# When the Hacking Starts, the Shooting Follows
Dmitri Alperovitch didn't invent the concept of cyber warfare — but he's spent more time watching it develop in real time than almost anyone alive. The CrowdStrike co-founder who gave the world terms like "Fancy Bear" and "Cozy Bear" has a new thesis worth sitting with: cyber operations have matured from a parallel intelligence activity into something structurally woven into modern kinetic conflict. Not a precursor. Not a sideshow. A fourth battlefield.
That framing deserves more scrutiny than it typically gets.
## Why "Fourth Battlefield" Is the Right Frame — and Why It Took This Long
Land, sea, air. For most of the 20th century, that was the full map of warfare domains. Space got added — reluctantly, bureaucratically — after the Cold War calcified it as a strategic necessity. Cyber has been hovering around the edges of that list for two decades, mostly treated as an espionage problem with a kinetic costume on.
What changed is doctrine, not capability. Nation-states have had sophisticated offensive cyber tools since at least the mid-2000s. What they lacked was operational integration — the ability to use cyber effects as a timed, coordinated element within a military campaign rather than a standalone covert operation.
Russia's invasion of Ukraine broke that open. On February 24, 2022, within hours of ground forces crossing the border, a wiper attack hit Viasat's KA-SAT satellite network, degrading Ukrainian military communications and incidentally taking out thousands of wind turbine control systems across Europe. That wasn't opportunistic. That was a fires mission — cyber as close air support.
The lesson for military planners globally: cyber has joined the battle rhythm.
## The Signal Before the Storm
The more underreported dimension of what Alperovitch describes is the *intelligence* function of cyber operations — specifically, as early warning indicators.
Hostile cyber activity against a target country doesn't just cause damage. It telegraphs. Before Russia's 2022 invasion, Ukrainian government networks and energy systems saw sustained intrusion campaigns for years. Before the 2008 Russo-Georgian war, DDoS waves hit Georgian government infrastructure days before tanks rolled. The pattern is consistent enough that threat intelligence teams with the right visibility have used adversarial cyber posture as a conflict predictor.
This is both a gift and a burden for defenders. It means pre-war cyber activity is observable — but only if you're collecting the right telemetry and have the analytical framework to interpret disruption attempts as strategic positioning rather than criminal noise.
Most organizations don't have that framework. Most governments struggle to share it even when they do.
## Volt Typhoon Changes the Equation
The most alarming current expression of this doctrine isn't happening in Ukraine. It's happening inside the United States, and it has a name: Volt Typhoon.
Since at least 2021, Chinese state-sponsored actors have been systematically pre-positioning inside American critical infrastructure — power grids, water systems, ports, telecommunications. The CISA advisory published in early 2024 was blunt in a way government cybersecurity communications rarely are: this activity is not espionage. There's little intelligence value in a water treatment plant. The access is being staged for use in a future conflict, almost certainly one that would coincide with a Taiwan contingency.
That's the fourth battlefield thesis in practice. China isn't just building cyber weapons — it's emplacing them inside American infrastructure like a military pre-positions supplies before a campaign. The "attack" doesn't require a new intrusion. The intrusion has already happened.
Defenders have been scrambling to understand this for two years and making only partial progress. The challenge is that living-off-the-land techniques — using legitimate system tools rather than custom malware — make Volt Typhoon actors extraordinarily difficult to detect. They blend into the noise of normal network administration in ways that signature-based detection simply cannot catch.
## What This Means If You're Not a Nation-State
For organizations outside the defense and critical infrastructure sectors, the fourth battlefield thesis can feel abstract. It shouldn't.
Three things follow directly from the integration of cyber into kinetic conflict:
Escalation uncertainty. When cyber operations are battle rhythm elements rather than standalone activities, the threshold for triggering them drops. A crisis that escalates militarily will now almost certainly escalate in cyberspace simultaneously — and the blast radius won't stay within military targets. NotPetya, which started as a Ukrainian accounting software update, eventually caused over $10 billion in damages globally because malware doesn't respect target lists.
Supply chain as terrain. The way you pre-position for fourth-battlefield operations is through software and hardware supply chains. SolarWinds was almost certainly a strategic access operation. So was the compromise of network edge devices that has characterized recent Chinese and Russian campaigns. If your organization touches critical infrastructure clients, you are potential terrain.
The intelligence gap. Commercial threat intelligence has never been more valuable — and more difficult to operationalize. The signals exist. The challenge is that most organizations lack the analysts, context, and relationships to translate raw threat data into defensive decisions before the shooting starts.
---
## HackWire Analysis
Alperovitch's "fourth battlefield" framework is correct, but it may already be understating where things are headed. The more precise framing is that we're watching cyber transition from a *domain* of conflict to an *enabler* of all other domains — something closer to what electronic warfare became in the 20th century. EW doesn't fight wars by itself; it shapes the electromagnetic environment in which every other weapon system operates. Cyber is heading the same direction.
The Taiwan scenario deserves specific attention here. Volt Typhoon's pre-positioning campaign was called out publicly, which is itself unusual — naming an ongoing intrusion campaign by a peer adversary is a political act. What the public attribution doesn't tell you is how many similar campaigns are still operating below the disclosure threshold, and what specifically has been done to evict actors who may have been present in critical systems for three-plus years.
The honest answer is: not enough. CISA has pushed hard on "secure by design" and critical infrastructure hardening, but voluntary frameworks against state-level adversaries with multi-year patience and government backing have a poor track record. The gap between what American critical infrastructure operators have been told to do and what they've actually implemented is substantial.
What most coverage misses about the fourth battlefield argument is the asymmetry problem. Democracies constrain their offensive cyber operations through legal processes, policy reviews, and political risk calculations. Authoritarian states do not face those constraints in the same way. That asymmetry doesn't mean the West loses — but it means that relying on deterrence through equivalent offensive capability is a more complicated bet than it sounds in think-tank white papers.
For defenders in critical sectors: now is the time to be running purple team exercises specifically modeled on living-off-the-land techniques, auditing legitimate admin tool usage baselines, and pressure-testing your incident response plans against a scenario where the attack begins on the same day geopolitical tension spikes to crisis level.
The fourth battlefield won't wait for your patch cycle.
— HackWire Editorial
---
## Related Coverage