A July 2023 memo from the Foundation for Defense of Democracies (FDD) argued that the United States should make cybersecurity capacity-building for allies and partners a priority. Its proposal was broader than technical training: it called for stronger critical-infrastructure defenses, more exercises, better coordination among U.S. agencies, and increased funding. The memo offers recommendations, not proof that every proposed program worked or a record of what was later implemented.
What does “cyber capacity-building” mean?
In this memo, cyber capacity-building means helping another country develop the people, policies, systems, and operational readiness to prevent, withstand, investigate, and recover from cyber incidents. The authors describe work spread across the Departments of State, Justice, Energy, Homeland Security, Treasury, and Defense, as well as the intelligence community.
- Policy and diplomacy: assistance with national cybersecurity strategies, laws, and information-sharing.
- Technical resilience: support for secure digital infrastructure, incident response, and protection of critical services.
- Law enforcement: training to investigate and prosecute cybercrime.
- Military cooperation: exercises and other collaboration focused on cyber defense, alongside proposals concerning cyber-force employment.
The central idea is that a partner with stronger defenses may be better able to protect its own services and reduce the risk that an attack spreads beyond its borders. That is the memo’s security rationale, not a measured guarantee.
Why did FDD point to Ukraine?
FDD contrasts Russia’s 2015 attack that disrupted power in Kyiv with Ukraine’s ability to withstand cyberattacks after Russia’s 2022 invasion. The authors argue that years of Ukrainian defense-building, supported by the United States and other partners, contributed to that resilience. They also argue that stronger partner defenses can help prevent incidents from cascading internationally, citing the 2017 NotPetya attack.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
At the memo’s release, Annie Fixler, then director of FDD’s Center on Cyber and Technology Innovation and a co-author, said: “What we’ve learned in Ukraine is that cyber defense works.” The statement captures the memo’s argument; it is not an independent evaluation isolating the effect of any single assistance program. CyberScoop’s July 2023 coverage described the paper’s focus on Ukrainian defenses of critical infrastructure, including the energy system.
What did the memo recommend?
Mark Montgomery and Annie Fixler’s FDD memo, “Building Partner Capabilities for Cyber Operations,” was published July 27, 2023. It made eight recommendations for the Biden administration’s international cybersecurity strategy:
- Make capacity-building for allies and partners a key part of the international cybersecurity strategy.
- Prioritize resilience for partners’ critical infrastructure.
- Increase funding for existing and new capacity-building programs.
- Consolidate State Department capacity-building funds under the Bureau of Cyberspace and Digital Policy.
- Conduct more bilateral and multilateral cyber exercises.
- Use selected bilateral memoranda of understanding (MOUs) to improve military cyber defense.
- Develop training on cyber-force employment, including legal and operational issues.
- Assess what future support for partner offensive cyber-force generation could entail.
The last two proposals go beyond conventional defensive assistance. The memo calls for training that addresses the legal and operational dimensions of employing cyber forces, and for the Department of Defense to assess possible support for partners’ offensive capabilities. It does not frame those steps as a blanket call for offensive operations.
Why did the authors emphasize infrastructure and logistics?
The memo names ports, railways, air transport, electricity, water, financial services, and pipelines as infrastructure that can matter to both a partner’s economy and military mobility. In the authors’ reasoning, disruption to these systems can weaken a country’s ability to function under attack and complicate U.S. forces’ and allies’ logistics. This is the memo’s rationale for prioritizing resilience; it does not quantify the effects of specific infrastructure programs.
Rank #3
Why did the memo call for more funding and coordination?
The authors describe assistance delivered through numerous civilian and military agencies, with activities ranging from policy support to technical response and exercises. They argue that demand was exceeding the government’s ability to provide help. Nathaniel Fick, then U.S. ambassador at large for Cyberspace and Digital Policy, was quoted in the memo saying “demand for capacity building around the world is just overwhelming.” At the release, he also said: “There’s very little that any one country or small group of countries or one company or set of companies can do on its own.” The FDD memo therefore calls both for more resources and for clearer coordination, including consolidating State Department funds under its cyberspace policy bureau.
The memo reports that U.S. Cyber Command conducted more than 47 missions in more than 20 countries over the preceding five years. That is an activity count reported by FDD, not a measure of effectiveness. It also reports that Congress appropriated $100 million per year for five years for a State Department fund supporting secure information and communications technology; that figure refers to the fund and period as described in the memo, not the total budget for all capacity-building work.
Rank #4
What the report does—and does not—establish
The memo lays out a policy agenda and uses Ukraine to make the case for investment in partner cyber defenses. The available contemporaneous coverage and the memo do not establish the current implementation status of its eight recommendations, present-day agency responsibilities or budgets, or the outcomes attributable to individual programs. Nor do the mission count and appropriation figure demonstrate that the overall portfolio improved security.
For readers asking how the United States can help allies defend against cyberattacks, the memo’s answer is a coordinated mix of resilient infrastructure, technical and policy assistance, law-enforcement cooperation, military exercises, and sustained funding—with legal and operational questions addressed where support touches cyber-force employment.
Recommended Free Tools
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

