Some of the hardest cyber policy debates begin with a surprisingly basic problem: people are using the same words to mean different things.
Terms such as "cyber operations," "cyber defense," and "active cyber defense” appear frequently in policy discussions. But government agencies, companies, lawyers, technical practitioners, and international institutions do not always use them in the same way. In some cases, the terminology can carry assumptions about legality, intent, authority, or risk before the underlying activity has even been clearly defined.
That is why one of the first steps for the Cyber Operations Policy Coalition was to develop a shared framework and lexicon. Our goal was not to invent an entirely new vocabulary. It was to establish a clearer foundation for the policy discussions that will follow.
Why start with terminology?
The Cyber Operations Policy Coalition was established to examine the policy, governance, and legal frameworks surrounding Collective Cyber Operations, particularly where government and the private sector may be working toward a shared cybersecurity objective.
These questions are increasingly important because cyber defense does not occur in isolation. Governments, private-sector organizations, service providers, researchers, legal experts, and other stakeholders can all play roles in understanding and responding to cyber threats. But those actors do not necessarily operate under the same authorities, responsibilities, legal frameworks, or risk considerations.
Before the Coalition can meaningfully examine questions involving authorization, oversight, accountability, public-private coordination, or international norms, members need a common understanding of the activities being discussed. A term like "active cyber defense," for example, can refer to very different activities depending on who is using it. One person may be describing activity conducted within an organization's own environment. Another may be referring to activity beyond that environment. Those differences can have significant legal and policy implications.
If those distinctions remain implicit, participants can appear to disagree about policy when they may actually be describing different activities altogether. A shared lexicon helps make those differences visible.
Starting with the activity, not the label
To accomplish this task, the Coalition's approach was to begin with the underlying conduct rather than immediately categorizing an activity as defensive, offensive, or something in between.
Our working definition of a Cyber Operation is “the use of cyber capabilities to cause cyber effects in or through cyberspace.” This definition is intentionally connected to other terms in the framework.
We define a Cyber Capability as “a tool, technique, service, system, or combination of software, firmware, hardware, or infrastructure used to create cyber effects.” Our definition of a Cyber Effect focuses on what actually occurs: “accessing, altering, disrupting, impairing, or destroying data, hardware, software, an information system, or a digital service in or through cyberspace.”
Taken together, these definitions give us a more structured way to discuss cyber operations. What is the actor doing? What capability is being used? What effect is being created? Where is the activity occurring? And under what authority? Those questions provide a more useful starting point for policy analysis than relying on a label that may mean different things to different participants.
Collective Cyber Operations
The Coalition's work is particularly focused on Collective Cyber Operations, which we define as “cyber operations coordinated among multiple public and/or private entities to address a shared cyber threat or common cybersecurity objective.” The collective dimension matters because coordination introduces additional policy questions.
Government and private-sector actors may be pursuing the same cybersecurity objective while operating under very different authorities and responsibilities. What one actor is legally permitted to do may be very different from what another actor can do. Oversight and accountability mechanisms may also differ.
That makes concepts such as Authorization especially important. We define "authorization" as “permission granted to an individual, organization, system, or process to access, alter, impair, disrupt, or destroy data, hardware, software, an information system, or a digital service.” That definition does not answer whether a particular activity is lawful or appropriate. Instead, it helps identify the questions policymakers need to examine more precisely: Who is authorized to act? Under what framework? With what oversight? And with what implications for other participants?
Cyber defense does not necessarily mean passive defense
The lexicon also seeks to bring greater precision to the relationship between cyber defense and the broader category of cyber operations. The Coalition defines Cyber Defense as “actions taken in or through cyberspace to prevent, detect, disrupt, respond to, mitigate, or recover from malicious cyber activity that has caused, or threatens to cause, cyber effects without authorization.” That definition recognizes an important point: defensive activity is not necessarily synonymous with passive activity.
Cyber defense can encompass a range of conduct. The policy implications of that conduct will depend on what the activity is, where it occurs, who conducts it, and what authorities apply. This is another reason terminology matters. A precise framework allows policymakers and practitioners to examine distinctions directly.
A foundation for the Coalition's next phase of work
The Coalition's lexicon is not intended to resolve every legal or policy question surrounding cyber operations; rather, it is a starting point. The Coalition's broader mission is to help close the gap between rapidly evolving cyber capabilities and the policies that govern their use. That requires engagement across government, industry, the legal community, and the broader security community. It also requires a common vocabulary.
While developing definitions may seem like a basic first step, for this work it was an essential one. With this lexicon, the Coalition can better distinguish between points of friction that arise from inconsistent terminology and genuine policy questions involving authorization, oversight, accountability, public-private coordination, international law, and international norms. Establishing that baseline gives the Coalition a clearer foundation for the policy work ahead and helps separate genuine policy conversations from confusion created by inconsistent language.
That same discipline should extend beyond the COPC. It is essential as policy professionals that we are able to acknowledge when a term is ambiguous, such as “active cyber defense” or “cyber operations," and clarify accordingly. What is the actor doing? Where is the activity taking place? What effect is being created? What authority applies? Greater precision will not answer every difficult policy question, it can help ensure that we are discussing the same question.
Read Next
UNGA Takeaways: Digital Sovereignty Without Digital Isolation
A central theme emerged across the conversation: greater digital sovereignty does not have to mean greater digital isolation.
Whitepaper on Coordinating Vulnerability Response in the Age of AI
The report highlights that open-source software faces particularly acute coordination challenges due to fragmented ownership and limited maintainer resources, compared to the more centralized response model in proprietary software.
FBI Releases First Public Cyber Strategy to Operationalize President Trump’s Cyber Strategy for America
On September 9, the Federal Bureau of Investigation (FBI) released its Cyber Strategy, outlining its approach to defending the homeland in cyberspace and imposing costs on cyber adversaries.
