Christopher Clark, Cyber Security Incident Response Team Director, Thrive
Geopolitical escalation can become a cyber security problem for businesses far more quickly than many boards expect.
The National Cyber Security Council (NCSC) has warned that UK critical infrastructure faced more than 200 cyber incidents over the past year, with around three-quarters believed to be linked to state actors. Analysis of the conflict involving Iran has also found cyber retaliation following military escalation within hours, bringing events overseas much closer to the day-to-day reality of UK organisations.
That risk has already been demonstrated on UK soil. In July, a cyber-attack reportedly linked to Iranian hackers forced a small UK power generator offline for four days. The government said there was no risk to the wider energy system, but the incident shows how quickly geopolitical cyber activity can translate into operational disruption.
Energy, healthcare, water and telecoms remain obvious targets because disruption can affect essential services. Yet, hostile state activity does not stop at the boundary of critical infrastructure.
Hostile state risk extends beyond critical infrastructure
A business does not have to be an obvious target to become one. It may be connected to a larger customer, supplier, regulator or public body that an attacker ultimately wants to reach. In other words, you do not have to be the objective. You just have to be the way in.
There is also the risk of spillover. Targeting can follow politics rather than the size of a company or its balance sheet. If an organisation has operations or suppliers connected to a live conflict, it can become collateral even when nobody set out specifically to target it.
Businesses also need to reconsider what hostile state activity is likely to look like inside their own environments. The most significant intrusions are not necessarily the noisiest.
Security teams may be watching for malware, failed logins or a sudden increase in DDoS activity. Capable attackers increasingly use valid credentials and legitimate administration tools, allowing malicious behaviour to resemble normal activity.
There may also be no obvious warning to investigate. If the plan is to wait for one, the organisation may already be too late by the time it appears.
A better working assumption is that a capable actor could already be inside, or could get in without immediately triggering an alert. The question then becomes what they can actually do once they have that foothold.
Trusted technology can create the same problem. Management platforms and legitimate system tools can be repurposed by attackers, while compromised software packages can provide access to many organisations at once. Activity entering through a tool or supplier that the business already trusts may attract less scrutiny because it appears legitimate.
The same principle applies to suppliers. If a connected partner has been compromised, one of the first questions should be what has been done to separate that organisation from your own environment. Continuing normal access without understanding what happened risks transferring their exposure into your network.
Organisations should know how they would isolate an affected supplier and what evidence would be required before connectivity resumed. They may need confirmation of how the attacker entered and which systems were affected, alongside assurance that the access has been removed. Shared applications or other connections may have to remain unavailable until that information is clear.
That can be uncomfortable for the business, but restoring connectivity too quickly can create a much bigger problem later.
The time available to make these decisions is shrinking. Threat actors can analyse newly disclosed vulnerabilities and move to exploitation quickly, with AI making parts of that process faster. In some cases, organisations can be exposed within hours of a vulnerability becoming known.
Patch management therefore cannot always wait for the normal maintenance cycle. Teams need to know which vulnerable systems create the greatest risk and be ready to prioritise them when a new vulnerability emerges.
Geopolitical risk can also outlast the immediate conflict. A ceasefire does not automatically remove access established during a period of heightened activity, nor does it mean proxy groups will stop operating. Attackers have good reason to preserve a foothold that may be useful later. I have seen access remain available inside an environment for three years or more.
That is why an easing of geopolitical tension should not automatically be treated as a reduction in cyber risk.
Containment depends on preparation and experience
Preparation has to focus on containing an attacker as well as keeping them out. Standing privileges should be kept to a minimum, networks should be segmented so an attacker cannot move freely towards critical systems or backups, and offline backups need to be regularly tested.
Organisations also need a clear view of their external attack surface and where their greatest points of exposure lie. Regular tabletop exercises should use realistic scenarios informed by current threat intelligence.
If an attacker gained access through a VPN or compromised supplier, what could they reach next? How far could the incident spread? And who has the authority to cut them off?
That authority needs to be clear before an incident. Time can be lost when technical teams know what needs to happen but must wait for decisions on whether systems can be disconnected or business processes interrupted.
Experience is equally important. Frameworks provide structure, but serious incidents rarely follow a script. Responders who have handled repeated compromises understand where investigations can stall, which decisions cannot wait and what needs to be secured before systems are safely returned to service.
For many organisations, maintaining that level of incident response experience entirely in-house is difficult. What matters is having access to people who have dealt with incidents under real operational pressure and can apply that experience quickly when normal assumptions no longer hold.
Hostile state cyber activity should now be treated as a routine business risk rather than something considered only when international tensions make the headlines.
Organisations should be asking a more immediate question: if something gets through today, how far can it spread before we stop it?
Answering that question before an attack happens can make the difference between a contained security incident and a prolonged operational crisis.

