Cybersecurity / Source date:

Wartime Cyber Risk: Ukraine and Spillover for Global Firms

Destructive attacks and sanctions compliance changed threat models for companies with no regional footprint.

Civilian technicians rehearse offline recovery using spare hardware, backup media and a contact tree, not footage of a conflict or cyber incident.

On the morning of the invasion, a wiper was pushed through the management plane of a satellite broadband service. The intended target was Ukrainian command communications. What it also did was brick tens of thousands of modems across Europe and knock out remote monitoring for close to six thousand wind turbines in Germany — operators who had no involvement in the conflict, no presence in the region, and no way to have seen it coming. That is the shape of wartime cyber risk for most organisations. Not being targeted. Being adjacent. Four months into the war, the useful question for a business with no Ukrainian or Russian operations is not whether someone intends to attack it. It is which of its dependencies sit close enough to the conflict that a weapon aimed at somebody else lands on its operations.

Three routes in

Collateral propagation. Destructive tooling built for a specific target rarely respects the target's boundaries. Several wiper families deployed this year were designed to spread within a network and to destroy rather than encrypt. Dependency. A satellite link, a logistics provider, a payments processor, a software vendor with an engineering office in Kyiv or Kharkiv, a managed service with staff who are now displaced or conscripted. Availability risk here is physical as much as digital. Alignment. Volumetric attacks now follow political decisions within days. Lithuanian state and commercial networks were hit hard just over a week ago after the transit dispute, and the pattern — a government takes a position, a nominally independent group attacks that country's banks, airports and ministries — has repeated all year. If your country, your parent company or your public statements put you on one side, expect the traffic.

Ransomware has a business model, and a business model is a form of mercy

Every incident response plan written in the last five years quietly assumes an extortionist: someone who wants to be paid, therefore holds a working decryption key, therefore operates a support channel and honours the deal often enough for the market to function. A wiper has no key. There is no negotiation, no portal, no partial recovery, no second chance. Data is gone and systems are structurally destroyed, frequently including the domain controllers and backup infrastructure that the recovery plan assumes will exist. Testing against that scenario is uncomfortable and it is the single most valuable exercise available this year. Can you rebuild identity infrastructure from scratch? Are backups genuinely offline or immutable, or merely on a different server in the same domain? Do the runbooks live somewhere that survives the loss of the environment they describe? How long does a bare-metal rebuild of the twenty systems that matter actually take, measured rather than estimated? Most organisations discover the honest answer is measured in weeks, and that the business continuity plan assumed days.

Sanctions compliance has moved into the incident room

The payment question has acquired a legal dimension that did not exist three years ago. If the actor behind an intrusion is a designated entity or operates from a sanctioned jurisdiction, a ransom payment may be unlawful regardless of operational necessity — and the criminal ecosystem took public political positions this year, which turned attribution from an intelligence curiosity into a compliance input. This cannot be worked out at two in the morning with production down. Decide in advance who performs the sanctions determination, on what evidence, with which external counsel, under what timescale — and, most importantly, what the organisation does if the answer is that payment is not lawfully available. A recovery strategy that depends on an option your legal team may have to remove is not a strategy.

The war exclusion is now the live insurance question

In January, a New Jersey court found that the war exclusion in a pharmaceutical manufacturer's property policy did not bar its claim for the destruction caused by a state-attributed wiper five years ago, reasoning that the language had historically contemplated armed conflict rather than a cyber operation striking civilian businesses. That is a significant result for policyholders and insurers will not absorb it quietly. Expect rewritten exclusions, new state-actor carve-outs and sharper attribution language as policies renew. The practical step is small and should happen this month: read the war and hostile-act exclusions in your current policy, then ask the broker, in writing, how a destructive attack attributed to a state and spreading collaterally to your systems would be treated. Get the answer on paper before renewal, because the wording you have today may be the most favourable you will see for some years.

Map the dependencies you cannot see

The exercise that pays for itself: list your thirty most critical suppliers and, for each, record where the service is actually delivered from, where the data sits, where the engineers are, and who the named alternative is. Then add the question nobody asks — which of these sit behind a single upstream provider that everybody in your industry also uses? Add a second list for goods and technology: components, licensed software and hardware subject to export controls or sourced from newly designated entities. Sanctions have moved faster this year than most supplier records have.

Prepare for destructive loss before the incidentArticle-derived preparation prompts. No recovery-time benchmark, sanctions determination or insurance coverage advice is implied.
PreparationEvidence to review
Identity rebuildTested recovery path independent of lost systems
Backup recoveryAccess, isolation and restoration test records
Payment decisionNamed sanctions-review responsibility and counsel
InsuranceActual policy wording and written broker interpretation
DependenciesDelivery geography and shared upstream providers
CommunicationsRehearsed out-of-band contact and decision path

Qualitative summary of this article's source text, not a measured outcome or performance estimate.

Practical Guidance for Geopolitical Risk Assessment

  • Test recovery against destruction, not encryption, including rebuilding identity infrastructure.
  • Verify that backups are offline or immutable and that restoring them does not require the environment you just lost.
  • Pre-decide the sanctions determination process for an extortion event, with named counsel and a stated fallback.
  • Read the war exclusion in your cyber and property policies and get the broker's interpretation in writing.
  • Map delivery geography for your top thirty suppliers, including their upstream concentration.
  • Patch the known-exploited list first, ahead of severity-scored backlogs.
  • Extend log retention now — investigations this year are running longer than the default retention window.
  • Rehearse an out-of-band communications plan that works when corporate systems are gone, not merely compromised.

The Regional Angle

Three regional realities sit behind this, and the first has nothing to do with malware. Trade has re-routed through the Gulf this year at remarkable speed, and the compliance consequence has arrived faster than most finance functions have adjusted. New counterparties are appearing with opaque ownership, intermediaries are being inserted into previously direct flows, and screening a company name against a list is no longer sufficient when designation rules reach through ownership percentages to entities that are not themselves named. Correspondent banks are applying far more scrutiny than they were a year ago, sharpened further by the Emirates' addition to the international financial action grey list in March, and their response to ambiguity is to exit relationships rather than to investigate them. Treat counterparty screening as a continuous control rather than an onboarding step, because the list changes weekly and your customer file does not. The second is that this region has already lived through the destructive-attack scenario that Europe is now rehearsing. Wiper attacks against Gulf energy and petrochemical operators a decade ago, and the safety-system intrusion that followed, produced rebuild capabilities that most local operators genuinely developed — gold images, offline configuration archives, vendor recovery contracts, spare engineering workstations. The question worth asking this quarter is whether any of that is still current. Capability built after a crisis decays quietly; the archive is three platform versions old, the vendor contact left, and nobody has restored from the offline copy since 2019. Re-auditing an existing recovery capability is faster and cheaper than building one, and almost nobody has done it. The third is an advantage. Regional insurance markets have deep, practical fluency in war risk, because marine and aviation underwriting here has priced hostile-act exposure for decades, with established language for listed areas, breach-of-warranty cover and cancellation terms. Cyber war exclusions are a new argument in an old vocabulary, and brokers in this market can translate between the two better than most. Use that when the renewal conversation starts.

The objection worth taking seriously

The strongest objection is that the predicted catastrophe has not arrived. Four months in, there has been no global cyber event remotely comparable to the 2017 worm that cost multinationals billions. Destructive activity has stayed overwhelmingly inside Ukraine; the satellite incident affected one operator's estate; hacktivist campaigns have produced hours of downtime rather than material loss. Meanwhile the advisory industry has generated a great deal of alerting, and the recommended actions turn out to be ordinary security hygiene wearing a flak jacket. Most of that is accurate, and the sceptics have had the better of the argument so far this year. But it is an argument for doing the hygiene rather than against it, and four of the actions above are not hygiene by any definition: reviewing a war exclusion, pre-deciding a sanctions determination, testing recovery against destruction rather than encryption, and mapping supplier delivery geography are all things a competent security programme has typically never done. Nor is a four-month quiet period strong evidence about a conflict that may run for years — the 2017 event arrived three years into a war that had already produced two grid attacks, at a moment when everyone had concluded that spillover was theoretical.

Common Questions

We have no operations in the region. Are we exposed?

Through dependencies, possibly. The relevant exposure is your suppliers' delivery geography and your shared upstream providers, not your own footprint.

Does cyber insurance cover this?

It depends entirely on the exclusion wording and on whether the attack is attributed to a state. That is precisely why the question should be asked of the broker in writing now rather than during a claim.

Should we block traffic from specific countries?

It is a weak control on its own — infrastructure is rented anywhere — but it reduces background noise. Prioritise phishing-resistant authentication and attack surface reduction over geographic blocking.

What should we expect over the next twelve months?

Expect insurers to tighten war and state-actor exclusions at renewal, and expect that to become a negotiation rather than a formality. Expect hacktivist campaigns to follow political decisions within days, which makes them predictable if you track the politics. Expect designation lists to keep expanding, turning screening into a continuous obligation. Expect the criminal groups that shut down or rebranded this spring to reappear under new names with the same people. And expect energy-sector alerting to intensify as the conflict moves into winter, when infrastructure becomes the most valuable target on the board.


Geopolitical Risk Assessment — we map where your dependencies actually sit, test recovery against destruction rather than extortion, and get the war exclusion answered in writing before your renewal.

Continue reading

Talk to OPS

Start with the operating problem.