An inside look at Ukrainian efforts to repel Russian cyberattacks on critical infrastructure, as some worry that early success might be unwound over time
Mehul Srivastava / Financial Times :
Context & Ripple Effects
Ukraine is not a new target: experts flagged years ago that repeated attacks culminating in mass power outages in Kiev were evidence of Russia using the country to test offensive capabilities. When the full-scale invasion came, Washington had already pre-positioned support, embedding US soldiers and cybersecurity experts with Ukrainian defenders before the first missiles flew.
First-order effects
- Ukrainian grid, government, and logistics operators are holding systems online against sustained Russian intrusion attempts, with foreign specialists working alongside local defenders rather than advising from afar.
Second-order effects
- The war has dissolved an old norm: hacking Russian targets was once considered off-limits by some Western operators, but Ukraine's defense has pulled a coalition of US tech companies and NATO-aligned intelligence into active operations against Russian networks.
Third-order effects
- If the pattern holds, critical-infrastructure cyberdefense becomes a standing allied function rather than a purely national one — with Ukraine serving as the live-fire proving ground where that coalition model is built, and where any relaxation of effort would be tested first.
The trend: Wartime cyberdefense is consolidating around a state-plus-private-tech coalition model proven in Ukraine, replacing the era when each country defended its infrastructure alone.