Entering the Cyber Battlespace
Digital Systems as Mission Terrain Evidence, Threat Intelligence, and Incident Response Authorization, Ethics, and Safe Practice What Cyberwarfare Is—and Is Not Cyberspace as an Operational Environment
The Road to Persistent Cyber Conflict
Estonia, Georgia, Stuxnet, and the First Shock Ukraine, 2015–2026: Campaigning Under Fire
Actors, Proxies, and Strategic Behavior
The State Cyber Ecosystem Strategic Cultures Without Stereotypes
Law, Authority, and Civilian Protection
Below Armed Conflict: Sovereignty, Intervention, Force, and Responsibility Armed Conflict: IHL and Cyber Effects
Intelligence, Indications, and Attribution
Intelligence Support to Cyber Operations Attribution Under Deception
Campaign Design and Command
From Policy Aim to Cyber Campaign Command, Authorities, and Deconfliction
Target Systems, Access, and Operational Security
Target-System Analysis and Cyber Key Terrain Access Stewardship, Capability Fit, and OPSEC
Effects Engineering and Campaign Assessment
Designing and Bounding Cyber Effects Measuring What the Campaign Changed
Critical Infrastructure and Cross-Domain Operations
Operational Technology, Safety, and Restoration Space, Telecommunications, and Multi-Domain Integration
Influence, Perception, and Public Truth
Cyber-Enabled Influence Operations Defending Truth, Trust, and Decision Space
Daily Defence in Competition and War
Mission Assurance and the Wartime Operations Floor Continuity, Recovery, and Collective Defence
Deterrence, Emerging Change, and the Final Campaign
Deterrence, Norms, and Collective Response The 2026 Horizon: AI, Supply Chains, Edge, and Identity Capstone: Build, Challenge, and Defend a Cyber Campaign
Deterrence, Emerging Change, and the Final Campaign

The 2026 Horizon: AI, Supply Chains, Edge, and Identity

Integrate the newest evidence into operations without mistaking novelty for strategic change.

About this learning content: Courses, lessons, assessments, explanations and illustrations may be created with the help of artificial intelligence. We review and check the material and do our best to avoid incorrect or outdated information, but mistakes, omissions or ambiguous questions may remain. Please verify information before relying on it for professional, security, legal or operational decisions. Read the full notice or report an issue.

In this lesson, you will learn to:

  • Produce a horizon assessment that separates observed change, extrapolation, uncertainty, and operational implication.

The 2026 Horizon: AI, Supply Chains, Edge, and Identity

This lesson updates the course through September 2026 using current frontline reporting, then converts trends into requirements, controls, exercises, and watch indicators.

Track acceleration and persistent fundamentals

Current evidence shows AI moving from occasional assistance toward scaled workflow integration. In May 2026, Google Threat Intelligence reported AI-assisted vulnerability discovery and exploitation activity and described broader operational augmentation. By September 2026, its reporting emphasized progression toward greater autonomy while still showing human-directed objectives and infrastructure. Treat these first-party findings as observations from one provider’s visibility, not a complete census.

The strategic implications are compressed discovery and decision cycles, cheaper multilingual influence, faster variation, and pressure on patch, validation, and intelligence workflows. Defenders also gain code review, triage, correlation, and simulation capacity. Require provenance, sandboxing, human release gates, evaluation against deception, protected data, and logs for consequential AI use.

Other fundamentals persist. M-Trends 2026 reported exploitation as the leading initial vector in its investigated intrusions, increased voice phishing, edge and native-function evasion, and very long dwell time for espionage and DPRK IT-worker cases. CISA’s 2025 Salt Typhoon advisory centers on routers and trusted network relationships. Identity, unmonitored infrastructure, and long-term access remain strategic terrain.

Watch supply chains and strategic technology

Cyberwarfare planning must track software supply-chain compromise because one trusted path can reach many targets. Google’s July 2026 guidance notes growth in attacks on open-source repositories after SolarWinds and 3CX. Map source, build, package, signing, distribution, identity, maintainer, dependency, and update trust. Maintain reproducible builds where practical, protected signing, dependency inventory, provenance, rapid revocation, and detection after trusted updates.

AI systems are also targets: model weights, research, data, prompts, agents, tools, and cloud capacity carry military and economic value. Google reported PRC-nexus targeting of AI research in 2026. Add AI assets to counterintelligence and supply-chain models rather than isolating them in an innovation program.

Maintain a horizon register with claim, source, observation period, confidence, potential mission impact, leading indicators, collection owner, and decision trigger. Avoid predicting that one technology “changes warfare” without a causal mechanism. Ask which constraint it relaxes, which dependency it creates, how an adversary adapts, and how evidence would show the change.

Resources