Why do states in alliances seek to build cybersecurity partnerships with non-allies?
For a state that is a junior partner in an asymmetric alliance, the senior partner would seem a natural source of assistance in cyber capacity-building and for supplementing its cybersecurity. However, we often see these states relying not only on their senior partners for these benefits, but instead developing cybersecurity partnerships with non-ally states, often states whose capabilities are more similar to their own. This paper seeks to understand why this occurs. It tests three possible hypotheses. First, that states create these partnerships in order to strengthen the security position of their senior partners and their allies, usually by partnering with other junior partners of the senior partner. Second, that states create these partnerships in order to hedge against possible abandonment by the senior partner, specifically the possibility that the senior partner may reduce its commitments in cyberspace or with regard to providing cybersecurity to the junior ally. Third, that states create these partnerships to develop their cybersecurity capabilities while preserving or enhancing their autonomy vis-a-vis the senior partners in their alliances. While a senior partner may make demands regarding a junior partner's cybersecurity-related policies in return for its aid, a non-ally peer is unlikely to do the same. The paper tests these three hypotheses by looking at when, why, and with whom Australia, Japan, and South Korea have developed cybersecurity partnerships in the face of a growing threat from China and domestic political changes in the United States.