Center for Cyber Diplomacy and International Security

The Digital Second Front: Iran, Critical Infrastructure, and the Cyber Risks of Military Escalation

Published by

on

collective ai art by Vladimir Tsakanyan

Reports of Iranian-linked attempts against U.S. water, energy and telecommunications systems show how quickly conventional confrontation can acquire a cyber dimension. The immediate attacks may be limited, but the strategic implications are considerably larger.

By Vladimir Tsakanyan, Ph.D.
Center for Cyber Diplomacy and International Security (CCD-IS)

War no longer expands only geographically.

It expands digitally.

As military confrontation between the United States and Iran intensified again this week, reports emerged that Iranian-linked hackers had been attempting to access American critical infrastructure, including water, energy and telecommunications systems.

The reported cyber operations have so far been unsuccessful and appear, according to available reporting, to have concentrated on relatively accessible internet-connected systems rather than sophisticated attacks capable of producing large-scale physical disruption.

That distinction matters.

There is currently no public evidence that these attempts caused major disruption to American critical infrastructure.

But focusing only on whether the attacks succeeded risks missing the more important strategic development.

Cyber operations are becoming part of the escalation environment surrounding the U.S.–Iran confrontation.

That changes the problem.

The question is no longer simply whether Iranian cyber actors can turn off an American power grid or contaminate a water system.

It is whether cyberspace is becoming a second front through which states and affiliated actors can signal, retaliate and impose costs while attempting to remain below thresholds that might trigger a substantially larger military response.

Cyber Operations Between Peace and War

Cyber operations occupy an unusual position in international conflict.

A missile launch is difficult to misunderstand.

A cyber intrusion is different.

An actor can scan infrastructure without disrupting it.

It can obtain access without immediately using that access.

It can steal information.

It can manipulate a small industrial device.

It can temporarily disrupt a service.

Or it can prepare capabilities that may become useful during a future crisis.

These activities exist across a spectrum of severity.

That ambiguity makes cyberspace particularly attractive during periods of geopolitical confrontation.

A government or affiliated actor may seek to demonstrate capability without conducting an attack serious enough to produce an uncontrollable response.

Cyber operations can therefore function as instruments of coercion and signaling.

They can communicate:

We can reach your infrastructure.

We understand where your vulnerabilities are.

And escalation could carry consequences beyond the battlefield.

Whether the current Iranian-linked activity represents centrally directed state operations, affiliated actors, opportunistic hackers or some combination remains important to establish.

But the strategic logic exists regardless.

Once conventional military confrontation intensifies, cyber activity surrounding critical infrastructure becomes part of the broader escalation environment.

Why Water Systems Matter

Water infrastructure is an especially revealing target.

Municipal water systems are not strategically important because they represent sophisticated technological environments.

Often the opposite is true.

Many operate with limited cybersecurity personnel, aging industrial equipment and operational technology that was designed primarily for reliability rather than exposure to hostile internet activity.

Some systems use relatively simple remote-management interfaces.

Others depend on equipment that cannot easily be patched or replaced without disrupting essential services.

That creates an asymmetry.

A cyber actor does not necessarily need extraordinary technical capability to create concern.

Even an unsuccessful intrusion against a water facility can generate public attention because the potential consequences involve an essential civilian service.

This gives water infrastructure unusual symbolic value.

A small technical operation can produce a disproportionately large psychological effect.

That may help explain why water systems repeatedly appear in politically motivated cyber campaigns.

The objective does not always have to be catastrophic disruption.

Sometimes demonstrating vulnerability is itself useful.

The Internet-Connected Industrial Problem

The current reporting also highlights a longstanding weakness in critical-infrastructure security: operational systems that remain directly or indirectly reachable from the public internet.

Industrial-control technology was historically designed for environments where physical isolation provided part of the security model.

Digital transformation changed that assumption.

Remote monitoring improved efficiency.

Internet connectivity reduced maintenance costs.

Cloud platforms improved visibility.

Remote administration made distributed infrastructure easier to operate.

But connectivity also created new pathways into systems that were never originally designed to face continuous hostile scanning.

This creates an uncomfortable reality.

Some of the infrastructure relevant to national security can potentially be reached using the same internet available to everyone else.

That does not mean compromising an internet-connected device automatically provides control over an entire industrial facility.

Modern infrastructure contains multiple layers of technology and protection.

But every unnecessary exposed interface expands the opportunity available to an adversary.

During peacetime, that is a cybersecurity problem.

During military confrontation, it becomes a national-security problem.

Iran’s Cyber Strategy Does Not Require Strategic Parity

Iran does not need cyber capabilities equivalent to those of the United States to make cyberspace strategically useful.

This is one of the fundamental asymmetries of cyber conflict.

Military power traditionally depends heavily on expensive capabilities: aircraft, ships, missiles, logistics networks, satellites and large defense-industrial systems.

Cyber capability operates differently.

A comparatively small group can conduct reconnaissance against thousands of systems.

An attacker can exploit poorly secured infrastructure without possessing technological superiority over the target state.

Commercial infrastructure can provide hosting.

Compromised devices can conceal activity.

Publicly available tools can perform significant portions of an operation.

Artificial intelligence may increasingly reduce the time required for reconnaissance and technical analysis.

The weaker actor therefore does not need to dominate cyberspace.

It needs to find weaknesses.

That makes cyber operations attractive to states confronting militarily superior adversaries.

Cyber capability becomes one instrument in a broader asymmetric strategy.

The Attribution Problem Becomes an Escalation Problem

The greatest danger may not be technical.

It may be political.

Cyber attribution is rarely instantaneous.

Infrastructure can be routed through multiple countries.

Actors can imitate other groups.

State agencies can work through contractors or loosely aligned organizations.

Hacktivists can act independently while claiming political affiliation.

Governments can deny involvement.

This creates uncertainty precisely when policymakers may be under pressure to respond quickly.

Consider the escalation problem.

A water facility experiences a serious cyber incident during an active military confrontation.

Investigators identify infrastructure previously associated with an Iranian-linked group.

Public speculation immediately attributes the attack to Iran.

Political pressure builds for retaliation.

But technical attribution may still be incomplete.

Was the operation directed by the Iranian government?

Was it conducted by an affiliated organization?

Was it an independent actor sympathetic to Iran?

Was the infrastructure reused by someone else?

Or was the apparent attribution intentionally manipulated?

These distinctions matter enormously when cyber activity intersects with military conflict.

A mistaken attribution is no longer merely an intelligence failure.

It can become an escalation mechanism.

Critical Infrastructure Creates a Civilian Threshold Problem

There is another difficult issue.

Most critical infrastructure is civilian infrastructure.

Water.

Electricity.

Telecommunications.

Healthcare.

Transportation.

Financial services.

Cyber operations against these systems therefore raise questions extending beyond cybersecurity.

International law applies to state conduct in cyberspace, but translating established principles into specific cyber incidents remains difficult, particularly when effects are limited or temporary.

What level of cyber disruption constitutes a prohibited intervention?

When does a cyber operation amount to a use of force?

How should states evaluate operations that create no physical destruction but substantially disrupt essential civilian services?

What obligations exist when state-linked actors operate through proxies?

And how should proportionality be assessed when responding to a cyber operation whose effects are uncertain?

These questions are no longer academic.

The more cyber operations become integrated into geopolitical confrontation, the more frequently governments will face them under real operational pressure.

The Difference Between Access and Attack

Policymakers should also resist collapsing all malicious cyber activity into the word “attack.”

Scanning infrastructure is not equivalent to compromising it.

Compromise is not equivalent to disruption.

Disruption is not necessarily equivalent to physical destruction.

And obtaining access does not prove an intention to use it.

These distinctions are essential for credible cyber diplomacy.

Exaggerating unsuccessful intrusion attempts can unintentionally increase escalation pressure.

Understating them can create complacency.

The appropriate response requires precision.

Based on currently available reporting, the recent activity should be understood as attempted targeting of critical infrastructure rather than evidence of a successful strategic cyberattack against the United States.

That still matters.

Reconnaissance and attempted access can reveal intent, preparation or interest.

But responsible analysis must distinguish capability from consequence.

Cyber Signaling Is Difficult to Control

Traditional military signaling relies on practices developed over decades.

States understand, imperfectly, what troop movements, military exercises, missile tests and deployments may communicate.

Cyber signaling is much less mature.

A state may intend a limited intrusion as a warning.

The target may interpret it as preparation for destructive attack.

An actor may compromise infrastructure only to collect intelligence.

The victim may assume sabotage is imminent.

A cyber operation designed to remain below the threshold of armed conflict can therefore generate precisely the escalation it was intended to avoid.

This is one reason confidence-building measures remain important in cyber diplomacy.

Communication channels between governments matter.

Incident-response contacts matter.

Clear public attribution standards matter.

And states need mechanisms for communicating when cyber activity risks crossing unacceptable boundaries.

Without those mechanisms, ambiguity can become dangerous.

The AI Multiplier

Artificial intelligence adds another variable.

AI does not automatically transform relatively unsophisticated actors into elite cyber operators.

But it can reduce friction.

It can help analyze technical documentation.

It can generate or modify scripts.

It can assist reconnaissance.

It can explain unfamiliar software.

It can accelerate vulnerability research.

It can help translate technical information across languages.

The strategic consequence is not necessarily that AI creates entirely new cyber weapons.

It may increase the number of actors capable of performing existing cyber tasks more efficiently.

For critical infrastructure operators, that means security assumptions based on the historical scarcity of sophisticated attackers may become increasingly unreliable.

The cost of probing infrastructure is falling.

The cost of leaving unnecessary exposure online therefore rises.

The United States Faces a Distributed Defense Problem

The United States possesses extraordinary cyber capabilities.

But protecting American critical infrastructure is fundamentally different from defending a military network.

Thousands of organizations operate essential services.

They vary enormously in resources and technical maturity.

A major energy company may employ sophisticated security teams.

A small municipal water utility may have only a handful of technical employees responsible for everything from networking to operational equipment.

Both provide essential services.

An adversary naturally looks for the easier target.

National cyber defense therefore cannot be measured solely by the capability of federal agencies or major corporations.

It is constrained by the security of thousands of smaller infrastructure operators.

This is the distributed-defense problem.

The national attack surface extends far beyond Washington.

Cyber Diplomacy Must Operate During Conflict, Not Only Before It

Much of international cyber diplomacy has concentrated on establishing norms for responsible state behavior during peacetime.

Those norms remain essential.

But today’s environment demonstrates why diplomacy must also address cyber activity during active geopolitical crises.

Governments need clearer expectations around civilian critical infrastructure.

They need reliable communication channels for serious cyber incidents.

They need mechanisms for rapidly sharing technical evidence with allies.

They need procedures for distinguishing state-directed operations from independent activity.

And they need response frameworks that preserve the possibility of imposing consequences without automatically creating pressure for military escalation.

The purpose of cyber diplomacy is not to eliminate strategic competition.

That is unrealistic.

Its purpose is partly to prevent competition from becoming uncontrolled escalation.

The U.S.–Iran confrontation provides exactly the type of environment in which those mechanisms are tested.

The Most Dangerous Attack May Be the One That Almost Works

The current reported attempts have apparently produced no major disruption.

That should be reassuring.

It should not be interpreted as evidence that the underlying risk is insignificant.

Unsuccessful operations reveal information.

Attackers learn which systems respond.

They identify technologies.

They discover authentication mechanisms.

They understand network architecture.

They determine which techniques fail.

Defenders should therefore treat attempted intrusions as intelligence about adversary interest.

The absence of immediate damage creates an opportunity.

Exposed systems can be removed from the internet.

Credentials can be changed.

Remote access can be restricted.

Networks can be segmented.

Logging can be improved.

Incident-response procedures can be tested.

The strategic objective should be to convert adversary reconnaissance into defensive urgency.

Bottom Line Assessment

The reported Iranian-linked targeting of American water, energy and telecommunications infrastructure does not currently appear to represent a successful strategic cyberattack.

Its significance lies elsewhere.

It demonstrates how quickly cyberspace can become integrated into conventional geopolitical confrontation.

Military escalation creates incentives for cyber retaliation.

Critical infrastructure provides politically sensitive targets.

Internet-connected industrial systems provide opportunities.

Attribution creates uncertainty.

And uncertainty creates escalation risk.

This is the emerging reality of hybrid conflict.

The physical and digital theaters are not separate.

A missile strike can change cyber threat levels thousands of miles away.

A cyber intrusion against a municipal utility can acquire geopolitical significance because of events occurring on another continent.

The most important lesson is therefore not that cyberwar has suddenly begun.

Cyber operations have accompanied international conflict for years.

The lesson is that the boundary between cyber competition and military confrontation is becoming increasingly thin.

Managing that boundary will require technical resilience.

But it will also require something cybersecurity alone cannot provide:

diplomacy.

Vladimir Tsakanyan, Ph.D.
Center for Cyber Diplomacy and International Security (CCD-IS)


Discover more from Center for Cyber Diplomacy and International Security

Subscribe to get the latest posts sent to your email.

Leave a comment

Discover more from Center for Cyber Diplomacy and International Security

Subscribe now to keep reading and get access to the full archive.

Continue reading