War in the digital age
When we think of war, we picture tanks, soldiers and fighter jets, images shaped by decades of physical conflict. Yet today, some of the most serious attacks don’t involve broken buildings or explosions. They start with a single file or piece of code.
How should countries respond when modern attacks no longer fit traditional ideas of warfare?
What defines an act of war?
After World War II, international law focused on armed force between nations. But today’s cyberattacks, disinformation campaigns and supply-chain disruptions can cause serious harm without matching those old definitions. They challenge governments, businesses and civilians alike, without a single bomb or soldier.
-
01CyberCode as a weapon
A targeted exploit, a wiper, a ransomware drop, all can disable critical infrastructure without crossing a border or firing a shot.
-
02DisinformationTrust as the target
Disinformation campaigns destabilise institutions, elections and markets, adding new layers of complexity that traditional conflict frameworks were never built to handle.
-
03Supply chainDisruption at scale
Compromising a single vendor can ripple through thousands of dependent organisations, weaponising legitimate update channels and trusted relationships.
Cyber attacks in modern warfare
Cyberattacks can cripple economies and infrastructure without physical destruction. Incidents like NotPetya and Stuxnet show the disruptive power of digital operations, reaching far beyond the original target, with consequences that play out for years.
The attribution challenge
Digital attackers operate in the shadows. Nation-states, criminal groups, individuals, often masking their identity through layered infrastructure and proxies. Governments sometimes outsource attacks to hacker groups, making attribution harder still, and decisive responses risk being based on assumptions.
Industry’s growing role in defense
Cyber defense is no longer just a government task. Businesses often detect and stop attacks first. The 2021 Microsoft Exchange attack showed how vital the private sector has become, today, cybersecurity providers and MSSPs are essential players in national resilience.
Private sector goes first
Vendors, MSSPs and corporate SOCs often see new attack patterns before any national CERT does, because they’re looking at production traffic at scale.
Public-private partnerships
Effective national resilience depends on sharing threat intelligence quickly across borders and between industry and government, the muscle is still being built.
More responsibility, more scrutiny
As industry takes on more of the defensive load, regulation follows. NIS2, DORA and national cyber laws make corporate cybersecurity a matter of public interest.
Redefining warfare in the cyber age
Cyberattacks often don’t fit traditional definitions of warfare, but they can seriously impact national security and the economy. When should a digital attack be treated as an act of war? How should international law evolve? These are the questions we’re thinking about, together with our customers and the broader industry.