Got any new ideas? (seriously)
First of all, START isn't even about non-proliferation. Has nothing to do with it. It's a series of agreements between two superpowers that served mostly as a diplomatic tool to de-escalate Cold War tensions and provide political cover for military budget reductions. It's been wildly successful in that regard.
The actual Nuclear Non-Proliferation Treaty is entirely about non-proliferation, a pre-emptive attempt to keep the capability of nuclear warfare out of the hands of most nations. It has absolutely nothing to do with preventing nuclear warfare between those nations already possessing them.
We haven't had nuclear war because so far, nobody who either actually wants to end the world, or is stupid enough to think he can "win" a nuclear war, has been in control of nuclear weapons. Not because of some piece of paper saying "I promise I won't kill you". Hilter had one of those with Stalin, how'd that work out?
"Cyber warfare" doesn't have the problems of nuclear warfare. It's unlikely to end the world, it's relatively cheap, the tools are widely available, and unlike physical warfare which destroys economies, it's actually about the economy. It's about getting a leg up on the competition. It's about money, period. The world some non-technical people live in where "cyber warfare" is all about winning actual wars is a world of fantasy.
In human history, only one thing has reliably stopped wars, and that is the tying together of nations' economies so closely that war between them becomes economically impossible. This just doesn't work in "cyber warfare".
Since hacking is usually hard to pin down definitively to a single actor, and it's difficult to justify a conventional armed response, you probably want a response that has similar properties.
If you assume that China is the perpetrator, then the best response to hacking attacks is to let it be known to the Chinese government that any hacking attempts will be responded to by attempts to destabilize communist party control (encouraging dissidents through side-channels, developing/distributing tech to bypass the great firewall, etc)
We can only HOPE that somewhere the US has a Top Secret Cyber Warfare group that's so good they never get caught.
Well, I have, occasionally, heard about such things, but personally, I don't live in China or Russia, I don't speak Chinese or Russian, I don't really know any Russians, the only ethnic Chinese I know are either Silicon Valley residents or employees of a Taiwan-based company I work for as an engineer (and at least two of them are also US citizens and spent the vast majority of their careers in Silicon Valley!), and at the end of the day, I just don't really care what goes on with Chinese and Russian websites. I'd venture a guess that I'm not unusual in that regard amongst Americans or, for that matter, most other non-Russian and non-Chinese people in the world.
I'd also note that laws and business culture in both places may well be even less conversant to public revelation of security breaches than in the English-speaking world.
Thus, I would find it very odd if a western news agency spent much time reporting on the security of Chinese and Russian websites.