ON2IT - Zero Trust Innovators

Select your region

Talk to us →
Digital Warfare

War in the digital age

When we think of war, we picture tanks, soldiers and fighter jets, images shaped by decades of physical conflict. Yet today, some of the most serious attacks don’t involve broken buildings or explosions. They start with a single file or piece of code.

How should countries respond when modern attacks no longer fit traditional ideas of warfare?

Get in touch Read the blog
Blurring the lines

What defines an act of war?

After World War II, international law focused on armed force between nations. But today’s cyberattacks, disinformation campaigns and supply-chain disruptions can cause serious harm without matching those old definitions. They challenge governments, businesses and civilians alike, without a single bomb or soldier.

  1. 01
    Cyber
    Code as a weapon

    A targeted exploit, a wiper, a ransomware drop, all can disable critical infrastructure without crossing a border or firing a shot.

  2. 02
    Disinformation
    Trust as the target

    Disinformation campaigns destabilise institutions, elections and markets, adding new layers of complexity that traditional conflict frameworks were never built to handle.

  3. 03
    Supply chain
    Disruption at scale

    Compromising a single vendor can ripple through thousands of dependent organisations, weaponising legitimate update channels and trusted relationships.

Invisible threats, real damage

Cyber attacks in modern warfare

Cyberattacks can cripple economies and infrastructure without physical destruction. Incidents like NotPetya and Stuxnet show the disruptive power of digital operations, reaching far beyond the original target, with consequences that play out for years.

NotPetya, 2017
$10B
Collateral damage across shipping, pharma, logistics
Stuxnet, 2010
First
Code that caused kinetic, physical damage to hardware
The next front
Civilian
Power grids, water, hospitals: assume you’re in scope
No flags, no borders

The attribution challenge

Digital attackers operate in the shadows. Nation-states, criminal groups, individuals, often masking their identity through layered infrastructure and proxies. Governments sometimes outsource attacks to hacker groups, making attribution harder still, and decisive responses risk being based on assumptions.

01Plausible deniability, built into the model. State actors can disclaim responsibility, blame criminal proxies, or attribute attacks to entirely different nations. The strategic ambiguity is the point.
02False flags in the artefacts. Code, language, timestamps, all can be planted to redirect blame. Confident attribution requires depth, not just one suspicious string.
03Wrong target, real consequences. An escalation based on faulty attribution is its own incident. The international community is still building the rules of engagement.
The takeaway Confident attribution is engineering, not headline material. Treat first-hour reports as hypotheses, not verdicts, and design your response to survive being wrong.
Private sector on the frontlines

Industry’s growing role in defense

Cyber defense is no longer just a government task. Businesses often detect and stop attacks first. The 2021 Microsoft Exchange attack showed how vital the private sector has become, today, cybersecurity providers and MSSPs are essential players in national resilience.

Detection

Private sector goes first

Vendors, MSSPs and corporate SOCs often see new attack patterns before any national CERT does, because they’re looking at production traffic at scale.

Coordination

Public-private partnerships

Effective national resilience depends on sharing threat intelligence quickly across borders and between industry and government, the muscle is still being built.

Accountability

More responsibility, more scrutiny

As industry takes on more of the defensive load, regulation follows. NIS2, DORA and national cyber laws make corporate cybersecurity a matter of public interest.

Preparing for the digital battlefield

Redefining warfare in the cyber age

Cyberattacks often don’t fit traditional definitions of warfare, but they can seriously impact national security and the economy. When should a digital attack be treated as an act of war? How should international law evolve? These are the questions we’re thinking about, together with our customers and the broader industry.

Get in touch Read the playbook