Cybersecurity in an Era of Digital Geopolitics

A cyber incident can now interrupt a public service, expose negotiating positions and disrupt a supplier in another country before an organisation understands how the intrusion began. The strategic problem for a board or ministry is to decide which dependencies matter most, who owns the response and what can reasonably be inferred about the actor. The loudest claim about an attack is rarely the most useful one. The evidence argues for care. In its 2026 EU threat assessment, ENISA analysed incidents and events observed during calendar year 2025. Distributed denial-of-service attacks accounted for 51 percent of its recorded cases, and…
September 24, 2026

A cyber incident can now interrupt a public service, expose negotiating positions and disrupt a supplier in another country before an organisation understands how the intrusion began. The strategic problem for a board or ministry is to decide which dependencies matter most, who owns the response and what can reasonably be inferred about the actor. The loudest claim about an attack is rarely the most useful one.

The evidence argues for care. In its 2026 EU threat assessment, ENISA analysed incidents and events observed during calendar year 2025. Distributed denial-of-service attacks accounted for 51 percent of its recorded cases, and public administration was the most targeted sector, at 32 percent of targeted organisations. These are observations from ENISA’s EU dataset, not worldwide incident rates. The agency also documents recurring overlap in the techniques and infrastructure reported for criminal, hacktivist and state-linked groups. An incident’s timing or a group’s public claim cannot alone establish state direction. [1]

Why geography enters a network

As Windear’s analysis of AI compute concentration also illustrates, institutions depend on networks they do not fully control: cloud providers, payment systems, telecommunications, outsourced software, cross-border data flows and contractors. A failure at one point can affect operations elsewhere. The geopolitical layer appears when a service is strategically important, when sensitive information has value in international negotiations, when suppliers sit under different jurisdictions or when an incident triggers diplomatic or legal responses.

Consider a government agency that relies on a foreign-hosted records system. Its immediate cyber question is whether data or services are compromised. Its strategic questions are wider: which authority can compel the provider to act, where are usable backups, what contracts govern access to logs, and can the agency continue to deliver essential services if a cross-border connection fails? Similar issues arise for a multinational with a single identity provider or for a regional bank that depends on one payment processor. These are illustrative dependency tests, not claims about a particular breach.

Three patterns deserve attention. First, information theft can pursue long-term access rather than visible disruption. Second, attacks on third parties can provide an indirect route into a better-defended target. Third, high-volume disruption and information manipulation can create political pressure even when the underlying intrusion is limited. ENISA’s European findings document aspects of these patterns, but they do not justify assuming the same prevalence in every region. [1]

Assessment requires restraint

Attribution is both technical and political. Investigators can compare infrastructure, malware, tradecraft, targeting and intelligence from multiple sources. Even then, confidence differs across cases. Public attribution is a separate decision with diplomatic and legal consequences. A leadership team should require an evidence standard and a confidence statement before repeating an allegation about a state. It should also avoid confusing a service outage with a confirmed data breach.

International rules remain part of the context. The United Nations’ 2021–2025 open-ended working group adopted a final report by consensus in July 2025 and agreed to a continuing global mechanism for discussion of responsible state behaviour in the use of information and communications technologies. That process creates a forum for cooperation; it does not remove uncertainty in individual incidents or guarantee that every state will interpret an event the same way. [2]

For countries building digital public services, cyber resilience is a governance and capacity issue as well as a technical one. The International Telecommunication Union assesses national commitments across legal, technical, organisational, capacity-development and cooperation measures in its Global Cybersecurity Index. The five-part approach is useful because a newly purchased security product cannot compensate for unclear incident authority or an untested recovery plan. [3]

A board-level response

Cybersecurity in an Era of Digital Geopolitics

The first question is: which digital dependencies would stop our essential work? Map the services and data that matter, then identify the providers, locations, access privileges and recovery times behind them. Pay particular attention to common points of failure. Do not ask only whether a supplier has a security certificate; ask how quickly it will alert you, share evidence and help restore service under the actual contract.

The second question is: who can make decisions in the first hour? The incident plan should name the people authorised to isolate a system, call a regulator, communicate with customers and approve public statements. Practise a scenario in which evidence is incomplete and a vendor is unreachable. NIST’s Cybersecurity Framework 2.0 explicitly places governance alongside identifying, protecting, detecting, responding and recovering, with added attention to supply-chain risk. Its structure is a useful starting point for an executive exercise, although local legal duties still require separate advice. [4]

The third question is: what can we still deliver while the investigation continues? Maintain tested offline or segregated backups and a practical manual or alternative route for critical services. Set realistic recovery priorities. For a ministry, a delayed service may harm citizens; for a firm, delayed payments may affect workers and smaller suppliers. The exercise should measure continuity as experienced by the people who depend on the service, not simply whether a server powers back on.

What to monitor

Windear’s advisory services frame this as a leadership question. Windear’s assessment is that leadership teams should watch four indicators together: attempts against critical suppliers, changes in the geopolitical exposure of those suppliers, the time needed to detect and contain incidents, and the time needed to restore essential functions. A rise in attempted attacks alone may reflect better reporting. A falling recovery time alongside a better-mapped supply chain is stronger evidence of resilience. The scenarios differ. An opportunistic criminal intrusion calls for containment, recovery and possible law-enforcement action. A credible espionage campaign may also require a longer investigation and diplomatic coordination. A supplier outage may occur without a hostile actor at all. Institutions need plans that work before they know which scenario they face. The strategic goal is to make the network less fragile and public decisions more evidence-based under pressure.

Sources

[1] ENISA, Threat Landscape 2026, 22 September 2026. https://www.enisa.europa.eu/news/exploring-the-evolution-of-the-cyber-threat-landscape-how-dependencies-weaken-our-digital-resilience

[2] United Nations, statement on conclusion of the 2021–2025 OEWG, 14 July 2025. https://www.un.org/sg/en/content/sg/statements/2025-07-14/statement-attributable-the-spokesperson-for-the-secretary-general-the-conclusion-of-the-open-ended-working-group-security-of-and-the-use-of-information-and

[3] ITU, Global Cybersecurity Index 2024. https://www.itu.int/en/ITU-D/Cybersecurity/Pages/Global-Cybersecurity-Index.aspx

[4] NIST, Cybersecurity Framework 2.0, 26 February 2024. https://www.nist.gov/news-events/news/2024/02/nist-releases-version-20-landmark-cybersecurity-framework

More Related Posts

Submit CV

Windear Consulting is actively seeking part-time independent researchers to join our team. As leaders in Geopolitics, Conflict, and Economics research, we offer a unique opportunity for dedicated professionals to contribute meaningfully to dynamic projects. Enjoy the flexibility to manage your schedule while collaborating with seasoned experts. We seek individuals with a strong academic background, exceptional research skills, and a profound interest in geopolitical dynamics and economic trends

Blank Form (#4) (#5)