Cyber Operations Are Now a Core Part of Modern War, Says CrowdStrike Co-Founder
Dmitri Alperovitch argues that hacking campaigns no longer just support military conflicts, they signal them, shape them, and sometimes replace them.

Key points
- CrowdStrike co-founder Dmitri Alperovitch has publicly argued that cyber operations now function as a distinct battlefield alongside land, sea, and air.
- Alperovitch contends that hacking campaigns can signal an impending armed conflict before the first shot is fired.
- His analysis, discussed in a SecurityWeek interview, covers how governments use offensive cyber tools to prepare for and extend conventional military action.
- No specific incident or regulation was announced; this is expert commentary on an evolving strategic reality.
What is Alperovitch actually saying?
His core claim is simple: cyberattacks are no longer a side-show to physical warfare. They are a stage of it, sometimes the opening act, sometimes the whole performance.
Alperovitch, who co-founded the security firm CrowdStrike and has advised the U.S. government on national-security matters, describes cyber operations as "the fourth battlefield" alongside traditional combat on land, at sea, and in the air. The phrase reflects a view that is increasingly common in defence policy circles, even if it has not yet been codified in most countries' legal frameworks.
How does hacking fit into real-world conflict?
Cyber operations serve governments in at least two ways before and during armed conflict.
First, they gather intelligence. Breaking into an adversary's computer systems quietly, weeks or months before fighting begins, gives a government visibility into the enemy's plans, troop movements, and communications. Think of it as picking the lock on someone's filing cabinet without them knowing.
Second, they degrade infrastructure. Power grids, railway signalling systems, and military communications can all be disrupted by hacking, sometimes without a single soldier crossing a border. Ukraine experienced this directly in 2015 and 2016 when attackers, later attributed to Russian military intelligence, switched off electricity for hundreds of thousands of people.
What does this mean for countries watching rivals?
Alperovitch's most pointed observation is that cyber activity can work as an early-warning signal. A surge in targeted intrusions against a country's military and government networks often precedes overt aggression. Policymakers who treat such intrusions as routine crime, rather than as pre-conflict preparation, may be reading the situation wrong.
From a regulatory standpoint, this analysis lands at an interesting moment. In the United States, the Cyber Incident Reporting for Critical Infrastructure Act of 2022, commonly called CIRCIA (pronounced "sir-see-ah"), requires operators of essential services to report significant cyber incidents to the Cybersecurity and Infrastructure Security Agency, known as CISA. The final rules under CIRCIA are still in development, with the proposed rule published in April 2024 and a comment period now closed. How the government uses those mandatory reports to detect pre-conflict patterns is an open question.
The European Union's NIS2 Directive, which sets binding cybersecurity standards for critical-sector organisations across member states, came into force in January 2023, with member states required to transpose it into national law by October 2024. Neither framework was written with battlefield signalling explicitly in mind.
Common questions
Does this affect ordinary people, not just governments?
Yes, indirectly. Critical infrastructure, meaning power, water, hospitals, and transport, sits on the front line of state-sponsored hacking. Disruptions that governments absorb in wartime are the same disruptions that leave households without heating or patients without care.
Is there a law that governs all this?
Not a single global one. Individual countries have national cybersecurity laws, and frameworks like CIRCIA and NIS2 impose reporting and security requirements on private companies, but international rules for cyber conflict remain contested and largely unwritten.



