Recent years have witnessed a significant increase in the scale and sophistication of global cyberattacks, highlighting the urgent need for clearly defined norms of responsible behaviour among nation-states in cyberspace. Traditionally, governments have dominated discussions on international cyber norms; however, the prominence of private sector involvement during wartime necessitates re-evaluation of conventional state-centric frameworks. Using the Russia–Ukraine conflict as a pivotal case study, this paper examines the increasingly integral role that private companies play in the strategic and operational dimensions of contemporary warfare. Through an analysis of documented instances from the Russia–Ukraine war, the paper examines how private sector entities have transcended traditional support roles by actively engaging in critical cyber security activities. These include protecting critical infrastructures, conducting independent attribution of cyber incidents and influencing public perceptions through strategic disclosures. The paper further identifies and analyses ambiguities and tensions arising from the sometimes blurred boundaries between public and private sector responsibilities, highlighting gaps in existing international norms and policy frameworks. As the private sector takes on a growing role in cyber operations during conflict and war, this paper examines potential future conflicts — particularly the escalating tensions between China and Taiwan — providing insights that will benefit policy makers, cyber security practitioners and academics alike. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Peer et al. (Wed,) studied this question.