Age of Deception: Cybersecurity as Secret Statecraft. By John R. Lindsay. Cornell University Press, 2025. 309 pp.
John R. Lindsay is an associate professor at the School of Cybersecurity and Privacy and the Sam Nunn School of International Affairs at the Georgia Institute of Technology. His research interests include emerging technologies and global security, reflected in his recent publications Elements of Deterrence: Strategy, Technology, and Complexity in Global Politics (2024) and Information Technology and Military Power (2020).
In his most recent book, Age of Deception: Cybersecurity as Secret Statecraft, Lindsay presents a competing and compelling view of the dangers associated throughout the cyber domain in our modern era. Although Lindsay does not dispute the severity and consequences of cyberwarfare, he raises many important questions about the political, technical, and international relations (IR) aspects surrounding warfare in this fifth domain of warfighting, adding greater context to the existing literature. Furthermore, Lindsay tries to consider nation-state and nonstate cybersecurity implications through the lens of secret statecraft, while challenging common narratives that cyberattacks alone can cripple a nation’s critical infrastructure or serve as justification for armed conflict between nation-states. As such, Lindsay argues that “cyber competition is a form of secret statecraft, or the use of organized deception for strategic advantage” (208).
Lindsay places a heavy emphasis on cyberspace intelligence collection processes from historical and modern perspectives. He provides relevant examples that include the Enigma, Stuxnet, 2016 Presidential election, Russia’s ongoing war in Ukraine, and Israel’s 2024 Hezbollah pager attacks. He also demonstrates that the fundamentals of intelligence collection as an instrument of statecraft have remained largely unchanged over time, even as modern and emerging technologies have transformed the methods through which intelligence is collected. Furthermore, Lindsay describes how ARPANET's developers attempted to address vulnerabilities that emerged during the network's development and deployment, but many of those efforts were subordinated to Cold War priorities that favored scalability and connectivity.
Lindsay devotes relatively little attention to the practical measures institutions can take to improve their resilience against existing and emerging cyber threats. Although, beyond the scope of this book, it would have been beneficial to a reader questioning how to defend against the cyber threats described. Lindsay argues that cybercrime occurs more frequently than cyberwarfare, though the evidentiary basis for this claim is not fully developed (12, 224). Yet, many institutions underreport cyberattacks because of concerns about reputational harm, public exposure, the acknowledgment of security vulnerabilities, and potential legal consequences. Additionally, cyberwarfare conducted by nation-states often occurs outside public view because of the secrecy associated with intelligence activities and national security operations. As a result, Lindsay's analysis relies primarily on open-source information and gives limited attention to activity that remains classified or otherwise inaccessible to public scrutiny.
While the author presents a compelling argument, the distinction between cybersecurity and cyberwarfare is not always clearly articulated. This ambiguity may prove problematic for policymakers and practitioners because the two concepts serve different purposes and carry different implications for cyber defense strategy and operations. The National Institute of Standards and Technology defines cybersecurity as the “prevention of damage to, protection of, and restoration of computers, electronic communications systems, electronic communications services, wire communication, and electronic communication, including information contained therein, to ensure its availability, integrity, authentication, confidentiality, and nonrepudiation.”1 Lindsay could have described some of these deceptive tactics from a cybersecurity perspective to eliminate confusion. While he presents a sound explanation regarding the origins of cyberspace as a domain, he inaccurately describes cyberspace as an institution. As noted by Robert J. Elder Jr., “although the Department of Defense (DoD) does not define ‘domain,’ it does define cyberspace as ‘a global domain within the information environment consisting of the interdependent network of information technology infrastructures and resident data, including the Internet, telecommunications networks, computer systems, and embedded processors and controllers’.”2
According to Lindsay, cyber operations do not function primarily through the logic of warfare or economic exchange but rather through organized deception. cybersecurity through the lens of intelligence collection, espionage, and subversion rather than as a series of discrete military engagements, Lindsay explains how and why states use digital tools to compete continuously in the gray zone. His analysis focuses on how trust in cyberspace enables these covert activities, arguing that their success depends less on technical superiority than on the political and institutional environments in which they occur.
Age of Deception: Cybersecurity as Secret Statecraft offers a thorough analysis of how and why cyber operations are employed in international relations, intelligence collection, and state competition by individuals, nation-states, and nonstate actors. This book is recommended for readers seeking strategic-level insight into the role of cyber operations within the Diplomatic, Information, Military, and Economic (DIME) framework, as well as a deeper understanding of how cyber operations influence contemporary statecraft and shape the battlespace of our modern era.
Lt Col Stephen J. Hoover, USAF, PhD
1 “Cybersecurity,” Computer Security Resource Center Glossary, National Institute of Standards and Technology (website), 12 May 2026, https://csrc.nist.gov/.