When people hear “cyber warfare,” they picture malware, zero-days, or hackers typing fast in dark rooms.
That’s the smallest part of the story.
It’s about influence, pressure, disruption, and patience.
The Shift: From Attacks to Control
Breaking systems is loud.
Controlling behavior is effective.
Nation-state cyber operations now focus on shaping outcomes rather than causing outages.
That includes:
1. Slowing response, not stopping systems
2. Creating doubt, not destruction
3. Nudging decisions instead of forcing them
No alarms.
No ransom notes.
Just long-term impact.
Information Manipulation Is a Core Weapon
An example of a successful cyber operation that does not involve hacking physical systems is as follows:
1. Hacked Emails released at strategic times
2. Selectively exposing data to damage the credibility of an organization
3. Amplifying false narratives through Bot and False Accounts
As a result, the systems remain intact but not the public trust.
An analogy
Rather than blowing up a bridge, drive the vehicles (traffic) through the streets in the wrong direction.
Supply Chain Pressure Beats Direct Attacks
Directly attacking a government network is risky.
Attacking its suppliers is easier.
This shows up as:
1. Compromised software updates
2. Backdoored libraries
3. Tampered hardware components
The target installs the problem themselves.
No intrusion required.
Once embedded, access looks legitimate.
Economic Disruption Without a Single Exploit
Cyber warfare often aims at wallets, not servers.
Examples seen in the wild:
1. Market manipulation through fake disclosures
2. Sabotaging logistics visibility, not logistics systems
3. Targeting payment processors during peak demand
The result isn’t chaos.
It’s uncertainty, which is worse.
The illegal, gray area, and "permissible" action types may not always appear to be malfeasance in the logs of various types of operations, but rather fall into various categories such as the following:
1. Publically scraping "huge" data sets;
2. Exploiting legal APIs to conduct intelligence gathering activities
3. Rental access to cloud resources instead of illegally accessing cloud resources.
While these activities may not constitute violations of current policies, they do undermine the premise of those policies.
Why Traditional Defenses Miss This
Security teams are trained to detect:
1. Intrusions
2. Malware
3. Anomalous traffic
Cyber warfare often avoids all three.
Instead, it blends into:
1. Business processes
2. Legal access
3. Normal user behavior
There’s no IOC for influence.
What Defense Looks Like Here
Defending against cyber warfare isn’t just a SOC problem.
It requires:
1. Cross-team awareness (security, legal, PR, operations)
2. Monitoring data exposure, not just access
3. Understanding how your systems affect real-world decisions
And most importantly:
Knowing what normal impact looks like, not just normal traffic.
A Simple Way to Think About It
Hacking breaks systems.
Cyber warfare bends outcomes.
If your defense only watches for broken systems, you’ll miss the war happening around them.