When Russia launched its major invasion of Ukraine in February 2022, it was thought by many knowledgeable observers in the West that it would also be accompanied by significant use of offensive cyber operations. Supposedly, many Ukrainian activities in both the civilian and military spheres that relied on the cyber realm would be significantly compromised. This, however, turned out not to be the case. Ukraine was not subject to devastating cyber attacks either in the initial phase of the operation or subsequently. While the Russian side did, indeed, try and make considerable use of offensive cyber operations their efficacy could be described as no more than limited. But why was this? The established orthodoxy was that the Russian military and intelligence services were supposed to be very good at offensive cyber. They should have wreaked havoc. This article investigates why this cyber activity turned out to be so ineffectual. It also, though, seeks to contextualise this lack of effect: to set this Russian cyber ‘failure’ in a particular light. It concludes by pointing out that NATO cyber specialists should be wary of what lessons are truly to be learned from the experience of Russia’s offensive cyber activities during the Ukraine war.
Thornton et al. (Tue,) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: