Change search
Link to record
Permanent link

Direct link
Publications (10 of 13) Show all publications
Huskaj, G. & Axelsson, S. (2026). Strengthening Analytical Competence in (Cyber) Intelligence. In: Furnell S., Almani D. (Ed.), European Conference on Information Warfare and Security, ECCWS: . Paper presented at 25th European Conference on Cyber Warfare and Security, ECCWS, June 29-30, 2026 (pp. 1057-1065). Curran Associates Inc.
Open this publication in new window or tab >>Strengthening Analytical Competence in (Cyber) Intelligence
2026 (English)In: European Conference on Information Warfare and Security, ECCWS / [ed] Furnell S., Almani D., Curran Associates Inc. , 2026, p. 1057-1065Conference paper, Published paper (Refereed)
Abstract [en]

Sweden’s intelligence education system lacks the technical-domain competence required to meet the analytical demands of contemporary cyber intelligence. This finding emerges from a diagnostic analysis of eleven international intelligence education programmes using the Intelligence Competence Framework (ICF), which combines a multi-level analytical structure (strategic, operational, tactical) with the domain classification (technical, formal, informal) of the Systemic-Holistic Approach. When applied to the programmes referenced by Sweden's government inquiry on intelligence reform (SOU 2025:78), the framework reveals that formal and informal domains receive strong coverage across all programmes while the technical domain is systematically underarticulated - particularly at the tactical level, where only one of eleven programmes achieves strong coverage. Three interdependent capability requirements emerge from an analysis of SOU 2025:78, five international programme models (the German BND, the Danish MICS, the French DIReM, the ICE CIADM module, and the Norwegian Etteretningsskolen), consultations with Swedish intelligence practitioners, and contemporary analyses of AI-supported intelligence (NSCAI, Snow Globe, Emergent Intelligence). Organisationally, the proposed intelligence academy requires a professional authority function that sets competence standards across the intelligence community rather than delivering education alone. Educationally, programmes that integrate technical content with professional practice through apprenticeship models, twin-track specialisations, and practitioner-led instruction produce broader competence coverage than purely academic programmes. Technologically, baseline digital literacy encompassing data provenance, tool limitations, and AI-assisted analytical workflows must be treated as a structural requirement in curriculum design rather than as an optional specialisation. The practitioner consultations identified three specific capability gaps in the current Swedish system: OSINT training that moves beyond keyword searching, exposure to AI-assisted analytical workflows before operational deployment, and secure technical environments for realistic practice. A Swedish intelligence academy built on existing European models will inherit the same technical-domain deficit unless technical competence is embedded as a design principle from the outset.

Place, publisher, year, edition, pages
Curran Associates Inc., 2026
Keywords
(Cyber) intelligence, Competence development, Intelligence education, Offensive cyberspace operations, Open-source intelligence, Systemic-holistic approach
National Category
Information Systems, Social aspects
Identifiers
urn:nbn:se:su:diva-258906 (URN)2-s2.0-105046839714 (Scopus ID)9781917204781 (ISBN)
Conference
25th European Conference on Cyber Warfare and Security, ECCWS, June 29-30, 2026
Available from: 2026-09-02 Created: 2026-09-02 Last updated: 2026-09-02Bibliographically approved
Huskaj, G. (2025). A Global Policy Perspective on Offensive Cyberspace Operations.
Open this publication in new window or tab >>A Global Policy Perspective on Offensive Cyberspace Operations
2025 (English)Report (Other academic)
Abstract [sv]

Offensiva cyberoperationer har under det senaste decenniet spridits snabbt och påverkar i ökad grad internationell säkerhet och strategisk stabilitet. Förmågor som tidigare främst fanns hos ett fåtal stormakter återfinns nu hos ett växande antal stater och i vissa fall även hos icke-statliga aktörer. Denna spridning förkortar beslutsfönster, ökar oklarheten kring gränsen mellan fred och konflikt och försvårar avskräckning genom osäker attribution, otydliga trösklar och juridisk tvetydighet. Denna policy brief analyserar hur offensiva cyberförmågor integreras i nationell doktrin och i kollektiva säkerhetsarrangemang, samt hur dessa praktiker samverkar med existerande rättsliga och normativa ramverk. Analysen identifierar risker kopplade till felbedömning och eskalation, inklusive oavsiktliga spridningseffekter och samhällskonsekvenser som följer av starkt beroende mellan militära och civila digitala infrastrukturer. Policy briefen argumenterar för att stabilitet i cyberrymden kan stärkas genom ökad transparens, utvecklade förtroendeskapande åtgärder, tydligare normtillämpning och uthållig multilateral dialog. Avslutningsvis presenteras rekommendationer för globalt samarbete som syftar till att minska eskalationsrisker och främja ansvarsfullt statligt agerande.

Abstract [en]

This policy brief examines the global diffusion of offensive cyberspace operations and its implications for international security, strategic stability, and escalation management. Once confined to a small number of major powers, offensive cyber capabilities are now widely distributed among states and, in some cases, non-state actors. This diffusion compresses decision timelines, blurs thresholds between peace and conflict, and complicates deterrence through attribution uncertainty and legal ambiguity. The analysis traces how major and middle-tier states have integrated offensive cyber capabilities into national doctrine and collective security arrangements, and assesses how these practices interact with existing legal and normative frameworks. It identifies key risks associated with miscalculation, inadvertent escalation, and civilian harm arising from the deep interdependence of military and civilian digital infrastructure. The brief argues that stability in cyberspace depends on greater transparency, strengthened confidence-building measures, clearer articulation of norms, and sustained multilateral dialogue. It concludes with policy recommendations aimed at fostering responsible state behaviour and enhancing global cooperation to reduce escalation risks while preserving international security.

Publisher
p. 15
Series
GCSP Policy Brief ; 22
Keywords
Offensive cyberspace operations, Cyber deterrence, Strategic stability, International security policy, Escalation dynamics, Offensiva cyberoperationer, Cyberavskräckning, Strategisk stabilitet, Internationell säkerhetspolitik, Eskalationsdynamik
National Category
Information Systems, Social aspects
Research subject
Information Society
Identifiers
urn:nbn:se:su:diva-250978 (URN)978-2-88947-450-9 (ISBN)
Note

Open peer-review, två externa granskare + intern granskning Geneva Centre for Security Policy

Available from: 2026-01-11 Created: 2026-01-11 Last updated: 2026-01-14Bibliographically approved
Huskaj, G., Blix, F. & Axelsson, S. (2024). A Theory of Offensive Cyberspace Operations and Its Policy and Strategy Implications. In: Martti Lehto (Ed.), Proceedings of the 23rd European Conference on Cyber Warfare and Security: . Paper presented at 23rd European Conference on Cyber Warfare and Security (ECCWS 2024), Jyväskylä, Finland, 27-28 June, 2024 (pp. 214-223). Reading: ACI Academic Conferences International
Open this publication in new window or tab >>A Theory of Offensive Cyberspace Operations and Its Policy and Strategy Implications
2024 (English)In: Proceedings of the 23rd European Conference on Cyber Warfare and Security / [ed] Martti Lehto, Reading: ACI Academic Conferences International, 2024, p. 214-223Conference paper, Published paper (Refereed)
Abstract [en]

The significance of Offensive Cyberspace Operations (OCO) in cyber warfare and national security is increasingly recognised, yet academic literature lacks a dedicated theoretical framework to fully articulate its unique aspects and strategic dimensions. Traditionally enveloped within the broader context of information warfare, OCO's distinct characteristics have often been overlooked. Addressing this gap, our paper aims to delineate the specificities of OCO and establish a structured conceptual model that enhances understanding and operational clarity. To achieve this, the study adopts an interpretive approach, drawing from existing literature on information warfare and cyberspace, alongside official U.S. government and military publications on cyberspace operations. Employing the theory-building method, we focus primarily on conceptualization. This involves creating a coherent conceptual framework through abstraction, synthesis, and diagramming, informed by seminal works in the field. Among the paper's key contributions are detailed conceptual models that shed light on OCO's integration within the broader cyber domain, the influence of U.S. policy and strategy on OCO, and the critical triad for successful operations: access, vulnerabilities, and payloads. Furthermore, we elucidate the primary and secondary components of OCO, specifically cyberspace attack and exploitation, offering new insights into their roles and implications. Thus, the framework includes conceptual maps highlighting OCO's key elements, relationships, and challenges, aiming to advance academic discourse, practical strategies, and policy in cyberspace operations. This effort marks a significant step forward in both theoretical engagement and practical application within the field.

Place, publisher, year, edition, pages
Reading: ACI Academic Conferences International, 2024
Series
European Conference on Information Warfare and Security, ECCWS, ISSN 2048-8602, E-ISSN 2048-8610 ; Vol. 23, No. 1
Keywords
Cyberspace Attack, Cyberspace Exploitation, Offensive Cyberspace Operations, Policy and Strategy
National Category
Security, Privacy and Cryptography
Identifiers
urn:nbn:se:su:diva-250492 (URN)10.34190/eccws.23.1.2391 (DOI)2-s2.0-105021468674 (Scopus ID)978-1-917204-06-4 (ISBN)978-1-917204-07-1 (ISBN)
Conference
23rd European Conference on Cyber Warfare and Security (ECCWS 2024), Jyväskylä, Finland, 27-28 June, 2024
Available from: 2025-12-16 Created: 2025-12-16 Last updated: 2025-12-16Bibliographically approved
Huskaj, G. (2024). Eight Principles for Intelligence Sharing: A Holistic and Strategic Approach. In: Martti Lehto (Ed.), Proceedings of the 23rd European Conference on Cyber Warfare and Security: . Paper presented at 23rd European Conference on Cyber Warfare and Security (ECCWS 2024), Jyväskylä, Finland, 27-28 June, 2024 (pp. 704-711). Reading: ACI Academic Conferences International
Open this publication in new window or tab >>Eight Principles for Intelligence Sharing: A Holistic and Strategic Approach
2024 (English)In: Proceedings of the 23rd European Conference on Cyber Warfare and Security / [ed] Martti Lehto, Reading: ACI Academic Conferences International, 2024, p. 704-711Conference paper, Published paper (Refereed)
Abstract [en]

This paper reviews the strategic use of warning intelligence to pre-emptively address threats in complex geopolitical scenarios through rapid intelligence sharing. Specifically, the paper reviews the question How, based on research and experience, can a set of principles be applied by states to enhance situational awareness and tackle threat actors through a holistic and collaborative approach to intelligence sharing? The paper examines historical and contemporary alliances like the Five Eyes and reviews a Signals Intelligence Alliance as a case in point, highlighting the importance of collaborative approaches to enhance situational awareness and tackle threat actors. The study, grounded in the philosophical paradigm of interpretivism, adheres to the principles for transparent science when researchers use tools such as large-language-models as grammar editors or research assistants. The paper also acknowledges limitations such as the generalisability of the SIGINT model and the need for continuous adaptation of intelligence sharing practices. The results discuss policy, process, and people challenges to intelligence sharing. The paper concludes that successful intelligence sharing should follow eight general principles. Future research directions include exploring the impact of emerging technologies, human aspects of intelligence sharing, and context-based intelligence sharing alliances.

Place, publisher, year, edition, pages
Reading: ACI Academic Conferences International, 2024
Series
European Conference on Information Warfare and Security, ECCWS, ISSN 2048-8602, E-ISSN 2048-8610 ; Vol. 23, No. 1
Keywords
Intelligence Sharing Principles, SIGINT Alliance, Strategic Warning Intelligence
National Category
War, Crisis, and Security Studies
Identifiers
urn:nbn:se:su:diva-250493 (URN)10.34190/eccws.23.1.2392 (DOI)2-s2.0-105021472471 (Scopus ID)978-1-917204-07-1 (ISBN)978-1-917204-06-4 (ISBN)
Conference
23rd European Conference on Cyber Warfare and Security (ECCWS 2024), Jyväskylä, Finland, 27-28 June, 2024
Available from: 2025-12-16 Created: 2025-12-16 Last updated: 2025-12-16Bibliographically approved
Huskaj, G. (2024). Future Elections and AI-Driven Disinformation. TDHJ Special Edition, 48-59
Open this publication in new window or tab >>Future Elections and AI-Driven Disinformation
2024 (English)In: TDHJ Special Edition, ISSN 2960-5687, p. 48-59Article in journal (Refereed) Published
Abstract [en]

This paper conceptualises how artificial intelligence (AI) reshapes disinformation campaigns by examining the operational shift from predominantly human-led activity to AI-enabled production, targeting, and adaptation. Using a framework that links Human Intelligence Collector Operations (HUMINT) and Offensive Cyberspace Operations (OCO), the analysis focuses on how recent advances affect operational tempo, content generation capacity, and responsiveness to feedback. The findings indicate that AI-enabled campaigns can accelerate the production and tailoring of narratives by processing large datasets at machine speed and adjusting outputs as conditions change. In comparative terms, AI-driven workflows show higher throughput and faster iteration cycles than human-operated approaches, which remain constrained by personnel scale, time, and coordination costs. These characteristics imply that the marginal cost of producing plausible, audience-specific disinformation decreases as models and automation pipelines mature, which in turn can widen exposure for institutions that rely on slower detection and response processes.

Keywords
Disinformation campaigns, Artificial intelligence, Offensive cyberspace operations, Information influence operations, Automation and scalability
National Category
Information Systems, Social aspects
Research subject
Computer and Systems Sciences
Identifiers
urn:nbn:se:su:diva-251039 (URN)
Available from: 2026-01-12 Created: 2026-01-12 Last updated: 2026-01-14Bibliographically approved
Huskaj, G. (2024). How innovation impacts global security. Kungl Krigsvetenskapsakademiens Handlingar och Tidskrift, 3(2024), 27-34
Open this publication in new window or tab >>How innovation impacts global security
2024 (English)In: Kungl Krigsvetenskapsakademiens Handlingar och Tidskrift, ISSN 0023-5369, Vol. 3, no 2024, p. 27-34Article in journal (Other academic) Published
Abstract [sv]

Artikeln behandlar hur teknologisk innovation påverkar den globala säkerheten, och betonar att framsteg inom områden som informations- och kommunikationsteknik och sammankopplade informationssystem, cyberförmågor och artificiell intelligens (AI) har dubbla användningsområden. Först definieras innovation och global säkerhet. Därefter granskas två fall av cyberspionage, som visar hur hotaktörer exploaterar framsteg inom teknologiska innovationer för att främja sina strategiska mål. Dessa fall understryker de sårbarheter och strategiska förändringar som teknologiska innovationer medför, särskilt i samband med ekonomisk stabilitet och geopolitisk maktbalans. Dessutom behandlas den snabba utvecklingen av AI och dess implikationer för krigföring och global säkerhet. Resultaten visar att det krävs en balanserad strategi för att omfamna teknologiska framsteg för internationell dialog och utnyttjandet av fördelarna med innovation samtidigt som riskerna för den globala säkerheten minskas.

Abstract [en]

The article examines how technological innovation affects global security, emphasising that advances in areas such as information and communication technologies and interconnected information systems, cyber capabilities, and artificial intelligence (AI) have dual-use applications. It first defines innovation and global security. It then examines two cases of cyber espionage, illustrating how threat actors exploit technological advances to advance their strategic objectives. These cases highlight the vulnerabilities and strategic shifts associated with technological innovation, particularly in relation to economic stability and the geopolitical balance of power. In addition, the article addresses the rapid development of AI and its implications for warfare and global security. The findings indicate that a balanced approach is required—one that embraces technological advances to support international dialogue and leverage the benefits of innovation while simultaneously reducing risks to global security.

Keywords
Technological innovation, Global security, Cyber espionage, Artificial intelligence, Strategic stability, Teknologisk innovation, Global säkerhet, Cyberspionage, Artificiell intelligens, Strategisk stabilitet
National Category
Information Systems, Social aspects
Research subject
Computer and Systems Sciences
Identifiers
urn:nbn:se:su:diva-251040 (URN)
Available from: 2026-01-12 Created: 2026-01-12 Last updated: 2026-01-14Bibliographically approved
Säberg, K. & Huskaj, G. (2024). Intelligence Agencies’ move to the Cloud: Challenges and Opportunities. In: Jaco du Toit; Brett van Niekerk (Ed.), The 19th International Conference on Cyber Warfare and Security (ICCWS 2024): . Paper presented at ICCWS 2024 : 19th International Conference on Cyber Warfare and Security, 26-27 March, 2024, Johannesburg, South Africa. (pp. 565-573). , 19
Open this publication in new window or tab >>Intelligence Agencies’ move to the Cloud: Challenges and Opportunities
2024 (English)In: The 19th International Conference on Cyber Warfare and Security (ICCWS 2024) / [ed] Jaco du Toit; Brett van Niekerk, 2024, Vol. 19, p. 565-573Conference paper, Published paper (Refereed)
Abstract [en]

The purpose of this research is to discover more about the challenges and opportunities faced by intelligence agencies wishing to move their data to the cloud. Intelligence agencies collect and process enormous amounts of data and information and need the tools to do so. Two intelligence communities have moved to the cloud to face these issues but there is little scientific knowledge about moving an intelligence agency’s data to the cloud. No research on the topic could be found and this study aims to fill part of that gap by using a case study research strategy and interviews with experts in the field. A literature review was completed to understand previously identified challenges when adopting cloud and was used to create two sets of interview questions. Five interviews were conducted, and a thematic analysis done resulting in fourteen themes. The themes revealed that there are many challenges with laws and regulations being the biggest one, while the opportunities brought by a cloud solution are the processing and analysis of data, and information sharing.

Series
International Conference on Cyber Warfare and Security (ICIW), ISSN 2048-9870, E-ISSN 2048-9889 ; 19:1
Keywords
intelligence, intelligence agency, cloud, cloud computing, information security
National Category
Information Systems, Social aspects
Research subject
Computer and Systems Sciences
Identifiers
urn:nbn:se:su:diva-251041 (URN)10.34190/iccws.19.1.2008 (DOI)978-1-914587-97-9 (ISBN)978-1-914587-96-2 (ISBN)
Conference
ICCWS 2024 : 19th International Conference on Cyber Warfare and Security, 26-27 March, 2024, Johannesburg, South Africa.
Available from: 2026-01-12 Created: 2026-01-12 Last updated: 2026-01-14Bibliographically approved
Huskaj, G. & Axelsson, S. (2023). A Whole-of-Society Approach to Organise for Offensive Cyberspace Operations: The Case of the Smart State Sweden. In: Antonios Andreatos; Christos Douligeris (Ed.), Proceedings of the 22nd European Conference on Cyber Warfare and Security: . Paper presented at 22nd European Conference on Cyber Warfare and Security (ECCWS 2023), Athens, Greece, 22-23 June, 2023 (pp. 592-601). Reading: Academic Conferences and Publishing International Limited
Open this publication in new window or tab >>A Whole-of-Society Approach to Organise for Offensive Cyberspace Operations: The Case of the Smart State Sweden
2023 (English)In: Proceedings of the 22nd European Conference on Cyber Warfare and Security / [ed] Antonios Andreatos; Christos Douligeris, Reading: Academic Conferences and Publishing International Limited, 2023, p. 592-601Conference paper, Published paper (Refereed)
Abstract [en]

Threat actors conduct offensive cyberspace operations for many purposes, such as espionage, to destroy information assets, and cybercrime. These operations are possible thanks to the innovation and development of information and communications technologies (ICT). Interconnected information systems have transformed societies positively. However, specific states exploit these systems' vulnerabilities to advance their strategic national interests. Therefore, it is important to know how a state can organise itself to defend against threat actors. The purpose of this research is to present how the smart state Sweden can through a whole-of-society approach organise for Offensive Cyberspace Operations. The intent is to conduct an active and independent foreign-, security- and defence policy, but also as a base for deterrence and defence. This article is based on a mixed methods approach. It uses the case study research strategy to discover new information. Fourteen men and women participated in individual semi-structured interviews. The respondents ranged in age from 40 to 65 with more than 20 years of experience in cyberspace operations, intelligence operations, military operations, special forces operations, and knowledge and understanding about information warfare and information operations. The analytic strategies include thematic analysis and quantitative methods to interpret the data. The results show many themes, but the article is especially focused on the themes of Operations, Capability, Policy & Governance, and Legal Frameworks. Finally, a conceptual map of a whole-of-society approach to organise for offensive cyberspace operations is presented inferred from the themes, codes, and content, and mapped to each responsible agency based on the interviews and codes. The answer to the research question is that Sweden should have a whole-of-society approach to organise for Offensive Cyberspace Operations to project power in and through cyberspace with the intent to conduct an active and independent foreign, security and defence policy and for deterrence, as described in Figure 2. 

Place, publisher, year, edition, pages
Reading: Academic Conferences and Publishing International Limited, 2023
Series
European Conference on Cyber Warfare and Security - Conference Proceedings, ISSN 2048-8602, E-ISSN 2048-8610 ; 22
Keywords
deterrence, cyberspace capabilities, information systems, offensive cyberspace operations, smart state
National Category
Information Systems, Social aspects
Research subject
Computer and Systems Sciences
Identifiers
urn:nbn:se:su:diva-224802 (URN)10.34190/eccws.22.1.1188 (DOI)2-s2.0-85167587161 (Scopus ID)978-1-914587-70-2 (ISBN)978-1-914587-69-6 (ISBN)
Conference
22nd European Conference on Cyber Warfare and Security (ECCWS 2023), Athens, Greece, 22-23 June, 2023
Available from: 2023-12-27 Created: 2023-12-27 Last updated: 2024-10-29Bibliographically approved
Huskaj, G. & Blix, F. (2022). Validating a Framework for Offensive Cyberspace Operations. Journal of Information Warfare, 21(3), 26-42
Open this publication in new window or tab >>Validating a Framework for Offensive Cyberspace Operations
2022 (English)In: Journal of Information Warfare, ISSN 1445-3312, Vol. 21, no 3, p. 26-42Article in journal (Refereed) Published
Abstract [en]

The Ambidextrous Framework for Offensive Cyberspace Operations was validated using a simulated cyber conflict emulating a cyber operation against critical infrastructure of a fictious country. The purpose of the validation was to assess how well the Framework supports both planning and execution of cyber operations. Data was collected using self-reporting by a team in the cyber range training facility. The study found that the framework works well to support the planning, preparation, and order giving to execute offensive cyberspace operations. However, it was found to be less suited to support operator actions during on ongoing offensive operation due to its current lack of capability to utilize real-time data from battle-stations.

Keywords
Ambidextrous Framework, Cyber Range and Training Environment (CRATE), Model, Offensive Cyberspace Operations, Validating
National Category
Information Systems
Research subject
Computer and Systems Sciences
Identifiers
urn:nbn:se:su:diva-224811 (URN)
Available from: 2023-12-27 Created: 2023-12-27 Last updated: 2024-06-17Bibliographically approved
Huskaj, G. & Wilson, R. L. (2020). Offensive Cyberspace Operations and Zero-days: Anticipatory Ethics and Policy Implications for Vulnerability Disclosure. Journal of Information Warfare, 20(1), 96-109
Open this publication in new window or tab >>Offensive Cyberspace Operations and Zero-days: Anticipatory Ethics and Policy Implications for Vulnerability Disclosure
2020 (English)In: Journal of Information Warfare, ISSN 1445-3312, Vol. 20, no 1, p. 96-109Article in journal (Refereed) Published
Abstract [en]

This article addresses the question under which circumstances zero-day vulnerabilities should be disclosed or used for offensive cyberspace operations. Vulnerabilities exist in hardware and software and can be seen as a consequence of programming errors or design flaws. The most highly sought are so-called zero-day-vulnerabilities. These vulnerabilities exist but are unknown and, when exploited, enable one way of entry into a system that is otherwise not thought possible. Therefore, from an anticipatory ethics perspective, it is important to understand in what cases zero-days should be disclosed or not.

National Category
Information Systems Political Science (excluding Public Administration Studies and Globalisation Studies) Peace and Conflict Studies Other Social Sciences not elsewhere specified
Identifiers
urn:nbn:se:su:diva-231091 (URN)
Available from: 2024-06-17 Created: 2024-06-17 Last updated: 2025-02-20Bibliographically approved
Organisations
Identifiers
ORCID iD: ORCID iD iconorcid.org/0000-0002-7552-9465

Search in DiVA

Show all publications