Technology & Science

War doesn’t start with a shot, but with a malfunction

The chilling scenario unfolds on a seemingly ordinary Monday morning: container terminals in the port of Antwerp fall silent, a significant portion of the national payment infrastructure grinds to a halt, and hospitals across the nation are forced to revert to emergency protocols. There are no explosions, no armored divisions massing at the border, nor fighter jets streaking across the skies. Yet, Belgium finds itself under attack. This vivid, unsettling tableau, far from being the stuff of science fiction, represents the stark reality of modern conflict – a war waged not with kinetic force, but with meticulously orchestrated digital disruption.

This profound shift in the nature of warfare forms the bedrock of the compelling keynote address to be delivered by Major General (ret.) Pieter Cobelens at Cybersec Netherlands 2026, scheduled for September 9th and 10th at the Jaarbeurs in Utrecht. Cobelens, a seasoned expert with extensive experience in national security and intelligence, will underscore that cyberattacks on vital infrastructure, sophisticated disinformation campaigns, and digital sabotage have irrevocably become mainstays of geopolitical power projection. The pertinent question, he argues, is no longer whether such digital conflicts will occur, but rather the extent to which nations and organizations are adequately prepared to withstand and respond to them.

The New Battlefield: From Bullets to Bytes

Cobelens’s central thesis is unambiguous: cybersecurity has transcended its traditional confines as a mere IT department concern. It has metastasized into a multifaceted strategic imperative, inextricably linking technology, economics, national defense, and geopolitics. The digital infrastructure underpinning governments, corporations, and daily civilian life is now as critically important as the tangible networks of roads, seaports, and energy grids. This redefinition necessitates a radical overhaul of national security paradigms, moving beyond conventional military thinking to encompass the pervasive and often invisible threats of the cyber domain.

The Hypothetical Becomes Reality: The Belgian scenario Cobelens paints is not an isolated thought experiment. Real-world incidents have demonstrated the crippling potential of cyberattacks. The NotPetya attack in 2017, initially targeting Ukraine, rapidly spread globally, causing billions of dollars in damages to businesses including major shipping companies, illustrating how digital contagion respects no borders. Similarly, the Colonial Pipeline ransomware attack in the United States in 2021 underscored the fragility of critical energy infrastructure, leading to widespread fuel shortages and panic buying. These events serve as stark reminders that the consequences of digital disruption are profoundly real and can cascade through entire societies, impacting everything from economic stability to public safety and national morale.

A Strategic Imperative: For nations like the Netherlands and Belgium, which are among the most highly digitized economies globally, this vulnerability is particularly acute. Their advanced digital ecosystems, characterized by dense internet exchange points, hyperscale data centers, intricate logistical supply chains, sophisticated financial services, and pervasive cloud platforms, collectively form the digital bedrock of their economic prosperity. While this position confers substantial economic advantages, it simultaneously transforms them into attractive, high-value targets for state-sponsored actors, sophisticated cybercriminal syndicates, and other malevolent entities seeking to exploit digital vulnerabilities for espionage, sabotage, or financial gain.

Vulnerability in a Digitalized World

The paradox of advanced digitalization is that it breeds both immense opportunity and profound risk. The Netherlands, for instance, consistently ranks among the top European nations in various digital economy and society indices (DESI index), showcasing its robust digital infrastructure and high adoption rates of digital services. This digital prowess, while a boon for innovation and economic growth, also presents an expansive attack surface.

The Dutch and Belgian Paradox: According to reports from the European Union Agency for Cybersecurity (ENISA) and Europol, the Benelux region, with its critical logistics hubs like Rotterdam and Antwerp, and its role as a major data transit point, is a prime target for cyber-espionage and disruptive attacks. The sheer volume of data flowing through these nations, coupled with their interconnectedness to global supply chains and financial markets, makes them particularly susceptible to attacks designed to sow chaos or extract valuable intelligence.

Economic Backbone at Risk: The economic impact of successful cyberattacks is staggering. Global estimates from sources like Cybersecurity Ventures suggest that cybercrime costs could reach trillions of dollars annually by the mid-2020s. A single major incident affecting a port, a payment system, or a hospital can lead to direct financial losses, reputational damage, operational downtime, and long-term erosion of public trust. The interdependent nature of modern economies means that a disruption in one sector can quickly ripple through others, magnifying the overall damage. For instance, a cyberattack on a logistics provider could paralyze food supply chains, affecting supermarkets and consumers, while a breach in a cloud provider could simultaneously compromise hundreds of businesses relying on their services.

Evolving Threat Landscape: Lessons from Global Conflicts

The ongoing conflict in Ukraine has provided an unprecedented real-world laboratory for the evolving nature of hybrid warfare, where conventional military operations are seamlessly integrated with a relentless barrage of cyberattacks and sophisticated information warfare. The conflict has illuminated how quickly the traditional boundaries of warfare are blurring, and how novel tactics are being deployed with devastating effect.

The Ukrainian Cyber Front: Ukraine has endured a sustained campaign of cyberattacks targeting its energy grid, government networks, financial institutions, and telecommunications infrastructure, even predating the 2022 invasion. These attacks, often attributed to state-sponsored actors, have served as a crucible for understanding the resilience needed in the face of persistent, high-intensity cyber warfare. The ability of Ukrainian cyber defenders, supported by international partners, to largely withstand these assaults has become a critical case study in national cyber resilience.

Democratization of Attack Capabilities: Cobelens highlights a crucial parallel between the physical and digital domains. Just as relatively inexpensive drones have democratized military strike capabilities, allowing smaller actors to inflict significant damage, advanced attack techniques are becoming increasingly accessible in the cyber domain. The proliferation of sophisticated hacking tools on dark web marketplaces, the rise of ransomware-as-a-service models, and the increasing availability of open-source intelligence (OSINT) tools have lowered the barrier to entry for malicious actors. This democratization means that the threat is no longer solely the purview of highly resourced state actors but extends to smaller, agile groups with diverse motivations.

Supporting Data: Notable Cyber Incidents: The timeline of major cyber incidents underscores this evolution.

  • Stuxnet (2010): A highly sophisticated computer worm, widely believed to be a joint U.S.-Israeli effort, targeted Iran’s nuclear program. It demonstrated the capability of cyber weapons to cause physical damage to critical infrastructure.
  • Sony Pictures Entertainment Hack (2014): Attributed to North Korea, this attack showcased the disruptive potential of cyberattacks for geopolitical objectives, including data theft and operational sabotage, in retaliation for perceived slights.
  • NotPetya (2017): A destructive cyberattack that masqueraded as ransomware but was primarily designed to cause maximum damage. It crippled businesses worldwide, illustrating the global interconnectedness and cascading effects of cyber warfare.
  • SolarWinds (2020): A supply chain attack that compromised numerous U.S. government agencies and private companies, demonstrating the insidious nature of stealthy, long-term espionage campaigns.
  • Colonial Pipeline (2021): A ransomware attack that forced the shutdown of a major fuel pipeline in the U.S., leading to widespread shortages and highlighting the vulnerability of critical national infrastructure to even financially motivated cybercriminals.

These incidents, among countless others, paint a clear picture of an escalating and increasingly complex threat landscape.

The Artificial Intelligence Frontier

The advent of artificial intelligence (AI) is fundamentally reshaping the battleground in cyberspace, acting as a force multiplier for both attackers and defenders. Cobelens emphasizes that AI is not just another tool but a game-changer, altering the economics and dynamics of cyber conflict.

AI as an Attacker’s Ally: Generative AI, in particular, dramatically lowers the technical barrier for launching sophisticated attacks. Where attackers once required specialized expertise to craft convincing phishing campaigns or develop novel malware, AI can now automate large portions of this process. It can generate highly personalized and grammatically flawless phishing emails, create realistic deepfakes for disinformation campaigns, and even assist in developing polymorphic malware that evades traditional signature-based detection. This capability allows malicious actors to scale their attacks rapidly, making them more pervasive and difficult to detect. The lines between cyber warfare, information warfare, and psychological manipulation blur further, as AI-powered disinformation campaigns become increasingly persuasive and tailored.

AI as the Defender’s Shield: However, AI is not exclusively an attacker’s weapon. On the defensive front, AI is becoming an indispensable ally. Modern security platforms leverage AI and machine learning to analyze millions of events per second, identifying subtle anomalies and patterns that would remain invisible to human analysts. AI-powered intrusion detection systems can detect suspicious network traffic, behavioral analytics can flag unusual user activity, and automated threat intelligence platforms can correlate vast amounts of data to predict and preempt attacks. The consequence, according to Cobelens, is that cybersecurity is progressively becoming less a contest between human operators and more a strategic confrontation between competing algorithms.

The Unending Arms Race: This dynamic sets the stage for a permanent technological arms race. The coming years will witness a continuous cycle where AI develops new attack vectors and techniques, only for another AI to be deployed to detect and neutralize those very attacks. This constant innovation on both sides will demand continuous investment in advanced AI capabilities and a workforce skilled in managing these sophisticated defense systems.

Quantum Computing: The Looming Cryptographic Apocalypse

Beyond the immediate horizon, the next technological revolution looms: quantum computing. While quantum computers promise monumental breakthroughs in fields such as simulations, logistics optimization, material science, and defense, they simultaneously pose a direct and existential threat to the encryption protocols that underpin virtually all digital communication today.

Harvest Now, Decrypt Later: This leads to a strategic risk that remains largely underestimated by many organizations. State-sponsored actors, particularly those with long-term strategic ambitions, are already engaging in a practice known as "Harvest Now, Decrypt Later" (HNDL). They are actively collecting vast quantities of encrypted data today, not because they can decipher it with current computational power, but because they anticipate that future fault-tolerant quantum computers will possess the capability to break these contemporary encryption standards. This means that sensitive information deemed secure today could be rendered public and vulnerable in a decade or two. Organizations handling highly sensitive data, particularly those with long-term confidentiality requirements (e.g., government agencies, financial institutions, healthcare providers, defense contractors), must therefore transition to post-quantum cryptography (PQC) far sooner than initially anticipated.

The Race for Post-Quantum Cryptography: The urgency to develop and standardize PQC is palpable. Global efforts, spearheaded by institutions like the U.S. National Institute of Standards and Technology (NIST), are underway to identify and standardize new cryptographic algorithms that are resistant to attacks from quantum computers. This transition will be a monumental undertaking, requiring significant investment in research, development, and the widespread implementation of new cryptographic primitives across all digital systems. Experts predict that fault-tolerant quantum computers capable of breaking current encryption could emerge within 5 to 15 years, making the window for transitioning to PQC relatively narrow.

Digital Sovereignty: Reclaiming Control

Cobelens also critically examines the escalating dependency on foreign digital infrastructure, arguing that digital sovereignty is not about protectionism, but about control. When vital data, cloud platforms, and communication channels reside entirely outside a nation’s own jurisdiction, that nation inevitably surrenders a significant portion of its strategic autonomy.

Beyond Protectionism: Digital sovereignty implies a nation’s ability to govern its digital future, protect its citizens’ data, and maintain control over its critical digital assets and services. This includes ensuring data localization, exercising oversight over cloud service providers, securing digital supply chains, and developing national capabilities in key digital technologies. The discussion around national cloud initiatives or other forms of digital governance therefore extends far beyond the IT sector, touching upon national economy, governance, and national security.

National Cloud Initiatives and Geopolitical Stakes: The European Union, for instance, has recognized this imperative with initiatives like Gaia-X, which aims to create a secure, sovereign European data infrastructure based on common standards and values. Such initiatives are crucial for reducing strategic dependencies on non-EU tech giants and safeguarding sensitive data from foreign surveillance or manipulation. The geopolitical stakes are high: control over digital infrastructure translates directly into influence and power in the 21st century.

A Collective Defense: Shared Responsibility and Modern Deterrence

Perhaps the most crucial takeaway from Cobelens’s address is the realization that resilience against cyber threats is no longer the sole purview of national defense agencies. A significant portion of vital infrastructure – from energy grids and water supplies to transportation networks and financial systems – is owned and operated by private entities.

The Public-Private Nexus: An attack on a logistics service provider can disrupt the national food supply. A major outage at a cloud provider can simultaneously incapacitate hundreds of organizations. A cyber incident at a hospital can quickly escalate into a national crisis, impacting public health and safety. Therefore, digital resilience is a shared responsibility, demanding an unprecedented level of collaboration among government, the private sector, and civil society. This necessitates robust public-private partnerships, information sharing initiatives (like National Cyber Security Centres and Information Sharing and Analysis Centers, ISACs), and coordinated incident response plans.

Redefining Deterrence in the Cyber Age: This collective approach forms the very essence of modern deterrence. During the Cold War, deterrence revolved around the credible threat of military retaliation. In the digital era, however, credible deterrence is defined by a complex interplay of cyber capabilities, economic strength, technological innovation, and societal resilience. A potential adversary must be convinced that the costs of a cyberattack—in terms of potential retaliation, the target’s ability to quickly recover, and the international condemnation—will far outweigh any perceived benefits. Security experts and government officials increasingly emphasize the need for a multi-layered deterrence strategy that combines offensive cyber capabilities, robust defensive measures, international norms, and diplomatic pressure.

Policy and Legislative Frameworks: The European Union’s NIS2 Directive, for example, represents a significant step towards enhancing cybersecurity resilience across critical sectors by mandating stricter security requirements and incident reporting for a wider range of entities. National cybersecurity strategies are also being continuously updated to reflect the evolving threat landscape and promote a whole-of-society approach to cyber defense.

Implications for Society and Economy

The implications of the digital battlefield extend far beyond technical challenges, touching every facet of society and the economy.

Economic Disruption and Supply Chain Vulnerabilities: The interconnectedness of global supply chains means that a cyberattack on a single node can have ripple effects across continents, leading to production halts, delivery delays, and significant financial losses. This amplifies the need for robust supply chain cybersecurity.

Erosion of Trust and Societal Impact: Successful cyberattacks can erode public trust in institutions, governments, and digital services. Disinformation campaigns, especially when amplified by AI, can destabilize democratic processes, sow discord, and undermine social cohesion. The impact on public services, particularly healthcare, can be devastating, directly affecting citizens’ well-being.

Geopolitical Stability and Escalation Risks: Cyberattacks, especially those conducted by state actors, introduce new vectors for international tension and potential escalation. The attribution challenges inherent in cyber warfare can complicate diplomatic responses and increase the risk of miscalculation, potentially leading to broader conflicts.

Conclusion: The War Has Already Begun

Pieter Cobelens’s strategic perspective on cybersecurity will serve as the guiding principle for his keynote, which opens the second day of Cybersec Netherlands 2026. His aim is not merely to outline a potential future scenario but to unequivocally declare that the digital war has already commenced. In this new era of pervasive digital conflict, investing in robust resilience, fostered through unprecedented collaboration between government, industry, and civil society, is perhaps the most critical form of defense any nation can organize today. The battle for digital security is a continuous engagement, demanding constant vigilance, adaptation, and a proactive, unified front.

Visit Cybersec Netherlands 2026

Discover the latest developments in cybersecurity during Cybersec Netherlands on 9 and 10 September 2026 at Jaarbeurs Utrecht. Be inspired by experts, practical case studies, and innovative solutions designed to bolster digital resilience in an increasingly volatile world.

Register for free

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button