As Global Conflicts Go Digital, Businesses Need Wartime Gameplans
The recent cyberattack on Ukrainian tax software company Intellect Services is a stark reminder that modern warfare has gone digital. The devastating consequences of the NotPetya malware, which spread globally and caused tens of billions of dollars in damage to thousands of companies, demonstrate how businesses far from the battlefield can become unwitting casualties of war. With nation-states increasingly using cyberwarfare as a tactic, it’s time for businesses worldwide to develop wartime gameplans.
Intellect Services’ platform, M.E.Doc, was ubiquitous across Ukrainian businesses, making it an attractive target for Russian foreign military intelligence. The company’s lack of advanced cybersecurity defenses made it vulnerable to the NotPetya backdoor planted by the notorious Sandworm threat actor. But Intellect Services wasn’t a direct participant in the conflict; its owners had no reason to anticipate they’d become embroiled in a regional cyberwar.
The fact is, nation-states often target businesses that are indirectly involved in military operations or have critical infrastructure that can be used as leverage. Allie Mellen, Forrester analyst and author of “Code War: How Nations Hack, Spy, and Shape the Digital Battlefield,” argues that private sector companies can be easier targets than governments or militaries. This is because they often lack the resources to defend themselves against sophisticated nation-state attacks.
The 1977 Geneva Conventions define military objectives as entities that contribute significantly to military action and whose destruction offers a clear military advantage. While this may seem straightforward, Mellen notes that the definition can be applied broadly. “If you have a contract with the military, you are a target,” she says. “That’s the reality because the adversary is looking to disrupt supply chains or cause harm.”
Even organizations without direct ties to militaries or governments can still become targets due to the complex nature of modern warfare. Medical equipment firm Stryker, which supplies medical equipment and patient systems to various US military branches, was targeted by Iranian hacktivists linked to the country’s Ministry of Intelligence and Security (MOIS). This highlights how digital infrastructure can serve both civilian and military purposes, putting neutral organizations and their customers at risk.
The increasing willingness of militaries to attack digital service providers – even with kinetic strikes – further underscores the need for businesses to prepare. If a cloud system used by a local municipal energy provider is targeted because it also supports a forward operating base, there are significant implications for all downstream customers.
In conclusion, the Intellect Services case serves as a warning that businesses worldwide must take seriously the threat of cyberwarfare. With nation-states increasingly using digital tactics to disrupt supply chains and cause harm, companies need to develop gameplans to protect themselves from these types of attacks. This requires a proactive approach to cybersecurity, including regular assessments, robust defenses, and contingency planning for worst-case scenarios. By doing so, businesses can minimize the risk of becoming collateral damage in a global conflict gone digital.
Source: Dark Reading — 2026-07-09