Cyberattacks at a nation state level have pitched businesses, enterprises and IT leaders into an all-out war where they are fighting a losing battle to protect their assets. The stark statistics behind the nature of nation state attacks – their objectives, strategies and targets – show why.
Dr. Michael McGuire’s recent study, Nation States, Cyberconflict and the Web of Profit, says it’s not the battlegrounds of smaller or rogue nations versus big government that is causing the real damage – or giving IT leaders sleepless nights – but the attacks on IT systems across every size of business.
So how do you quantify a field as inherently opaque as nation state cyberconflict? Well, for Dr. McGuire, Senior Lecturer of Criminology at the University of Surrey, his were metrics gained from whistle-blowers and insider leaks reported in the press, as well as analysis of more than 200 known incidents between 2019-2021.
The study surveyed over 50 leading practitioners in relevant fields, such as cybersecurity, intelligence, government, academia and law enforcement and draws upon informants across the dark net and other covert sources.
Discourse on the topic of nation state cyberconflict is so often skewed towards political and social implications – influencing of voter behaviour, misinformation and interference with critical national infrastructure. This has relegated IT to being the collateral footnote.
Dr. McGuire’s study illuminates why nation state attacks should be at the forefront of everyone in the global IT community’s mind.
What’s the objective of nation state cyberattacks?
State-backed cyber-attackers are more interested in a general enterprise’s email database than straight-up money heists or the spread of misinformation.
Elaborating on this, the study says: “The most frequent target for Nation State cyberconflict (representing 35% of cyber-attacks analysed) is business and enterprise. Irrespective of sector or size, business appears now to face comparable risks from Nation States as it has done from traditional cybercriminals.”
The study goes on to say: “No enterprise appears to be safe from the threat of Nation State cyber-attacks. For example, the APT10 group (aka Menupass or Red Apollo) which has specialised in IP theft, has also been associated with hacking into US law firms in order to obtain data on clients in key industries.”
These groups spend much of their time attacking a range of industries – from retail to aerospace, the back-end of any business is not safe. And, small businesses are just as much at risk of attack as big industry, a fact highlighted in the APT10’s cyber-attacks across 2017/18.
The study also talks about the APT28 threat group, which was previously associated with the US Democratic Party hack during the 2016 election, saying it has recently “begun to probe vulnerable email servers across the enterprise and other sectors – probably to acquire credentials and to extract useful data from emails.
“Thousands of small business and home-based routers were hacked and placed under the group’s control. [APT28] have also explored a growing trend in acquiring access to corporate networks through the use of IoT devices such as office printers and video decoders.”
One of starkest examples in recent memory in which a businesses’ vulnerabilities were impacted by a nation state attack was was in 2020 when Orion Software was targeted.
This supply chain attack gave hackers unfettered access to the systems of over 15,000 clients of SolarWinds – who were using Orion Software. These clients included many within the IT sector, including Cisco, FireEye, Intel and Microsoft.

Recommended
- The spy who loved me – how Apple are failing stalkerware victims
- Can new rules clean up Binance’s act on money laundering?
- NHS data sharing plans delayed again as millions of patients opt-out
Sophisticated, custom-made weapons
What makes cyberweaponry distinct is its application when compared to normal weaponry – which has literal destructive implications. Digital weaponry can be pernicious, used without the victims knowledge and create collateral damage that goes beyond straight currency.
“Deciding what to count as a cyberweapon has often been less than clear. Cyberweaponry could refer to a tool or a technique. It could refer to a destructive capability – one that damages systems or simply steals data or may involve tools that seek to influence public opinion on social media.”
Dr. McGuire’s study found that: “Applications for surveillance (around 50% of weapons use) appear to far exceed uses for damage (10%) or overt destruction (4%) at present.
“Similarly, network incursion and takeover uses, such as lateral movement (where attempts are made to broaden and cement a foothold to valuable data or systems) or the use of RATs (remote access Trojans), appear to be more frequent than extraction – i.e. stealing data or assets (around 8%).”
This explains the increasing pressures that nation state cyber-attacks are placing on IT leaders – strategy and objective are fairly ubiquitous, it’s attackers’ targets. Not governments or state agencies, but local enterprises and businesses that are at most risk.
More often than not, the purpose of these attacks isn’t something that’s easily quantifiable. If surveillance is the main goal, that’s of huge concern, because you can’t pre-empt an attack if you don’t know the intention or the net-gain on the part of the attacker.
Nation state cyberconflict is a self-sustaining economy that is growing. Fast
State cyberconflict appears to have become interwoven with many of the activities more typical of the (illicit) digital economy, The Web of Profit, this is how nation state cyberconflict continues to evolve and develop at a pace not just abreast, but beyond what any kind of reactive security architecture can currently keep up with or pre-empt.
Discussing this, the study says: “Tools standardly used by cybercriminals (such as malware, keylogging and surveillance devices) are being acquired and weaponised by Nation States.
“For example, the sample of cyber-attacks between 2010-2020 that were analysed for this research suggest that around 50% involved low budget, straightforward tools easily purchased on the dark net, or other cybercrime markets; around 20% involved more sophisticated custom-made weapons, such as targeted malware or weaponised exploits, probably developed within dedicated state cybersecurity programmes.”
A further 30% were of uncertain, or un-attributable origin. The trade in unmonitored, off-the-shelf cyberweapons, acquired by nation states through the dark net or more covert sources, may be significant – though this is impossible to establish definitively.
According to a sample of dark net vendors interviewed for Dr McGuire’s research, anything between 10–15% of their sales now go to ‘atypical’ purchasers or those acting on behalf of other clients. Some of these involve the phenomenon of ‘stock-piling’ tools like zero-day exploits.
The study goes on to say: “It is also clear that many dark net markets now operate along nation state lines, with listings in the language of the state in question and products customised to the specific needs of domestic producers and consumers.”
One feature of nation state cyber-attacks is frequency and ever-adapting strategy. This means that the tools for these attacks are in constant demand creating an illicit supply chain that not only gives attackers the tools they need but in turn, the money invested in their purchase is reinvested in creating newer, more elaborate weaponry.
This is an issue becoming ever more dangerous with the proliferation of AI and machine learning, which can be leveraged in countless ways for nation state attacks.
Nations are now dedicating huge amounts of resources to enhance their cyber-capabilities
Government’s are now prepared to devote significant time and resources towards achieving strategic advantages in cyberspace, which simply adds to the proliferation of nation state cyberwarfare.
The study explains: “With spending on cybersecurity projected to rise by 11% in the US (between 2019-2021), by 25% in China (to 2023), by 50% in the EU (to 2023) and by up to 200% in Russia (to 2023), the increasing strategic interest of Nation States in cyberspace is clear enough.
“And with dedicated research programmes aimed at developing new kinds of cyber-attacks, the stockpiling of ‘exploits’, or the combining of attack tools and techniques – there has been a significant complexification in the methods used by Nation States to further these strategic objectives.”
What can be done to protect your business?
“The endpoint remains the most common point of infection: Individuals and businesses alike need to protect themselves; the best way to do this is by defending the endpoint,” says Ian Pratt, Global Head of Security for Personal Systems at HP.
“Whether it’s social engineering and phishing being used to infect targets, steal credentials and maintain persistence, the endpoint is the number one point of infection for all breaches,” he adds.
Mr. Pratt discusses how businesses can give themselves the best possible chance of defending themselves against nation state attacks: “As the severity, sophistication, scale and scope of Nation State activity continues to increase, we need to reinvent security to stay ahead.
“This will require a more robust endpoint security architecture built on zero trust principles of fi ne-grained segmentation coupled with least privilege access control. We are all in the crossfire now, so it’s critical that every business does what it can to protect itself and its wider network.”
Commenting on the study, it’s impact and the action IT leaders should take, Mitch Mellard, Principle Threat Analyst at Talion says: “In recent months, we have seen nation state attacks become more common with government agencies, but we have also seen non-government agencies increasingly becoming victims to these attacks.
“Non-Government sectors, such as technology, media outlets, critical infrastructure, manufacturing, healthcare, law firms, education, financial institutes and telecommunications are all witnessing a rise in nation state attacks.
“This is because these kinds of organisations are able to provide intellectual property and sensitive/classified information, which can be just as useful as the data that is held by governments.”
Mellard adds: “Just as these attacks become more frequent, they are also becoming more dangerous, with cyber warfare spilling over into the real world in destructive and dangerous ways.
“Therefore, it is advised that in order to mitigate the likelihood of an attack, organisations within these sectors should use strong login credentials/MFA, stay up to date with the ever changing and diverse threat landscape & ensure that staff are security aware and sceptical of unsolicited external communication.”
When you parse the numbers behind nation state cyber-attacks, it doesn’t tell of a coming storm. It shows that IT leaders, and even the broader technology community – involved in business of any size – are afraid because they already have their backs to the wall, trying to protect themselves from nation state cyberattackers.





