The most consequential battles of the present era may leave no crater and produce no front line. They unfold in the systems that quietly keep a society running — the grid that powers a hospital, the valves that move water and fuel, the ledgers that settle payments. When these falter, the cause is increasingly not a storm or an accident but a deliberate intrusion, and the line between crime, espionage and armed conflict grows harder to draw.
Over the past two decades, conflict has migrated steadily into the network. States that would hesitate to fire a missile now probe, map and pre-position inside the digital systems of their rivals, frequently in peacetime and frequently without acknowledgement. The appeal is plain: a capable operation can impose real-world harm at a distance, at modest cost, and with a level of deniability that conventional force can rarely offer.
What follows is an analytical overview — neutral in tone and necessarily provisional — of how this shift occurred, the forms it takes, the persistent problem of attribution, and the unsettled question of how the laws of war apply to operations that travel down a fibre-optic cable rather than across a border.
How conflict moved into the network
The systems that modern life depends upon — electricity, water, gas and oil pipelines, hospitals, transport and the financial plumbing that clears payments — were largely designed for reliability and efficiency, not for resisting a determined adversary. Many run on industrial control systems decades old, increasingly connected to wider networks for remote monitoring. That connectivity brings efficiency, and exposure.
Critical infrastructure is an attractive target precisely because it sits at the intersection of two worlds. A successful operation can produce tangible, kinetic-like effects — darkened cities, halted fuel, disrupted care — without a single soldier crossing a frontier. The harm is felt by civilians and economies, yet the act itself remains, for a time, invisible and unattributed. Reported incidents in recent years, from disruptions to electricity supply in conflict zones to attacks on fuel distribution and healthcare providers, illustrate the pattern, even where the precise origin and intent of each remains contested.
It is difficult to think of a domain in which the gap between capability and accountability is wider: states can now reach into the systems on which civilians most depend, while the rules governing such reach remain unsettled and, in places, contested.
The principal forms of cyber conflict
Operations against infrastructure are not monolithic. They span a spectrum from quiet intelligence-gathering to destructive sabotage, and the same technical access may serve very different ends. Several broad categories recur in publicly reported incidents.
- State-sponsored intrusions. Sophisticated, well-resourced groups — often linked, on the basis of publicly reported analysis, to particular states — penetrate networks to gather intelligence or to establish persistent access that could later be exploited. Much of this activity is preparatory rather than immediately destructive.
- Wiper malware. Unlike software designed to steal data, wipers exist to destroy it, rendering systems inoperable. Several incidents reported during recent conflicts have involved tools of this kind aimed at government and infrastructure systems.
- Ransomware as a geopolitical tool. Criminal ransomware — which encrypts data and demands payment — has at times appeared to serve state interests, whether through tolerated criminal groups or operations where extortion masks a disruptive purpose. The line between profit-driven crime and statecraft can be genuinely indistinct.
- Supply-chain compromises. Rather than attacking a target directly, an operation may compromise a trusted software vendor or component, so that the malicious code is distributed, unwittingly, to thousands of downstream users. These are among the most difficult intrusions to detect and to defend against.
The attribution problem and the appeal of deniability
The defining feature of cyber operations, from a legal and strategic standpoint, is the difficulty of saying with confidence who is responsible. A cyber operation can be routed through compromised machines in third countries, can borrow tools associated with other actors, and can be designed to mislead investigators. Even where technical analysis points strongly toward a particular source, translating that into the legal standard of attribution required to justify a response is a separate and harder task.
This ambiguity is not incidental; for states, it is much of the point. Deniability lowers the political and legal cost of acting. An operation that cannot be confidently attributed is one that is difficult to condemn, to sanction, or to answer in kind without risk of error. The result is a grey zone of activity that falls below the threshold the public associates with "war," yet may impose serious harm. Attribution today rests on a mixture of technical forensics, intelligence and political judgement, and governments increasingly make attributions publicly — though such claims are, by their nature, assertions that others may dispute.
Does international law reach cyberspace?
There is broad agreement among states that existing international law applies to cyberspace; the difficulty lies in how. The most influential effort to map the principles is the Tallinn Manual process — a study by independent experts, convened in connection with a NATO-affiliated centre, examining how established law might apply to cyber operations. It is an academic analysis rather than a binding treaty, and it is best read as a careful articulation of contested questions, not a settled code.
Two thresholds dominate the analysis. The first is whether a cyber operation amounts to a "use of force" under the UN Charter, or rises further to an "armed attack" that may trigger a state's right of self-defence. Many experts suggest that an operation causing physical destruction or loss of life comparable to a conventional attack could cross these thresholds, but a great deal of disruptive activity — espionage, data theft, temporary outages — is widely thought to fall below them, leaving its legal character genuinely unsettled.
The second concerns the conduct of operations during armed conflict, where the principles of international humanitarian law apply. Distinction requires parties to separate military objectives from civilian objects; proportionality forbids attacks whose expected civilian harm would be excessive relative to the military advantage anticipated. Applying these to interconnected networks is fraught: an operation aimed at a military system may cascade into the civilian infrastructure it shares, and the dual-use nature of much digital infrastructure complicates every assessment.
No single answer commands universal agreement, but the legal debate tends to turn on a handful of recurring questions:
- Did the operation cause physical destruction, injury or death comparable to a kinetic attack?
- Can responsibility be attributed to a state, or to actors whose conduct is fairly traceable to one?
- Does the effect cross the threshold of a "use of force," or further still an "armed attack"?
- Were civilian objects deliberately or foreseeably harmed, engaging the principle of distinction?
- Would any responsive measure itself be necessary, proportionate and lawful?
Resilience and what organisations should do
Because deterrence and attribution remain imperfect, much of the practical burden falls on resilience — the capacity to withstand, contain and recover from an intrusion rather than merely to repel it. For organisations operating critical or sensitive systems, the measures below are widely regarded as foundational rather than optional.
- Map and segment your systems. Understand where critical functions live, separate them from general networks, and limit the paths an intruder can travel once inside.
- Plan for compromise, not just prevention. Maintain tested incident-response and continuity plans on the assumption that a breach will eventually occur, including offline backups that ransomware cannot reach.
- Scrutinise the supply chain. Assess the security of vendors and software components, since a trusted supplier can become the vector of an attack.
- Meet your regulatory obligations. Sectors deemed critical face growing duties around security and incident reporting; understanding which regimes apply is now a governance question, not merely a technical one.
- Treat people as the perimeter. Training, access controls and credential hygiene address the human routes by which many intrusions still begin.
- Conflict has moved into the network, with power grids, water, pipelines, hospitals and financial systems now treated as targets.
- The principal forms range from state-sponsored intrusions and wiper malware to ransomware deployed for geopolitical ends and supply-chain compromises.
- Attribution is hard by design; deniability lowers the cost of acting and sustains a grey zone below the public's idea of "war."
- International law is broadly accepted to apply, but the thresholds of "use of force" and "armed attack," and the principles of distinction and proportionality, remain contested online.
- With deterrence imperfect, resilience — segmentation, tested recovery, supply-chain scrutiny and regulatory compliance — carries much of the practical weight.
How Crejj & Partners can help
Our teams advise organisations on the legal dimensions of cyber risk before, during and after an incident. On cyber-incident response, we help clients preserve evidence, manage breach-notification and regulatory obligations, and coordinate with the appropriate authorities under pressure. On regulatory and governance matters, we assess which security and reporting regimes apply to a given operation and help boards discharge their duties. And on corporate risk, we advise on contractual allocation of liability, supply-chain assurance, and the cross-border exposures that arise when an intrusion touches several jurisdictions at once. Our role is to bring legal clarity to a domain defined by uncertainty.
This article is provided for general information and analysis only. It is not legal advice, does not constitute political endorsement of any party, and does not create a solicitor–client relationship. Descriptions reflect publicly reported information as of mid-2026 and may since have changed. Crejj & Partners is a fictional firm presented for illustrative purposes on this website.