• 08/31/2026
  • Technical contribution

Cyberwarfare as a geopolitical tool: Why Europe's digital capacity to act is becoming a key strategic issue

Cyberattacks on critical infrastructure, influence operations on social media, digital espionage campaigns and attacks on global supply chains demonstrate that cyberwar has long since become an integral part of geopolitical conflicts. For Europe, security depends on whether states and companies remain capable of acting digitally even under crisis conditions.

Written by Uwe Sievers

Laptop with source code on the screen in front of the European Union flag
Digital operational capability as a European security issue: when digital technology becomes an instrument of geopolitical conflict.

Over the past two decades, cyberspace has evolved from a technical infrastructure into a geopolitical arena. Today, state actors use digital operations not only for espionage, but increasingly to exert political influence, cause strategic destabilisation and support military and economic objectives. NATO and numerous national security agencies now regard cyberspace as a distinct domain of operations alongside land, sea, air and space.

At the same time, society's dependence on digital systems is growing. Energy supply, healthcare, transport, financial markets and public administration are based on highly interconnected infrastructures. Whilst this interconnectedness boosts efficiency and innovation, it also creates new vulnerabilities and strategic dependencies.

Against this backdrop, a key security question arises for Europe: can digital operational capability be maintained even as critical technologies, communications networks and digital supply chains increasingly become the subject of geopolitical conflicts?

How companies and CNI operators can strengthen their digital operational capability in the face of exactly these geopolitical cyber threats is a central theme at the it-sa EXPO & Congress – Europe's leading trade fair for IT security. Find out more and be there.

 

 

Cyberwar as an instrument of geopolitical influence

The term ‘cyberwar’ is used differently in politics, academia and by security agencies. To date, there is still no generally accepted definition. In particular, the question of when digital operations cross the threshold into acts of war remains contentious.

Regardless of debates over definitions, however, there is broad consensus that cyber operations are now an integral part of state power projection. They enable impact below the threshold of open military conflict, incur comparatively low costs and, at the same time, offer a high degree of strategic flexibility.

The importance of digital operations is growing for several reasons. Firstly, modern societies are highly digitised. Secondly, attacks can often be carried out covertly. Thirdly, cyber operations can produce political, economic and societal effects without the direct use of physical force. NATO member states officially recognised cyberspace as a domain of operations as early as 2016. This places its strategic importance on a par with traditional military theaters of operations.

This opens up new possibilities for state actors: gathering intelligence, influencing public opinion, preparing potential acts of sabotage and establishing a long-term presence within critical infrastructure can all take place in parallel – often over a period of years and largely unnoticed.

 

 

The grey area between peace and conflict

A key feature of modern cyber conflicts is that they are embedded in a grey area between peace and open conflict. Unlike conventional military operations, it is often difficult to clearly attribute cyberattacks. Attackers conceal their identity through technical workarounds, compromised systems or third countries. So-called attribution therefore remains one of the greatest challenges in cyberspace.

Furthermore, false-flag operations complicate the situation. In such operations, technical traces are deliberately planted in such a way as to divert suspicion towards other actors. Even where technical evidence is available, a robust attribution usually requires a combination of technical, intelligence and geopolitical information.

This uncertainty has significant political consequences. States must make decisions even though there is often no 100 per cent conclusive evidence. At the same time, many cyber operations operate in legal grey areas that are only partially covered by existing international law. For businesses and operators of critical infrastructure, this means that geopolitical cyber risks are not merely relevant in times of military crisis. Many operations take place long before that – as ongoing campaigns aimed at gathering information, exerting influence or preparing potential disruptive measures.

 

 

Hybrid threats and the digital battlefield

Cyberwar is not limited to infiltrating IT systems. Rather, its strategic impact arises from the combination of various instruments. The most important elements of hybrid threats include:

  • Cyber espionage
  • Digital sabotage
  • Disinformation
  • Psychological influence
  • Information manipulation
  • Economic pressure

These tools often do not pursue a single objective. Rather, they are designed to undermine trust in institutions, influence political decisions, exacerbate social polarisation or impair a state's critical capabilities.

Current assessments by international security agencies show that state-backed actors are, in particular, carrying out long-term espionage operations against government bodies, research institutions and critical infrastructure. At the same time, information operations and digital influence campaigns are gaining in significance.

Cyberwarfare differs fundamentally from traditional cybercrime in this respect. Whilst criminal groups primarily pursue financial objectives, state actors focus on political, strategic or military interests. Added to this is the use of so-called proxies. These are hacker groups or other actors who support state interests without officially being part of state structures. Such arrangements increase political deniability and make it more difficult to take countermeasures.
 

 

Critical infrastructure as a strategic target

Critical infrastructure is increasingly becoming the focus of state-sponsored cyber operations. The reason is obvious: it forms the functional backbone of modern societies. Of particular relevance are:

  • Energy supply
  • Telecommunications
  • Healthcare
  • Transport and logistics
  • Public administration
  • Finance

From the perspective of state-sponsored attackers, these sectors are of great strategic importance. Even limited disruptions can have significant social, economic and political repercussions.

A frequently cited example is the attack on the KA-SAT satellite network immediately prior to the start of the Russian invasion of Ukraine in February 2022. According to the European Union's assessment, the cyber operation led to communication outages in Ukraine and simultaneously had repercussions in several EU Member States.

The EU regarded the incident as an example of how cyberattacks against critical infrastructure can have cross-border and systemic consequences.

The KA-SAT incident highlights a key development: digital infrastructures are rarely confined to national borders. Attacks on communication systems, satellite networks or cloud services can have consequences extending far beyond the actual target area.

For Europe, this means that the security of critical infrastructure must increasingly be viewed as a pan-European resilience issue.

 

 

When digital dependencies become vulnerabilities

Europe's greatest vulnerability does not necessarily stem from individual cyber-attacks, but from digital dependencies. Modern organisations are now part of complex technology ecosystems. These include:

  • Cloud platforms
  • Software supply chains
  • Communication platforms
  • Global semiconductor supply chains
  • Digital service providers
  • Platform economies

These structures generate significant efficiency gains. At the same time, they give rise to concentration risks.
If a key service provider fails or comes under geopolitical pressure, the repercussions can affect numerous organisations simultaneously.

The fact that digital dependencies are increasingly viewed as a risk factor is demonstrated by recent threat analyses from ENISA, which highlight digital infrastructure and supply chains as particularly vulnerable targets. Geopolitical tensions can also suddenly bring technological dependencies to light. Export restrictions, sanctions, supply bottlenecks or political conflicts can affect the availability of critical technologies.

For companies and critical infrastructure operators, this means that traditional risk management is expanding. The question is no longer simply whether systems are sufficiently secure. Equally relevant is analysing which external technologies, platforms and supply chains the organisation's own operational capability depends on.

 

 

Digital operational capability as a new dimension of security

The key management question is therefore increasingly not: How do we prevent every attack? But rather: ‘How do we remaincapable of operating if attacks are successful?’

This shift in perspective marks the transition from a security approach focused primarily on prevention to one centred on resilience. Security authorities and international organisations are increasingly emphasising the importance of organisational resilience. NATO explicitly highlights the central role of resilient national structures and critical infrastructure for collective security.

Digital operational capability encompasses several dimensions:

  • Maintaining critical business processes
  • Rapid restoration of disrupted systems
  • Robust crisis management structures
  • Alternative communication channels
  • Effective decision-making structures
  • Transparent crisis communication

Operators of critical infrastructure in particular must assume that individual protective measures may be circumvented. It is therefore crucial to be able to limit disruptions and maintain critical functions. Redundancies take on strategic importance in this context. They encompass not only technical reserve capacities, but also alternative suppliers, fallback processes, emergency communication and organisational crisis plans.

Resilience thus becomes a management task at board and executive level. Cyber risks no longer affect the IT department alone. They influence business continuity, corporate governance and strategic risk positions.

 

 

What digital sovereignty really means

Hardly any other term is currently the subject of more controversial debate than digital sovereignty. The impression is often given that digital sovereignty means technological self-sufficiency. However, such an interpretation falls short.

For open and globally interconnected economies, complete technological independence would be neither realistic nor economically sensible. Modern innovation arises within international value-creation networks.

Digital sovereignty rather means the ability to choose autonomously from various courses of action and to maintain critical functions even in crisis situations.

At its core, it is about:

  • Risk transparency
  • Strategic room for manoeuvre
  • Resiliently structured dependencies
  • Availability of alternatives
  • Manageable risks

Digital sovereignty is therefore not a state of complete independence, but a question of the ability to exercise control. Europe faces the challenge of combining economic openness with strategic resilience. It will be crucial to reduce dependencies where they could have system-critical implications, without fundamentally calling into question the benefits of global digitalisation.

 

 

Recommendations for decision-makers

For board members, managing directors, CNI officers and CISOs, this gives rise to several strategic areas for action:

  1. Embed cyber resilience as a management priority: Cyber risks should be assessed as corporate and business risks – not exclusively as IT risks.
  2. Strengthen business continuity management: Emergency and recovery plans must be regularly reviewed, tested and adapted to geopolitical risk scenarios.
  3. Professionalise crisis management: Clear decision-making processes, crisis management teams and communication procedures are crucial when technical disruptions have operational consequences.
  4. Analyse digital dependencies: Organisations should systematically assess critical suppliers, cloud providers, software dependencies and communication platforms.
  5. Review multi-cloud and exit strategies: Having alternatives to individual critical service providers increases an organisation's ability to act in the event of a crisis.
  6. Integrate supply chain risks: Security assessments should take the entire digital value chain into account.
  7. Conduct resilience exercises: Scenario analyses and crisis exercises help to identify vulnerabilities at an early stage and to hone decision-making skills.
  8. Promote information sharing: Collaboration with industry associations, CERTs, security authorities and CNI networks improves situational awareness and response capabilities.
  9. Expand cooperation with authorities: The BSI, national cyber security centres and European institutions are increasingly offering support and knowledge-sharing platforms for operators of critical infrastructure.
  10. Establish strategic resilience metrics: Metrics for recovery times, dependencies, emergency preparedness and crisis response should form part of modern governance structures.

 

 

Conclusion

Cyberwarfare today is far more than just digital sabotage. It is an integral part of hybrid conflicts and combines espionage, influence operations, disinformation and the targeted exploitation of digital dependencies. Its greatest impact stems not from spectacular individual incidents, but from the gradual erosion of trust, stability and the ability to act.

For Europe, therefore, the key vulnerability lies not solely in technical weaknesses, but in the growing dependence on digital infrastructures, platforms and global technology ecosystems.

The key challenge in the coming years will be to ensure the ability to act digitally even under crisis conditions. Resilience, crisis preparedness and strategically managed dependencies will thus become essential components of European security.

Digital sovereignty does not, therefore, mean self-sufficiency. It means the ability to act in a self-determined manner even when geopolitical tensions increasingly turn the digital sphere into an arena for international power politics. Europe's future stability will depend to a large extent on how successfully this capacity to act can be safeguarded.

 

Sources

NATO: Cyber defence

Microsoft: Digital Defense Report 2025

Delegation of the European Union to Ukraine: Russian cyber operations against Ukraine: Declaration by the High Representative on behalf of the European Union

European Repository of Cyber Incidents: KA-SAT 9A

ENISA: Threat Landscape 2025

BSI: Die Lage der IT-Sicherheit in Deutschland 2025