Cyberspace is now the fourth domain of military conflict.
Geopolitics can be summarized as the behavior of a country or region influenced by its location in time (history and current events), and space (geographical proximity to other countries or regions). Those geopolitical actions are also influenced by the state of the economy and the psychology of its leaders.
Geopolitical disagreements between countries are usually settled by diplomacy but sometimes by physical force of arms. The latter is usually a kinetic war involving, as necessary and available, land (an Army), air (an Air Force) and the sea (a Navy).
Over the last few decades, cyberspace has been increasingly co-opted into these conflicts as a fourth force. This article is a discussion on the confluence and effect of using adversarial cyber activity to support kinetic force of arms in solving geopolitical conflict. It is, in short, a discussion on geopolitics and cyberspace.
Background
In the modern world there are three types of warfare: kinetic war (traditional ‘boots on the ground’ physical conflict involving armed forces and usually preceded by cyber operations); cyberwar (aggressive cyber operations); and cyber-kinetic (cyber operations that result in physical damage). All three are generally motivated by politics or geopolitical differences, which makes the intersection of geopolitics and cyberspace an important study.
The three primary geopolitical motivations for nation state cyber operations in support of geopolitical differences are espionage, a desire for regime change, and territorial disputes. In each case the cyber activity has become a common precursor to kinetic activity.
In broad terms, nation state activity is ideologically East versus West. The East is primarily China, Russia, Iran and North Korea (CRINK for short). The West is primarily North America, UK, EU, and the remaining members of the 5Eyes (Australia and New Zealand).
Nation state geopolitical cyber operations differ in motivation and practice from simple criminal activity. Criminal activity is motivated by monetary gain. The desire is to achieve this with as much speed and as little cost as possible. Being noisy is not a problem if you can get in, grab what you want, and leave as quickly as possible.
Nation state activity is very different. It is low and slow. Stealth and continuous dwell time are important. “If you detect nation state actors on your network,” comments Dmitri Alperovitch, “chances are they have already been there for weeks or months.”
Alperovitch was a co-founder of CrowdStrike, is a renowned expert on geopolitics and cyberspace, and is author of World on the Brink. He spoke to SecurityWeek about the intersection of geopolitics and cyberspace, and provided invaluable thoughts and insights.
Cyberspace and espionage
Nation state espionage alone is not generally considered to be war, although it is often a prelude to, or part of, war. It has been practiced for as long as civilization has existed. There are records from ancient Mesopotamia (perhaps 4,000 years ago). The Amarna Letters (14th century BCE) from Ancient Egypt provide diplomatic and intelligence correspondence inscribed on clay tablets. More recently, approximately 2,500 years ago, Sun Tsu’s The Art of War has a chapter titled ‘The use of spies’ treating espionage as the foundation of military activity.
Cyber, however, now raises espionage to a new level of scale and purpose. Its motivation is as often economic as it is military. Nation states use cyber espionage to monitor other nations’ military capabilities and where possible steal military secrets, but also now to steal intellectual property from foreign enterprises. The latter means that commerce as well as the military must protect against nation state low and slow incursions.
Every nation with a cyber capability is engaged in cyber espionage. The West, with the Five Eyes (FVEY) alliance, is probably the better actor.
“It’s an intelligence alliance (US, Canada, UK, Australia and New Zealand) that evolved from the work of Alan Turing and Bletchley Park during the Second World War,” comments Alperovitch. It started as a signals intelligence alliance collecting from airwaves and detecting radio signals, but its activities have broadened into cyber espionage.
“NSA, GCHQ, and the other countries in the alliance are now using cyber to accomplish national security priorities – which is the collection of intelligence on our adversaries. So, yes, we’re doing that. And I think we’re the best in the world at it.”
What we don’t do, he continues, “We don’t steal intellectual property from private companies for the benefit of our own industries. That’s what China does.”
A hypothetical example could be drawn with AI. AI will be seriously important in the future, militarily, sociologically, and economically. It is to be expected that both sides are already surveilling the state of AI in the other. Five Eyes might wish to watch DeepSeek-like companies for intelligence purposes; but that’s all. Beyond intelligence, China, however, might wish to watch, and exfiltrate, Anthropic-like intellectual property – and pass that IP on to its own DeepSeek-like AI enterprises. Other CRINK nations would do similar.
There are additional behaviors that CRINK might engage in that Five Eyes does not. “We don’t engage in ransom operations or theft of currency and cryptocurrency as North Korea does. Our operations follow the rule of law, both domestic and international. The operations are designed generally to not be escalatory unless we’re in a military conflict, in which case, anything goes.”
The last comment is interesting and explains the difficulty in understanding the role of cyberspace in geopolitics. When, exactly, can two nations be defined as ‘at war’? It used to be the presence of opposing armies on a battlefield, or a formal declaration of war between nations.
However, since 2011 in the US, and 2016 in the rest of NATO, cyber is officially a military domain, and cyberspace is therefore a potential battlefield. In the US, Cyber Command was ordered by Secretary of Defense Robert Gates in 2009 and became operational within Strategic Command in 2010 before becoming an independent unified combatant command in 2018.
The logical implication of this process is that the moment one nation engages in cyber espionage against another nation on the cyberspace battlefield, the two nations are effectively at least at military quasi-war with each other.
But “We’re not going to go [full kinetic] war over espionage, because everyone does it,” adds Alperovitch. If espionage led to war, the world would have been at continuous war since ancient Mesopotamia.
Nevertheless, his earlier qualification (‘unless we’re in a military conflict, in which case, anything goes’) marks a major change in the role of cyberspace that comes to a head when kinetic conflict has either started or is inevitable.
Cyberspace and kinetic conflict
There are two primary causes for kinetic war: regime change and territorial disputes. In both cases, any kinetic activity is generally preceded by or concurrent with aggressive cyber activity. Cyber activity is unlikely to ever win kinetic wars – its purpose is to prepare for, support, and hasten a kinetic victory.
There are two recent examples of attempted regime change (Venezuela and Iran), and two examples of territorial disputes: Russia with Ukraine, and China with Taiwan.
Venezuela. Nicolás Maduro, then president of Venezuela, was arrested and removed from Venezuela through a kinetic US operation on January 3, 2026. This operation was almost certainly, and is commonly believed, to have included a cyber element, if only pre-kinetic espionage intelligence gathering. Operational support (possibly in assisting the power blackout that was part of the extraction) is likely, but unproven. This is not surprising – US intelligence would avoid disclosing any cyber access to Venezuelan networks in case it is needed again in the future.
In a press conference following the operation, General Dan Caine (chairman of the joint chiefs of staff) specifically mentioned Cyber Command as part of the layering of ‘different effects’ leading up to the operation.
Maduro was arrested and extracted to face charges related to ‘narco-terrorism’ and is currently being held in New York. The primary purpose of the extraction was, however, to effect regime change, prevent future narco-terrorism, and give the US greater influence over Venezuelan oil. It succeeded only in oil, where the US now has considerable influence.
It failed in preventing the flow of narcotics into the US since Venezuela was a transit route for narcotics produced elsewhere (primarily Colombia). And it failed to effect regime change. The current ‘acting’ president is Delcy Rodríguez, previously Venezuela’s Executive Vice President. Officially, her position is that Maduro is still the legal and rightful president.
Iran. Epic Fury and Roaring Lion were respectively the joint US and Israeli combat missions launched on February 28, 2026, against Iran. The primary purposes were to destroy Iran’s potential to develop nuclear weaponry and to effect regime change to prevent any continuing desire for nuclear weaponry. Cyber activity was an important component at the launch of kinetic action.
Cyber operations degraded Iran’s radar grids to allow the initial wave of US and Israeli airstrikes. These were remarkably successful, including killing supreme leader Ayatollah Ali Khamenei. Many of the top military leaders were also killed. It is believed that cyber espionage played a part in knowing precisely when and where they were located.
The initial kinetic action amounted to regime decapitation that would hopefully lead to the rise of a new regime. Psychological cyber operations were used to deliver anti-regime messaging and normal state media, government communication lines, and public apps were all targeted, hoping that the Iranian people would rise up against the Iranian government. This didn’t happen. Despite the success of the ‘remote’ kinetic action against Iranian military capabilities, Iran continues.
Iran has retaliated with its own kinetic activity against US and Israeli regional allies, and with its own cyberattacks against the US. On July 22, 2026, CISA warned that Iranian actors were exploiting ‘programmable logic controllers across US critical infrastructure’.
This war is ongoing. At the time of writing, it is four months and four weeks since the commencement of kinetic activity. It has involved action in the air, on the seas, and in cyberspace – but not specifically on the ground. Ground forces are not currently involved. The implication here is that cyber activity can assist in areas of kinetic activity, but cannot ultimately succeed without human boots, troops, on the ground in the battlefield.
Cyberspace and territorial disputes
We have two examples of major geopolitical territorial disputes. One involves an ongoing war – in Ukraine. The second dispute is over Taiwan. China insists it is part of China. Taiwan and much of the West disputes this. There is, again at the time of writing, no kinetic war in or for Taiwan. However, if we accept that the role of cyber in geopolitics is to prepare for and assist in kinetic warfare, there are worrying signs.
Ukraine. On February 24, 2022, Russia invaded Ukraine. This was fundamentally a territorial dispute. Putin, that is Russia, considered Ukraine to be part of the Russian empire. He wished to return Russia to the preeminence it had in the USSR prior to the collapse that ended the Cold War. Ukraine disagreed.
Other factors played into this dispute. Historically, Ukraine and Russia have always been linked. When Zelensky came to power, he spoke Russian more fluently than Ukrainian.
Ukraine is effectively a buffer between Russia and its adversary NATO and the EU. Ukraine, however, displayed distinct preferences toward NATO and indicated a wish to join the EU in the future. Putin felt he had no option but to force Ukraine back into the Russian fold.
Physically attempting to do this started almost exactly eight years before the current ongoing war in mainland Ukraine when Russia took Crimea.
On both occasions he employed the now textbook style of first disrupting the enemy via cyberspace. For Crimea, a cyber espionage campaign dubbed Operation Armageddon and targeting government, law enforcement, and defense agencies was conducted from 2013. Ukraine attributed it to the FSB.
Russian malware, including Snake and Uroburos (closely related malware) that was developed and distributed by the Turla APT group, was used against Ukrainian government systems.
As the kinetic invasion began, Russian special forces and cyber units raided Crimean telecommunications centers and cut communication between Crimea and mainland Ukraine, disrupted government phones, and DDoSed government websites, news outlets and social media.
Three months prior to the later invasion of mainland Ukraine in 2022, in late 2021, Alperovitch had declared that kinetic war was inevitable. “What convinced me,” he told SecurityWeek, “was what I was seeing in the cyber domain. Not exclusively – there was a buildup of Russian forces and rhetoric from the Russian government – but I was also seeing cyber intrusions into Ukrainian systems unlike any that I had seen since Crimea in 2014. This was a clear indication that Russia was again preparing for a full scale invasion.”
He believes that aggressive cyberactivity is effectively a ‘canary in the coalmine’ warning on imminent kinetic warfare.
In some ways, Russian activity never ceased after 2014, with long running Sandworm (GRU Unit 74455), APT28 / Fancy Bear (GRU Unit 26165), and Gamaredon (FSB‑linked) campaigns.
However, cyber activity escalated dramatically immediately prior to the 2022 invasion. Ukrainian government websites were defaced using WhisperGate. HermeticWiper struck hundreds of systems across Ukrainian financial, defense, aviation, and IT sectors. A second wiper (IsaacWiper) targeted government networks. And as the invasion began, a cyberattack disrupted Viasat’s KA-SAT satellite network, disabling thousands of modems across Ukraine and Europe, but more specifically severely degrading Ukrainian military C2 capabilities.
Kinetically, Ukraine (supported by the US and the EU, has proven remarkably resilient. Four years into the war (again at the time of writing) Russia has not succeeded in its kinetic invasion. While the cyber activity did what it was designed to do, history again suggests that cyber can assist kinetic but cannot guarantee kinetic success.
Taiwan. A second territorial dispute exists today, with China insisting that Taiwan is part of mainland China. Like Ukraine with Russia, Taiwan disagrees, insisting it is an independent island nation. But just as an independent Ukraine inhibits Russian influence eastward, so an independent Taiwan off the eastern coast constrains China’s strategic freedom of action across military, economic, diplomatic, and informational domains in the Pacific region.
While there is currently no specific kinetic activity from China, there is massive cyber hostility targeting Taiwan that has been ongoing for years. There is also massive Chinese pre-positioning in western critical industries. This latter is not a precursor to a Chinese kinetic invasion of the US, but more likely a defensive position to disrupt the US in interfering in any kinetic action against Taiwan.
China’s Volt Typhoon is an example, combining pre-positioning with living-off-the-land for stealth. It has been operating for years, quietly embedding itself inside utility sectors, including communications, energy, transportation, and water systems. The belief is this is designed to give China the ability to disrupt critical services in the event of a future crisis. That crisis could be any US reaction to an invasion of Taiwan.
All of this is necessary because of the importance of Taiwan to western economy. Unlike Ukraine, which has little direct relevance to the US if lost to Russia, Taiwan is critically important to US technology companies. It supplies around 90% of the world’s most advanced chips.
Without Taiwan’s fabrication capacity, it is unlikely that companies like Apple, AMD, Google or AMD would be able to manufacture the processors they use; and the progress of AI would be inhibited by difficulties in building the necessary data centers. It would take many years and many billions of dollars for the US to build its own industry to replace Taiwan’s current capacity.
For this reason, the US is more aggressive in its support for Taiwan than it is in support of Ukraine. We do not know if this support is preventing a Chinese kinetic invasion of Taiwan or merely delaying it. It’s certainly not stopping China’s desire to take Taiwan. China wants Taiwan, and the US doesn’t want it to have Taiwan.
Interpretation of what is really happening is all conjecture. Is China ramping up cyber activities to force the US to be less reliant on Taiwan? If that were to happen, US defense of Taiwan might relax, enabling China to absorb Taiwan with less difficulty. Or should we see this aggressive cyberactivity as an indication of Alperovitch’s ‘a canary in the coalmine’? Only time will tell. The longer it takes for China to invade Taiwan, the less dramatic it will be. But if China were to invade Taiwan tomorrow, all bets are off.
Summary
The four examples of Venezuela, Ukraine, Iran and Taiwan demonstrate that over the last 15 years, cyberspace has become deeply embedded in geopolitical military actions around the globe. Nowhere, at least so far, has cyber activity done more than assist kinetic military force. The only successfully completed kinetic action was the arrest of Maduro in Venezuela, which involved boots on the ground. Boots on the ground have so far been excluded from the Iran war, and nobody seems to know what will happen without them. But there have been boots on the ground in Ukraine for the last four years, and there is still no winner.
Neither successful cyber activity nor greater force on the ground guarantees a successful kinetic operation – but there is little doubt that cyberspace and ground force will continue hand in hand in the future. Taiwan is a big concern. The geopolitical peculiarities of this situation suggest that any future kinetic conflict will be, for the first time, between two major powers each with nuclear capabilities.
We must hope that for Taiwan, geopolitical hostilities between East and West remain in cyberspace.
Related: China Admitted to Volt Typhoon Cyberattacks on US Critical Infrastructure: Report
Related: The Impact of Geopolitics on CPS Security
Related: Geopolitics Will Drive Aggressive Cyber Activity Throughout 2020
Related: The Increasing Effect of Geopolitics on Cybersecurity