Cyberwarfare: From Statecraft to Operations
About this course
Cyberwarfare is not hacking with a flag attached. It is the use of digital access, information, people, infrastructure, authorities, and timing to create strategic or military advantage. This course teaches students to connect those parts. It begins with the nature of cyber power, follows the evolution of operations from Estonia and Stuxnet to Ukraine, and then develops the judgment needed to plan, support, defend against, and assess operations in daily practice.
The course is written for cyber threat intelligence analysts, military and government cyber personnel, incident responders, security leaders, red and purple team members, and defenders preparing for advanced work. It is self-contained: the opening lessons establish the networking, identity, cloud, logging, intelligence, incident-response, authorization, and ethical foundations used throughout the later modules. Offensive operations are then treated seriously: students study target systems, access stewardship, operational infrastructure, effects, coordination, operational security, and assessment. The course does not provide malware, exploit code, credentials, or a turnkey intrusion recipe. Its purpose is professional decision-making under lawful authority.
Real cases remain the spine of the journey. Estonia, Georgia, Stuxnet, the Ukrainian power-grid attacks, NotPetya, Olympic Destroyer, the SolarWinds compromise, Operation Glowing Symphony, Viasat KA-SAT, the wartime campaign in Ukraine, Volt Typhoon, and the Salt Typhoon telecommunications campaign are examined for what they reveal—and for what the public record cannot establish. Sources are dated and linked. A final capstone asks the learner to build and challenge an integrated cyber campaign while protecting civilians, intelligence equities, partners, and the mission.
What you'll learn
- ✓ Distinguish cybercrime, espionage, influence, offensive cyber operations, and cyber warfare by objective, authority, context, and effect.
- ✓ Analyze a state or state-aligned cyber campaign as a system of ends, ways, means, dependencies, partners, risks, and observable outcomes.
- ✓ Produce a defensible multi-source attribution assessment that separates technical linkage, actor identity, sponsorship, and state responsibility.
- ✓ Design a notional cyber campaign and target-development process with explicit legal, civilian-harm, intelligence-gain-or-loss, escalation, and operational-security controls.
- ✓ Evaluate intended, unintended, direct, indirect, and cross-border effects across enterprise, cloud, telecommunications, space, and operational-technology systems.
- ✓ Build a daily defensive operating rhythm that converts strategic warning and adversary behavior into hunting, hardening, response, continuity, and partner action.
- ✓ Assess campaign performance with measures that distinguish task completion, technical effect, operational effect, and strategic outcome.
- ✓ Brief senior decision-makers on cyber options, uncertainty, proportionality, reversibility, escalation, resilience, and viable alternatives.
Course content
Module 1: Entering the Cyber Battlespace
This self-contained entry module first builds the technical, analytic, incident-response, authorization, and ethical foundations required for professional practice. It then replaces the image of cyberwar as isolated hacking with a disciplined model of cyber power, connecting technical action to missions, institutions, people, and national purpose.
Digital Systems as Mission Terrain
Learn how packets, names, identities, hosts, cloud services, telemetry, and controls combine to produce a mission service.
Evidence, Threat Intelligence, and Incident Response
Learn to read advisories critically, distinguish observables from behavior, express uncertainty, and connect intelligence to response decisions.
Authorization, Ethics, and Safe Practice
Establish authority, scope, rules of engagement, civilian and mission safeguards, data handling, and stop conditions before practical work.
What Cyberwarfare Is—and Is Not
Build a precise vocabulary for conflict, competition, espionage, crime, influence, and operations in cyberspace.
Cyberspace as an Operational Environment
Map physical infrastructure, logical relationships, identities, missions, ownership, geography, and time as one battlespace.
Module 2: The Road to Persistent Cyber Conflict
Case history becomes useful when it reveals recurring mechanisms. This module follows cyber operations from politically charged disruption through industrial sabotage and into sustained wartime campaigning. Students compare what was observed, what was attributed, what changed afterward, and which popular lessons outrun the evidence.
Estonia, Georgia, Stuxnet, and the First Shock
Study three early cases that changed thinking about disruption, combined operations, attribution, and cyber-physical effect.
Ukraine, 2015–2026: Campaigning Under Fire
Follow a decade of power disruption, destructive malware, satellite effects, espionage, influence, adaptation, and resilience.
Module 3: Actors, Proxies, and Strategic Behavior
State cyber power is produced by institutions, contractors, vendors, criminals, volunteers, and infrastructure—not by a single monolithic “APT.” This module teaches learners to model control relationships, compare strategic behavior, and avoid treating nationality or tool overlap as doctrine.
The State Cyber Ecosystem
Map services, military units, contractors, criminals, hacktivists, vendors, and access brokers as distinct relationships.
Strategic Cultures Without Stereotypes
Compare Russian, Chinese, Iranian, North Korean, US, UK, and allied behavior through observed missions and constraints.
Module 4: Law, Authority, and Civilian Protection
Cyber operations do not occur in a legal vacuum. This module gives non-lawyers an operational issue-spotting method for peacetime international law, domestic authority, state responsibility, use of force, armed conflict, and international humanitarian law. It emphasizes early legal integration and the protection of civilians, civilian data, and shared infrastructure.
Below Armed Conflict: Sovereignty, Intervention, Force, and Responsibility
Navigate the legal questions that shape access and effects before international humanitarian law applies.
Armed Conflict: IHL and Cyber Effects
Apply distinction, proportionality, precautions, necessity, and humanity to interconnected digital systems.
Module 5: Intelligence, Indications, and Attribution
Operations depend on intelligence before, during, and after action. This module turns policy questions into collection, develops layered attribution, and treats deception, source protection, and uncertainty as operational constraints.
Module 6: Campaign Design and Command
This module turns strategy into executable, governed action. Learners build a theory of success, integrate cyber with other instruments, and design command, approval, deconfliction, partner, and operational-security processes that can function at real tempo.
From Policy Aim to Cyber Campaign
Translate strategy into objectives, effects, actions, sequencing, alternatives, and a testable theory of success.
Command, Authorities, and Deconfliction
Design decision rights and coordination that survive global infrastructure, partner equities, and operational tempo.
Module 7: Target Systems, Access, and Operational Security
Offensive competence begins with understanding the system that produces an adversary function, then stewarding access as a finite operational asset. This module covers target-system analysis, access lifecycle, capability fit, infrastructure, exposure, and safe exercise practice without deployable intrusion procedures.
Target-System Analysis and Cyber Key Terrain
Find the function, dependencies, control points, observability, and recovery paths behind a target label.
Access Stewardship, Capability Fit, and OPSEC
Manage access and capabilities as finite assets subject to discovery, decay, interference, and policy.
Module 8: Effects Engineering and Campaign Assessment
Effects must be bounded, observed, and connected to objectives. This module compares collection, denial, degradation, manipulation, destruction, and cognitive effects, then builds assessment from measures of performance through strategic outcomes.
Module 9: Critical Infrastructure and Cross-Domain Operations
Digital action can affect power, water, transport, communications, space services, logistics, and weapons. This module teaches IT/OT and satellite-system reasoning, safety, manual operations, and the integration of cyber effects with physical maneuver and the electromagnetic spectrum.
Operational Technology, Safety, and Restoration
Understand how industrial processes, control, safety, engineering, and human operators determine physical consequence.
Space, Telecommunications, and Multi-Domain Integration
Connect satellite, carrier, cloud, spectrum, physical, and cyber dependencies to maneuver and command.
Module 10: Influence, Perception, and Public Truth
Cyber operations can acquire, alter, deny, and release information to shape behavior. This module examines hack-and-leak operations, false flags, DDoS theater, narrative laundering, synthetic media, and the defensive combination of forensics, communication, and public trust.
Cyber-Enabled Influence Operations
Follow stolen or fabricated material from acquisition through framing, laundering, amplification, and audience response.
Defending Truth, Trust, and Decision Space
Integrate incident response, verification, audience analysis, leadership, legal review, and communication.
Module 11: Daily Defence in Competition and War
Wartime cyber defence is a sustained operating rhythm, not an emergency checklist. This module integrates mission assurance, threat intelligence, attack-surface reduction, hunting, incident command, evidence, continuity, recovery, partners, and learning.
Mission Assurance and the Wartime Operations Floor
Organize intelligence, defence, engineering, command, communications, and partners around mission risk.
Continuity, Recovery, and Collective Defence
Keep essential missions operating through degraded modes, clean recovery, external support, and repeated attack.
Module 12: Deterrence, Emerging Change, and the Final Campaign
The final module moves from national and alliance strategy into the 2026 operating environment and then requires full synthesis. Learners assess deterrence and norms, examine AI and supply-chain change without hype, and complete a governed campaign capstone from requirement through lessons learned.
Deterrence, Norms, and Collective Response
Build credible response portfolios when attribution, thresholds, signaling, and adversary values vary.
The 2026 Horizon: AI, Supply Chains, Edge, and Identity
Integrate the newest evidence into operations without mistaking novelty for strategic change.
Capstone: Build, Challenge, and Defend a Cyber Campaign
Synthesize strategy, intelligence, law, targeting, access, effects, command, defence, assessment, and communication.