Summary
China’s cybersecurity capabilities have rapidly evolved into a comprehensive and multifaceted system integrating advanced offensive and defensive measures, regulatory oversight, and talent development. This transformation reflects China’s strategic prioritization of cyberspace as a critical domain for national security, economic development, and military competition under the leadership of the Chinese Communist Party (CCP) and President Xi Jinping. Institutional reforms, such as the establishment of the Cyberspace Administration of China (CAC) and the creation of the People’s Liberation Army Cyberspace Force, underscore the centralized control and militarization of cyber operations.
China’s military doctrine emphasizes cyberspace as a foundational battlefield, aiming to achieve information dominance through integrated cyber, electronic, and psychological warfare tactics. The People’s Liberation Army (PLA) seeks to disable adversaries’ command and control networks early in conflict to gain strategic advantage, reflecting a “peacetime-wartime integration” approach that merges civilian and military cyber resources. Alongside military advances, China has developed cutting-edge AI-driven cybersecurity tools, such as Zhipu AI’s open-weight GLM-5.2 model, which rivals Western counterparts like Anthropic’s Mythos in vulnerability detection and cyber offense capabilities, challenging existing global controls on AI technologies.
Internationally, China’s cyber activities have prompted significant scrutiny and concern, especially regarding state-linked espionage campaigns targeting the United States, its allies, and critical infrastructure sectors worldwide. High-profile cyber incidents and ongoing operations attributed to China have heightened geopolitical tensions and triggered coordinated responses from security alliances like the Five Eyes and the European Union. These developments highlight the complex interplay between China’s ambitions for cyberspace sovereignty, its expanding technological capabilities, and global cybersecurity governance challenges.
China’s cybersecurity expansion has also sparked controversies and ethical debates, particularly about the militarization of cyberspace, state-sponsored hacking, and the balance between technological innovation and regulatory control. While China continues to push forward with integrating advanced AI tools, comprehensive regulatory frameworks, and talent cultivation, its trajectory raises critical questions about the future of international cyber norms, trust, and stability in an increasingly contested digital environment.
Background
China’s cybersecurity landscape has undergone significant transformation since the early 1990s, evolving from basic infrastructure projects into a comprehensive strategy that integrates offensive cyber capabilities with defensive measures. This multifaceted approach reflects China’s growing recognition of cybersecurity as a critical domain for both national security and economic development. The Chinese government’s increasing focus on digital security aligns with broader policy goals aimed at maintaining sovereignty over cyberspace and protecting critical information infrastructure.
Institutionally, China has made substantial organizational reforms to strengthen its cyber governance. In 2014, the Central Leading Group for Cybersecurity and Information was established, with the Cyberspace Administration of China (CAC) serving as its external office, emphasizing centralized control over cyberspace policy and regulation. The military dimension of China’s cyber strategy is embodied in the People’s Liberation Army (PLA), which established the Strategic Support Force (PLASSF) in 2015 to consolidate cyber intelligence, defense, and offensive operations under a unified command. In April 2024, the PLASSF was dissolved, and its cyberwarfare capabilities were transferred to the newly created People’s Liberation Army Cyberspace Force, underscoring the ongoing evolution of China’s cyber military structure.
Chinese military doctrine explicitly prioritizes cyberspace as a fundamental battlefield. The PLA’s 2020 Science of Military Strategy described cyberspace as the “basic platform for information warfare,” highlighting the importance of blinding adversaries’ command, control, communications, computers, intelligence, surveillance, and reconnaissance (C4ISR) systems to achieve information dominance early in conflict. Under the leadership of Xi Jinping, cybersecurity has been elevated to a critical area of military competition, with calls to overcome outdated attitudes and enhance technological and strategic capabilities across government, military, and industry sectors.
Externally, China’s cyber activities have drawn significant international scrutiny, especially regarding state-linked hacking operations targeting US and allied networks. Reports from US agencies, including the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the National Security Agency (NSA), have documented persistent exploitation of common vulnerabilities by Chinese state-sponsored groups over the past two decades, reflecting China’s expanding cyber footprint in pursuit of political and economic objectives. This dynamic has fueled concerns in Washington and beyond about the implications of China’s cyber advancements for global security.
At the same time, China continues to invest in building a robust cybersecurity workforce and fostering cooperation among public, private, and academic sectors to address an increasingly complex threat environment. The government’s plans to enhance data security within critical industries further signal an intent to bolster defensive capabilities alongside offensive cyber tools. Collectively, these developments underscore China’s ambition to position itself as a leading power in cyberspace, narrowing the technological gap with other global actors and asserting its model of cyberspace sovereignty.
Organizational Structure
China’s cybersecurity organizational structure is complex, involving multiple government and military bodies that coordinate to manage both defensive and offensive cyber operations. At the core of this structure is the Cyberspace Administration of China (CAC), which functions as the national internet content regulator and censor. The CAC operates directly under the Central Committee of the Chinese Communist Party (CCP) and serves as the executive arm of the CCP’s Central Cyberspace Affairs Commission, which was established following reforms in 2014 that created the Central Leading Group for Cybersecurity and Information.
Within the military domain, the People’s Liberation Army (PLA) has integrated cyber capabilities extensively into its doctrine and structure. The PLA Strategic Support Force (PLASSF) was established to consolidate various cyber, space, and electronic warfare units. It combines cyber intelligence, defense, and offensive capabilities, incorporating former departments such as the Third Department (cyber espionage) and Fourth Department (electronic support measures) of the PLA General Staff Department. The PLASSF is further divided into the Network Systems Department, responsible for cyber operations, and the Space Systems Department, which was reorganized in 2024 as the independent PLA Aerospace Force.
In 2015, the PLA created the Cyberspace Force as part of a broader military modernization effort, alongside the PLA Aerospace Force and the PLA Information Support Force. The Cyberspace Force oversees offensive cyberwarfare, psychological operations, and advanced cybersecurity research. It is organized under the General Staff Department and the Political Work Department, with subordinate units such as Unit 32047 under the Logistics Department. The Equipment Department manages seven local military representative offices to support the force’s operations. The PLA emphasizes the integration of cyber operations with traditional military capabilities, recognizing cyberspace as a fundamental domain for achieving information dominance in line with their “three dominances” strategy across information, air, and sea.
Aside from state organs, China’s cybersecurity ecosystem includes collaboration with non-state actors such as major technology companies (e.g., Alibaba, Huawei) and contractors, who participate in research, development, and operational execution of cyber initiatives. This public-private synergy is reinforced through Chinese disclosure laws and strict regulatory enforcement, ensuring alignment with CCP cybersecurity objectives.
The Ministry of State Security (MSS) also plays a critical role, particularly through its highly technical 13th Bureau and the China National Information Technology Security Evaluation Center (CNITSEC), focusing on information assurance. While maintaining a low public profile, the MSS is regarded as one of the most capable entities in China’s cybersecurity landscape.
Strategic Doctrine and Guiding Principles
China’s strategic doctrine in cybersecurity is deeply intertwined with its broader military strategy, reflecting an emphasis on integrating cyber capabilities into multi-domain operations. The People’s Liberation Army (PLA) has increasingly focused on leveraging information operations to achieve dominance across the information, air, and sea domains—referred to as the “three dominances” (三权)—which are critical for determining the success of military campaigns, particularly against Taiwan, the United States, and allied forces.
Cyber capabilities were formally incorporated into PLA doctrine and detailed in key policy documents such as the 2013 and 2020 editions of the Science of Military Strategy. These documents highlight cyberspace as the foundational platform for information warfare, underscoring that disabling an adversary’s command, control, communications, computers, intelligence, surveillance, and reconnaissance (C4ISR) networks through cyberattacks can effectively paralyze their combat operations at the outset of conflict, thereby securing information dominance for China. This dominance is defined as the operational advantage gained by controlling, manipulating, and defending information to maximize warfighting effects.
A core element of this doctrine is the principle of “peacetime-wartime integration,” which aims to blend civilian and military cyber capabilities seamlessly, forming a unified front under China’s military-civil fusion strategy. This integration facilitates constant readiness and rapid transition between peacetime and wartime cyber operations.
Further emphasizing the multifaceted nature of China’s strategic approach, the PLA incorporates the “three warfares” doctrine—Public Opinion Warfare, Psychological Warfare, and Legal Warfare—into its psychological and information campaigns. Notably, the base designated as the center for psychological warfare efforts against Taiwan was brought under the control of the PLA Strategic Support Force (PLASSF) in 2016, highlighting the institutionalization of these tactics within China’s military structure.
Chinese leadership under Xi Jinping has explicitly recognized cyber conflict as a critical domain of military competition. At the New Gutian Conference, Xi called for overcoming outdated mindsets and methodologies within the PLA to meet the demands of the cyber era, advocating for improved situational awareness and technological parity with rival powers across government, military, and private sectors.
Taken together, China’s cybersecurity strategy is characterized by its emphasis on information dominance, multi-domain integration, and the fusion of military and civilian resources, designed to enable China to challenge and potentially rival Western dominance in AI-driven cybersecurity and other advanced technologies.
Key Cybersecurity Capabilities
China has developed a robust and multifaceted cybersecurity ecosystem that integrates advanced technologies, regulatory frameworks, and talent development to address both domestic and international digital threats. A significant highlight in this ecosystem is Zhipu AI’s open-weight GLM-5.2 model, which demonstrates frontier-level cybersecurity capabilities. Benchmarking tests by Semgrep in June 2026 showed that GLM-5.2 outperforms leading AI models such as Claude Code in identifying insecure direct object references (IDOR), achieving a 39% F1 score compared to Claude Code’s 32%. Additionally, Graphistry’s independent CyBT-CTF evaluation confirmed that GLM-5.2 matches Opus 4.8 in cybersecurity investigative tasks, indicating a substantial leap in AI-driven vulnerability detection.
This progress challenges existing Western approaches to controlling AI access through hardware restrictions and access controls, prompting critical reassessments regarding the maintenance of global cybersecurity dominance. China’s advancements are bolstered by government institutions such as the Cyberspace Administration of China (CAC), which acts as the central internet content regulator and enforcer of cybersecurity, data security, and privacy laws under the aegis of the Chinese Communist Party. The CAC oversees regulatory bodies including the National Computer Network Emergency Response Technical Team and the Cybersecurity Standardization Technical Committee (TC260), implementing standards and certifications aimed at strengthening data protection and personal information management.
China’s cybersecurity regulatory framework is grounded in laws like the 2017 Cybersecurity Law and the 2021 Data Security Law, which collectively establish stringent controls over cyberspace governance. These laws emphasize state control, data lockdown, increased surveillance, and the subordination of technology firms to national security and self-reliance goals. This comprehensive strategy exceeds the scope of regulations seen in the US and Europe, potentially influencing emerging markets’ alignment in global cybersecurity governance.
On the research and development front, China’s military and civilian institutions have long contributed to foundational cybersecurity and computing capabilities. The PLA’s NSD 56th Research Institute, founded in 1951 and located in Wuxi, is notable for pioneering computing milestones such as China’s first supercomputer and advanced GHz-level computing. This institute continues to support network systems, communications, information assurance, and cybersecurity research aligned with national defense priorities.
China’s cybersecurity sector also invests heavily in bridging the talent gap through collaborative initiatives involving academia, industry, and government. Institutions like the University of Electronic Science and Technology of China (UESTC) play a pivotal role in training cybersecurity professionals and developing innovative tools. Despite rapid industry growth, China faces a significant shortage of skilled cybersecurity experts, which it aims to address through expanded education and workforce development programs. Moreover, Chinese civilian researchers contribute actively to international vulnerability disclosure programs, exemplified by their submission of 27% of vulnerabilities reported to major bug bounty programs between 2017 and 2023. The domestic Tianfu Cup hacking competition further nurtures this talent pool.
Together, these capabilities position China as a formidable actor in cybersecurity, capable of rivaling leading Western technologies such as Anthropic’s Mythos, and underpinning a strategic vision that integrates advanced AI tools, comprehensive regulation, military doctrine, and human capital development.
Notable Cyber Incidents and Operations
China has been implicated in numerous significant cyber incidents and operations, often characterized by espionage and strategic disruption. Between 2000 and 2020, China engaged in 114 documented cyber campaigns, with 90 attributed to espionage activities targeting various sectors, including private commercial entities across at least ten industries. These campaigns frequently aim to extract sensitive information or influence critical infrastructure.
One prominent example includes the advanced persistent threat (APT) groups aligned with China that have targeted critical U.S. infrastructure, particularly in the communications sector, which encompasses telecommunications, internet service providers, satellite systems, and cloud services. Such operations demonstrate China’s intent to influence or disrupt key technological and economic domains.
In recent years, cyber espionage campaigns linked to China have expanded geographically and technologically. In 2023, a previously unknown China-aligned APT group, dubbed “GopherWhisper” or “Burrow,” launched a campaign against entities in Mongolia. This operation utilized tools developed in the Go programming language to maintain persistent access and exfiltrate data. Similarly, the “Volt Typhoon” APT was identified targeting critical infrastructure in multiple countries, including New Zealand and the United States, with U.S. authorities disrupting an ongoing operation that had persisted for at least five years by early 2024.
Noteworthy is the exposure in February 2024 of approximately 190 megabytes of data from a Chinese cybersecurity firm, revealing espionage activities against the governments of the United Kingdom, India, Indonesia, and Taiwan. This incident highlighted the extent of Chinese cyber intelligence efforts against foreign governments.
These activities have prompted international responses. For instance, the European Union debates regulatory approaches toward Chinese technology vendors amid security concerns, while countries within the Five Eyes alliance publicly attribute sophisticated cyberattacks to Chinese state-sponsored groups. Furthermore, advanced AI models are increasingly recognized as critical tools in cyber offense and defense, influencing the dynamics of cyber warfare involving China and other global actors.
Collectively, these incidents and operations demonstrate China’s multifaceted approach to cyber capabilities, spanning espionage, sabotage, and influence operations, with significant implications for global cybersecurity and geopolitical stability.
Zhipu AI and the “Zai” Narrative
China’s Zhipu AI, also known as Z.ai, has positioned itself prominently within the cybersecurity and AI landscape by releasing its open-weight language model, GLM-5.2. This model has been noted for its ability to rival Anthropic’s proprietary Mythos model in tasks related to bug-finding and cybersecurity vulnerability detection. Unlike Mythos, which Anthropic developed with significant computing power and hardware investment, Zhipu AI’s approach leverages accessible open-weight models, making GLM-5.2 widely available as a free download, contrasting sharply with restricted access to models like Mythos in the United States.
The release of GLM-5.2 marks a strategic move by China to assert technological parity in AI-driven cybersecurity, despite domestic models reportedly trailing behind Western counterparts by 20 to 30 percent in fundamental capabilities. Zhipu AI’s CEO highlighted the urgency for China to develop alternative pathways to produce Mythos-grade bug-finders rather than waiting for gradual improvements in foundational model strength. This reflects a broader narrative in China’s AI ambitions, where innovation seeks to compensate for hardware and resource
International Reactions and Diplomatic Implications
China’s expanding cyber capabilities and persistent cyberespionage activities have elicited significant international concern and a range of diplomatic responses. Western nations, particularly the United States and the European Union, have increasingly framed China as a major cyber threat, reacting with heightened security measures, policy adjustments, and public condemnation.
The United States has been particularly vocal in attributing numerous cyber intrusions and espionage campaigns to Chinese state-backed actors. The U.S. Department of Defense and various intelligence agencies have documented extensive Chinese efforts to infiltrate government, corporate, and critical infrastructure networks over the past two decades. Recent actions include sanctions against Chinese entities and individuals linked to cyberattacks, highlighting ongoing tensions around cybersecurity and innovation theft. The Cybersecurity and Infrastructure Security Agency (CISA) continues to develop advisories and defensive tools aimed at countering sophisticated Chinese cyber operations, such as those attributed to the Salt Typhoon group targeting telecommunications infrastructure.
Similarly, the European Union has increasingly recognized cybersecurity as a critical political issue, motivated in part by Chinese cyber activities directed at diplomatic missions, NATO, and EU institutions. This has led to strengthened legislative frameworks like the Network and Information Systems Directive (NIS2) and the Cybersecurity Act, as well as closer alignment with U.S. positions on China as a cybersecurity threat. The EU’s focus remains on protecting civilian and economic sectors while fostering cooperation among member states to counter cyber threats. However, divergent national capabilities pose challenges for a unified response.
Diplomatic tensions tied to cybersecurity reflect broader geopolitical frictions. For instance, China’s cyberespionage spikes during regional crises—such as disputes with Vietnam and the Philippines—suggest a strategic use of cyber operations to influence bargaining positions and undermine opposing diplomatic efforts. Historical events, including the 1999 NATO bombing of the Chinese embassy in Belgrade, have contributed to China’s impetus to develop robust cyberwarfare capabilities as a means to bolster its international leverage.
The increasing sophistication and scale of Chinese cyber operations have prompted calls from security alliances like the Five Eyes to adopt coordinated responses against emerging cyber threats, including concerns over advanced technologies like open-weight models with frontier cybersecurity capabilities. While the United States and Europe emphasize defensive measures and sanctions, it remains uncertain how other major economies will position themselves relative to China’s vision of cyberspace sovereignty and its broader cyber strategy.
Criticisms, Controversies, and Ethical Concerns
China’s expanding cybersecurity capabilities have drawn significant international criticism and sparked ongoing controversies regarding their ethical implications. A central point of contention is the alleged use of state-sponsored cyber espionage activities. For instance, U.S. indictments accuse Chinese hackers linked to the Ministry of State Security of targeting intellectual property and sensitive business information, including COVID-19 research, via front companies operating abroad. These accusations underline persistent concerns about China’s approach to cyber operations as not merely defensive but actively offensive and clandestine.
Another dimension of controversy revolves around the geopolitical implications of China’s cybersecurity measures and policies. The European Union has faced lobbying pressure against proposals to phase out low-cost Chinese technology vendors, with groups like Connect Europe warning such measures would weaken cybersecurity sectors rather than strengthen them. Huawei has argued that exclusion based on country of origin violates principles of fairness, non-discrimination, and proportionality enshrined in EU law and World Trade Organization commitments, highlighting the complexity and divisiveness of supply chain security debates in Europe.
China’s military doctrine further complicates international cybersecurity dynamics. Observers note that the People’s Liberation Army (PLA) prioritizes cyber conflict as a key area of military competition, emphasizing the need for a constant “situational awareness posture” and modernization of cyber warfare strategies under Xi Jinping’s leadership. The establishment of China’s Cyberspace Force was explicitly aimed at reinforcing national cyber border defense and maintaining information security, reflecting the state’s commitment to assert cyber sovereignty aggressively. However, these developments also raise ethical questions regarding the militarization of cyberspace and the potential escalation of cyber conflicts globally.
Additionally, allegations of cyberattacks targeting Chinese firms by U.S. intelligence agencies suggest a tit-for-tat cyber espionage environment, further obscuring the lines between national defense and offensive cyber operations. The mutual accusations between the U.S. and China illustrate a broader challenge in establishing international norms and trust in cyberspace governance.
Moreover, ethical concerns extend into the realm of emerging cybersecurity technologies. Chinese firms such as 360 Security Technology claim advancements comparable to Western AI cybersecurity models like Anthropic’s Mythos, which are regarded as significant national security assets by the U.S. due to their autonomous vulnerability detection capabilities. This competition prompts critical reassessments of hardware and model access restrictions, as the rapid proliferation of AI-driven cybersecurity tools may challenge existing frameworks for technology control and ethical oversight.
Future Prospects and Challenges
China’s cybersecurity landscape is poised for continued evolution, characterized by an emphasis on both defensive and offensive capabilities, as well as increased collaboration across multiple sectors. Looking ahead, China is expected to strengthen its cooperation between public, private, and academic actors to address an increasingly complex threat environment. Talent development programs are anticipated to play a critical role in bridging the cybersecurity skills gap and expanding the workforce, exemplified by initiatives such as the Ministry of Industry and Information Technology’s 2024 plan to enhance data security within the industrial sector.
The country’s regulatory framework is likely to become more comprehensive, building on foundational laws like the 2017 Cybersecurity Law. Under the leadership of Xi Jinping, cybersecurity has been elevated as a strategic pillar of economic development, with China seeking to outpace other major economies in scope and control over cyberspace. This approach integrates broad digital governance with national security concerns, reflecting Beijing’s ambition to secure its digital infrastructure amid rising global cyber threats.
However, China’s offensive cyber operations and their implications present significant challenges. Despite public reports of targeting U.S. critical infrastructure with campaigns such as Volt Typhoon, no cyberattack attributed to China has matched the scale or strategic impact of notable incidents like the Stuxnet attack on Iran or Russian strikes on Ukraine’s power grid as of mid-2024. Nevertheless, Chinese military and intelligence bodies have long recognized the potential of cyberattacks to affect both civilian and military targets strategically, and the country continues to develop sophisticated tools within this domain.
On the international front, China faces a complex strategic environment. Western security alliances such as the Five Eyes have responded with policy measures addressing emerging threats, including those posed by advanced artificial intelligence models with cybersecurity implications. China’s model of cyberspace sovereignty and its expansive regulatory strategies contrast with the approaches taken by the United States and Europe, which emphasize differing balances between military, civilian, and economic cybersecurity priorities. The extent to which other major economies and regional blocs will align with China’s vision of cyberspace governance remains uncertain, posing potential diplomatic and operational challenges.
Moreover, ongoing geopolitical tensions and global cyber conflicts, such as the cyber dimensions of the Russia-Ukraine war, underscore the dynamic and contested nature of cyber capabilities. China’s continued advancement in this arena will require navigating an environment marked by both rapid technological change and shifting international norms and alliances.
The content is provided by Sierra Knightley, 12minread