. These included 11 hunt-forward operations in at least nine countries where US cyber forces worked with partners to address malicious actors (Gazis, 2021; Vavra, 2020). Nor is the United States alone in conducting cyber operations within the boundaries of TPCs. The opening salvos of the Russian invasion of Ukraine in February 2022 targeted a satellite communications company in California that disabled internet service to tens of thousands of users (Burgess, 2022). Amid such trends and the ongoing proliferation of cyber capabilities (Blessing, 2021; DeSombre et al., 2021), it is essential to understand how these are perceived within TPCs and the political fallout these may produce.
Accounting for third-party countries
To date, the issue of third-party countries in cyber conflict is conceived as a legal question focusing on the rights and protections afforded to TPCs under the laws of war (Lin, 2012; Schmitt, 2017). However, these concerns cannot be divorced from broader domestic and international political dynamics. Specifically, disclosing covert actions can inflame public sentiment (Otto and Spaniel, 2021) and stymie even the soundest geopolitical partnerships (Easley, 2014).
Despite their clandestine nature and emphasis on deception (Gartzke and Lindsay, 2015), cyber operations have the potential for highly visible and substantial effects (Saltzman, 2013). As cyber conflict is normalized as a domain of geopolitical competition, an improved understanding of public perceptions of these threats is a necessary step toward assessing cybersecurity as a political issue. Elite behavior does not unfold in a political vacuum, and public sentiment can be essential in guiding decisionmakers, especially in democracies (Risse-Kappen, 1991). Understanding popular sentiment in the wake of cybersecurity incidents provides a crucial window into how the public responds to threats emanating from the digital domain and the ensuing pressures that can shape national and foreign policies (Kreps and Schneider, 2019; Leal and Musgrave, 2023; Shandler and Gomez, 2023).
Scholarly inquiries into public reactions following cybersecurity incidents focus on issues like attribution (Gomez, 2019), threat perception (Kostyuk and Wayne, 2021; Kreps and Schneider, 2019), and retaliation (Hedgecock and Suskin, 2023; Leal and Musgrave, 2023; Shandler et al., 2021, 2022). These dimensions are substantive advances in understanding the popular responses to cyber operations but only consider the public’s immediate reaction in states directly targeted by cyber operations. Consequently, little is known about the reactions of third-party populations who are bystanders to cyber operations involving their digital infrastructure. The reactions of TPC governments and their publics can have significant consequences and pose significant challenges for future cooperation (Smeets, 2019).
Our study aims to understand how TPC populations respond to cyber operations conducted within their national networks and whether the context surrounding these incidents can substantively influence public opinion. In addition to furthering our understanding of popular sentiment and cyber operations, we examine whether existing theories of public opinion in military operations apply to cyber conflict.
Public reactions
Foreign operations within the territory of sovereign states are controversial, and public disclosure of these incidents can trigger significant public outcry regardless of their provenance (Lin-Greenberg and Milonopoulos, 2021; Otto and Spaniel, 2021; Smith, 2019). However, would such public backlash extend into cyberspace? Would the revelation of a foreign cyber operation within a country’s cyber infrastructure elicit widespread hostility towards the aggressor and punitive measures even if the population are bystanders rather than victims?
As a point of reference, evidence from covert or clandestine activities suggests that populations respond poorly when foreign actors exercise extraterritorial prerogatives and conduct operations inside TPC territory. Notable incidents include Israel’s capture of Adolf Eichmann in 1960, which sparked violent protests in Argentina, and the United States’ abduction of Abu Omar from Milan, severely compromising US–Italian relations. 4 A similar dynamic may color popular responses to foreign cyber operations especially given public apprehensions about cybersecurity (Carson, 2018; Poznansky and Perkoski, 2018).
However, widespread hostility cannot be assumed. Studies on public reactions to cyber operations have identified public anger following a cyber incident and a desire for retaliation. 5 Nevertheless, in all these studies, the population being examined is also the direct victim of the attack. It is unclear if this ferment would manifest within TPCs. Interconnectivity is a founding principle of the Internet (Mueller, 2020), and populations may not assert the same expectations of sovereignty to the digital domain that they accord to their country’s physical territory. Furthermore, given the pervasive malfeasance online and the already dim view of cybersecurity (Kostyuk and Wayne, 2021), the expectation that foreign actors operate within their digital space may be baked into citizen expectations. Rather than eliciting a public backlash, the presumed commonality of such cyber operations may yield a muted reaction, with populations failing to be shocked when informed that gambling is happening in the proverbial digital casino.
These considerations yield two rival expectations for how TPC populations may respond to being told that foreign cyber operations are being conducted on their network.
H.1A: The disclosure of cyber operations involving TPC cyber infrastructure will elicit a negative reaction from the public.
H.1B: The disclosure of cyber operations involving TPC cyber infrastructure will elicit no reaction from the public. (Null)
Seeking permission
Despite the possible backlash, we assert that adverse public opinion is assuaged through prior consent from the TPC government. As TPCs routinely authorize the use of their airspace or waterways for military operations, so will the TPC’s granting of permission for a cyber operation signal both foreknowledge and approval to its population. Furthermore, authorization from a TPC government could provide an essential cue for elite consensus on the operation, which may ameliorate widespread angst (Kreps, 2010).
The absence of domain expertise suggests that publics may depend on elite cues regarding the significance of specific operations. This view is reinforced by scholars who observe that cyberspace constrains the ability to account for possible contingencies (Dunn Cavelty, 2013; Kaminska, 2021). Consequently, individuals not directly involved in such affairs may defer to elites, given the cost and complexity of the issue (Holsti, 2004). Building on this argument, prior authorization may address public aversion, particularly democratic ones, that stem from perceived violations of a ‘transparency norm’ (Myrick, 2020; Poznansky, 2019). Proponents of this line of reasoning assert that the lack of approval creates costly domestic audience costs that could manifest in public disapproval. However, recent studies (Carnegie et al., 2023; Myrick, 2020) highlight that the desire for ‘transparency’ may be weaker than anticipated in that publics are willing to compromise certain normative expectations in favor of positive policy outcomes. Concerning TPCs, prior government approval may communicate the net positive outcome of a given cyber operation.
H.2A: Prior authorization from the TPC government reduces negative reactions from the public.
H.2B: Prior authorization from the TPC government will not influence reactions from the public. (Null)
Existing alliances
An established relationship between the TPC and the perpetrating state may shape public expectations. Absent more detailed information, the status of a perpetrating state as either a ‘partner’ or ‘ally’ may signal the benign nature of the operation and that it may even be in the best interests of the TPC. This argument coincides with value-signaling in other alliance arrangements (Berejikian and Justwan, 2022; Chu et al., 2021; Tomz and Weeks, 2021). Furthermore, it reflects the ability of the public to judge the merits of a foreign policy issue even without explicit elite cues (Kertzer and Zeitzoff, 2017). We have already seen that such trends carry into cyber conflict, with studies indicating that general populations are willing to aid allied governments being victimized by cyber aggression (Gunther and Musgrave, 2022; Gomez and Winger, forthcoming).
Conversely, having the perpetrator be an ally may exacerbate negativity in the TPC population. As seen with the Snowden revelations and ensuing uproar in Europe, the idea that one country would take advantage of an ally’s digital infrastructure is seen as a breach of trust and geopolitical partnership (Crowley, 2023). Populations may expect and accept that adversaries will violate their digital infrastructure. However, they may hold partners to a higher standard of conduct and be angered by such conduct from an ally.
H.3A: The status of the initiator as a TPC ally reduces negative reactions from the public.
H.3B: The status of the initiator as a TPC ally increases negative reactions from the public.
H.3C: The status of the initiator as a TPC ally has no effect on reactions from the public. (Null)
Target identity
Just as the relationship between the perpetrator and the TPC may influence public perceptions, so too may the nature of the operation’s target. Populations have expressed a strong willingness to conduct retaliatory cyber operations after a severe cyberattack (Shandler et al., 2021). However, this enthusiasm for striking back is moderated by concerns over future harm with the fear of escalation or further attacks tempering retaliatory desires (Gunther and Musgrave, 2022; Kreps and Schneider, 2019; Shandler et al., 2021). Consequently, we believe that a TPC population’s response to a foreign cyber operation on their networks might be substantively affected by the nature of the operation’s target and the possibility of becoming further embroiled in a more destructive cyber conflict. Specifically, Jarvis et al. (2017) note that identity and purported skill sets directly influence the level of concern expressed in news articles. While this does not explicitly distinguish between state and non-state actors, this does introduce an essential point of rival expectations. Notably, would the increased capabilities of state actors elicit more significant opposition from a TPC population given the prospect of entanglement in a state vs. state cyber conflict?
H.4A: Negative reactions from TPC publics increase if the ultimate target is believed to be a state actor.
H.4B: Negative reactions from TPC publics decrease if the ultimate target is believed to be a non-state actor.
H.4C: Reactions from TPC publics will not be affected by the target’s nature as a state or non-state actor. (Null)
Methodology
The article employs an Internet-based between-subject survey experiment with participants from the United Kingdom and Canada. It presents a fictitious scenario involving a cyber operation conducted by an unnamed state actor (aggressor) targeting cyber infrastructure owned and operated by organizations within these two countries (TPCs) that an unnamed adversary (target) previously utilized to conduct its own activities. The decision to run the experiment with two different country samples addresses the possibility of country-specific idiosyncrasies influencing the results. The United Kingdom and Canada were selected for theoretical and practical considerations. The UK and Canada have large digital infrastructures and, as of 2023, rank as two of the top ten countries in the web hosting market share. 6 This digital infrastructure means each country is a popular host for entities operating outside their geographic borders and a prominent target for malicious cyber actors (Center for Strategic and International Studies, 2023; Valeriano and Maness, 2014). These considerations make both countries probable TPCs to be entangled in outside cyber operations.
Furthermore, the geopolitical dispositions of each country also make them candidates to test how allies and prior authorization may color widespread reactions in TPCs. Both the UK and Canada are members of NATO, which has been explicitly targeted by malicious cyber operations and consequently been proactive in extending alliance responsibilities into the digital domain (Burton, 2015). As such, an ‘allied’ country operating in Canadian or British networks is highly plausible. Both countries are also members of the Five Eyes Intelligence Alliance (Pfluke, 2019), which facilitates intelligence sharing and the potential that a foreign state would be permitted to conduct a cyber operation within the borders of a TPC by that country’s government.
Treatments, outcomes, and covariates
To evaluate how cyber operations influence public opinion within TPCs (H.1) and if this sentiment is shaped by prior authorization (H.2), the existence of a prior alliance (H.3), or subject to the identity of the ultimate target (H.4), the scenarios are varied across the authorization, alliance, and actor treatments to create a fictitious news article.
7
Authorization establishes the operational parameters of the cyber operation as either having been approved (or not) by the TPC government and draws parallels between cyber operations and covert actions (Carson, 2018; Poznansky and Perkoski, 2018).
8
Complementing this, both alliance and actor introduce the underlying strategic context. Alliance clarifies whether an alliance exists between the initiator and the TPC.
9
Simultaneously, actor identifies the ultimate target as either a state or non-state actor. The full text of the scenario is as follows:
A document listing cyber operations by a foreign government has been leaked online.
The document reveals that the
These operations targeted servers located in
A fundamental feature of the scenario is that the initiator and target of the cyber operation are anonymized. Often, publicly disclosed information following a cybersecurity incident is ambiguous due to the difficulty of attribution or strategic (or operational) necessity (Egloff and Smeets, 2023; Hedgecock and Sukin, 2023). Furthermore, the identity of either party may influence participants to anchor their decisions on preconceptions of individual state and non-state actors (Herrmann et al., 1997; Holsti, 1967). For example, while Canada is allied with the US and Albania through NATO, would attributing the operation to either Washington or Tirana introduce a new point of bias, given the subjects’ respective sentiments towards each country? By not naming the perpetrator country but merely specifying whether it is an ally, we can examine the overall utility of ‘ally’ as a variable (Tomz and Weeks, 2021) without adding additional bias by identifying the specific country.
For our dependent variables, we focus on gauging the reactions of populations to the revelation of this outside cyber operation. However, our interest is not only in capturing the immediate fallout from these episodes but also understanding how this sentiment may translate into policy actions. Research has shown that while general populations largely lack the expertise to be effective policy barometers (Herrmann et al., 1999; Holsti, 1979; Rathbun, 2007), public sentiment is still an essential component of the policy process. Even in non-democracies, citizens can place considerable political pressure on their governments, which guides decisionmakers (Knecht and Weatherford, 2006; Weeks, 2008). This model of populations wielding indirect policy influence is common in public opinion research (Baum and Potter, 2008) and the most relevant outcome for our study. Specifically, individuals may lack either the means or knowledge to take direct action against foreign states who violate their nation’s cyber sovereignty. However, they can spur their own governments to action with potentially serious consequences for the aggressor state. Not only has this dynamic been evident in studies of clandestine operations (Myrick, 2020; Poznansky, 2019), but it may be especially relevant during cyber conflict where existing norms are weak and popular sentiment can play an essential role in shaping the political environment and guiding subsequent government actions (Gomez and Whyte, 2021; Shandler and Gomez, 2023).
These elements are measured using the binary response variables interest, consequences, and cooperate. Interest captures participant belief that the operation is beneficial to their country. The instrument is worded as follows: Do you believe that cyber operations of this nature are in the best interest of
Inversely, consequences indicate whether participants believe the cyber operation will negatively affect their country. The instrument is worded as follows: Do you believe that cyber operations of this nature would have negative consequences for the security of
Finally, the willingness of the participant to cooperate with the initiator is solicited. The instrument is worded as follows: Would you be in favor of continued cyber operations by the
Lastly, the cyber conflict literature acknowledges alternative explanations for public preferences following cybersecurity incidents. Specifically, established foreign policy attitudes and domain expertise may shape the public perception of incidents. Despite ongoing debate on foreign policy expertise among the public, evidence demonstrates that elite cues do not wholly govern public opinion and that the public hold beliefs independent of elites (Herrmann et al., 1999; Holsti, 1979; Rathbun, 2007). The experiment gauges support for militant, cooperative, and isolationist preferences (Kertzer et al., 2014). Using a seven-point Likert scale, participants are instructed to evaluate their support for statements representing these policy positions. The mean for each category is ascertained, and values closer to 7 indicate greater support.
Relatedly, domain expertise shapes participant perceptions of the incident. This is captured by knowledge using the instrument developed by Gomez and Whyte (2021), wherein participants are asked questions concerning cybersecurity concepts and incidents. The indicator is computed by tallying correct responses and dividing by the number of questions. Values closer to 1 suggest greater knowledge.
Recruitment
Internet-based panels such as Mturk, Prolific Academic, and Lucid Theorem provide researchers with a pool of participants for public opinion research whose performance does not differ radically from traditional in-person studies (Thomas and Clifford, 2017). However, this trend introduces challenges such as participant familiarity with experimental protocols and reduced engagement with the material. To address these concerns, specific recruitment criteria were introduced. This involved inviting only individuals who received reviews of at least 90% from other researchers on Prolific Academic and those who had not participated in the authors’ previous experiments. The latter reduced the likelihood of familiarity with the experimental design or cross-contamination. Furthermore, attention checks were included in the experimental design to ensure participant engagement with the material.
While our results explore the overarching dynamics of cyber conflict, the findings may not be generalizable beyond participants from the United Kingdom and Canada. Furthermore, while we did not recruit a representative sample from either country, studies have shown that results from convenience samples are comparable to their representative counterparts (Coppock, 2019; Coppock et al., 2018). These constraints do not detract value from the study but instead highlight the need for replications and further inquiry.
Results and analysis
We recruited 904 participants from the United Kingdom (UK) with a median age of 34, near-evenly divided between males (50.2%) and females (49.7%). The majority (57.2%) report having an annual income at or above the national median, with most participants (61%) possessing a Bachelor’s degree or higher. As for foreign policy attitudes, the sample favors cooperative policies (5.03, SD = 0.73) in contrast to militancy (3.58, SD = 0.84) or isolationism (3.29, SD = 0.88). Finally, domain knowledge is low (0.45, SD = 0.27).
For the outcome variables, 42.1% of participants felt that the operation was in the national interest of the UK. Furthermore, most (69.9%) felt the incident would negatively affect the UK. These trends are confirmed by the fact that 54% of participants do not wish to cooperate with the initiator in the future. These observations correspond with the expectation that foreign cyber operations engender a backlash among TPC publics, as hypothesized by H.1A.
The corresponding balance checks shown in the Online appendices confirm successful randomization. 10 This increases our confidence that the covariates are equally distributed across the different groups such that the corresponding values of interest, consequences, and cooperation could be ascribed to the effects of the authorization, alliance, and actor treatments – the goal of experimental design and the advantage it holds over observational studies. As the outcome variables are binary, we regress these three variables on the above treatments and covariates using a generalized linear model (i.e. logistic regression). 11 The results of these models are shown in Figure 1. For ease of interpretation, the coefficients are exponentiated such that exposure to a treatment or a unit increase in a continuous covariate increases the likelihood of the outcome variable by a given factor.

Model plots for United Kingdom participants.
Although negativity among participants is present (H.1A), this appears to be a function of the treatment conditions. The belief that this episode is in the best interest of the UK increases by a factor of 2.084 and 2.453 (p < 0.05) if the operation received prior authorization and is conducted by an ally. Relatedly, concerns about the consequences of such are suppressed by a factor of 0.679 and 0.376 (p < 0.05) if the initial conditions are present. Furthermore, the identity of the ultimate target is only statistically significant with respect to perceived consequences and increases by 1.385 if this is identified as a state actor (H.4A). These findings are further validated as the willingness to cooperate with the initiator increases by a factor of 1.895 and 3.017 (p < 0.05) with prior authorization and in the context of an alliance. Interestingly, militancy increases this willingness by 1.215 (p < 0.05). Consequently, these results appear to support H.2A and H.3A consistently – and H.4A to a lesser extent.
While these findings appear to validate that TPC backlash can be ameliorated through alliances and prior permission, the possibility exists that these results are unique to the United Kingdom. Consequently, we replicate the experiment with Canadian participants. As with the United Kingdom, Canada is a member of NATO and the Five Eyes Intelligence Alliance, which has been targeted by malicious cyber actors (Valeriano and Maness, 2014). A replication with a Canadian sample allows us to validate the results by controlling for the possibility of national confounders.
The instrument used for this replication corresponds with the one previously administered, except for an additional measure and the localization of the scenario for Canadian participants. Noting the possibility that participant preferences surface from a perceived violation of national sovereignty, we measure participant support for conventional activities that may be interpreted as violating sovereignty. These are represented by statements concerning (1) basing agreements, (2) overflights, and (3) foreign intelligence operations (Allen et al., 2020). Participants evaluate each statement using a seven-point Likert scale, the mean of which represents the value given to national sovereignty.
A total of 866 participants from Canada were recruited for this iteration. This sample has more female participants (54.5%), while its median age (31) remains comparable. As with their counterparts from the UK, the majority (60.77%) report having an annual income at or above the national median, while 66.5% possess at least a Bachelor’s degree. Concerning foreign policy attitudes, this sample is less inclined to favor cooperative policies (4.78, SD = 0.83) and appears more militant (3.67, SD = 0.83). However, support for isolationist policies between the two is low (3.29, SD = 0.93) and statistically comparable. Furthermore, both samples have comparatively low cybersecurity knowledge.
As with the earlier experiment, a minority (33.8%) perceive the operation is in Canada’s interest, while 79% believe that negative consequences will emerge from this episode. 61.3% of participants do not wish to cooperate with the initiator. Again, this supports our H.1A hypothesis that foreign cyber operations stoke public disapproval from TPC populations. As shown in Figure 2, both prior authorization and an existing alliance increase perceptions of national interest (1.594 and 2.259, p < 0.05) and suppress fears of consequences (0.067 and 1.577, p < 0.05). This pattern is also observed for cooperate (1.490 and 2.565, p < 0.05). Interestingly, actor exerts a statistically significant effect across all three dependent variables, with the involvement of a state actor decreasing interest (0.642, p < 0.05), increasing consequences (1.505, p < 0.05), and decreasing willingness to cooperate (0.670, p < 0.05). Consequently, the replication illustrates added support for the H.4A hypothesis that the nature of the target influences reactions.

Model plots for Canadian participants.
Complementing these findings is whether perceptions of sovereignty influence TPC public opinion in the wake of a cybersecurity incident. The results from the replication indicate that sovereignty concerns work in the expected direction, independently increasing concern for consequences by a factor of 1.488 (p < 0.05) while reducing perceptions of national interest (0.608, p < 0.05) and the willingness to cooperate (0.670, p < 0.05) in the future. This indicates that citizens assert ownership over their country’s cyberspace and react negatively toward violations of this digital sovereignty. However, interacting sovereignty beliefs with the appropriate treatments does not result in statistically significant coefficients. Consequently, while participants value the sovereignty of their state in general, this belief is not used to contextualize authorization, alliance, or actor. This, however, is not the case for all prior beliefs.
Further analysis reveals that militancy consistently moderates treatment effects on the outcome variables in the case of the UK sample. Regarding interest, militant UK participants tend to see the operation align with its national objectives if prior authorization is given (1.479). However, this is tempered when the ultimate target is a state actor (0.614). A similar trend is observed concerning consequences that find militant participants less concerned when the operation involves an allied state (0.565) and receives prior authorization (0.487). Furthermore, militant UK participants favor future cooperation with an allied state (1.558). Contrasting these findings, 12 militancy only plays a moderating role for the Canadian sample for cooperation. More militant individuals favor future operations with the initiator provided prior authorization (1.472) was given.
The moderating effect of militancy, especially in the case of the UK, suggests that participants perceive cyberspace as a domain of conflict – in keeping with the dominant elite narrative. While the experiment does not explicitly prove the susceptibility of publics to elite cues, it suggests the potential for resonance among a particular subset. This would imply that while participants would be able to evaluate the context (i.e. authorization, alliance, actor) and respond according to their understanding of interstate affairs, the possibility exists that elites could successfully instrumentalize established beliefs to their benefit (Guisinger and Saunders, 2017).
Discussion
The article reflects the growing trend in cyber conflict scholarship that sees a sustained effort in evaluating how the public responds to cybersecurity incidents. The article distinguishes itself by uniquely offering insight into how the public in third-party countries responds when it is disclosed that their infrastructure is involved in an operation that does not ultimately target them. We find that populations have an overwhelmingly negative response to such episodes. Most participants in the UK and Canada thought such operations were not in their country’s interests and would negatively affect their nations. This supports our backlash hypothesis (H.1A) and indicates that widespread opposition to foreign covert operations extends into the digital domain. However, while public reactions are negative, the formulation of the question wording does not allow us to discern how much this negativity is directed towards the aggressor, their own government, or both. Additional research would be beneficial to identify how publics assign blame for such cyber incidents.
Our results also provide insights into the larger issue of cooperative dynamics in cyber conflict. Whereas states have had decades to establish collaborative norms in conventional security, cyberspace remains a new arena of security cooperation, and confidence-building measures remain an essential task for security partners (Nye, 2014; Winger and Gomez, 2022). Consequently, it is significant that while both populations have negative reactions to cyber operations within their networks, prior permission (H.2A) and alliance relationships (H.3A) increased their willingness to cooperate with the perpetrator. For alliances, this suggests that the population may be willing to forgive their ally’s transgressions in cyberspace or at least not allow momentary displeasure to derail the overall partnership. Furthermore, these findings also strongly indicate that while seeking prior authorization from a TPC government may not be expedient, it yields real benefits by ameliorating public backlash and laying a firm foundation for future cooperation. However, our design does not account for the effects of either covert or overt cyber operations (Baram, 2023; Carson, 2018). This is worth noting as the inherent characteristics of cyberspace are thought to favor covert operations (Gartzke and Lindsay, 2015). Scholars wishing to build on our findings should take this alternative mechanism into consideration.
It also appears that the nature of the operation’s target may be a significant factor in determining reactions for TPC populations. In both the UK and Canada, the target being a state actor significantly increases concerns over incurring consequences from the operation. These results align with our H.4A hypothesis and indicate that the presence of a state actor increases concern for negative consequences for TPCs and erodes support for such activities. This is further evident in Canada, where a state target also reduced both beliefs that the operation was in Canada’s interests and overall willingness to cooperate with the perpetrator. This suggests that while TPC populations may be willing to support activities like Operation Glowing Symphony that target non-state actors, they would be more reticent about comparable actions against Russia or China.
Lastly, whereas past experimental research finds that established foreign policy attitudes and cybersecurity knowledge feature prominently in contextualizing the development of public opinion, our results are mixed. For participants in the United Kingdom, the moderating effects of militancy led participants to perceive the incident as supporting their respective national interests, reducing fear of consequences, and increasing preferences for future cooperation. Relatedly, militant Canadian participants saw the opportunity for continued collaboration with the initiator, provided that prior authorization was sought. This pattern is relevant as it (1) confirms the tendency of publics to rely on prior beliefs to ascribe meaning to events while (2) suggesting the resonance of narratives about cyberspace as a domain of conflict.
Surprisingly, participant cybersecurity knowledge does not appear to feature across both iterations of the experiment. This is of note as knowledge is perhaps the most consistent finding in the literature (Gomez and Whyte, 2021; Kostyuk and Wayne, 2021; Shandler et al., 2021). The absence of an independent or moderated effect may result from the participants’ beliefs regarding the relationship between cyberspace and interstate affairs. Suppose these events are treated as a new expression of existing interstate relationships. In that case, this belief (reflected by the moderating effect of militancy) is used as a reference point in place of their familiarity with recent events in cyberspace (i.e. knowledge). However, we cannot definitively assert this conclusion based on the existing research design, but this phenomenon warrants further study. Nonetheless, this finding surfaces the possibility that public opinion within TPCs is not exclusively derived from the motivated reasoning grounded in prior beliefs, but critical assessments of the strategic environment, as shown by the divergent results between the two experiments regarding the moderating effects of militancy.
While reduced dependence on prior preferences and limited expertise enables greater objectivity, information valuation is contextualized within the broader socio-political environment where individuals find themselves. Consequently, the experiment surfaces the possible influence of elite cues on public opinion concerning cyberspace and conflict. Although it is uncontroversial to state that elites have and continue to stir public perceptions of cybersecurity with different analogies and narratives (Lawson, 2013; Lawson and Middleton, 2019), these are often applied to publics, who are immediate victims of cyber operations rather than intermediaries.
As states adopt strategies that necessitate operating in allied or neutral cyberspace, TPC elites may need to solicit public support for such initiatives. Consequently, considerations such as appropriately framing underlying treaty obligations, managing partisan preferences, and weighing the need to keep the public abreast of these operations surface. Moreover, while scholarship focused on conventional interstate interactions has long since tackled these, such considerations remain conspicuously under-explored in cyber conflict scholarship. This gap in scholarly work is particularly pointed, owing to the possible variation in which publics may evaluate information across TPCs, as demonstrated using the Canadian sample.
Conclusion
Our research illustrates that cyber conflict cannot be conceived as merely a contest between blue and red teams. Instead, we must recognize that the domain itself is populated and can respond sharply to actions within its midst. Gray space is not merely a technical terrain but also a political domain with the potential for real consequences that cyber operators ignore at their peril. Whereas the literature finds that public opinion is inflamed by cyberattacks (Gomez and Whyte, 2021; Kreps and Schneider, 2019; Shandler et al., 2022), our findings illustrate that widespread backlash is not merely a matter of victimization. Instead, subjects in both the United Kingdom and Canada were sensitive to foreign intrusions into their nation’s digital infrastructure – even when their own country was not itself the ultimate target. Cyberspace may straddle the virtual and physical worlds, but populations assert ownership over their country’s digital space and react negatively to violations of that precept.
This aversion to foreign network intrusions, even when merely a bystander to a cyber operation, echoes the relationship between popular preferences and perceptions (Tomz and Weeks, 2021) and has immediate implications for more active cyber strategies. Notably, while persistent engagement and the use of externally oriented operations to ‘defend forward’ is viewed as a potential means of advancing US cybersecurity (Nakasone, 2019), it considers neither public opinion nor how relationships (i.e. allies versus partners versus adversaries) influence this strategic preference. Although repeated interaction may result in stability (Fischerkeller et al., 2022), these interactions do not occur in a vacuum and may prove counterproductive if diplomatic and political capital with the TPC is sacrificed. These findings suggest that episodes like Operation Glowing Symphony, where a TPC government was alerted to a cyber operation but not asked permission, may have been particularly detrimental in triggering a backlash from within the TPC and eroding support for future cooperation.
That both prior authorization and alliances assuaged this furor indicates that cyber operations involving TPCs need not be abandoned but rather must be institutionalized. Cyber persistence must not merely apply to behavior within the digital domain but also the political and diplomatic engagement needed to sustain international support for such endeavors and avoid suboptimal policy choices. While seeking authorization from TPC governments imposes constraints on speed, intensity, and control (Maschmeyer, 2021), permission-seeking can yield benefits beyond the confines of a specific operation by blunting widespread ire and providing a boon for future cooperation. Already we have seen this evolution unfolding in US cyber operations and the emergence of hunt-forward missions. US Cyber Command may incur added constraints and delays by approaching TPC governments as partners and developing hunt-forward missions as collaborative endeavors. However, our findings suggest that such engagement is essential for avoiding blowback and a boon for future cooperation. Consequently, the hunt forward model is more politically sound than hunting alone and paves the way for successful repeat interactions with TPC partners.
While the political benefits of the hunt-forward model are real, the ad hoc nature of these missions is insufficient to address the growing realities of cyber conflict. Even as cyber operations broaden the policy toolkit available to capable actors, scholars and policymakers alike must recognize that actions in cyberspace are neither detached from geopolitical considerations nor shaped solely by the underlying technologies. The political consequences for the intentional (or unintentional) involvement of TPCs in cyber operations cannot be ignored and must be accounted for within the strategic calculus of the digital domain. As the interconnectedness of the digital domain lends itself to TPCs being ensnared in cyber conflicts, it is imperative that cyber actors think through this challenge and proactively establish mechanisms for navigating these kinds of operations.
In situations where international alliances exist, these pre-established partnerships can provide an excellent mechanism for guiding cyber operations between allied states that strongly resonates with general populations. Indeed, it is worth noting that the publicly known partners in US hunt-forward missions have been US treaty allies or participants in established cooperative programs like the Partnership for Peace. Such initiatives should be expanded to other alliances where cyber cooperation may be limited (Winger, 2023) and institutionalized within the partnership frameworks. Even outside of alliances, just as Status of Forces Agreements have emerged to govern conventional military means, similar diplomatic and legal measures in cyberspace are warranted to resolve latent uncertainty and guide operational planners. Ultimately, the transnational nature of the Internet means that the inclusion of TPCs in cyber operations may not be avoidable, but it must be managed. Moreover, the intentional (or unintentional) involvement of TPCs and the consequences that may emerge cannot be ignored and must be accounted for within the strategic calculus of the digital domain.
Footnotes
Acknowledgements
We would like to thank the NATO Cooperative Cyber Defence Centre of Excellence (CCDCOE) for allowing us to present the preliminary version of the article at the International Conference on Cyber Conflict in 2022. We also extend our gratitude to the reviewers and editors at the Journal of Peace Research who provided thoughtful comments that helped to improve our article.
Replication data
The dataset, codebook, and do-files for the empirical analysis in this article, along with the Online appendix, are available at https://www.prio.org/jpr/datasets/ and
. All analyses were conducted using [R].
Funding
The author(s) received no financial support for the research, authorship, and/or publication of this article.
Notes
MIGUEL ALBERTO GOMEZ, PhD in Political Science (University of Hildesheim, 2023); Senior Research Fellow, Lee Kuan Yew School of Public Policy, National University of Singapore (2023–present); Senior Researcher, Center for Security Studies, Swiss Federal Institute of Technology (2016–23).
GREGORY H WINGER, PhD in Political Science (Boston University, 2017); Assistant Professor, School of Public and International Affairs, University of Cincinnati (2019–); Faculty Fellow, Center for Cyber Strategy & Policy (2019–present).
