Course

Cyberwarfare: From Statecraft to Operations

About this learning content: Courses, lessons, assessments, explanations and illustrations may be created with the help of artificial intelligence. We review and check the material and do our best to avoid incorrect or outdated information, but mistakes, omissions or ambiguous questions may remain. Please verify information before relying on it for professional, security, legal or operational decisions. Read the full notice or report an issue.
Difficulty Advanced
Modules 12
Lessons 28
Time 43 hr 15 min
Language en
Created by Threat Intelligence Lab
Updated 14 September 2026
Cyber power connects state purpose to real-world consequence A central cyberspace node connects state purpose, intelligence, military operations, infrastructure, and society, with governance surrounding the system. CYBER POWER access • information • effects STATE PURPOSEinterests • policy • authorityINTELLIGENCErequirements • access • judgmentOPERATIONSdefend • exploit • influenceCONSEQUENCEmission • services • people LAW • OVERSIGHT • ALLIANCES • ESCALATION CONTROL • RESILIENCE

About this course

Cyberwarfare is not hacking with a flag attached. It is the use of digital access, information, people, infrastructure, authorities, and timing to create strategic or military advantage. This course teaches students to connect those parts. It begins with the nature of cyber power, follows the evolution of operations from Estonia and Stuxnet to Ukraine, and then develops the judgment needed to plan, support, defend against, and assess operations in daily practice.

The course is written for cyber threat intelligence analysts, military and government cyber personnel, incident responders, security leaders, red and purple team members, and defenders preparing for advanced work. It is self-contained: the opening lessons establish the networking, identity, cloud, logging, intelligence, incident-response, authorization, and ethical foundations used throughout the later modules. Offensive operations are then treated seriously: students study target systems, access stewardship, operational infrastructure, effects, coordination, operational security, and assessment. The course does not provide malware, exploit code, credentials, or a turnkey intrusion recipe. Its purpose is professional decision-making under lawful authority.

Real cases remain the spine of the journey. Estonia, Georgia, Stuxnet, the Ukrainian power-grid attacks, NotPetya, Olympic Destroyer, the SolarWinds compromise, Operation Glowing Symphony, Viasat KA-SAT, the wartime campaign in Ukraine, Volt Typhoon, and the Salt Typhoon telecommunications campaign are examined for what they reveal—and for what the public record cannot establish. Sources are dated and linked. A final capstone asks the learner to build and challenge an integrated cyber campaign while protecting civilians, intelligence equities, partners, and the mission.

What you'll learn

  • Distinguish cybercrime, espionage, influence, offensive cyber operations, and cyber warfare by objective, authority, context, and effect.
  • Analyze a state or state-aligned cyber campaign as a system of ends, ways, means, dependencies, partners, risks, and observable outcomes.
  • Produce a defensible multi-source attribution assessment that separates technical linkage, actor identity, sponsorship, and state responsibility.
  • Design a notional cyber campaign and target-development process with explicit legal, civilian-harm, intelligence-gain-or-loss, escalation, and operational-security controls.
  • Evaluate intended, unintended, direct, indirect, and cross-border effects across enterprise, cloud, telecommunications, space, and operational-technology systems.
  • Build a daily defensive operating rhythm that converts strategic warning and adversary behavior into hunting, hardening, response, continuity, and partner action.
  • Assess campaign performance with measures that distinguish task completion, technical effect, operational effect, and strategic outcome.
  • Brief senior decision-makers on cyber options, uncertainty, proportionality, reversibility, escalation, resilience, and viable alternatives.

Course content

Module 2: The Road to Persistent Cyber Conflict

Case history becomes useful when it reveals recurring mechanisms. This module follows cyber operations from politically charged disruption through industrial sabotage and into sustained wartime campaigning. Students compare what was observed, what was attributed, what changed afterward, and which popular lessons outrun the evidence.

Module 3: Actors, Proxies, and Strategic Behavior

State cyber power is produced by institutions, contractors, vendors, criminals, volunteers, and infrastructure—not by a single monolithic “APT.” This module teaches learners to model control relationships, compare strategic behavior, and avoid treating nationality or tool overlap as doctrine.

Module 4: Law, Authority, and Civilian Protection

Cyber operations do not occur in a legal vacuum. This module gives non-lawyers an operational issue-spotting method for peacetime international law, domestic authority, state responsibility, use of force, armed conflict, and international humanitarian law. It emphasizes early legal integration and the protection of civilians, civilian data, and shared infrastructure.

Module 5: Intelligence, Indications, and Attribution

Operations depend on intelligence before, during, and after action. This module turns policy questions into collection, develops layered attribution, and treats deception, source protection, and uncertainty as operational constraints.

Module 6: Campaign Design and Command

This module turns strategy into executable, governed action. Learners build a theory of success, integrate cyber with other instruments, and design command, approval, deconfliction, partner, and operational-security processes that can function at real tempo.

Module 7: Target Systems, Access, and Operational Security

Offensive competence begins with understanding the system that produces an adversary function, then stewarding access as a finite operational asset. This module covers target-system analysis, access lifecycle, capability fit, infrastructure, exposure, and safe exercise practice without deployable intrusion procedures.

Module 8: Effects Engineering and Campaign Assessment

Effects must be bounded, observed, and connected to objectives. This module compares collection, denial, degradation, manipulation, destruction, and cognitive effects, then builds assessment from measures of performance through strategic outcomes.

Module 9: Critical Infrastructure and Cross-Domain Operations

Digital action can affect power, water, transport, communications, space services, logistics, and weapons. This module teaches IT/OT and satellite-system reasoning, safety, manual operations, and the integration of cyber effects with physical maneuver and the electromagnetic spectrum.

Module 10: Influence, Perception, and Public Truth

Cyber operations can acquire, alter, deny, and release information to shape behavior. This module examines hack-and-leak operations, false flags, DDoS theater, narrative laundering, synthetic media, and the defensive combination of forensics, communication, and public trust.

Module 11: Daily Defence in Competition and War

Wartime cyber defence is a sustained operating rhythm, not an emergency checklist. This module integrates mission assurance, threat intelligence, attack-surface reduction, hunting, incident command, evidence, continuity, recovery, partners, and learning.

Module 12: Deterrence, Emerging Change, and the Final Campaign

The final module moves from national and alliance strategy into the 2026 operating environment and then requires full synthesis. Learners assess deterrence and norms, examine AI and supply-chain change without hype, and complete a governed campaign capstone from requirement through lessons learned.