Cyberpower, an interview
Contenu tiré d'un entretien mené par Bruna Toso de Alcântara en janvier 2025 dans le cadre de la rédaction de son futur ouvrage.
How do you see interactions in cyberspace? Do they involve power relations? Among which actors?
The technical and functional interdependence of actors in the digital sphere has not resulted in a horizontal arrangement in which each stakeholder would share governance, possess leverage, and thus be able to assert its voice and technological model. On the contrary, cyberspace reproduces and intensifies classical forms of domination, while inventing new modalities of power. It is far from the borderless global village once promised by the early web: it is composed of digital territories, of routes created, controlled, and maintained by border guards–complete with smugglers, pirates, and customs officers–who form the core of digital geopolitics. Power relations are omnipresent, opposing very different actors: states, transnational digital corporations, industrial consortiums, infrastructure managers... The ability to impose standards, to control critical chokepoints such as undersea cables, data centers, software infrastructures, or certain essential functional components, or even to concentrate data processing, creates hierarchy, reinforces asymmetry, and generates new forms of dependence. These power relations shape the room for maneuver or vulnerability of each actor. To analyze these actors, it seems essential to adopt a power-based approach grounded in dependency, in order to identify their capacity for control. This is why I rarely use the concept of "value chain," a notion from business theory intended for corporate strategy. Instead, we propose the concept of a "dependency chain": by decentering the focus from "value," the dependency chain appears as a more adequate methodological tool for grasping power relations, as it considers actors' leverage, their influence over technological, political, and geopolitical decisions.
How do you see cyber actors' capacity for achieving power in cyberspace? Would it be easier for one of them to gain cyber power? Why?
Many factors influence the acquisition of power, and therefore the favorable or unfavorable position of an actor within the dependency chain. From this perspective, we suggest considering two types of power that are useful for understanding the specific levers of power in the digital realm and for apprehending the hierarchy among involved actors. First, there is what one might call structural power. This term is used by Strange (1997), although I interpret it somewhat differently. Among the levers of structural power, one key advantage is being–or belonging to–an already constituted empire. Thus, serving the U.S. government or being a U.S.-founded company is a major advantage in a context of global expansion. Especially when that state puts in place a regime of funding and programs designed to foster business growth–either through a State-Science-Enterprise association of Big Science, or via a more liberal model of technological development, involving public subsidies to private actors or state-linked investment funds, which have enabled the emergence of Big Technology in the private sphere. Another structural lever is the actor's reach: limited to a national field or operating as a transnational, even global, entity. Transnational corporations enjoy particular advantages, such as choosing implantation sites based on favorable legislation, laying cable landing stations, or installing data centers. They can pit territories–often both clients and potential hosts–against each other, which one might also describe as peripheral zones. Other structural factors, similarly, must be taken into account, some of which are specific to digital actors. Secondly, there is another form of power especially relevant in the digital sector: nodal power. Without naming it as such, various scholars have highlighted levers of nodal power without ever fully defining them. Nodal power lies in the control of nodes or links within the dependency chain, which can become points of control and, in some cases, result in immediate and direct subordination for other actors, including states. Certain nodes may become mandatory passage points in the digital ecosystem–whether as functional gateways (cabled routes, data center hubs, computational capacity, software infrastructure nodes, etc.), relational intermediaries (platforms mediating between merchants and clients, the press and its audience, etc.), or as technological raw material (training data, hybrid open source–proprietary products, etc.). These two types of power ultimately shape an actor’s capacity for influence: structural power outlines the framework of influence, while nodal power specifies its critical points.
What elements do you believe would be necessary to constitute "cyber power"?
In a power approach grounded in dependency, what defines cyber power is the ability of a technology to exert control. Beyond the elements already discussed–structural and nodal forms of power–cyber power is also reinforced by an actor’s ability to adopt a rhizomatic structure. By rhizomatic structure, we are not referring to Deleuze and Guattari’s concept of the rhizome as a philosophical model of non-hierarchical organization, but rather to a naturalist metaphor of the rhizome as an organism extending both vertically and horizontally, expanding through nodes that nourish the network of secondary products. In this view, cyber power strengthens through two complementary movements: when an actor masters its core technologies and vertically integrates its production chains, and when it extends its influence into sectors beyond its own.
How do you see having and projecting cyber power? Are they the same thing?
To me, possessing cyber power refers to an actor’s position within the dependency chain, whereas projection reflects the exertion of its control–its capacity to influence architectures, practices, norms, technological or even political choices. There is a fundamental difference: one can possess technical power without projecting it beyond one’s own space; conversely, projection necessarily entails both the capacity and the will to affect others’ trajectories, to organize their dependency, to restrict their options. Major platforms, for instance, do not simply control their technical environment–they turn it into the matrix of their influence.
What would be, in your opinion, feasible ways for a state to project cyber power? For instance: using cyber proxies, cyber diplomacy, export national emerging technologies…
In the current context, it seems more relevant to first consider the relationship between states and dominant technology producers. We appear to be in a historical phase marking a new cycle in the relationship between the state apparatus and private actors with imperial ambitions. Each time a private entity has gained excessive influence over national or international political domains, states have responded by seeking to curb its power. One can recall the decline of chartered companies in the 18th and 19th centuries, arguably the most powerful manifestations of private imperialism in history. Faced with the excesses of the British East India Company–which held governmental functions in India, including tax collection, administering justice, and maintaining its own army–the British Empire ended its outsourcing of imperial power to such private corporations after the Sepoy Rebellion (1857). Later, when major trusts like Standard Oil, American Tobacco Company, or U.S. Steel were seen as threats to American democracy, the United States implemented antitrust policies to rein in these new private empires. Today, following a period of globalization and liberalization of key sectors–which was accompanied by the weakening of antitrust enforcement and state governance–public authorities are once again confronted with massive private entities that they struggle to regulate at a global scale. The present moment is likely one of reckoning, where efforts are emerging to reclaim state sovereignty, through known strategies such as antitrust policy or sovereign technological ambitions. In my view, to counter the dominance of private empires, states must step beyond market logics and focus on the essential foundations of society. In the digital realm, this means identifying areas such as health, education, journalism, and access to vital resources like energy or water as sanctuarized zones, in which private interests and profit-driven logics should be absent. In this way, states can exit the logic of delegation to individual predation and ensure protected spaces, immune to the prevailing economic models of the digital sphere (attention economy, filter bubbles, darkpaterns, etc.). To achieve this, technical responses are possible–likely based on open-source technological infrastructures in which industrial actors could participate, abandoning proprietary vendor lock-in models. But this also, and perhaps primarily, depends on a fundamental reorientation of the state's role–amounting, in truth, to a reconsideration of the dominant economic model.
How do you see the relationship between cyber power and national power (political, diplomatic, economic, and military)? Would these powers be detached from each other?
I believe cyber power is only one component of a state's broader power. It can serve as a tool for direct action–such as cutting access to a digital service–but also as a means of negotiation, used to obtain a concession, to influence legislation, or to secure the continuation of a service. Once again, these are relations grounded in asymmetrical dependency, but this extends beyond the digital domain to include other sectors as well, such as pharmaceuticals or energy.
How do you see the relationship between cyber power and states' position in the international system? For instance: Would this relationship exist? What format would it take (hierarchical/horizontal)? Would it justify states acting strategically in cyberspace?
Cyberspace tends to reinforce existing inequalities of power. It does not eliminate international asymmetries–if anything, it often magnifies them. The structure of core powers and dependent peripheries is particularly applicable to the digital world. That said, the international hierarchy of states, and what might be called state cyber power, rests above all on the position of technological actors that states help foster–provided those actors do not break away–rather than on technical capacities originating directly from states themselves. States do retain control over their digital borders: they can choose whether to allow certain technologies, to approve the landfall of transoceanic cables, or to authorize the construction of data centers. These prerogatives are sometimes used in defensive, authoritarian, or offensive ways, but they often give way to financial interests tied to digital expansion within a territory.
How do you think offensive and defensive capabilities affect cyber power? Would one of them be preferable over the other? Why?
I'm not entirely sure I understand this question... But I would say that it depends on the role digital technologies play in these offensive or defensive frameworks. Neither is inherently preferable to the other.
What elements do you consider essential for a state to maintain cyber power? How would you prioritize them?
It is impossible to answer on behalf of all states. In reality, each statefor continent – has its own specific factors contributing to cyber power. For example, a country with a long coastline acting as a gateway to a continent, and thus to neighboring states, can benefit from this initial geographical configuration to negotiate certain privileges in the dependency chain. By contrast, landlocked countries must rely on major infrastructures over which they have no control, and which could be cut off if needed. On another note, a country with a highly urbanized population and a political system that favors widespread surveillance may find a particularly favorable path through surveillance technologies and large-scale data processing–potentially exporting such systems elsewhere. One can thus imagine a wide array of national and international configurations, shaped by each actor’s specific positioning.
How would you rank your country scaling from 1 to 10, being 1 with no cyber power at all and ten as a cyber-superpower, both internationally and regionally? Justify your score.
You may find me a bit hard to deal with … ! But to produce a credible ranking, one would need to analyze each technological layer, each major dependency affecting national companies or even the state itself, in order to assess both strengths and weaknesses. Today, one of the most critical missing elements is the lack of a true observatory of dependencies–something that would allow for the beginning of a measurement process, and eventually a ranking. It is also through this preliminary measurement of dependencies that a state can begin to develop a genuine industrial strategy in a sector like digital technology.