Geopolitical tensions:
How to prepare ICT operations when conflicts intensify?

Our generation has experienced a long period of peace time, and life was calculable, and success depended on our own behavior. With Russia's attack on Ukraine, Europe was confronted with a new reality: war is no longer unimaginable but has become a real possibility that must be considered. Politicians needed time to understand this new reality: before the attack, those who considered war a realistic possibility were often dismissed.

However, international and globally operating companies had to turn around quickly, because today war is a reality in Ukraine, Iran, and all near east; around Taiwan, the political situation is tense. In these areas, war has unfortunately become a sad reality. Putin said recently that a limited attack against NATO states is for him an option in the next 2-3 years. He believes that, after testing with many small incidents, he will get away with such an operation without a large-scale war.

Against this background, the topic of ICT operations in times of growing political tension and in war areas is of paramount importance for large companies and should be taken seriously.

In conclusion, war readiness of ICT operations is complex, and must have a sound balance between organization (what we can do up front) and improvisation (what is case-specific, and we cannot plan). However, Compliance and Frameworks are still important and a “must” through all situations, including war. Just as in most difficult times, a balance between functionality and compliance is needed– in this case, operation and functionality are more important.

Key benefits are often declared as follows:

  • Extended view on resilience, including war and war-like situations.
  • Understanding that political conflicts must be observed, and in case of escalating conflicts, the CISO must understand that a new dimension of preparedness is needed. At this time, it is probably more about sites in or near conflict zones, but escalation might be very fast, as we experienced with the Russian attack on Ukraine, February 24, 2022.
  • Understanding in-depth why improvisation is an utmost important capability in ICT operations in warlike situations.

Keynotes I:

Enterprise Security Risk Management (ESRM): A Converged Approach to Security Governance

Since the end of the Cold War, resurgent geopolitical fault lines — Eastern Europe, the Middle East, the Taiwan Strait, the Indo- Pacific — are pressuring enterprises, supply chains, and critical infrastructure. Regulators are catching up: DORA, NIS2, and the EU Cyber Resilience Act signal hardening statutory duty-of-care obligations.

Doron Zimmermann argues traditional siloed security — IT security dominant, cyber security secondary, physical and personnel security lagging — is no longer adequate. Each silo gap is a self-inflicted attack surface. Without structured risk dialogue among key stakeholders (CISO Office, ERM, HR, Legal, Audit, Procurement, Corporate Security, Business Units, IT), individual gaps become an enterprise-wide vulnerability.

ESRM offers a converged, risk-principle-led alternative, anchored in the ESRM Cycle: Identify, Analyze & Assess, Treat & Mitigate, Monitor & Review, Stakeholder Dialogue. It treats security as integrated governance aligned to enterprise risk and objectives. Its Value Chain operationalizes this via five domains — Threatscape analysis, Value at Risk identification, Maturity & Resilience assessment, Countermeasures, and Program management — each answering a distinct strategic question.

Tailored to organizational maturity and supported by relevant standards (NIST CSF, ISO 27001, ASIS ESRM, GDPR, DORA), ESRM is delivered via modular or end-to-end engagement models.

Discussion Round I:

Enterprise Risk Management in times of political conflicts: What has changed, and which additional use cases are important?


Keynotes IIa:

A production camp in Ukraine – preparation, incidents, lessons identified

Normal operation with framework- and compliance-oriented security is excellent for peacetime – but when war crosses the production camp, everything is different. Experience sharing from a real case in East Ukraine will position regular top security and provide a clear view of what we do not cover in our mainstream security thinking when war hits production camps.

The pictures of the devastating actions of soldiers give a clear understanding that war is completely beyond our imagination and that actions of preparation must be beyond what the security community has developed in standards, frameworks, and compliance requests.


Keynotes IIb:

Cyber Defense of Critical Infrastructure Under Armed Conflict: Lessons from the Russian–Ukrainian War

Modern critical infrastructure faces unprecedented cyber threats in conflict zones, where adversaries combine sophisticated APT operations with kinetic warfare. This talk presents findings from a master's thesis research project examining how Ukrainian critical infrastructure has been targeted by Russian state-sponsored threat actors – and what lessons other sectors and nations can draw from this experience.

Drawing on three major case studies (NotPetya, SolarWinds, and the Viasat/KA-SAT attack) and expert interviews, the presentation introduces the Cyber Shield Framework – a five-layer diagnostic model addressing the failure modes that emerge under wartime conditions. Key findings include how governance gaps, ZTA-monitoring coupling failures, and compressed decision-making cycles degrade cyber defenses precisely when they are needed most. The talk will offer practical recommendations for security professionals and policymakers responsible for protecting critical systems in high-pressure environments.

Discussion Round II:

Making ICT operation war resilient: what is needed?


For more details please see the Personal Invitation