Entering the Cyber Battlespace
Digital Systems as Mission Terrain Evidence, Threat Intelligence, and Incident Response Authorization, Ethics, and Safe Practice What Cyberwarfare Is—and Is Not Cyberspace as an Operational Environment
The Road to Persistent Cyber Conflict
Estonia, Georgia, Stuxnet, and the First Shock Ukraine, 2015–2026: Campaigning Under Fire
Actors, Proxies, and Strategic Behavior
The State Cyber Ecosystem Strategic Cultures Without Stereotypes
Law, Authority, and Civilian Protection
Below Armed Conflict: Sovereignty, Intervention, Force, and Responsibility Armed Conflict: IHL and Cyber Effects
Intelligence, Indications, and Attribution
Intelligence Support to Cyber Operations Attribution Under Deception
Campaign Design and Command
From Policy Aim to Cyber Campaign Command, Authorities, and Deconfliction
Target Systems, Access, and Operational Security
Target-System Analysis and Cyber Key Terrain Access Stewardship, Capability Fit, and OPSEC
Effects Engineering and Campaign Assessment
Designing and Bounding Cyber Effects Measuring What the Campaign Changed
Critical Infrastructure and Cross-Domain Operations
Operational Technology, Safety, and Restoration Space, Telecommunications, and Multi-Domain Integration
Influence, Perception, and Public Truth
Cyber-Enabled Influence Operations Defending Truth, Trust, and Decision Space
Daily Defence in Competition and War
Mission Assurance and the Wartime Operations Floor Continuity, Recovery, and Collective Defence
Deterrence, Emerging Change, and the Final Campaign
Deterrence, Norms, and Collective Response The 2026 Horizon: AI, Supply Chains, Edge, and Identity Capstone: Build, Challenge, and Defend a Cyber Campaign
Deterrence, Emerging Change, and the Final Campaign

Capstone: Build, Challenge, and Defend a Cyber Campaign

Synthesize strategy, intelligence, law, targeting, access, effects, command, defence, assessment, and communication.

About this learning content: Courses, lessons, assessments, explanations and illustrations may be created with the help of artificial intelligence. We review and check the material and do our best to avoid incorrect or outdated information, but mistakes, omissions or ambiguous questions may remain. Please verify information before relying on it for professional, security, legal or operational decisions. Read the full notice or report an issue.

In this lesson, you will learn to:

  • Deliver and defend a complete campaign package with evidence, alternatives, approvals, safeguards, measures, and branches.
  • Demonstrate how the defensive plan changes the offensive theory and vice versa.

Capstone: Build, Challenge, and Defend a Cyber Campaign

The final lesson is a tabletop campaign laboratory. Learners produce a professional package for a fictional crisis, challenge it from adversary, civilian, partner, and defender perspectives, and revise it before a decision brief.

Scenario and required campaign package

The fictional state of Orinth is coercing neighboring Beloria while positioning forces near a disputed corridor. Intelligence indicates long-term access to regional telecom providers, phishing against logistics firms, reconnaissance of electric distribution, and prepared influence personas. Attribution to an Orinth military-intelligence ecosystem is moderate confidence; evidence of an approved destructive decision is low confidence. Civilian networks, allied traffic, hospitals, and commercial satellite service share dependencies.

Your authorized planning team must support Belorian resilience and develop proportionate cyber options. No live target, exploit, malware, credential, or real infrastructure may be used. Produce:

  1. policy aim, decision deadline, constraints, and completion criteria;
  2. actor ecosystem and three competing intent hypotheses;
  3. prioritized intelligence requirements and collection matrix;
  4. five-layer mission and target-system maps with civilian and partner co-use;
  5. three courses of action, including a defence-led option and a non-cyber alternative;
  6. legal-issues list, authority map, IHL analysis if armed conflict begins, and counsel questions;
  7. access-stewardship, capability-validation, OPSEC, deconfliction, and abort plan;
  8. effects estimate with best, expected, and worst cases;
  9. defensive hunt, continuity, communications, and collective-support plan;
  10. measures of performance, effectiveness, strategic outcome, unintended effects, and review cadence.

Make every claim traceable. State what is unknown and what would change the choice. The package should let a decision-maker select, modify, defer, or reject action.

Challenge cells and decision injects

Assign independent challenge cells to test the cyber campaign from adversary, civilian, partner, defensive, and legal-policy perspectives. The adversary cell adapts, deceives, reroutes, retaliates, and exploits publicity. The civilian-protection cell maps essential services, vulnerable groups, shared data, and reverberating effects. The partner cell applies caveats, competing intelligence equities, jurisdiction, and communication needs. The defence cell hunts access, changes architecture, restores services, and decides what to reveal. The red legal-policy cell challenges authority, thresholds, proportionality, and escalation.

Inject changes: the suspected telecom access appears on a neutral provider; a hospital begins using the same identity service; a vendor plans an emergency patch; an allied collector depends on the access; a forged leak alleges Belorian escalation; armed conflict begins; execution telemetry becomes incomplete; service degradation crosses a civilian threshold; and the adversary shifts to manual military communications.

At each inject, record decision, owner, authority, evidence, dissent, and effect on the theory of success. Reward teams for stopping or changing an operation when assumptions fail. A responsible operator protects the mission by refusing an obsolete plan.

Final brief, evaluation, and continuing practice

Deliver a ten-minute decision brief: situation, key judgments and confidence, objective, options, recommended course, legal and civilian safeguards, partner position, expected effects, worst case, abort conditions, defensive posture, assessment, and immediate decision. Provide the evidence annex and dissent.

Evaluate six dimensions:

Dimension Completion standard
Strategic coherence Actions have a credible, challenged link to policy behavior.
Evidence Material claims are sourced, dated, bounded, and open to revision.
Operational quality Access, timing, capability, OPSEC, command, and alternatives are realistic.
Law and protection Authorities, uncertainty, civilian harm, precautions, and abort rules shape design.
Defence and partnership Continuity, hunting, communication, and partner equities are integrated.
Assessment Baselines and measures can distinguish execution from outcome and harm.

Complete the journey by writing a personal operating doctrine: how you will define the mission, protect evidence, challenge assumptions, include counsel and engineers, safeguard civilians, preserve options, communicate uncertainty, and learn after action. Revisit it after exercises and incidents. Cyberwarfare competence is not possession of a clever technique. It is disciplined integration under pressure.

Resources

  • Course Source and Case Review Set — Revisit the UN, NATO, ICRC, DoD, UK NCF, CISA, DOJ, CCDCOE, ENISA, Microsoft, and Google sources linked throughout the course; distinguish primary facts, official claims, and analytic assessments in the capstone.