Negligence of Allies: Cyber Due Diligence in Alliance Structures
Allied states operate within deeply interconnected military, intelligence, and technological ecosystems. Intelligence sharing arrangements, joint military scrutctures, integrated cyber defence systems, and interconnected digital infrastructure create relationships in which inadequate cyber security by one state may directly expose allied states to foreseeable harm. A vulnerable or underprepared ally may compromise shared intelligence, facilitate supply-chain intrusions, or create entry points into integrated defence and communication systems.The paper argues that participation in such alliance structures should influence the interpretation of cyber due diligence standards. Where states knowingly engage in high levels of strategic and technological integration, the foreseeable risks arising from inadequate cyber capabilities increase accordingly. As a result, due diligence may require not only that states keep cybersecurity measures adequate in reaction to current threats, but also that they make positive efforts to increase their cyber capabilities to keep up with the cybersecurity level across such alliance. Failure to develop such capabilities may itself contribute to cyber harm suffered by allied states and, therefore, establish liability for notwithstanding the due diligence standard. The paper therefore proposes that cyber due diligence should be interpreted relationally. The expected standard of care is shaped not only by a state’s own cyber environment, but also by the degree of strategic interdependence it creates through alliance cooperation.