China’s Cyber Rise Under Xi Jinping

▶ Watch (3:34)

When Xi Jinping took power in 2012, China was a large network power. He moved to make it a cyber superpower. The PLA was reorganized into the Strategic Support Forces to integrate cyber with electronic, psychological, space, and information warfare. Chinese cybersecurity researchers were forced to hand most discovered vulnerabilities to the state, cutting them off from international competitions. R&D budgets doubled over two decades. The primary scenarios driving this buildup: Taiwan and South China Sea disputes over fishing, oil, and natural gas.

Volt Typhoon: Prepositioning, Not Espionage

▶ Watch (6:47)

Volt Typhoon is the US government and Microsoft name for Chinese state actors prepositioning malware on American critical infrastructure. The US government has consistently said the purpose is not espionage. It is preparation for disruption, creating conditions for societal chaos in a conflict scenario. Targets include command and control systems, critical infrastructure broadly, and staging areas in Guam and Southeast Asia where US forces would concentrate. The difference from earlier Chinese intrusions: these aren’t exfiltrating data. They’re waiting.

US Military Cyber’s Three Missions

▶ Watch (10:18)

US Cyber Command has three core missions. First: defend its own networks. Military comms must work in a war, so C2 channels need protection above all. Second: generate offensive options for combatant commanders. That means building capability to strike in cyberspace before a conflict starts, not scrambling to develop it after. Third: defend the nation from significant cyber attacks, supporting DHS and law enforcement below the level of armed conflict. The Navy in particular, Sulmeyer said, treats cyber as an IT or intelligence function rather than a power projection domain.

▶ Watch (21:49)

From 2015 to 2017, state-controlled and proxy actors hit US companies with IP theft and ID theft at scale, below the level of armed conflict. Leadership kept telling Cyber Command to stop it. The legal framework, set up before the internet existed, made proactive responses legally murky. Congress eventually modified the relevant provision. Civilian defense leadership changed policy to allow the military to act below armed conflict. The first test: protecting the 2018 midterm elections. That was the first use of new authorities to disrupt malicious activity before it hit the homeland.

Belt and Road Shifts from Ports to Fiber

▶ Watch (27:57)

China’s Belt and Road Initiative started with ports and rail lines through Pakistan into Africa. That physical build has lost popularity in recipient countries after displacing local workers. The shift is to digital infrastructure: satellite links, fiber optics, and 5G. Segal cited General Hayden’s remark that after Snowden, the US benefited from proximity to its tech companies. China drew the same lesson: push Chinese technology into those regions, gain similar access to networks and chokepoints.

Three Phases of Chinese Cyber Operations

▶ Watch (36:07)

Segal outlined Chinese hacking in three phases. Phase one: mass IP theft, high-volume and sloppy. Comey called it a drunk burglar. The 2015 Obama-Xi agreement on cyber-enabled theft ended that wave. China reorganized, shifting work from the PLA to the Ministry of State Security. Phase two: Operation Cloud Hopper and directed campaigns through contractors like iSoon. Phase three, now current: Volt Typhoon, prepositioning for conflict rather than collection. The shift from data theft to strategic positioning marks a change in Chinese intent.

Q&A

What threats from China’s evolving strategy should practitioners watch most closely? Segal said unpredictable domestic politics is the biggest wildcard: Taiwan making a decision China interprets as moving toward independence could trigger rapid escalation that neither side is ready for. ▶ 39:17

Notable Quotes

networks. That’s not your networks. Michael Sulmeyer · ▶ 10:25

Stop it. Make it make it stop. Michael Sulmeyer · ▶ 23:58

it was uh pretty sloppy uh mass hacking Adam Segal · ▶ 36:20

Key Takeaways

  • China forced security researchers to hand discovered zero-days to the state, cutting off international competition.
  • Volt Typhoon prepositions malware on US critical infrastructure for future disruption, not espionage.
  • US Cyber Command first tested defend-forward authorities by protecting the 2018 midterm elections.
  • The Navy historically treats cyber as an IT or intelligence problem rather than a force projection domain.
  • Chinese hacking evolved across three phases: mass IP theft, targeted MSS operations, and Volt Typhoon prepositioning.

About the Speaker(s)

John Mauger served as Rear Admiral in the US Coast Guard for over 33 years. As Commander of the First Coast Guard District, he led 12,000 people and oversaw port operations in New England. At US Cyber Command he held the J7 role, responsible for training and force generation across military cyber units. He now leads PORTS LLC, advising clients on maritime and critical infrastructure challenges.

Michael Sulmeyer served as the first Assistant Secretary of Defense for Cyber Policy and Principal Cyber Advisor to the Secretary of Defense. He held senior cyber roles at the US Army, Office of the Secretary of Defense, US Cyber Command, and the National Security Council. He holds a doctorate from Oxford University where he was a Marshall Scholar, and a law degree from Stanford Law School.

Adam Segal holds the Ira Lipman chair in emerging technologies and national security at the Council on Foreign Relations, where he directs the Digital and Cyberspace Policy program. From 2023 to 2024 he served as a senior advisor in the State Department’s Bureau of Cyberspace and Digital Policy, leading development of the US International Cyberspace and Digital Policy. He is the author of The Hacked World Order (2016).