With cybercrime costs projected to exceed $10 trillion and state-backed attacks targeting critical infrastructure worldwide, cyberspace is no longer a technical domain; it is the frontline of modern geopolitical conflict.
No missiles were launched, no troops crossed a border either, yet within hours a nation’s critical systems began to fail. National structures began to collapse; fuel pipelines stopped moving, hospital networks slowed under pressure, government communications became unstable. The disruption was silent, precise, and easy to deny. It was a cyberattack. In May 2021, a cyberattack forced the shutdown of Colonial Pipeline, the largest fuel pipeline in the United States. This is now the reality of modern conflict.
Across the world, governments are confronting a shift in how power is exercised. It is no longer defined only by military strength or economic size, but by control over networks, data, and digital infrastructure. In recent years, attacks on energy systems, financial institutions, and public services have demonstrated that cyber operations can produce real economic and social disruption without a single shot being fired.

The scale of this threat is measurable. Global cybercrime costs are projected to exceed $10 trillion annually, according to Cybersecurity Ventures. If measured as an economy, that figure would rank behind only the United States and China, making cybercrime the third largest economic force in the world. At the same time, the World Economic Forum reports that a clear majority of organizations have experienced an increase in cyber risk, reflecting a steady rise in both the frequency and sophistication of attacks.
What makes this domain uniquely dangerous is the difficulty of attribution. Cyber operations can be launched remotely, routed through multiple jurisdictions, and concealed behind layers of anonymity. This allows states and affiliated groups to weaken rivals, extract intelligence, and disrupt essential services while avoiding direct military confrontation.
The result is a form of conflict that is continuous, global, and largely invisible to the public. Its consequences, however, are immediate and increasingly difficult to contain.
Why The Shift in Warfare?
This paradigm shift is driven in part by economics, just like everything in modern life. Traditional military operations are expensive, logistically complex, and politically risky. Cyber operations, by contrast, require far fewer resources but can deliver outsized impact. A small team with advanced technical capability can disrupt national infrastructure, compromise sensitive data, or interfere with economic activity. This imbalance has lowered the barrier to entry, allowing not only major powers but also smaller states and organized groups to participate in strategic competition.

Evidence of this transformation is already visible in state behavior. First uncovered in 2010, the Stuxnet operation, widely attributed to the United States and Israel, demonstrated that malicious code could physically damage critical infrastructure by targeting Iran’s nuclear program. More recently, cyber operations have been integrated into active conflict. During the war in Ukraine, cyberattacks have accompanied military actions, targeting government networks, financial systems, and communication channels.
While governments and corporations are pouring billions into cybersecurity, the economics of cyber conflict look very different at the operational level. Individual cyber operations remain significantly cheaper than traditional military action. The Stuxnet attack, one of the most sophisticated cyber operations ever conducted, is estimated to have cost roughly 10 million dollars to develop. By comparison, conventional military campaigns can cost billions within days. In the early stages of the 2026 conflict with Iran, for example, United States operations were estimated at nearly $1 billion per day.
At the same time, cyberspace enables a form of engagement that sits below the threshold of war. States can conduct espionage, disrupt services, or probe defenses without triggering a formal military response. This constant, low-level activity reflects what analysts describe as persistent engagement, where competition is ongoing rather than episodic. According to strategic assessments from organizations such as NATO, cyberspace is now recognized alongside land, sea, air, and space as a domain of operations, reinforcing its central role in modern defense planning.

Cyber Power and Global Rivalries
Much like nuclear weapons during the Cold War, cyber operations now shape how states compete, deter adversaries, and project influence beyond their borders. The difference is that cyber power is less visible, more ambiguous, and far more frequently used.
At the center of this competition are major powers such as the United States, China, and Russia, each pursuing distinct cyber strategies aligned with their broader geopolitical objectives. The United States has emphasized persistent engagement, aiming to disrupt threats before they materialize. China has focused heavily on cyber espionage, particularly targeting intellectual property and strategic industries to accelerate economic and technological advancement. Russia, meanwhile, has demonstrated a willingness to use cyber operations for disruption and political influence, as seen in its interference in the 2016 United States presidential election.
United States intelligence agencies have repeatedly attributed large-scale cyber espionage campaigns to Chinese state-linked actors, including the breach of the Office of Personnel Management in 2015, which exposed sensitive data of more than 20 million individuals. Russian-linked groups have been connected to operations ranging from election interference to disruptive attacks such as the NotPetya malware in 2017, which caused an estimated $10 billion in global damages, according to assessments by the White House and private sector analysts.
At the same time, cyber power is not limited to the world’s largest economies. Smaller states and even non-state actors can exert disproportionate influence by exploiting vulnerabilities in more advanced systems. North Korea, for example, has been linked to cyber operations that generate revenue through illicit means and target financial institutions globally, demonstrating how cyber capabilities can offset conventional military limitations.
The result is a more crowded and volatile strategic environment. Power is diffused, competition is constant, and the barriers that once separated major powers from smaller actors are steadily eroding.
The Civilian Battlefield
The front lines of cyber conflict are not confined to military systems or government networks. Increasingly, they run through the infrastructure that sustains everyday life. Power grids, hospitals, transportation systems, financial networks, and water facilities have all become targets, turning civilian spaces into active zones of strategic competition.
In 2021, a ransomware attack on Colonial Pipeline, one of the largest fuel pipelines in the United States, forced operations to shut down, disrupting fuel supplies across the East Coast. The company paid approximately $4.4 million to regain access to its systems, according to the Federal Bureau of Investigation. The incident exposed how a single cyberattack could ripple through an economy, affecting supply chains, prices, and public confidence.
Healthcare systems have proven equally vulnerable. During the COVID-19 pandemic, hospitals around the world faced a surge in ransomware attacks, with the World Health Organization warning of increased targeting of critical medical infrastructure. In some cases, these attacks delayed patient care and disrupted essential services, highlighting the real-world consequences of cyber operations beyond data loss or financial theft.
Energy infrastructure remains a particularly high-risk domain. In 2015 and again in 2016, cyberattacks on Ukraine’s power grid caused widespread outages, leaving hundreds of thousands without electricity. These incidents marked the first confirmed cases of cyber operations directly disrupting a national power supply, demonstrating that critical infrastructure can be both a target and a weapon in geopolitical conflict.
The economic costs are substantial, but the societal impact runs deeper. Disruptions to essential services erode trust in institutions and create a sense of insecurity among populations. According to the World Economic Forum, large-scale cyberattacks on critical infrastructure rank among the most significant global risks in terms of both likelihood and impact. This convergence of economic damage and social disruption makes cyberattacks uniquely suited to modern strategic objectives. Cyber conflict is no longer limited to disabling systems or stealing data. It increasingly targets something less tangible but equally critical: public perception. In this domain, the objective is not to shut down infrastructure, but to shape how societies think, vote, and respond to events.
This shift has been demonstrated most clearly in election interference campaigns. In 2016, United States intelligence agencies concluded that Russian state-linked actors conducted a coordinated effort to influence the presidential election. The operation combined hacking, through the breach and release of political emails, with large-scale disinformation campaigns across social media platforms. According to the United States Senate Intelligence Committee, these efforts reached tens of millions of voters, amplifying political divisions and undermining trust in democratic institutions.
The scale and sophistication of such operations have grown. Social media platforms have become central battlegrounds, where false narratives can be rapidly produced, targeted, and amplified. Investigations by companies such as Meta and Twitter have repeatedly uncovered networks of coordinated inauthentic behavior linked to state actors, including campaigns originating from China, Iran, and Russia. These campaigns often blend truth with falsehood, making them more difficult to detect and counter.
What distinguishes information warfare from traditional propaganda is its precision and speed. Digital platforms allow actors to micro target specific audiences, tailoring messages based on demographics, interests, and political beliefs. This level of targeting was not possible in earlier eras of mass communication. According to data from the Oxford Internet Institute, organized social media manipulation campaigns have been identified in more than 80 countries, reflecting the global scale of this phenomenon.
As a result, the battlefield has expanded beyond infrastructure into the realm of cognition. Power is exercised not only through the ability to disrupt systems, but through the ability to influence what people believe to be true. In an interconnected world, controlling the narrative can be as consequential as controlling territory.
What emerges is a battlefield without clear boundaries. Civilians are no longer distant from conflict; they are directly exposed to it through the systems they rely on daily. In this environment, the distinction between national security and public safety begins to collapse, as protecting infrastructure becomes synonymous with protecting society itself.
The Deterrence Problem, Non-State Actors, and the Global Governance Gap
Cyber conflict is harder to control than traditional warfare because the rules are unclear and the players are difficult to identify. In the nuclear era, deterrence relied on certainty. Countries know who their adversaries are and what actions would trigger retaliation. In cyberspace, that clarity is missing. Attacks can be hidden or routed through several regions, which makes attribution difficult and slows decision-making. Governments are left in a bind. If they respond too quickly, they risk escalation. If they wait, they may appear vulnerable. Without clear red lines, even defining what counts as an act of war becomes a challenge. This uncertainty is not theoretical. Incidents like the SolarWinds cyberattack and the Colonial Pipeline ransomware attack show how difficult it can be to respond with confidence or consistency.
At the same time, the field is no longer limited to nation states. Independent hackers, ransomware groups, and private firms now operate alongside governments, often with overlapping motives. Some act for political reasons, others for profit, and many operate in between. This blurs the line between state action and criminal behavior. Governments may tolerate or quietly support certain groups when their actions align with national interests, while still denying any formal link. Attacks on hospitals, businesses, or infrastructure may look like acts of war, yet they are often carried out for financial gain. Groups such as DarkSide, which was linked to the Colonial Pipeline incident, illustrate how criminal actors can create consequences that ripple into national security.
All of this unfolds in a system with few enforceable global rules. Efforts to establish norms exist, such as discussions within the United Nations Group of Governmental Experts, but these guidelines are voluntary and often loosely defined. There is no binding international framework that clearly sets limits or ensures consequences when those limits are crossed. Enforcement is weak, and responses are often limited to public statements or sanctions. At the same time, major powers have competing interests and are reluctant to accept restrictions on their own capabilities. This leaves the system fragmented and inconsistent.
Africa’s Position in the Cyber Battlefield
As cyber conflict reshapes global power, Africa is entering the battlefield under very different conditions. The continent is experiencing rapid digital expansion, driven by mobile technology, fintech innovation, and growing internet penetration. According to the GSM Association, Sub-Saharan Africa had more than 500 million mobile subscribers by 2023, with mobile internet usage continuing to rise sharply. This growth is transforming economies, but it is also expanding the attack surface for cyber threats.
Financial technology is at the center of this shift, and its scale is measurable. In Kenya, mobile money transactions processed through M Pesa exceeded $300 billion in 2022, equivalent to more than half of the country’s gross domestic product, according to the Central Bank of Kenya. In Ghana, mobile money transactions reached over $190 billion in 2023, surpassing the country’s GDP. Nigeria, Africa’s largest economy, recorded over 800 million electronic payment transactions in a single month in 2023 through its interbank settlement system, reflecting the rapid digitization of financial flows. These systems are not peripheral; they are central to how economies function.
This scale has made African digital infrastructure an increasingly attractive target. In South Africa, a 2021 cyberattack on Transnet disrupted port operations, affecting cargo movement and supply chains across the region. In Nigeria, financial institutions have faced repeated cyber fraud incidents, with the Nigeria Inter Bank Settlement System reporting losses of hundreds of millions of dollars annually due to electronic fraud. Kenya’s mobile money ecosystem has also experienced rising cases of social engineering and SIM swap fraud, targeting users at scale.
The challenge is not only technological but institutional. Many African states face constraints in cybersecurity capacity, including limited funding, shortages of skilled professionals, and fragmented regulatory frameworks. According to the International Telecommunication Union, a significant number of countries on the continent still rank in the lower tiers of global cybersecurity readiness, highlighting gaps in legal, technical, and organizational measures.
However, framing Africa solely in terms of vulnerability misses a critical part of the story. Several countries are actively investing in cybersecurity frameworks and regional cooperation. The African Union’s Convention on Cyber Security and Personal Data Protection, adopted in 2014, represents an effort to establish common standards across the continent. Countries such as Nigeria, South Africa, and Kenya have also developed national cybersecurity strategies aimed at strengthening resilience and protecting critical infrastructure.
Africa’s strategic importance in the cyber domain is also growing. As global competition intensifies, external powers are increasingly investing in the continent’s digital infrastructure, from undersea cables to data centers and telecommunications networks. These investments create development opportunities, but they also introduce new dependencies and potential vulnerabilities, particularly when infrastructure is tied to foreign technology providers.
Conclusion: The Future of Power
Cybersecurity is no longer a niche concern or a technical detail. It sits at the center of how countries protect themselves, compete, and maintain stability. What makes this moment different is that conflict is no longer occasional. It is constant, unfolding quietly across networks that power economies, governments, and daily life.
The risks are not just about data or systems going offline. They reach deeper, affecting trust in institutions, the reliability of information, and the functioning of essential services. At the same time, there are still few clear rules guiding how states should act in cyberspace. That uncertainty makes it harder to prevent conflict and easier for it to escalate in ways that are difficult to predict.
The direction is clear. In the years ahead, power will depend not only on military strength or economic size, but on how well countries can secure their digital systems and respond to threats in real time. Those that adapt will be better positioned to shape events. Those that do not risk being shaped by them.
Written by H.E. Olivier Noudjalbaye Dedingar, Global Peace Ambassador, USA/UN Correspondent.

