DATE

July 29, 2026

Cybersecurity is no longer shaped by technology alone. Geopolitical tension, state competition and hybrid warfare are changing who attacks organisations, why they attack and what is ultimately at stake.

Joe McCann speaking on hybrid warfare at the George C. Marshall European Center for Security Studies in Germany

The front line of geopolitical conflict no longer sits only at national borders. It now runs through cloud platforms, corporate networks, operational technology, supply chains, email systems and digital identities.

An organisation can become a target because of the services it provides, the information it holds, the countries in which it operates, the infrastructure it supports—or simply what it represents.

This places Chief Information Security Officers at the centre of a profound change. CISOs are no longer responsible only for protecting systems and data from conventional cybercrime. They must now help their organisations navigate threats shaped by international conflict, strategic competition, economic coercion, espionage, disinformation and state-aligned cyber operations.

The CISO has become one of the organisation’s most important geopolitical risk leaders.

Hybrid warfare has entered the corporate environment

Joe McCann recently spoke on hybrid warfare at the George C. Marshall European Center for Security Studies, a German-American security studies partnership based in Garmisch-Partenkirchen, Germany.

The discussions reflected a reality that security leaders across the public and private sectors can no longer ignore: organisations increasingly operate within the wider environment of geopolitical competition.

NATO describes hybrid threats as a combination of military and non-military, overt and covert methods. These can include cyberattacks, disinformation, economic pressure, political interference and the use of conventional or irregular forces. Their purpose is often to create uncertainty, undermine confidence and destabilise institutions while remaining below the perceived threshold of open conflict. NATO’s overview of hybrid threats makes clear that both state and non-state actors can employ these methods.

For businesses, the significance is immediate.

Cyber activity may be used to steal intellectual property, gather strategic intelligence, disrupt essential services, compromise supply chains or create economic pressure. An attack may also be one part of a broader operation involving physical disruption, influence activity and the manipulation of public narratives.

The organisation sees a cyber incident. The adversary may see one move within a much larger campaign.

Why organisations are being drawn into geopolitical conflict

Many organisations still assess cyber risk primarily through a commercial lens: ransomware, fraud, data theft and regulatory exposure. These risks remain serious, but they are no longer the whole picture.

Nation-state and state-aligned groups can have different objectives. Financial gain may be secondary—or irrelevant. Their goals can include:

  • Accessing commercially or strategically valuable information.
  • Mapping critical infrastructure and supply chains.
  • Establishing persistent access for future operations.
  • Disrupting services during periods of political tension.
  • Undermining trust in an institution or sector.
  • Applying indirect pressure to governments and their partners.
  • Using compromised organisations to reach more sensitive targets.

This means an organisation does not need to consider itself part of the defence sector to become strategically relevant. Financial services, telecommunications, energy, healthcare, aerospace, transport, technology, professional services and public-sector suppliers can all hold information or provide capabilities valuable to an adversary.

Even a smaller company can become an attractive entry point when it sits inside the supply chain of a larger organisation or critical national service.

The CISO’s role has fundamentally changed

The modern CISO sits at the intersection of technology, business continuity, regulation, intelligence, communications and executive decision-making.

During a geopolitically motivated incident, the CISO may need to help leadership answer questions extending far beyond technical containment:

  • Is this an isolated attack or part of a coordinated campaign?
  • Could the activity be connected to a geopolitical event?
  • What does the organisation’s geographic, sectoral or supply-chain exposure mean?
  • Which authorities, regulators, customers or partners should be informed?
  • Could public attribution increase political or reputational risk?
  • Is the organisation prepared for simultaneous cyber, physical and information threats?

These are strategic questions. They require the CISO to work closely with the board, executive leadership, legal counsel, risk teams, communications specialists, government partners and external security experts.

Cybersecurity can no longer operate as an isolated technical function.

Joe McCann discussing the implications of hybrid warfare and state-aligned cyber activity for organisations and security leaders

Building resilience for an era of persistent confrontation

There is no single technology capable of solving a hybrid threat. Organisations need an integrated approach built around intelligence, preparedness and resilience.

Understand geopolitical exposure

Security planning should consider where the organisation operates, who it supplies, what information it possesses and how changes in international relations could alter its threat profile.

A geopolitical event can transform an ordinary commercial relationship into a source of cyber exposure almost overnight.

Make intelligence operational

Threat intelligence must be connected to security controls, vulnerability management and executive decision-making. Knowing that a state-aligned group is targeting a particular sector has little value unless that knowledge changes defensive priorities.

Organisations need processes that turn external intelligence into specific action.

Protect identity and critical access

State-aligned adversaries frequently seek long-term, discreet access. Strong identity controls, privileged-access management, multifactor authentication, network segmentation and continuous monitoring are essential to limiting that access.

The objective is not only to prevent intrusion, but also to make persistence and lateral movement far more difficult.

Rehearse geopolitical cyber incidents

Exercises should move beyond conventional ransomware scenarios. Leadership teams need to practise responding to incidents involving suspected state actors, uncertain attribution, simultaneous disruption, disinformation, supplier compromise and intense public scrutiny.

A response plan that has never been exercised is still only a theory.

Treat suppliers as part of the security boundary

Attackers will often choose the least-defended route into a strategically important ecosystem. Organisations should identify critical dependencies, establish clear security expectations and ensure that incident information can be exchanged quickly with key suppliers.

Bring cyber risk into the boardroom

Boards need clear explanations of geopolitical cyber exposure, including the potential effects on operations, customers, regulatory obligations and organisational reputation.

The conversation should focus not only on whether an attack can be prevented, but also on whether the organisation can continue operating safely when prevention fails.

Collective defence begins with collaboration

NATO’s approach emphasises preparedness, resilience, situational awareness, education and cooperation. These principles are equally relevant to the private sector.

No organisation can understand or counter this threat environment alone. Effective defence depends on collaboration between governments, industry, security providers, researchers and international partners. Information must move quickly enough to support action, and lessons from incidents must be shared before the next organisation is targeted.

For CISOs, that means building trusted relationships before a crisis—not during one.

The front line has moved

Cybersecurity leaders are now protecting more than systems. They are protecting the continuity, confidence and strategic value of the organisations they serve.

As geopolitical tensions continue, businesses will increasingly find themselves exposed to campaigns that blur the boundaries between espionage, crime, disruption, influence and warfare. The organisations best positioned to withstand those campaigns will be those that recognise the change early and treat cybersecurity as an essential component of strategic resilience.

The CISO is already on the front line.

The question is whether the rest of the organisation is standing there with them.

Further reading

Explore Hybrid Threats and Hybrid Warfare, NATO’s reference curriculum examining the concepts, actors, instruments and strategic considerations shaping today’s hybrid threat environment.

Read “Hybrid Threats and Hybrid Warfare” on the NATO website.

Joe McCann at the George C. Marshall European Center for Security Studies, Garmisch-Partenkirchen, Germany