18+ / NSFW AI4 мин. чтения

How Businesses Can Defend Against Cyberthreats During Global Conflicts

Modern conflicts increasingly spill into digital arenas, making businesses vulnerable to cyberattacks. Discover key defense strategies and essential security measures.

How Businesses Can Defend Against Cyberthreats During Global Conflicts
Cybersecurity illustration featuring data protection elements and digital shields

Global conflicts now routinely involve large-scale cyberattacks targeting not just military and government entities but commercial enterprises too. The Ukrainian tax software attack demonstrated that businesses anywhere can become targets regardless of location or industry. Effective defense requires a multilayered approach—from system updates to employee training. CrowdStrike reports that 80% of 2023 attacks exploited supply chain vulnerabilities, making partner network protection essential.

How Digital Warfare Impacts Businesses

Cyberattacks have become tools for economic and political pressure. In 2022, 58% of companies reported increased attacks during conflicts. Primary threats include:

  • Targeted critical infrastructure attacks (energy, transport, finance)
  • Mass phishing campaigns with geopolitical themes
  • Malware distribution via supply chains (SolarWinds breach)
  • Operational disruption through DDoS (peaking at 3.47 Tbps in 2023)

IBM's 2023 report shows the average attack cost $4.45 million, though companies with response plans saved $1.23 million.

Key Cybersecurity Risks

Businesses face three threat levels:

  1. Direct attacks on conflict-affiliated companies (Norwegian energy firms)
  2. Collateral damage from viral malware (NotPetya caused $10B in damages)
  3. Exploitation amid reduced security focus (70% of zero-days exploited within 24 hours)

Ransomware remains especially dangerous, causing $20B in global 2023 losses. Emerging trends include double extortion (data theft + encryption) and backup system targeting.

Building Cyber Resilience

An effective strategy has three phases:

1. Vulnerability Assessment

Audit all systems with focus on:

  • Critical data (customer databases, IP, financial records)
  • External connections (VPNs, cloud services, APIs)
  • Third-party access (contractors, integrators)
  • Legacy hardware (IoT devices, industrial controllers)

Use NIST CSF or ISO 27001 frameworks for structured evaluation.

2. Incident Response Planning

Develop action scenarios for:

  • Attack detection (SIEM system thresholds)
  • Threat containment (network segmentation, account lockdowns)
  • System recovery (service prioritization, restoration SLAs)
  • Crisis communications (templates for clients, regulators, media)

Conduct biannual drills with varied scenarios.

3. Employee Training

Top 5 Defense Strategies

Essential measures for mid-sized businesses:

  1. Multi-factor authentication for critical systems (preferably hardware tokens)
  2. Weekly software updates (prioritized by CVSS scores)
  3. Network microsegmentation with tiered access
  4. Daily backups following the 3-2-1 rule (3 copies, 2 media types, 1 offsite)
  5. 24/7 threat monitoring via SIEM (Splunk, IBM QRadar, AlienVault)

Supplement with EDR solutions, penetration testing, and cyber insurance.

Security Checklist

Before conflict escalation, verify:

  • Antivirus/firewall updates (including remote work policies)
  • Backup availability (test restoration on clean systems)
  • 90-day security log retention
  • Remote access policies (ZTNA over VPN where possible)
  • Attack communication plan (designated spokespersons, prepared statements)
  • Physical server room access controls
  • Terminated employee account deactivation procedures

Lessons From Recent Attacks

2022-2023 cases revealed:

  • Companies with response plans recovered 65% faster (Ponemon Institute)
  • Security training reduced attack success by 47%
  • International cooperation accelerated threat neutralization (Viasat attack)
  • MSP provider breaches created cascading effects (Kaseya impacted 1,500 businesses)
  • Data encryption reduced leak damages by 72%

Questions & Answers

How do global conflicts affect business cybersecurity?

Conflicts trigger sophisticated attacks, including state-sponsored APTs. Businesses become targets regardless of location—Norwegian energy firms and US banks proved geographic neutrality offers no protection. Supply chain attacks are particularly dangerous, compromising hundreds through single vulnerable vendors.

Which companies are most vulnerable?

Highest-risk sectors:

  • Critical infrastructure providers (energy, water, transport)
  • Companies with international ties (especially in conflict regions)
  • Data-rich organizations (healthcare, finance, retail)
  • SMBs with limited IT resources (60% fold after major breaches)
  • SaaS providers (risking mass client compromise)

How to harden IT infrastructure?

Start with vulnerability scans (Nessus, OpenVAS), system updates (especially VPN/RDP), and backups. Implement MFA (preferably FIDO2). Additional steps:

  1. Segment networks (VLANs, microsegmentation)
  2. Enable comprehensive logging
  3. Configure automated threat alerts
  4. Restrict admin privileges (least-access principle)
  5. Conduct attack simulation drills

First steps during an attack?

1. Isolate compromised systems (disconnect without powering off for forensics)
2. Collect evidence (logs, memory dumps)
3. Activate recovery plan (prioritize critical services)
4. Notify regulators per GDPR/CCPA timelines
5. Interview staff about suspicious activity
6. Engage cyber insurers if applicable
Critical: Preserve attack artifacts for investigation.

Choosing cybersecurity providers?

Evaluation criteria:

  • Industry-specific incident experience
  • 24/7 SOC monitoring capabilities
  • ISO 27001/NIST/CIS compliance
  • Rapid response SLAs
  • Transparent reporting and improvement recommendations
  • Existing infrastructure compatibility

Should you pay ransomware demands?

Security experts unanimously advise against paying because:

  1. No data restoration guarantee (17% of payers regained no access)
  2. Funds criminal operations
  3. Triples likelihood of repeat attacks
  4. Potential legal consequences (banned in some jurisdictions)
Focus on prevention (backups) and recovery planning instead.