- Opinion Articles
- Cyber Warfare: The Invisible Battlefield of the Twenty-First Century
Cyber Warfare: The Invisible Battlefield of the Twenty-First Century
Faisal Gul
In February 2025, the Eastern European power grid experienced power failures in certain areas. No line failed due to a storm. No transformer failed. A hacker wrote and deployed malware from thousands of miles away, causing the damage. Few, if any, people outside the region knew about it. That is the area that we should be concerned with. Century. For decades, we've envisioned cyber warfare as a movie: a countdown timer, a lonely hooded figure, a single cataclysmic event that makes itself known. The truth is less dramatic and much more deadly: an unseen, invisible, barely noticed war, conducted by the secret service of government, most of which most of its citizens think only uses spies for old-fashioned purposes.
The numbers we're not counting on
Don't let the headlines fool you, and the moment you start watching, the footage gets uncomfortable quickly. There were more than 220 major cyberattacks by states against the United States in 2025 than against any other nation in the world. In the first five months of that year, Ukraine reported more than a hundred incidents that were related to the Russians. Germany, India, Israel, Japan, South Korea and Brazil have all confirmed dozens of attacks to be state-sponsored operations. With global losses to the tune of almost $13 billion, almost 40% of major cyberattacks last year resulted from a government sponsor, the highest proportion on record.
Numbers such as these are easy to see and not bother with. So, what were they actually like on the ground? A small bakery in Russia couldn't take any orders because their office systems were knocked out in January 2026. In the coordinated attack in late 2025, around 30 facilities connected to the Polish energy grid were attacked, causing damage and preventing blackouts. Industrial security researchers now call the Jaguar Land Rover shutdown one of the worst events of the past ten years. Meltdowns in flight operations for weeks due to software failure at Collins Aerospace. Software failure at Collins Aerospace grounded flight operations for weeks. Interestingly, this follows a drop in ransomware-caused disruption in 2025, despite a 100% increase in attacks targeting critical infrastructure by nation-states and hacktivists. Governments are creating more space for themselves by driving out payday criminals. Governments are squeezing the payday criminals out of the way, and criminals seeking a payday are being squeezed out.
That change, however, should be on policymakers' minds. It's no more opportunistic crime. It's strategy.
The main reason why we can't get away from it
I believe the truthful response is that cyber warfare is undermining the 2 elements deterrence theory has always been based on: being able to attack and retaliate proportionately and knowing who attacked you in the first place.
No one would ever want to put the pieces of the cyberspace attribution puzzle together. Proxy servers, criminal middlemen, and third-country infrastructure bounce operations so no government has to own what it did. Legal scholars who've dissected the Russia-Ukraine war and the 2008 Russo-Georgian conflict repeat the same plaintive lesson: both show only the loosest and most theoretical applicability to existing law—the UN Charter and the Tallinn Manual's efforts to adapt armed-conflict law for the cyber domain. No one knows what is considered a "use of force" in the online world, and few rules are enforced.
Diplomacy has not helped narrow this gap. The UN has been trying for over two decades to establish voluntary norms in cyberspace, and even that has proved to be a long uphill struggle: the world's largest cyber powers continue to resist the idea of this area being a theatre of war, preferring instead to label it a "zone of peace". Fitting, as that's exactly how they retain the freedom to keep doing what they do. What you end up with is a battlefield governed by rules that are rarely enforced, a place where you are unlikely to be caught by the enemy, and a place where the traditional enforcement of rules for spying, crime and armed conflict has virtually disintegrated.
Security researchers call this pre-positioning. Today, governments don't necessarily attack the power grid and water supply; instead, they secretly install access points and keep them in reserve until a crisis makes them useful. In short, not long ago, one of the executives in charge of threat intelligence said, "By 2026, we will be living with the fallout of 10 years of this sort of pre-positioning. A war zone has been created within the infrastructure that we use daily.
The results that must be achieved
I don't believe there is any way to remedy this issue with another statement of concern. Several of the following, however, would make a difference:
Governments should implement a mandatory reporting system for cyberattacks on critical infrastructure, as aviation does for incident reporting, and move to speedy action. Governments should make it mandatory to report cyberattacks on critical infrastructure, such as energy, water, healthcare, and telecoms, and do it quickly. We're learning about attacks, such as the Poland grid incident, now through private researchers and the trade press, rather than a real-time shared picture.
NATO and the EU should make clear in advance the consequences of a joint economic and diplomatic response in case of attacks on critical infrastructure, and not sow confusion over cyber tit-for-tat. There's been no peace since ambiguity. It's simply a matter of cost.
The same level of money should go to resilience as to offence. None of these activities is “cool”, and that's the difference between an attack that can succeed and one that can succeed “catastrophically” — separating out OT from corporate IT, verifying signals such as GPS after the incidents on the waterways last year, running real intrusion drills at critical operators. But even with the realisation that agreement on binding rules is not likely, the push for binding rules on critical-infrastructure targeting is a priority again. A binding deal with willing democracies and teeth is better than the next 10 years of promises that adversaries otherwise ignore.
Cyber warfare won't blow its horns with a siren. It's going to be like systems locking up at a hospital, a grid flickering, a bank freezing mid-transaction — all deniable, and all going to test how much we take before we react. The battleground has already been activated. The only question that really remains is whether governments construct the rules and barriers to match it before it becomes a loud blackout.
This is my own interpretation of the facts. There is reasonable disagreement – over the rate of this escalation, over what is better – binding law or flexible norms – and over the degree of aggressiveness that democracies should afford to show on the matter of attribution, which is often more probable than proven.
Disclaimer: The views expressed in this article are solely those of the author and do not necessarily reflect the official stance of The Himalayan Research Institute Pakistan (THRIP)
_________________________________
Faisal Gul is an undergraduate student of Defense and Strategic Studies at Quaid-i-Azam University, Islamabad, Pakistan and can be reached at [email protected]
Contact us
Write with Us
The Himalayan Research Institute is proud to introduce "Himalayan," a dynamic and insightful magazin...
- [email protected]
- +923426470466
- website