DATE
July 29, 2026
The front line of geopolitical conflict no longer sits only at national borders. It now runs through cloud platforms, corporate networks, operational technology, supply chains, email systems and digital identities.
An organisation can become a target because of the services it provides, the information it holds, the countries in which it operates, the infrastructure it supports—or simply what it represents.
This places Chief Information Security Officers at the centre of a profound change. CISOs are no longer responsible only for protecting systems and data from conventional cybercrime. They must now help their organisations navigate threats shaped by international conflict, strategic competition, economic coercion, espionage, disinformation and state-aligned cyber operations.
The CISO has become one of the organisation’s most important geopolitical risk leaders.
Joe McCann recently spoke on hybrid warfare at the George C. Marshall European Center for Security Studies, a German-American security studies partnership based in Garmisch-Partenkirchen, Germany.
The discussions reflected a reality that security leaders across the public and private sectors can no longer ignore: organisations increasingly operate within the wider environment of geopolitical competition.
NATO describes hybrid threats as a combination of military and non-military, overt and covert methods. These can include cyberattacks, disinformation, economic pressure, political interference and the use of conventional or irregular forces. Their purpose is often to create uncertainty, undermine confidence and destabilise institutions while remaining below the perceived threshold of open conflict. NATO’s overview of hybrid threats makes clear that both state and non-state actors can employ these methods.
For businesses, the significance is immediate.
Cyber activity may be used to steal intellectual property, gather strategic intelligence, disrupt essential services, compromise supply chains or create economic pressure. An attack may also be one part of a broader operation involving physical disruption, influence activity and the manipulation of public narratives.
The organisation sees a cyber incident. The adversary may see one move within a much larger campaign.
Many organisations still assess cyber risk primarily through a commercial lens: ransomware, fraud, data theft and regulatory exposure. These risks remain serious, but they are no longer the whole picture.
Nation-state and state-aligned groups can have different objectives. Financial gain may be secondary—or irrelevant. Their goals can include:
This means an organisation does not need to consider itself part of the defence sector to become strategically relevant. Financial services, telecommunications, energy, healthcare, aerospace, transport, technology, professional services and public-sector suppliers can all hold information or provide capabilities valuable to an adversary.
Even a smaller company can become an attractive entry point when it sits inside the supply chain of a larger organisation or critical national service.
The modern CISO sits at the intersection of technology, business continuity, regulation, intelligence, communications and executive decision-making.
During a geopolitically motivated incident, the CISO may need to help leadership answer questions extending far beyond technical containment:
These are strategic questions. They require the CISO to work closely with the board, executive leadership, legal counsel, risk teams, communications specialists, government partners and external security experts.
Cybersecurity can no longer operate as an isolated technical function.
There is no single technology capable of solving a hybrid threat. Organisations need an integrated approach built around intelligence, preparedness and resilience.
Security planning should consider where the organisation operates, who it supplies, what information it possesses and how changes in international relations could alter its threat profile.
A geopolitical event can transform an ordinary commercial relationship into a source of cyber exposure almost overnight.
Threat intelligence must be connected to security controls, vulnerability management and executive decision-making. Knowing that a state-aligned group is targeting a particular sector has little value unless that knowledge changes defensive priorities.
Organisations need processes that turn external intelligence into specific action.
State-aligned adversaries frequently seek long-term, discreet access. Strong identity controls, privileged-access management, multifactor authentication, network segmentation and continuous monitoring are essential to limiting that access.
The objective is not only to prevent intrusion, but also to make persistence and lateral movement far more difficult.
Exercises should move beyond conventional ransomware scenarios. Leadership teams need to practise responding to incidents involving suspected state actors, uncertain attribution, simultaneous disruption, disinformation, supplier compromise and intense public scrutiny.
A response plan that has never been exercised is still only a theory.
Attackers will often choose the least-defended route into a strategically important ecosystem. Organisations should identify critical dependencies, establish clear security expectations and ensure that incident information can be exchanged quickly with key suppliers.
Boards need clear explanations of geopolitical cyber exposure, including the potential effects on operations, customers, regulatory obligations and organisational reputation.
The conversation should focus not only on whether an attack can be prevented, but also on whether the organisation can continue operating safely when prevention fails.
NATO’s approach emphasises preparedness, resilience, situational awareness, education and cooperation. These principles are equally relevant to the private sector.
No organisation can understand or counter this threat environment alone. Effective defence depends on collaboration between governments, industry, security providers, researchers and international partners. Information must move quickly enough to support action, and lessons from incidents must be shared before the next organisation is targeted.
For CISOs, that means building trusted relationships before a crisis—not during one.
Cybersecurity leaders are now protecting more than systems. They are protecting the continuity, confidence and strategic value of the organisations they serve.
As geopolitical tensions continue, businesses will increasingly find themselves exposed to campaigns that blur the boundaries between espionage, crime, disruption, influence and warfare. The organisations best positioned to withstand those campaigns will be those that recognise the change early and treat cybersecurity as an essential component of strategic resilience.
The CISO is already on the front line.
The question is whether the rest of the organisation is standing there with them.
Explore Hybrid Threats and Hybrid Warfare, NATO’s reference curriculum examining the concepts, actors, instruments and strategic considerations shaping today’s hybrid threat environment.

Read “Hybrid Threats and Hybrid Warfare” on the NATO website.