- What: Businesses need wartime plans as global conflicts go digital
- Impact: Organizations must prepare for cyber threats amid geopolitical tensions
Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands An Informa TechTarget Publication Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise Newsletter Sign-Up Newsletter Sign-Up Cybersecurity Topics Related Topics Application Security Cybersecurity Careers Cloud Security Cyber Risk Cyberattacks & Data Breaches Cybersecurity Analytics Cybersecurity Operations Data Privacy Endpoint Security ICS/OT Security Identity & Access Mgmt Security Insider Threats IoT Mobile Security Perimeter Physical Security Remote Workforce Threat Intelligence Vulnerabilities & Threats Recent in Cybersecurity Topics Cyber Risk AI Gateways Offer Attackers the Keys to the Kingdom AI Gateways Offer Attackers the Keys to the Kingdom by Jai Vijayan Jul 9, 2026 4 Min Read Cybersecurity Operations European Organizations Have a Collaboration Security Confidence Gap European Organizations Have a Collaboration Security Confidence Gap by Jai Vijayan Jul 9, 2026 4 Min Read World Related Topics DR Global Middle East & Africa Asia Pacific Latin America Recent in World See All Cybersecurity Operations State IDs for AI Agents: Will Estonia Set a Precedent? State IDs for AI Agents: Will Estonia Set a Precedent? by Nate Nelson Jul 8, 2026 5 Min Read The Edge DR Technology Events Related Topics Upcoming Events Podcasts Webinars SEE ALL Resources Related Topics Resource Library White Papers Reports Webinars Newsletters Podcasts Heard It From a CISO Reporters' Notebook Dark Reading's 20th Videos Dark Reading Polls Partner Perspectives Meet the Editors Advertise With Us About Us Dark Reading Resource Library Cybersecurity Operations Cyber Risk Physical Security Сloud Security Cybersecurity In-Depth: Feature articles on security strategy, latest trends, and people to know. As Global Conflicts Go Digital, Businesses Need Wartime Gameplans The fate of a Ukrainian tax software company shows how modern cyberwarfare can claim casualties far beyond the battlefield, and how businesses across the ocean still need to protect themselves. Nate Nelson , Contributing Writer July 9, 2026 5 Min Read Source: sonmez karakurt via Getty Images Intellect Services could hardly be less interesting. A midsized, family-owned business in Ukraine that sold tax software. Its owners really can't be faulted for not anticipating that they might one day be a huge pawn in a regional cyberwar. To Russian foreign military intelligence, Intellect Services was totally interesting. The company's platform, M.E.Doc, was ubiquitous across Ukrainian businesses. Compromising M.E.Doc they could, in effect, impact most of the country's economy. And like other midsize businesses, the company wasn't likely to have any kind of exceptional cybersecurity defenses getting in Russia's way. The rest is history. The world's most notorious cyber threat actor, Sandworm , planted a backdoor in an M.E.Doc software update that came to be known as " NotPetya ." Beyond the damage to Intellect Services, NotPetya caused tens of billions of dollars in damage to thousands of unwitting companies around the world, an example of how cyberwarfare can spill far beyond the borders of warring nations. Related: Why Identity Security Is Your Cyber Career Entry Point Nation-states at war won't necessarily look to attack the government or the military, because the private sector can be a much easier target, argued Allie Mellen, a Forrester analyst and author of "Code War: How Nations Hack, Spy, and Shape the Digital Battlefield." It's very difficult for an enterprise to strike back. A lot of businesses that don't think of themselves as targets in war in fact are, and a lot more executives need to be gameplanning around it, Mellen argued at Zenith Live 2026 in Las Vegas last month. Why Businesses Become Military Targets Why would a nation-state drag you into a war? Jonathan Horowitz, legal advisor for the International Committee of the Red Cross (ICRC), quotes the 1977 Geneva Conventions, which defines a military objective under international humanitarian law (IHL) as things "which by their nature, location, purpose or use make an effective contribution to military action and whose total or partial destruction, capture or neutralization, in the circumstances ruling at the time, offers a definite military advantage." Whom does this rule include? First and most obviously, "If you have a contract with the military, you are a target," Mellen says. "That's the reality, because the adversary is looking to cut off the supply chain to the U.S. military, or at least to make them hurt in any way possible." Even organizations with no direct ties to a military or government might still look like military objectives to the right nation-state, though, thanks to the messy nature of modern warfare. The medical equipment firm Stryker supplies medical equipment and patient systems to a variety of US military branches. The company was targeted by Handala, an Iranian hacktivist group linked to the country's Ministry of Intelligence and Security (MOIS). Related: Zoom CISO: AI as a Security Enabler, Not Role-Replacer "In the battlefields of yesteryear, everything happened on fields where there was no civilian presence. Now times have changed," Horowitz explains. "There's been urban buildup. Armed conflict has entered into urban populations, where you have a mixture of civilian infrastructure and military infrastructure." Just as a bridge or a railway can serve both military and civilian purposes during war, putting civilians at unnecessary risk, digital infrastructure can serve both military and civilian purposes, putting neutral organizations and their customers in the firing line. Militaries have already demonstrated a willingness to attack digital service providers, even with kinetic strikes , which also have ramifications for all of those service providers' downstream customers. "If you're a local municipal energy provider using someone's cloud system, and that cloud system gets targeted because it's also providing assistance to some forward operating base, there are real questions to be considered about how much exposure both the provider and the municipality understand that they have," Horowitz explains. Related: Anthropic's Mythos Has Landed: Here's What Comes Next for Cyber Besides directly weakening enemy militaries, warring states can also have a variety of other interests that bring more organizations into their list of plausible targets. International laws aside, hacking organizations run by politically outspoken individuals might carry propaganda value. Hacking supply chain vendors like M.E.Doc — or businesses of any kind, really — can sow discord in an adversary's economy and inspire political pressure from an adversary's populace. Businesses Need Wartime Cybersecurity Strategies The Trump administration's March 2026 " Cyber Strategy for America " directive could ratchet up the wartime risk to civilian organizations even more. The very first point of the document declares that, beyond just defending American organizations, "We will deploy the full suite of U.S. government defensive and offensive cyber operations." (Emphasis added.) Without commenting on the merits of hackbacks, Mellen argues that "That is going to change the narrative of how some of these other countries approach the cyber operations they perpetrate. We're going to start to see more countries saying: 'How far can we push [private sector cyberattacks] before it serves as an escalatory measure?'" For these reasons and more, Mellen and Horowitz urge organizations of all kinds to evaluate the cyber risks that they face thanks to geopolitical conflicts. That means, first, having consistent conversations about geopolitical shifts and their potential impact on one's organization as they occur. Step two is putting intelligence into practice: investing in meaningful cybersecurity, physical security, or even small steps that make an organization less appealing to a nation-state threat actor. Horowitz suggests that service providers could segment their civilian and public sector services and take care to locate data centers away from military sites. Mellen suggests that companies be aware of what customers they publicly associate with. Even just not listing the U.S. military as a client on the company website helps manage the brand presence and make it less of a target, she says. Mellen acknowledges some of those precautions are not realistic for small and midsize businesses, but they can still augment their security with help from a vendor in that area that can add visibility to that risk. "We're not living in a world where threat actors are known to target certain industries or regions, and you don't have to worry about them if you're not in those industries or regions," she emphasizes. "You need to be aware of how a threat actor may change their motivation, and may change to targeting you because of the changing geopolitical situation." About the Author Nate Nelson Contributing Writer Nate Nelson is a journalist and award-winning scriptwriter. In addition to Dark Reading he writes for Darknet Diaries, the most popular show in cybersecurity across all media. He began his career as a freelancer, ghostwriting Forbes and CNBC op-eds for executives in tech and finance. Then he transitioned to journalism at Threatpost, where he covered cybersecurity news and trends. Throughout those years he co-created a cybersecurity podcast, Malicious Life, which in its day climbed into the Top 20 technology podcasts charts on Apple Podcasts and Spotify. He holds degrees from New York University and Bard College. As a born and bred New Yorker, he enjoys a superiority complex, but is polite enough to keep it to himself. See more from Nate Nelson Want more Dark Reading stories in your Google search results? Add Us Now More Insights Industry Reports The State of Cloud Security: The Latest Challenges The total economic impact™ of Snyk