The next war may not begin with a missile. It may begin with a login. A power grid may fail. A hospital database may be locked. A port may stop processing cargo. A telecom network may be silently compromised. A satellite link may be disrupted. A military email system may be breached. A fake video may spread before an election. A banking network may slow just as panic begins. No border is crossed, no war is declared and no soldier appears on television. Yet the state may already be under attack.
This is the new logic of conflict. Cyber attacks have become instruments of state power because they allow countries to spy, sabotage, coerce and destabilise without immediately triggering conventional war. They can be cheaper than missiles, harder to attribute than conventional attacks and easier to deny than an invasion.
Cyber conflict is no longer science fiction. It has become part of national security, foreign policy, economic competition and military strategy. Microsoft’s 2025 Digital Defense Report said nation-state threat actors were using increasingly advanced and scalable cyber and influence operations, while the UK’s National Cyber Security Centre warned that state actors remained a significant threat and that its incident teams had faced a record number of nationally significant cases.
Cyber attacks are no longer merely a technical nuisance. They are becoming weapons of state conflict.
The Battlefield Has Moved Into Networks
Traditional war attacks territory. Cyber warfare attacks systems. A country’s sovereignty today does not exist only on land, at sea or in the air. It also depends on data centres, cloud systems, payment networks, telecom exchanges, railway-control systems, electricity grids, military networks, identity databases, satellite communications, ports and hospitals.
This creates a new form of vulnerability. A country may defend its physical border with soldiers while leaving its digital nervous system exposed. It may possess fighter aircraft, tanks and missiles, but if electricity, banking or military communications can be disrupted, national security is already weakened.
Modern societies depend heavily on digital trust. Citizens assume that money will move, hospitals will function, trains will run, electricity will flow, government records will remain accessible and emergency services will respond. A cyber attack can target that trust directly.
The weapon may be invisible, but its effects can become physical.
Why States Find Cyber Weapons Attractive
Cyber operations offer states several strategic advantages.
1. Deniability
A missile usually provides visible evidence of an attack. Cyber operations can be routed through compromised servers, criminal infrastructure, proxy groups and networks located in several jurisdictions. This makes attribution slower and politically more complicated.
2. Scale
A relatively small group of skilled operators can probe or attack thousands of systems across borders. Software can be replicated at a scale that conventional weapons cannot easily match.
3. Lower Cost
Cyber operations can be substantially cheaper than conventional military campaigns. The attacker does not need to deploy armies, aircraft or naval forces to create disruption.
4. Peacetime Utility
States can use cyber capabilities for espionage, reconnaissance, intellectual-property theft and pre-positioning without formally going to war. Networks can be mapped and access established long before a political crisis begins.
5. Strategic Ambiguity
The victim may know that it has been attacked while struggling to prove publicly who was responsible. That uncertainty can delay diplomatic, economic or military retaliation.
These characteristics make cyber operations particularly suitable for grey-zone conflict: aggressive activity below the threshold of conventional war.
Critical Infrastructure Is the New Strategic Target
In earlier wars, armies targeted bridges, ports, factories, railways and communications. In cyber conflict, the strategic logic remains similar, but the entry point is increasingly digital.
Electricity grids, telecommunications, pipelines, water systems, ports, banks and transport networks are now high-value targets. Disrupting them can create economic damage, public fear and political pressure without a bomb being dropped.
CISA and partner agencies warned in 2024 that China-linked Volt Typhoon actors had compromised information-technology environments across several US critical-infrastructure sectors, including communications, energy, transportation and water systems. In 2025, the NSA and allied agencies also issued guidance concerning Chinese state-sponsored actors associated with global espionage activity.
The deeper danger is that access obtained today may be used during a future crisis.
An attacker may enter a network without immediately causing visible damage. Malware or persistent access can remain dormant until conflict escalates. At that point, compromised systems could potentially be used to interfere with military logistics, civilian infrastructure or communications.
Cyber warfare therefore begins long before open war.
Cyber Espionage Has Become Permanent
Not every cyber operation is designed to destroy. Many are designed to steal.
States use cyber espionage to obtain military secrets, diplomatic communications, industrial designs, scientific research, technology blueprints, negotiating positions and information about political or military officials.
The difference from traditional espionage is scale. A human spy may steal a folder. A successful cyber intrusion can expose entire databases.
This has implications for diplomacy and economic competition. A government entering trade negotiations may already have had confidential communications compromised. A defence company may lose intellectual property before a weapons system is completed. A research institution may lose years of work without immediately knowing that information has been copied.
Mandiant’s M-Trends 2026 report, as cited in the draft, noted that the global median dwell time for detected intrusions increased to 14 days in 2025, while cyber-espionage and North Korean IT-worker incidents had much longer median dwell times.
The most dangerous intrusion may therefore be the one that remains unnoticed.
Artificial Intelligence Is Changing the Cyber Battlefield
Artificial intelligence is making cyber operations faster, cheaper and more convincing.
Attackers can use AI to produce phishing messages, translate communications, imitate voices, create synthetic identities, scan vulnerabilities and automate influence campaigns. Defenders can also use AI to identify anomalies, analyse malicious code and accelerate incident response.
The competition is therefore two-sided.
Microsoft’s 2025 report said nation-state actors were increasingly using AI in cyber and influence operations. The technology can make deception more personalised and scalable.
Previously, phishing messages could often be identified by poor grammar or awkward wording. AI can now generate culturally fluent, professionally written and highly targeted messages. A fake government instruction, cloned executive voice or synthetic political video can therefore appear much more credible.
AI does not have to create perfect deception. It only needs to create enough uncertainty before verification arrives.
In cyber conflict, speed itself becomes a weapon.
Cyber Attacks and Information Warfare Are Converging
Cyber operations increasingly overlap with information warfare.
An attacker may breach a database, steal genuine documents, release selected material, distort its meaning and then amplify the resulting controversy through fake accounts or coordinated influence campaigns.
The breach is only the first stage. The narrative built around the stolen information can become equally important.
This is especially dangerous during elections, armed conflicts, communal tensions and periods of economic instability. A cyber operation can steal information, an influence operation can weaponise it, AI can scale the manipulation and social platforms can distribute it rapidly.
Domestic political actors may then amplify the material, sometimes without knowing its origin.
Cybersecurity and information integrity can therefore no longer be treated as completely separate fields.
A democracy can survive disagreement. It becomes more vulnerable when citizens cannot determine whether the information shaping public debate is authentic, manipulated or deliberately planted by a foreign actor.
Ransomware Shows How Crime and State Conflict Can Overlap
Ransomware is generally classified as cybercrime, but the line between criminal activity and geopolitical conflict can become blurred.
Some criminal groups operate from jurisdictions where authorities tolerate them. Others may serve state interests directly or indirectly. A state does not always need to control an operation to benefit from it.
This creates a hybrid environment in which criminals provide operational capability while governments may provide tolerance, protection or safe haven.
ENISA’s 2025 Threat Landscape described evolving attack models, reused tools, exploitation of vulnerabilities and collaboration among threat groups targeting the resilience of digital infrastructure. IBM’s 2025 Cost of a Data Breach report placed the global average cost of a data breach at approximately $4.4 million.
A ransomware attack on a hospital, bank, port or electricity provider may begin as financially motivated crime, yet its effect can still weaken public trust, disrupt economic activity and create strategic pressure.
Cybercrime is therefore no longer only a policing problem. It can become a national-security vulnerability.
Attribution Is the Central Problem
Identifying an attacker is more difficult in cyberspace than in many forms of conventional conflict.
Cyber operators can use proxy servers, stolen credentials, compromised devices, false identities, criminal intermediaries and widely available malware. They may operate from one country, route activity through another and target systems in a third.
Evidence may exist but remain classified because revealing it could expose intelligence methods.
This creates a difficult decision for governments. Respond too quickly and they risk acting on incomplete evidence. Wait too long and attackers may interpret restraint as weakness. Share too little evidence and allies may hesitate to support a response. Reveal too much and intelligence capabilities may be compromised.
Cyber conflict is therefore partly a contest over proof.
Deniability does not require convincing everyone that an attacker is innocent. It may only require creating enough uncertainty to complicate retaliation.
Why Cyber Deterrence Is Difficult
Nuclear deterrence operates partly because an attack is visible, attribution is comparatively clear and the consequences are catastrophic.
Cyber deterrence is much harder.
Cyber incidents can be small, frequent and ambiguous. One intrusion may be espionage, another sabotage, another financially motivated crime and another preparation for future conflict.
This makes thresholds difficult to define.
What level of cyber attack should trigger sanctions? When should a state conduct a counter-cyber operation? Could a sufficiently destructive cyber attack justify a conventional military response? What happens if civilian deaths occur indirectly? How should governments respond when the apparent attacker is a proxy group?
There are no universally accepted answers.
This is why resilience becomes as important as retaliation. A country must be able not only to threaten consequences but also to absorb attacks, restore services and continue functioning.
International Law Is Still Catching Up
Cyber warfare has exposed gaps in international law and enforcement.
The United Nations has spent years discussing norms of responsible state behaviour in cyberspace. The UN Open-Ended Working Group on security and information and communications technologies concluded in July 2025 with a consensus report recommending a permanent mechanism for continued negotiations.
Such efforts matter, but norms are difficult to enforce when attribution remains contested.
States may agree that critical civilian infrastructure should not be attacked during peacetime, yet an attacker can deny responsibility or present an operation as ordinary criminal activity.
Questions surrounding proportional response also remain difficult.
The international system has centuries of legal experience regulating conflict on land and at sea. Cyberspace has evolved much faster than the institutions attempting to govern it.
Until enforcement improves, cyber power will frequently move faster than cyber law.
Modern Militaries Are Digitally Dependent
Modern armed forces depend heavily on digital systems.
Satellite communications, navigation systems, encrypted networks, sensors, drones, logistics software, command-and-control platforms, surveillance tools and cloud-based services all increase military capability.
They also create new vulnerabilities.
A cyber operation may disrupt logistics, interfere with communications, expose troop locations, corrupt battlefield information or degrade weapons-support systems.
An attacker does not always need to destroy a weapon physically. Making the information or communications around that weapon unreliable may be sufficient to reduce its military usefulness.
Cyber operations can also complement conventional attacks. Before a kinetic strike, an adversary may attempt to interfere with radar, communications or emergency-response networks.
Cyber warfare is therefore no longer separate from conventional warfare. It increasingly operates alongside it.
Ukraine Demonstrated the Cyber-Physical War Model
The Russia-Ukraine war demonstrated how cyber and conventional military operations can coexist.
Before and after the full-scale invasion, Ukrainian government institutions, energy systems, communications networks and other infrastructure faced repeated cyber operations.
These attacks served several purposes: disruption, espionage, intimidation and information warfare.
The broader lesson is that the digital battlefield can open before the physical battlefield.
A state preparing for conflict may first map networks, compromise infrastructure, collect intelligence and shape narratives. Those capabilities can later be activated as conventional hostilities intensify.
Cyber preparedness must therefore begin before a crisis, not after missiles start flying.
India’s Digital Expansion Also Expands Its Attack Surface
India has a particular challenge because its digital transformation is taking place at extraordinary scale.
Digital payments, Aadhaar-linked services, online governance, telecom networks, health systems, education platforms, banking services, logistics platforms and smart infrastructure have expanded state capacity and economic efficiency.
They have also increased the number of systems that attackers can target.
CERT-In reported that it handled more than 29.44 lakh cyber incidents in 2025 and issued large numbers of alerts, vulnerability notes and advisories. It also launched the Cyber Bharat Setu programme to strengthen cybersecurity culture among states and Union Territories.
This is the central contradiction of rapid digitisation.
The more efficient a digital state becomes, the more seriously it must protect the systems on which that efficiency depends.
Digital transformation without cybersecurity can turn administrative strength into strategic vulnerability.
Cyber Attacks Can Become Economic Warfare
A country’s economy can be damaged through cyber operations without the attacker imposing sanctions or launching a conventional military campaign.
An attack on banks can damage trust. An attack on stock exchanges can create uncertainty. Disruption at ports can delay trade. Attacks on energy companies can increase costs. Manufacturing networks can be stopped. Large data breaches can affect corporate reputation and consumer confidence.
IBM reported that India’s average data-breach cost reached INR 220 million in 2025, according to the material cited in the draft.
Cybersecurity has therefore become a balance-sheet issue as well as a national-security issue.
For India, which wants to expand manufacturing, digital public infrastructure, financial services and global technology exports, digital trust will increasingly affect competitiveness.
Investors will not ask only whether a country offers talent, infrastructure and market access. They will also ask whether its digital systems can be trusted.
The Private Sector Is on the Front Line
Many critical systems are owned or operated by private or semi-private organisations.
Telecommunications networks, banks, data centres, cloud platforms, airlines, logistics companies, hospitals, media organisations and energy infrastructure may all become targets during a cyber crisis.
An attack on a private company can therefore become a national-security emergency.
Government cannot defend this environment alone.
Companies need strong security controls, trained staff, supply-chain oversight and recovery plans. Governments need to share threat intelligence, establish standards and coordinate incident response.
The distinction between business risk and national-security risk is becoming increasingly difficult to maintain.
A small supplier with weak security can become the entry point into a much larger network.
Supply Chains Are Cyber Targets
Modern organisations depend on extensive digital supply chains.
Software providers, cloud companies, consultants, payment processors, logistics platforms, outsourced IT teams and third-party applications may all have some form of access to critical systems.
Attackers know this.
Instead of targeting a heavily defended organisation directly, they can compromise a smaller vendor and use trusted connections to move deeper into the network.
A company is therefore not secure simply because its own systems are well protected. It must understand who has access, what software is installed, how updates are distributed, where information is stored and how third parties are monitored.
Digital supply-chain security has become part of national resilience.
Elections Face Both Cyber and Influence Threats
Elections are attractive targets because attackers do not necessarily need to change votes to undermine democracy.
Election systems, political parties, voter databases, media organisations and campaign communications can all be attacked.
An adversary may simply try to create doubt about whether the election was secure.
If citizens believe that voting systems have been compromised, trust can fall even when the final count remains accurate. Synthetic media, stolen communications and manipulated leaks can further distort political debate.
Cyber operations and information manipulation are therefore closely connected threats to electoral legitimacy.
For democracies, the answer cannot simply be censorship.
The stronger defence is secure election infrastructure, transparent communication, rapid verification, better cyber hygiene for political organisations and a public capable of recognising manipulated information.
Cyber conflict targets democratic trust itself.
Cyber Attacks Can Cause Physical Harm
Cyber attacks should not be treated as inherently bloodless.
A hospital disabled by ransomware may delay medical treatment. A compromised water system can threaten public health. A power-grid failure can endanger vulnerable populations. Transport-system disruption can cause accidents. Military cyber failures can expose soldiers.
The attack may begin digitally, but the consequences can become physical.
This is why civilian critical infrastructure deserves particular protection. Hospitals, water systems, nuclear facilities, energy grids and emergency services should not become normalised targets in geopolitical competition.
A world that accepts routine cyber attacks against civilian systems will make every connected society more vulnerable.
India Needs a Clearer Cyber Deterrence Doctrine
India needs to move beyond a purely reactive cybersecurity posture.
A credible cyber deterrence doctrine should define national priorities, responsibilities, response options and broad thresholds while keeping sensitive operational details classified.
India should clearly identify critical systems and enforce appropriate security standards. Public-private threat-intelligence sharing needs to improve. Attribution capability should be strengthened. Cyber crisis exercises should include ministries, the armed forces, state governments and private-sector infrastructure operators.
India also needs deeper cyber diplomacy. International cyber norms, cross-border cybercrime, digital public infrastructure security, data protection and technology supply chains should increasingly form part of foreign policy.
Cybersecurity is no longer a narrow technical function. It is an element of national power.
Cyber Skills Are a National-Security Asset
The quality of a country’s cyber defence ultimately depends on people.
Governments and businesses need malware analysts, forensic investigators, cryptographers, AI-security specialists, cloud-security architects, hardware experts, incident responders, threat-intelligence analysts, cyber lawyers, digital diplomats and ethical hackers.
India has a large technology workforce, but cybersecurity cannot be reduced to short-term certification programmes.
Long-term capability requires specialised university education, research laboratories, public-sector career paths and closer collaboration between government and industry.
A country seeking digital sovereignty must develop cyber expertise at scale.
The most important cyber weapon may ultimately be human capability.
Citizens Are Part of Cyber Defence
Cybersecurity is not only a responsibility for governments and companies.
Citizens themselves are frequent targets.
Phishing messages, OTP fraud, fake customer-service calls, malicious links, deepfake voices, loan-app scams and identity theft are everyday threats. During a wider geopolitical crisis, similar techniques can be scaled to create panic, confusion and distrust.
A digitally literate population therefore contributes to national resilience.
Citizens should know how to verify suspicious communications, protect passwords, use multi-factor authentication, update devices and recognise manipulated content.
Cyber hygiene and media literacy increasingly belong within basic civic education.
In a digital society, national security can begin on an individual phone screen.
The Risk of Overreaction
Governments need strong powers to investigate serious cyber threats, but cybersecurity can also become an excuse for excessive surveillance, censorship or arbitrary control.
That creates another form of danger.
A secure digital state should also respect rights and due process.
Investigative powers need accountability. Technology platforms may require regulation, but regulation should not become political capture. Cybercrime must be punished, but legitimate dissent should not be redefined as a security threat.
The challenge is balance.
Cybersecurity without liberty can become digital authoritarianism. Liberty without adequate security can leave society dangerously exposed.
A democratic cyber doctrine must protect both.
Cyber Conflict Will Shape Future Geopolitics
Every major strategic rivalry now has a cyber dimension.
US-China competition involves cyber espionage, semiconductors, telecommunications, artificial intelligence and critical infrastructure. Russia-West tensions include cyber sabotage, disinformation and operations linked to the war in Ukraine. Iran-Israel tensions include cyber activity directed at infrastructure and military systems. North Korea has used cyber operations for espionage, disruption and illicit finance.
Cyber power is becoming part of the wider measurement of state power.
A country that cannot protect its networks will struggle to protect its economy, military and democratic institutions. A country with strong cyber capability can exercise influence far beyond its physical size.
The future great power will therefore be measured not only by aircraft carriers, nuclear weapons or economic output, but also by cyber resilience, secure supply chains, AI capability, data governance and digital trust.
Ten Priorities for India’s Cyber Strategy
India needs a preventive cyber strategy rather than one driven mainly by reaction after incidents.
1. Protect Critical Digital Infrastructure
Critical systems in power, banking, telecommunications, transport, health, defence and ports should be clearly identified and subjected to mandatory security standards appropriate to their national importance.
2. Strengthen National Coordination
CERT-In coordination with state governments, regulators, law-enforcement agencies and private infrastructure operators should become deeper and more routine.
3. Improve Incident Reporting
Organisations should be encouraged to report breaches quickly instead of hiding incidents because of reputational concerns. Faster reporting improves national threat awareness and allows other potential victims to protect themselves.
4. Conduct Sector-Specific Cyber Drills
Power utilities, banks, telecom providers, hospitals, ports and transport systems should regularly conduct realistic cyber exercises testing both technical recovery and organisational decision-making.
5. Secure Digital Public Infrastructure by Design
Systems that millions of citizens depend on should incorporate cybersecurity, privacy, redundancy and grievance mechanisms during design rather than after vulnerabilities appear.
6. Strengthen MSME Cybersecurity
Small companies often form part of larger supply chains while possessing much weaker security. Supporting MSMEs with affordable tools, standards and training would reduce a major source of systemic vulnerability.
7. Develop AI-Security Capability
India needs stronger tools and expertise for detecting deepfakes, automated phishing, adversarial AI and other emerging uses of artificial intelligence in cyber operations.
8. Expand Cyber Education
Cybersecurity education should extend from schools and universities to professional training, government administration and public awareness.
9. Deepen International Cyber Partnerships
India should strengthen cooperation with trusted partners on threat intelligence, cybercrime investigations, supply-chain security, standards and responsible state behaviour.
10. Clarify Deterrence and Accountability
India needs clearer legal and strategic frameworks defining responsibility, lawful response options and accountability for severe cyber operations.
Together, these measures would move India from a primarily reactive cybersecurity posture towards a more resilient national cyber strategy.
The Silent Front Line
Cyber attacks have become a new weapon of state conflict because power increasingly flows through networks.
A state can be weakened without invasion. A society can be divided without occupation. A military can be disrupted without a battlefield defeat. An economy can be damaged without traditional sanctions. An election can be undermined without changing a single vote.
That is what makes cyber conflict so difficult to manage.
It is often silent before it becomes visible, deniable before it is proven, inexpensive for the attacker before it becomes costly for the victim, and digital before its consequences become physical.
The first strike in a future crisis may be a compromised password, a poisoned software update, a breached telecom network, a synthetic video or malware waiting quietly inside critical infrastructure.
The central lesson is therefore clear: cybersecurity is not merely the responsibility of an IT department. It is national security, economic security, democratic security and social security.
The modern border is not guarded only by soldiers. It is also defended by engineers, analysts, researchers, investigators, companies, teachers and citizens.
The next major war may still involve missiles, aircraft and tanks. But long before those weapons appear, the networks may already be under attack.
That is the silent front line of the twenty-first century.


