Public discussion often uses it more broadly, but no universally settled technical or legal boundary makes every state-linked intrusion, espionage campaign, disruptive incident, or destructive cyberattack an act of war.
Cyber operations in conflict can collect intelligence, disrupt communications or logistics, impair services, support physical operations, or affect connected civilian infrastructure. International humanitarian law (IHL) applies to cyber operations conducted in the context of armed conflict, but determining whether an operation triggers or forms part of such a conflict depends on facts, effects, circumstances, attribution, and decisions by competent authorities.
Key points
Operational contextAssess the cyber activity alongside military events, stated objectives, target function, timing, scale, effects, and dependencies rather than classifying it from malware or a target name alone.
Defensive prioritiesProtect essential and safety-related services, maintain resilient communications and recovery options, coordinate technical and executive decision-making, and account for cross-border or cascading effects.
Evidence and escalationPreserve technical findings with confidence levels and separate observed facts from intelligence assessments, state attribution, legal characterization, and policy response.
Important limitationSecurity teams can describe behavior and impact but cannot by themselves determine state responsibility, a use of force, an armed attack, or the existence of armed conflict. Those are fact-specific legal and governmental judgments.