Take a Product Tour Request a Demo Cybersecurity Assessment Contact Us

Blogs

The latest cybersecurity trends, best practices, security vulnerabilities, and more

Geopolitical Volatility and Infrastructure Resilience

While global attention focuses on the aftermath of the early 2026 campaigns in Iran, a far more strategic campaign is silently underway: The systematic targeting of the global economy's "physical backbone." Geopolitical adversaries are not simply seeking intelligence. They are actively prepositioning within critical systems to achieve quiet, long-term persistence in global communications, destabilize distributed operational technology (OT) assets, and deliberately fracture the global internet into isolated digital territories. In this new era of volatility and structural subversion, your most critical vulnerability is no longer a localized technical flaw, but the escalating risk of digital fragmentation and the physical disruption of global commerce.

This blog is a part of a three-part series. If you haven’t already, check out the first blog in this series, “The Collapse of Digital Trust: Abuse of Relationships” for more information.

Why this matters to you

The primary implication of this strategic shift is the immediate exposure of corporate assets to state-level strategic subversion. When geopolitical adversaries prioritize quiet persistence within critical communications and OT assets, traditional perimeter defense is rendered ineffective. For executive stakeholders, the "so what" is a clear mandate: Resilience must move from a compliance-based, static posture to a model of structural readiness. This new framework prioritizes technological diversification and the establishment of geopolitical playbooks to ensure business continuity amid digital fragmentation and the physical disruption of global commerce.

Salt Typhoon: The strategic subversion of global telecom

Background: Salt Typhoon, a Chinese state-backed group, accessed dozens of telecom providers in a multi-year espionage campaign that escalated in early 2026. In the U.S., the hackers targeted the communications of top political officials by accessing the government's lawful intercept systems used for court-ordered wiretapping.

Salt Typhoon is an advanced persistent threat (APT) believed to be operated by China's Ministry of State Security (MSS). This group is described as a component of China's "100-year strategy," focusing primarily on counterintelligence targets and the long-term exfiltration of strategic insights from "sensitive but unclassified" environments.

Strategic 'so what': Salt Typhoon prioritizes "quiet persistence" within the communications layer. The FBI assesses that this data is likely held in perpetuity for future theft and cyber exploitation. This is a massive counterintelligence risk that targets the very systems designed to protect the state.

Actionable Insight: Implement end-to-end encryption for sensitive corporate communications. Companies that engaged with federal agencies early were successful in mitigating the impact.

Poland’s energy sector: targeting the distributed grid

Background: In December 2025 and January 2026, coordinated attacks targeted more than 30 wind and solar farms and a large combined heat and power plant in Poland. Attributed to the state-linked group Sandworm (also tracked as ELECTRUM), the attacks used wiper malware to damage system firmware and disrupt communication between facilities and the grid operator.

This campaign is attributed to the Sandworm group (part of Russia's GRU) or to Berserk Bear (an FSB-linked unit), specifically the Static Tundra activity cluster. These actors are known for their "Phase Zero" strategy—prepositioning and sabotage to destabilize infrastructure and undermine regional cohesion.

Strategic 'so what': This marks a shift from Russia targeting centralized control to attacking the distributed edge of the grid. It is part of a Phase Zero campaign to destabilize infrastructure and undermine NATO cohesion. While production continued, the loss of remote control highlights the vulnerability of operational technology in a fragmented geopolitical climate.

Actionable insight: Mandate firmware verification for all industrial devices to prevent permanent hardware damage. Incident response plans must specifically account for inoperative OT devices to mitigate prolonged outages.

Russia’s messaging blockade (WhatsApp/Telegram)

Background: In February 2026, Russia moved to fully block WhatsApp and throttle Telegram to force citizens and businesses onto the state-controlled MAX app.

The Russian state's pursuit of digital sovereignty centers on the construction of a national splinternet designed to isolate its population and enhance state surveillance. Critically, this mandated infrastructure is fully integrated with state surveillance capabilities, exemplified by the compulsory use of the MAX application, effectively eliminating avenues for unmonitored communication and establishing a pervasive system of state control over its citizens’  digital lives.

Strategic 'so what': This signifies the end of private communications in the region and creates immediate business continuity risks for multinational corporations. It accelerates the fragmentation of the global internet into isolated digital territories. This initiative involves the systematic dismantling of secure international communication channels for over 100 million users, forcing them onto domestic digital infrastructure. 

Actionable insight: Develop geopolitical risk playbooks for digital fragmentation. Organizations must have redundant communication channels and technology diversification plans for regions where digital splinternets are emerging.

Beyond compliance: The mandate for continuous readiness

The 2026 threat landscape, catalyzed by geopolitical conflicts like those in Iran, has fundamentally redefined security. The convergence of three distinct, yet mutually reinforcing crises—the collapse of digital trust, the industrialization of AI-driven deception, and escalating geopolitical fragmentation—renders traditional perimeter and compliance-based defenses obsolete. Adversaries are leveraging autonomous, machine-speed capabilities to orchestrate campaigns that weaponize identities, bypass technical filters, and subvert critical infrastructure for quiet, long-term persistence.

The strategic "so what" is undeniable: Compliance is not security. A green checkmark on an audit will not stop a $25 million deepfake heist like the one at a built-environment engineering company, nor can it halt the self-directed, machine-speed autonomous espionage seen in the GTG-1002 campaign. The fundamental risk is now the complete breakdown of verification protocols.

To reclaim control, executive leadership must move decisively from static defense to a posture of continuous readiness. This requires operationalizing the four strategic pillars, shifting our focus entirely from blocking threats at the edge to validating every action at the core. Our survival hinges on embracing an identity-first future, where we stop trusting the login and start verifying the intent. The perimeter hasn't just moved; it has vanished. It’s time to log in to this new reality of structural resilience.

Operationalizing continuous readiness: The four strategic pillars

The case studies of GrayCharlie and ShinyHunters demonstrate a critical reality: Traditional, static security perimeters are obsolete. To mitigate these risks, the transition from a compliance-based mindset to a continuous readiness mindset is mandatory.

Identity-first defense (immediate mitigation)

Because adversaries now "log in" rather than "break in," the primary point of failure is the user’s identity.

The shift: Organizations must move beyond basic passwords and SMS-based MFA. These are easily bypassed by AI-driven vishing and proxy attacks.

Action: Deploy phishing-resistant MFA (FIDO2/WebAuthn) for all high-value roles. In a post-trust landscape, an executive’s identity is the most critical asset.  Its compromise creates a blast radius that impacts organizational reputation and market valuation.

Dynamic privilege management (just-in-time access)

Breaches of persistent admin grants highlight the danger of always-on admin access. A single stolen credential becomes a permanent key to the kingdom.

The shift: We must adopt a "just-in-time" (JIT) access model.

Action: Privileges should be granted only for the duration of a specific task and automatically revoked upon completion. This limits the temporal window of opportunity for any compromised identity.

Geopolitical resilience and governance (structural readiness)

Organizations must prepare for digital fragmentation, where sanctions or regional outages can cripple single-cloud dependencies.

The shift: Move from a single-vendor reliance to technological diversification.

Action: Implement geopolitical playbooks to establish escalation/de-escalation protocols for regional crises.

  • AI governance (ISO 42001): Treat AI systems not just as tools, but as privileged insider threats that require rigorous inventorying and monitoring.

Continuous behavioral intelligence (verification)

The "all green" problem observed in SaaS-based phishing (e.g., Atlassian Jira) proves that reputable traffic is no longer a reliable signal of safety.

The shift: Security must evolve from asking, "Is this a valid login?" And instead ask, "Is this user acting like themselves?"

Action: Implement behavioral biometrics to track cross-channel signals—such as keystroke dynamics, navigation rhythms, and transaction patterns. This adds a layer of "human logic" that AI-driven automated attacks cannot easily replicate.

In this new era of geopolitical volatility, your greatest vulnerability isn't a line of code—it’s the trust you place in your digital ecosystem.

1 https://www.cyber.nj.gov/Home/Components/News/News/1935/214
2 https://www.cisa.gov/news-events/alerts/2026/02/10/poland-energy-sector-cyber-incident-highlights-ot-and-ics-security-gaps

Discover the latest cybersecurity research from the Trellix Advanced Research Center.

Get the latest

Stay up to date with the latest cybersecurity trends, best practices, security vulnerabilities, and so much more.
Please enter a valid email address.

Zero spam. Unsubscribe at any time.