Taiwan Digital Blockade: How Wargaming Taught Me About ICS Vulnerabilities and Small Islands

Nina Kollars (Research Professor · US Naval War College), Jay Vogt (Research Professor · US Naval War College)

ShmooCon XX (Final) · Day 2 · Belay It

Overview

In a compelling ShmooCon presentation, research professors Nina Kollars and Jay Vogt from the US Naval War College unveiled the insights gleaned from a unique war game designed to explore Taiwan's resilience against a potential digital blockade and invasion. Inspired by the "Zelenskyy Playbook" witnessed during the Russian invasion of Ukraine, where private sector and cybersecurity communities played a crucial role in maintaining communications and shaping narratives, Kollars and Vogt questioned whether Taiwan, a small island nation heavily reliant on digital connectivity and complex energy infrastructure, could replicate such a defense. The talk, delivered in their personal capacity and not representing the Department of Defense, highlighted the critical vulnerabilities of modern, digitally-dependent societies facing sophisticated, multi-domain attacks.

Watch on YouTube

Visual summary for Taiwan Digital Blockade: How Wargaming Taught Me About ICS Vulnerabilities and Small Islands by Nina Kollars, Jay Vogt
Visual summary for Taiwan Digital Blockade: How Wargaming Taught Me About ICS Vulnerabilities and Small Islands by Nina Kollars, Jay Vogt

Key moments

  1. 0:00 Introduction: Can Taiwan defend against digital blockade?
  2. 1:08 Ukraine's 'Zelenskyy Playbook' inspired Taiwan research.
  3. 2:55 Decision to wargame Taiwan's defense at Black Hat/Defcon.
  4. 4:28 Taiwan's digital connectivity and subsea cable vulnerability.
  5. 5:10 Taiwan's brittle energy infrastructure and import reliance.
  6. 6:10 Details of the wargame setup and player teams.
  7. 7:00 Wargame scenario: PRC cyber attacks, EW, and sabotage.

Taiwan Digital Blockade: How Wargaming Taught Me About ICS Vulnerabilities and Small Islands

Speakers: Nina Kollars, Research Professor, US Naval War College; Jay Vogt, Research Professor, US Naval War College

Conference: ShmooCon

YouTube: https://www.youtube.com/watch?v=5YHcw-qj094

Overview

In a compelling ShmooCon presentation, research professors Nina Kollars and Jay Vogt from the US Naval War College unveiled the insights gleaned from a unique war game designed to explore Taiwan's resilience against a potential digital blockade and invasion. Inspired by the "Zelenskyy Playbook" witnessed during the Russian invasion of Ukraine, where private sector and cybersecurity communities played a crucial role in maintaining communications and shaping narratives, Kollars and Vogt questioned whether Taiwan, a small island nation heavily reliant on digital connectivity and complex energy infrastructure, could replicate such a defense. The talk, delivered in their personal capacity and not representing the Department of Defense, highlighted the critical vulnerabilities of modern, digitally-dependent societies facing sophisticated, multi-domain attacks.

The core of their research involved developing and executing a war game that simulated a 2030 scenario of a Chinese attack on Taiwan. What made this initiative particularly innovative was the decision to recruit participants from the Black Hat and Defcon communities, leveraging their deep technical expertise and unconventional thinking. These players, acting as advisors to the Taiwanese government, explored defensive strategies against cyberattacks, electronic warfare, sabotage, and eventually conventional military strikes, providing a unique, ground-up perspective on national resilience. The findings underscored not only the expected technical solutions but, more profoundly, the indispensable role of the civilian population and social preparedness in a modern conflict.

This talk is particularly significant for its interdisciplinary approach, blending geopolitical strategy, cybersecurity, critical infrastructure protection, and social dynamics. It offers invaluable lessons for policymakers, cybersecurity professionals, and military strategists contemplating the future of conflict in an increasingly interconnected world. By focusing on Taiwan, a global linchpin in technology manufacturing and a focal point of international geopolitical tension, Kollars and Vogt's research provides a timely and practical framework for understanding and enhancing national resilience in the face of complex threats.

Background

▶ Watch: Introduction: Can Taiwan defend against digital blockade? (0:00)

Taiwan, a densely populated island nation of approximately 20 million people, sits just 100 miles off the coast of the People's Republic of China (PRC), which views it as a breakaway province. This geopolitical reality forms the immediate backdrop for any discussion of Taiwan's security. Beyond its strategic location, Taiwan is a global economic powerhouse, particularly in the manufacturing of advanced semiconductors, a sector that consumes a significant portion of its energy. This economic and technological prominence makes its resilience against disruption a matter of international concern.

From an Information Communications Technology (ICT) perspective, Taiwan is one of the most digitally connected populations globally. It boasts extensive fiber optic networks and advanced 5G infrastructure, making its citizens and industries highly reliant on digital services. However, this connectivity comes with a significant vulnerability: its international internet traffic is heavily reliant on subsea cables. The fragility of these critical undersea links poses a clear target for any adversary seeking to isolate the island.

Taiwan's energy infrastructure presents another critical area of concern. While modern in many respects, it is also described as aging and brittle. A staggering 80% of its energy production comes from coal and liquefied natural gas (LNG), 90% of which is imported from off-island. This external dependency creates a severe supply chain vulnerability. Furthermore, the geographical distribution of energy production, largely in the south, versus population centers in the north, combined with the island's susceptibility to natural disasters like typhoons and earthquakes, frequently leads to major blackouts. These outages, sometimes affecting millions of customers, can result in hundreds of millions of dollars in lost revenue from the vital manufacturing sector, which alone accounts for 50% of Taiwan's energy consumption.

The inspiration for this research stemmed directly from the Russian invasion of Ukraine in February 2022. Nina Kollars and Jay Vogt observed what they termed the "Zelenskyy Playbook" – a unique phenomenon where private sector firms, service providers, and the global cybersecurity community became instrumental in enabling President Zelenskyy to coordinate responses. Crucially, communications technology allowed him to maintain contact with his citizens and military, while simultaneously communicating with the international community to shape the narrative and counter Russian attempts to isolate Ukraine digitally. The central question for Kollars and Vogt became: "Can the Taiwanese play this game? Is it the same lesson? Can we learn the same things from Ukraine and can we transport them over to Taiwan?" This inquiry led them to devise a novel war game to explore Taiwan's specific vulnerabilities and potential resilience strategies, particularly focusing on the role of the civilian technical community.

Key Findings

▶ Watch: Decision to wargame Taiwan's defense at Black Hat/Defcon. (2:55)

The war game, conducted in two iterations with approximately 15 players each, brought together technical experts divided into three teams, all advising the Taiwanese government in a "blue team" capacity. The scenarios simulated a 2030 attack by the PRC, initially focusing on cyberattacks, electronic warfare, and sabotage (e.g., cable cutting), followed by a round incorporating conventional attacks damaging physical infrastructure. The players were tasked with developing recommendations for present-day investment based on the simulated outcomes. The findings were categorized into expected and unexpected insights.

Expected Findings: The "Cheap and the Many" & Stockpiling

Many of the recommendations aligned with anticipated strategies for building resilience in a contested environment. These included investing in widely distributed, low-cost solutions:

  • Ham radios: For resilient, off-grid communication.
  • Raspberry Pi-based mesh networks: Enabling decentralized, point-to-point communication even if central infrastructure is compromised.
  • Bluetooth-enabled apps: For localized, short-range communication independent of traditional cellular networks.
  • Drones: To augment or temporarily replace compromised cell towers, extending communication range and capacity.

These solutions were favored for their ability to be deployed broadly throughout communities, enhancing overall resilience.

Beyond these decentralized communication tools, players also identified bigger ticket items and the need for stockpiling critical spares. This included:

  • Power infrastructure components: Items costing hundreds of thousands to millions of dollars, crucial for rapidly restoring the electrical grid after physical or cyber attacks.
  • Smaller necessities: Such as batteries and fuel, essential for sustaining distributed systems and emergency operations.
  • Containerized data centers: Suggested for rapid deployment and recovery, with some even proposing more unconventional ideas like submerging them for enhanced protection and rapid setup. These solutions, while more complex and costly to implement, were seen as vital for maintaining critical services.

Unexpected Findings: The Social Component and Strategic Concentration

Perhaps the most significant and unexpected finding was the substantial time players dedicated to the social component of resilience. This highlighted the critical role of the civilian population in preparing for and responding to a crisis:

  • Public education on cyber security: Emphasizing government announcements and school curricula to raise general awareness and skills.
  • Formation of "cyber core" or "hacker core" groups: Training citizens deeply in technology, repair, and incident response, enabling them to fix issues on the ground when government resources are stretched. This decentralized technical expertise was seen as crucial for local resilience.

Another intriguing, and somewhat counter-intuitive, idea that emerged was the concept of strategic concentration of resources. In contrast to the "spread it far and wide" approach, some players suggested:

  • Concentrating ICT and power infrastructure in specific, highly critical locations like chip manufacturing sites or certain cultural sites. The rationale was that an adversary might be less likely to attack these specific sites due to their global economic importance or cultural significance, thereby keeping essential services connected for longer. This approach introduces a calculated risk, leveraging potential adversary restraint to protect critical assets.

These findings collectively painted a picture of national resilience that extends beyond purely technical or military solutions, emphasizing the intertwined nature of technology, infrastructure, and societal preparedness.

Technical Deep Dive

▶ Watch: Taiwan's digital connectivity and subsea cable vulnerability. (4:28)

The war game served as a sophisticated simulation environment to explore the technical implications of a digital blockade and multi-domain attack on Taiwan. The scenarios were crafted to progressively escalate, moving from purely digital and electronic disruptions to physical destruction, allowing players to grapple with a wide spectrum of technical challenges.

The initial phase of the simulated attack focused on cyberattacks, electronic warfare, and sabotage.

  • Cyberattacks would target Taiwan's highly digitized infrastructure, including its extensive fiber optic networks, 5G cellular systems, and the underlying Industrial Control Systems (ICS) that manage its power grid, water supply, and manufacturing facilities. The goal here would be to disrupt, deny, or degrade these services through means such as Distributed Denial of Service (DDoS) attacks, malware deployment (e.g., ransomware or wiper malware), and supply chain compromises. The players, many of whom are experts in these attack vectors, would have implicitly considered how to defend against such sophisticated intrusions.
  • Electronic warfare (EW) would aim to blind and deafen Taiwan. This could involve GPS jamming to disrupt navigation and timing systems, radio frequency (RF) interference to sever military and civilian communications, and the use of directional energy weapons to disable specific electronic systems. The impact on satellite communications, critical for international connectivity, would be severe, necessitating alternative communication strategies.
  • Sabotage, specifically subsea cable cutting, was highlighted as a critical vulnerability. Taiwan's heavy reliance on these cables for international internet connectivity means their severance could effectively isolate the island digitally, mirroring historical precedents of such attacks in other regions.

In response to these threats, the technical experts in the game proposed a range of resilient ICT solutions:

  • Decentralized Communication Networks: The emphasis on Ham radios, Raspberry Pi-based mesh networks, and Bluetooth apps directly addresses the fragility of centralized infrastructure. Mesh networks, in particular, allow devices to communicate directly with each other, forming a self-healing network that can operate without a central server or traditional internet access. This distributed architecture offers inherent redundancy and resistance to single points of failure.
  • Augmented Connectivity: The use of drones to act as temporary cell towers or communication relays ("drone-based cellular augmentation") is a novel approach to restore localized connectivity quickly after ground-based infrastructure is damaged or overwhelmed. These mobile platforms can provide temporary coverage in critical areas, allowing emergency services and citizens to communicate.

The second phase introduced conventional attacks and their impact on physical infrastructure, particularly the electrical grid. This shifted the focus to Industrial Control Systems (ICS) and Operational Technology (OT) resilience.

  • Physical damage to power plants and transmission lines would necessitate rapid repair and restoration. This is where the concept of stockpiling critical spares becomes technically crucial. These spares would include large transformers, circuit breakers, and other long-lead-time components specific to Taiwan's 80% coal and LNG-based power generation system. The ability to quickly replace these components directly impacts the duration and severity of blackouts.
  • Containerized data centers represent a modular and rapidly deployable solution for disaster recovery. These self-contained units, pre-equipped with servers, storage, networking, and power, can be transported to affected areas and brought online quickly, maintaining critical data services even if traditional data centers are destroyed. The suggestion of submerging them adds a layer of physical protection against both conventional and cyber attacks, potentially leveraging the natural cooling properties of water and making them harder to detect or target.

The technical deep dive also implicitly covered the challenges of supply chain security for critical components, especially given Taiwan's reliance on imported energy and the global nature of ICT hardware. Ensuring the availability of components for both the "cheap and many" solutions and the "bigger ticket items" would be a significant logistical and strategic challenge in a blockade scenario. The recommendations from the players underscore a multi-layered technical defense strategy: from robust, distributed communication at the edge to hardened, rapidly recoverable core infrastructure, all while considering the unique geopolitical and geographic constraints of Taiwan.

Demo / Proof of Concept

▶ Watch: Details of the wargame setup and player teams. (6:10)

The "demo" or "proof of concept" for this research was the war game itself, rather than a traditional technical demonstration of a tool or exploit. Nina Kollars and Jay Vogt designed and executed a unique research methodology that leveraged the collective intelligence and practical experience of the cybersecurity community.

The war game was played in two distinct iterations: one at a business suite at the Cosmopolitan Hotel and another, notably, on the Defcon floor in the ICS Village. This choice of venue for the second iteration was deliberate, immersing players in an environment synonymous with cutting-edge cybersecurity research and unconventional thinking. Each iteration involved approximately 15 players, all serving as "blue team" advisors to the simulated Taiwanese government. These players were divided into three teams, each bringing their professional expertise to bear on the challenges presented.

The game's scenario was set in 2030, simulating a People's Republic of China (PRC) attack on Taiwan. The first phase focused purely on non-kinetic attacks: cyberattacks, electronic warfare, and sabotage, including the cutting of subsea cables. The second phase introduced conventional attacks, with missiles striking and damaging physical electrical infrastructure. Following these simulated events, players were "transported back in time to today" (the present) and tasked with making concrete recommendations for investment in various areas to enhance Taiwan's resilience. The teams presented their findings, and other players voted on the best ideas, ensuring a consensus-driven outcome rather than a subjective judgment by the researchers.

This war game served as a powerful qualitative research tool and a live simulation of complex geopolitical and technical challenges. By engaging a diverse group of highly skilled cybersecurity professionals, the researchers effectively demonstrated how such a methodology could:

  1. Uncover novel solutions: The unexpected findings, particularly regarding the social component and strategic concentration, might not have emerged from traditional policy or military-focused simulations.
  2. Validate existing strategies: Reinforcing the importance of distributed communication and stockpiling.
  3. Identify critical vulnerabilities: Highlighting specific weaknesses in Taiwan's ICT and energy infrastructure.
  4. Foster interdisciplinary thinking: Bridging the gap between technical cybersecurity expertise and national security policy.

The "unofficial challenge coin" with the Formosan sunbear, inscribed "don't [expletive] it up," served as a tangible artifact of participation, symbolizing the community's engagement and the serious yet collaborative nature of the exercise. The war game itself was the proof of concept for a methodology capable of generating actionable insights into national resilience in the digital age.

Defensive Implications

▶ Watch: Wargame scenario: PRC cyber attacks, EW, and sabotage. (7:00)

The findings from the Taiwan digital blockade war game offer critical defensive implications for Taiwan and, by extension, other small island nations or highly connected societies facing similar threats. The strategies identified emphasize a multi-layered approach combining technological resilience, logistical preparedness, and, crucially, societal engagement.

  1. Decentralized and Resilient Communications: The overwhelming consensus on solutions like Ham radios, Raspberry Pi-based mesh networks, and Bluetooth apps highlights the imperative for decentralized communication infrastructure. Defenders must invest in and deploy systems that are not reliant on central points of control or traditional internet connectivity. This includes establishing a robust, community-level capability for off-grid communication, ensuring that citizens and emergency services can stay connected even if major network infrastructure is compromised by cyberattacks, electronic warfare, or physical sabotage (e.g., subsea cable cuts). Public education and training on the use of these tools are essential.
  1. Strategic Stockpiling and Supply Chain Resilience: Given Taiwan's brittle energy system and reliance on imports, stockpiling critical spares for power infrastructure (e.g., large transformers, circuit breakers) and essential commodities like batteries and fuel is paramount. This requires a comprehensive assessment of key vulnerabilities in the Industrial Control Systems (ICS) and Operational Technology (OT) supply chains. Furthermore, exploring the feasibility of containerized data centers and other rapidly deployable infrastructure can significantly reduce recovery times after physical attacks, minimizing economic disruption and maintaining critical government and financial services.
  1. Empowering the Civilian Cyber Community: The most striking defensive implication is the need to cultivate and integrate a "cyber core" or "hacker core" within the civilian population. This involves government-backed initiatives for cybersecurity education from school-age through adult professional development. Training citizens in technical skills—from network repair to incident response—creates a distributed pool of expertise that can act as first responders at the local level. This approach recognizes that in a widespread attack, government resources will be stretched thin, and local communities will need to be self-sufficient in maintaining essential digital functions.
  1. Hardening Critical Infrastructure & Strategic Concentration: While decentralization is key for communications, the concept of strategic concentration for highly critical assets like chip manufacturing sites and their associated power and ICT infrastructure warrants further investigation. This would involve physically hardening these sites, deploying advanced cybersecurity defenses, and potentially exploring international agreements or norms that could deter attacks on such globally vital facilities. However, this strategy carries inherent risks and requires careful geopolitical calculation.
  1. Multi-Domain Defense Planning: The war game underscored the need for integrated defense planning that considers cyberattacks, electronic warfare, sabotage, and conventional attacks as intertwined elements of a single threat. Defenders must move beyond siloed approaches, developing comprehensive strategies that address the cascading effects of attacks across ICT, energy, and other critical sectors. This involves regular, realistic exercises (like the war game itself) to test and refine these integrated plans.

In essence, the defensive implications point towards building national digital resilience through a combination of technological redundancy, logistical foresight, and, most importantly, the active empowerment and engagement of the entire society in a whole-of-nation defense strategy.

Key Takeaways

  • The "Zelenskyy Playbook" is a viable model for small nations: Leveraging private sector and civilian technical expertise is crucial for maintaining communications and shaping narratives during a conflict.
  • Decentralized, low-cost communication solutions are essential: Investing in widely distributed Ham radios, Raspberry Pi-based mesh networks, and Bluetooth apps enhances resilience against centralized infrastructure failures.
  • Stockpiling critical spares and resources is vital: Preparing for physical damage requires pre-positioning power grid components, batteries, and fuel to ensure rapid recovery of essential services.
  • The social component of resilience is paramount: Educating the public on cybersecurity and establishing "cyber core" or "hacker core" groups empowers citizens to maintain local digital functions.
  • Taiwan's energy infrastructure is a critical vulnerability: High reliance on imported coal and LNG (80% production, 90% imported) and a brittle grid make it a prime target for disruption.
  • War gaming with technical experts provides unique insights: Engaging the Black Hat/Defcon community offers unconventional, practical, and actionable recommendations for national defense strategies.

About the Speaker(s)

Nina Kollars and Jay Vogt are Research Professors at the US Naval War College. They specialize in cyber and military research, bringing an academic lens to complex national security challenges. Nina, also known as "Kitty" to some, and Jay conducted this research in their personal capacities, explicitly stating that their opinions do not necessarily reflect those of the Department of Defense or the Department of the Navy. Their work often involves innovative methodologies, as demonstrated by their decision to engage the cybersecurity community in a war game to explore critical infrastructure vulnerabilities and national resilience. Their dedication to understanding and addressing contemporary threats is evident in their ongoing research and engagement with both academic and practitioner communities.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

This talk presents a crucial wargaming exercise focused on Taiwan's cyber resilience against a digital blockade, drawing lessons from Ukraine. While not a deep dive into a specific vulnerability, the research methodology—engaging top-tier community experts in a structured wargame—is novel and impactful. The findings offer actionable, pragmatic recommendations for critical infrastructure and societal preparedness, moving beyond theoretical discussions to address a pressing geopolitical threat. It's direct, well-executed, and delivers real value.

Heather Calloway (CISO) — STRONG ACCEPT

This war game simulation offers critical insights into national resilience against multi-domain attacks, particularly for highly digitized island nations like Taiwan. By engaging the Black Hat and Defcon communities, the research uncovers actionable strategies beyond purely technical solutions, emphasizing the indispensable role of decentralized communications, strategic stockpiling, and, most notably, societal preparedness through a "cyber core" of technically skilled citizens. The findings provide a robust framework for policymakers and security leaders to evaluate and enhance national defense, connecting technical vulnerabilities to institutional accountability and executive action.

→ Top-rated talks at ShmooCon XX (Final)

All talks from ShmooCon XX (Final)