NordVPN Promotion

Home / Blogs

What Reagan-Era Cyber Strategists Can Teach America Today

At a time when somewhat disturbing extra-territorial Executive Orders have recently emerged, it seems worth considering what a conservative icon from another era would be doing. The closest approximation of Ronald Reagan’s Cybersecurity Treaty was manifested in a set of events that actually occurred thirty years ago.

The History

At the outset, it is worth noting that the challenges of global cybersecurity and cybercrime have existed since the creation of transnational information networks. However, the mid-1990s were a special time when a trifecta of unfettered open global networks policies, lack of attention to infrastructure protection, and rapidly growing incentives of adverse threats by individuals and nation-state actors exponentially scaled the challenges. Several legendary figures came together.

The initiator was Prescott Bowman Winter who had emerged in the 1990s as the wunderkind principal internal leader within the National Security Agency. Winter went to Stephen Lukasik who as former DARPA Director, FCC Chief Scientist, and Defense Science Board chair had for decades developed the principal U.S. protection systems and by chance authorized the TCP/IP internet that was giving rise to the cybersecurity challenges. Lukasik was also a close colleague and friend of US DOD threat analyst Yoda Andy Marshall who masterminded U.S. security threat strategy since the early 1970s. They brought into the fold one of the foremost international legal mavens of the time—Abe Sofaer—who had served as a Federal judge, as Ronald Reagan’s advisor on international law at the State Department, and been appointed to the George Schultz chair at the conservative Hoover Institution.

The initiative was dubbed the Consortium for Research on Information Security and Policy (CRISP) under the aegis of Stanford University’s Center for International Security and Arms Control (CISAC). Lukasik also significantly engaged former colleague Seymour Goodman who had moved to Georgia Tech’s Sam Nunn School and David Longhurst at the UK’s Ministry of Defence. The mission was to develop means to deal with cyber-attacks directed against critical national infrastructures. The work was instantiated in numerous working papers—that were published in part in the Sofaer and Goodman draft treaty Proposal for an International Convention on Cyber Crime and Terrorism, The Adelphi Papers Protecting Critical Infrastructures Against Cyber-Attack, and a Hoover book The Transnational Dimension of Cyber Crime and Terrorism. Several years later in April 2005, a workshop of many of the original actors was convened at Georgia Tech.

Among the original CRISP papers in May 1997 is a prescient seminal paper authored by Lukasik alone on Public and Private Roles in the Protection of Critical Information-Dependent Infrastructure. In typical Lukasik fashion, he analyses every dimension of the challenge including methods and “red teaming” risks and benefits. His concluding observations provided a game plan for moving forward.

The earlier CRISP Draft International Convention To Enhance Protection from Cyber Crime and Terrorism continued to evolve. The Sofaer-Goodman August 2000 version sought to find a multilateral means for dealing with intractable challenges that included defining offenses, international cooperation for investigation and cooperation, jurisdiction and extradition, an international agency, and human rights. Notably, it also attempted extensively to deal with Lukasik’s treatment of private roles as well as the Council of Europe Cybercrime Convention which had emerged independently but failed to treat many of the most significant challenges. The effort was essentially a construct of the cybersecurity treaty that the Reagan Administration might have enacted to deal with enduring cybersecurity challenges.

Some of the Convention provisions built on the first attempt to instantiate an international treaty for cybersecurity in 1988 at Melbourne at the end of the Reagan Administration. Under International Telecommunication Union (ITU) auspices, it would have put in place provisions that implemented the National Security Agency’s Secure Data Network System (SDNS) begun in 1986 that was also supported by the National Communications System (NCS). However, a combination of subsequent marketplace and political developments put an end to its implementation.

The events of September 11 began changing everything. The COE Cybercrime Convention was adopted the next month as a fait accompli, and cyber-terrorism was wrapped into an array of unilateral and bilateral initiatives. Cybersecurity looked to other means instantiated under NSA’s Information Assurance Directorate (IAD) Systems and Network Attack Center (SNAC) and other agency entities, as well as numerous private-sector organisations such as the Center for Internet Security and SAFECode.

Today

Thus, the 12 August 2026 Executive Office of the President Executive Order is hardly novel. The Reagan cyber sages of another era contemplated in considerable detail the variables and means of treating transnational cyber-enabled crime using private action. They devised blueprints and programmes for challenges that have changed little and with significant cybersecurity harms suffered globally that emanate from the United States itself.

The “rub” comes in implementing “ensuring strict compliance with the U.S. Constitution and laws, as well as applicable international agreements” and avoiding collateral damage to U.S. companies and employees. Substantial consideration is also due the U.S. agencies and expert Federal employees who have invested their careers in nurturing the tenets and expanding the worldwide signatories of the COE Cybercrime Convention as well as the Second Protocol extension to cloud facilities. In an ideal world, the First Additional Protocol on Racist and Xenophobic cyber-crime would obtain U.S. support and ratification!

Epilogue

Lukasik continued working on cyber threat challenges under numerous programs—even on his deathbed—until he passed away in 2019. He sometimes referred to it as his “penance” for enabling the TCP/IP Internet in public infrastructure. He often did the work for Andy Marshall through the Defense Threat Reduction Agency (DTRA). One of his last papers was “Mass-Effect Network Attacks.” Lukasik and Marshall died within a few months of eachother, and their last interview together remains unavailable.

Prescott Winter retired from NSA dismayed at the state of cybersecurity, briefly joined the private sector, and retired. Notably, he briefly engaged in 2022 in the President’s National Security Advisory Committee (NSTAC) to initiate the policy of Zero Trust.

Roger Callahan who had led the SDNS initiative at NSA subsequently retired, instituted many of the financial industry’s security mechanisms at Bank of America, continued the efforts many years leading the cybersecurity group of the President’s NSTAC, and recently passed away.

Almost everyone who was part of the history settled into retirement. The author -became Lukasik’s assistant in 1979 and often Zeligesque facilitator living the related events over the past five decades - keeps the history alive.

NORDVPN DISCOUNT - CircleID x NordVPN
Get NordVPN  [74% +3 extra months, from $2.99/month]
By Anthony Rutkowski, Principal, Netmagic Associates LLC

The author is a leader in many international cybersecurity bodies developing global standards and legal norms over many years.

Visit Page

Filed Under

Comments

Comment Title:

  Notify me of follow-up comments

We encourage you to post comments and engage in discussions that advance this post through relevant opinion, anecdotes, links and data. If you see a comment that you believe is irrelevant or inappropriate, you can report it using the link at the end of each comment. Views expressed in the comments do not represent those of CircleID. For more information on our comment policy, see Codes of Conduct.

CircleID Newsletter The Weekly Wrap

More and more professionals are choosing to publish critical posts on CircleID from all corners of the Internet industry. If you find it hard to keep up daily, consider subscribing to our weekly digest. We will provide you a convenient summary report once a week sent directly to your inbox. It's a quick and easy read.

Related

Topics

New TLDs

Sponsored byRadix

Cybersecurity

Sponsored byVerisign

DNS

Sponsored byDNIB.com

IPv4 Markets

Sponsored byIPv4.Global

DNS Security

Sponsored byWhoisXML API

Brand Protection

Sponsored byCSC

Domain Names

Sponsored byVerisign

NordVPN Promotion