As tensions rise between the United States and Iran, the question arises as to whether we should prepare for a full-fledged cyberwar. I want to emphasize that an organized, purely digital war without conventional weapons is unlikely for the time being. However, it is almost certain that a wave of targeted digital attacks will follow, ranging from DDoS bursts to destructive wipers.
Military doctrines still lack a unified definition of "cyberwarfare." A large-scale digital war would allow the U.S. to take out Iran's vital infrastructure for long periods of time and vice versa. But without international treaties or ethical frameworks on retaliation, such an escalation is neither politically nor strategically obvious. Most hacks therefore remain below the threshold of an "act of war" and are characterized by espionage (intelligence collection) or sabotage (targeted disruption) rather than total destruction of systems.
Historical precedents such as Stuxnet (US attack on Iranian centrifuges) and the Russian blackout operation in Ukraine show their enormous complexity and lead-time. Such Industrial Control Systems (ICS) intrusions required years of intelligence building, onsite reconnaissance and custom malware. Without in-depth knowledge of protocols, firmware and hardware variants, it is virtually impossible to disable controlling SCADA (Supervisory Control And Data Acquisition) systems for an extended period of time.
DDoS and wipers: the most likely threats
Distributed Denial of Service (DDoS):
Easier to set up via botnets of IoT nodes and hacked routers, but the impact is often temporary AND limited. Modern scrubbing centers and cloud mitigation platforms can absorb peak determinations of up to tens of terabits per second.
Destructive wiper malware:
Viruses that overwrite master boot records or irreversibly delete files promise the highest disruption at relatively low stakes. Examples such as Shamoon (attack on Saudi Aramco) and NotPetya show how a single zero-day exploit combined with lateral movement can cause enormous damage to corporate networks, without physical casualties.
Escalation pattern and risks
Iran has already conducted large-scale DDoS campaigns against U.S. banks in the past and regularly deploys wipers against adversaries. Future attacks are expected to primarily target Western companies that appear to be actively cooperating with sanctions or military actions. A cat-and-mouse game full of Advanced Persistent Threats (APT) groups, phishing campaigns and supply-chain infiltrations is thus breaking loose.
A "digital cold war" is now the most likely scenario: sporadic APT infiltrations, periodic DDoS attacks and occasional wipers follow one another. A large-scale, sustained cyberwar without nuclear weapons remains out of the question for now, thanks to technical barriers and political trade-offs. Citizens and businesses would be wise to be especially vigilant about social engineering, patch management and backup strategies, because in this dormant cyberwar, the next attack is always just around the corner.