Cyber Operations Are Now a Core Part of Modern War, Says CrowdStrike Co-Founder
Dmitri Alperovitch argues that hacking campaigns no longer just support military conflicts, they signal them, shape them, and sometimes replace them.

Key points
- CrowdStrike co-founder Dmitri Alperovitch has argued publicly that cyber operations now function as a distinct battlefield alongside land, sea and air.
- Hacking campaigns can signal an impending armed conflict before the first shot is fired.
- His analysis, discussed in a SecurityWeek interview, covers how governments use offensive cyber tools to prepare for and extend conventional military action.
- No specific incident or regulation was announced; this is expert commentary on strategic reality.
What is Alperovitch actually saying?
His core claim is blunt: cyberattacks aren't a side-show to physical warfare. They're a stage of it, sometimes the opening act, sometimes the whole performance.
Alperovitch, who co-founded CrowdStrike and has advised the U.S. Government on national-security matters, describes cyber operations as "the fourth battlefield" alongside traditional combat on land, at sea and in the air. The phrase is increasingly common in defence policy circles, even if most countries haven't codified it in law.
How does hacking fit into real-world conflict?
Cyber operations serve governments in at least two ways before and during armed conflict.
First, intelligence. Breaking into an adversary's networks quietly before fighting begins gives a government visibility into the enemy's plans and communications. Second, degradation. Power grids and military communications can be disrupted by hacking without a single soldier crossing a border. Ukraine experienced this in 2015 and 2016 when attackers, later attributed to Russian military intelligence, cut electricity for hundreds of thousands of people.
That second threat is closer to home than it sounds. Our 23 July report on Iranian hackers targeting industrial control systems named the specific techniques used to break into the computers that run factories, water plants and power grids, exactly the category of infrastructure Alperovitch is talking about.
What does this mean for countries watching rivals?
Alperovitch's sharpest observation is that cyber activity can work as an early-warning signal. A surge in targeted intrusions against military and government networks often precedes overt aggression. Policymakers who treat such intrusions as routine crime may be misreading the situation entirely.
This analysis lands at a pointed moment for U.S. And European regulators. The Cyber Incident Reporting for Critical Infrastructure Act of 2022, known as CIRCIA (pronounced "sir-see-ah"), requires operators of essential services to report significant cyber incidents to the Cybersecurity and Infrastructure Security Agency (CISA). The proposed rule was published in April 2024; the comment period has closed and final rules are still in development. The EU's NIS2 Directive, which sets binding cybersecurity standards for critical-sector organisations across member states, came into force in January 2023, with national transposition required by October 2024. Neither framework was written with battlefield signalling in mind.
Common questions
Does this affect ordinary people, not just governments?
Yes, indirectly. Critical infrastructure sits on the front line of state-sponsored hacking. Disruptions governments absorb in wartime are the same disruptions that leave households without heating or patients without care.
Is there a law that governs all this?
There's no single global one. CIRCIA and NIS2 impose reporting and security requirements on private companies, but international rules for cyber conflict remain contested and largely unwritten. That gap is worth watching: the frameworks exist to collect incident data, yet whether governments will use that data to detect pre-conflict patterns remains an open question.



