The first cyberattack in a NATO conflict probably won’t look like a missile launch. It’ll more likely look like a successful Microsoft 365 login, and that’s the underlying lesson behind NATO’s changing posture toward the Russian Federation.
- NATO now calls Russia its “most significant and direct threat”, citing military rebuilding alongside critical-infrastructure sabotage, malicious cyber activity, electronic interference, disinformation, and political influence.
- The UK’s 2025 Strategic Defense Review is more sobering still: cyberspace is contested every day, and “the first blows of any conflict will likely be struck” there.
Now, I keep an eye on geopolitics. But the old newspaper man in me has deliberately kept the facts in this post measured: Globally, Russia is presented as “a persistent and serious threat,” but NATO intelligence is not specifically predicting open conflict in Q4 2026.
This nuance is how we should think about identity infrastructure. In a cybersecurity conflict, the question isn’t only whether an attacker can breach the perimeter. It’s whether compromised identities, tokens, service accounts, and cloud entitlements will give them somewhere useful to go afterward. It’s about readiness, not reactiveness.
Cybersecurity conflict starts before the shooting
- NATO’s 2025 annual report says adversaries are using cyber campaigns to undermine support for Ukraine, spy on Allied societies, disrupt critical infrastructure, and “pre-position for future conflicts.” And “pre-positioning” is the phrase worth circling in dayglo Sharpie.
- In May 2025, the UK National Cyber Security Center (NCSC) and ten partners exposed a Russian GRU campaign targeting Western logistics and technology organizations involved in supporting Ukraine. The campaign included credential attacks and compromised internet-connected cameras near military installations and border crossings to monitor aid movements. That isn’t a random attack. It’s reconnaissance.
The European Union now describes a Russian “cyber ecosystem” spanning intelligence services, cybercriminals, hacktivists, and private companies. In July 2026, it linked that ecosystem to government network infiltration and critical infrastructure sabotage across Europe.
Russia’s cyber ecosystem also extends beyond its own state-sponsored groups, drawing on aligned actors in countries such as China and Iran, as well as cybercriminal networks and private military organizations that support or complement its operations. Only last month, China was responsible for intrusions at the Justice Department, NASA, the Federal Reserve, and the Senate.
So our multi-cloud security model can’t assume peacetime behavior simply because no one has officially declared a conflict.
Identity infrastructure is part of the cybersecurity conflict
Russian state operators repeatedly target identity because valid access is quieter than malware.
- In 2025, the NCSC disclosed AUTHENTIC ANTICS, malware attributed to Russia’s GRU-linked APT28. It steals credentials and OAuth authentication tokens, enabling persistent access to Microsoft cloud services while blending with legitimate activity.
That makes the old authentication-versus-authorization distinction rather important. MFA (multi-factor authentication) can make credential theft harder, but authn vs authz becomes decisive once a legitimate session has been compromised. What can that identity actually reach?
If an ordinary account is compromised, damage may be contained. If the account retains broad permissions, persistent administrator rights, or inherited cloud entitlements, an attacker gets a ready-made escalation path and we’re in a whole world of avoidable pain.
That’s why privileged access management and cloud infrastructure entitlement management need to move closer to strategic resilience rather than remain “the IAM project we’ll revisit next quarter.” Next quarter is too late. Q4 2026 is going to be interesting, to say the least.
Cybersecurity conflict punishes standing privilege
Current NCSC heightened-threat guidance tells organizations to strengthen defenses during periods of geopolitical tension, including access controls, MFA, monitoring, vulnerability management, backups, and incident readiness.
We should go further where cloud access allows it.
A Zero standing privileges approach reduces the useful access available to an attacker during a compromise. Just-in-time access grants privilege when work requires it rather than leaving it permanently available. Access automation can then remove that privilege when the task ends.
That matters for human administrators, but service account security deserves equal attention. Modern environments also contain workloads, applications, bots, CI/CD pipelines, and AI agents. A serious non-human identities strategy has to ask the same question we ask about employees: what does this identity need now, and why does it still have everything else?
Otherwise, identity debt and access sprawl quietly accumulate until yesterday’s convenience becomes tomorrow’s lateral movement.
NATO is treating cyber effects as military effects
This isn’t simply a security-industry interpretation.
NATO has stated that a serious cyberattack, or the cumulative effect of sustained malicious cyber activity, could reach the threshold for Article 5 collective defense. In July 2026, the Alliance condemned Russia’s persistent cyber campaigns and said it was prepared to use the “full range of capabilities” to deter, defend against, and counter cyber threats.
That doesn’t mean every phishing email is Sarajevo with Outlook. It means cyber operations are now formally integrated into deterrence and defense planning.
For organizations running AWS (Amazon Web Services), Microsoft Azure, Google Cloud, SaaS (software as a service) applications, and distributed infrastructure, access security therefore becomes part of operational resilience.
A zero trust posture helps, but only if it survives contact with real entitlements. Identity-first access should continuously minimize privilege, examine context, and remove access when it’s no longer justified. Standing privilege should be treated for what it is: stored blast radius.
Preparing identity infrastructure for cybersecurity conflict
We don’t need to predict whether NATO and Russia will enter direct military conflict to act sensibly in the digital world.
- Estonia’s 2026 intelligence assessment says Russia currently has no intention of attacking a NATO member in the coming year. That’s reassuring, though goalposts move. It also says continued preparedness is what keeps that calculation intact. Cybersecurity should follow the same logic.
Strong identity controls make espionage harder today and conflict-driven disruption harder tomorrow. They limit what stolen credentials can do, reduce persistent footholds, improve visibility, and force attackers to repeatedly regain privilege rather than inherit it. That’s good identity security in peacetime. In a cybersecurity conflict, it’s defensive depth.
Start reducing the access an attacker could inherit
A stolen identity shouldn’t arrive with months or years of accumulated privilege attached. Start a Trustle free trial to discover cloud entitlements, reduce standing access, and make just-in-time privilege part of the defenses already in place before the threat level changes.



