Why Global Conflict is Raising Cyber Risk

At the end of February, joint strikes from the United States and Israel hit Iran, targeting nuclear facilities, military infrastructure, and leadership. But the conflict hasn’t been confined to those isolated attacks; retaliatory cluster bombs explode in the Tel Aviv sky, and cyber-warfare and cyber-espionage are expected to escalate on the homefront. Ted Kollender, former Israeli cyber-defence specialist and founder of a cyber security platform, Remedio, told the BBC, “Cyber isn’t usually the decisive weapon on its own; it’s a force multiplier.” 

Cyberattacks are being used as strategic tools alongside kinetic warfare. Businesses and critical infrastructure are both potential targets.

When Conflict Spills into Cyberspace

Cyberattacks are used for disruption, intelligence gathering, and psychological impact through ransomware and wiper malware. However, experts speculate if Iran is a paper tiger in terms of cyber-warfare, claiming they lack a “symmetrical response” in cyberspace. There is an exception to this theory. An Iran- linked hacking group, Handala, infiltrated American medical technology company Stryker in early March, claiming to have affected more than 200,000 devices across 79 different countries.

Additionally, over the past 15 years, the Iranian government has invested heavily into offensive cyberwarfare capabilities. This was in direct response to the 2010 Stuxnet attack on Iran’s nuclear programThe Cyber & Infrastructure Security Agency (CISA) recent report highlights the most vulnerable points of attack, stating, “[h]acktivists and Iranian-government-affiliated actors routinely target poorly secured U.S. networks and internet-connected devices for disruptive cyberattacks.”

How Cyberattacks on Infrastructure Affect Everyday Business Operations

When cyber activity strikes infrastructure, supply chains, or widely used platforms, businesses of all sizes are affected indirectly.

Small Businesses

Small and medium-sized businesses are often indirectly impacted via supply chains, as threat actors expand their reach beyond primary objectives. Rather than targeting these organisations directly, attackers compromise communication networks, software providers, or essential commerce platforms.

This has been seen in attacks such as SolarWinds and Kaseya, where a single breach, suspected to be coordinated by a nation-state, harmed tens of thousands of their respective clients and other downstream businesses.

Businesses can also anticipate phishing and ransomware activity to increase during times of tension. Crisis opportunists — unrelated to Iran — may take advantage of chaos, confusion, and media attention to craft convincing campaigns.

Enterprises

Large enterprises are more likely to be directly targeted due to their scale, visibility, and role in critical infrastructure and global supply chains. The exposure these businesses receive puts them directly in the crosshairs of cyberattacks.

These attacks include:

  • Disruption of cloud or internet service providers
  • Attacks on logistics and supply chain systems
  • Data exfiltration tied to geopolitical intelligence gathering
  • Hack-and-leak campaigns that expose businesses’ intellectual property

Inevitably, cyberattacks lead to financial losses and reputational damage for businesses. The destruction of networks and exposure of sensitive data requires a costly recovery. The primary goal of these attacks is economic and communications disruption.

Cybersecurity Industry

Security teams are already operating under heightened alert as they monitor for potential retaliatory cyber activity. This increased pressure is forcing organisations to detect and respond to more advanced tactics, including those typically associated with nation-state actors. The line between traditional cybercrime and state-sponsored activity continues to blur, making detection and response more complex.

Businesses do not need to be directly involved in a conflict to feel its effects, and in many cases, they become exposed through the systems and networks they rely on every day.

Why Cybersecurity Matters Right Now

Cyberattacks are not only occurring during times of conflict, but they can further increase and expand beyond their initial focus. Nation-state attackers are less focused on specific businesses; instead, they seek easy targets with a large customer base. These opportunistic attacks can be avoided with robust cybersecurity protocols.

For cybersecurity strategy, this means:

  • The threat landscape is less predictable, requiring broader monitoring and real-time threat intelligence
  • Mitigation is critical, use strong, unique passwords and MFA
  • Faster detection and response are critical to limiting operational impact
  • Resilience becomes just as important as prevention, with a focus on backups, segmentation, and recovery planning

As these threats continue to shift and change, preparation and adaptability will define how well businesses can manage disruption.