Skip to main content
Have a personal or library account? Click to login
Cyber Resilience Under Fire: OT Systems and Critical Infrastructure in the Russia-Ukraine War Cover

Cyber Resilience Under Fire: OT Systems and Critical Infrastructure in the Russia-Ukraine War

By:   
Open Access
|Sep 2026

Abstract

The Russia-Ukraine war has provided an unprecedented opportunity to examine the effectiveness of cyber operations against critical infrastructure and operational technology (OT) systems during an active armed conflict. Prior to the invasion, many experts expected Russia to launch large-scale cyberattacks capable of causing strategic-level disruption to Ukrainian critical infrastructure. However, the practical impact of such operations proved significantly more limited than anticipated. This study examines the extent to which Russian cyber operations against Ukrainian critical infrastructure have produced direct cyber-physical effects at the OT layer and how their operational relevance has varied across different phases of the conflict. The research employs a qualitative design combining structured literature and document analysis, case-study analysis, and selected findings from the Digital Mohács 3.0 research project. The SANS ICS Cyber Kill Chain model is applied to distinguish incidents affecting conventional IT systems from operations progressing towards direct manipulation of industrial processes. The findings indicate that the vast majority of incidents affecting critical infrastructure remained at the conventional IT layer, while operations producing direct cyber-physical effects through specialised OT protocols and control logic were exceptional. The analysis further suggests that the conditions for complex OT-targeting operations are most favourable during hybrid confrontation and the initial phase of armed conflict, whereas their relative utility decreases during protracted conventional warfare. The study is limited by its reliance on publicly documented incidents, as classified, undisclosed, or unsuccessful operations cannot be systematically assessed. The findings underline the importance of protecting IT environments, maintaining effective IT–OT segmentation, and ensuring rapid incident-response capabilities as central components of critical-infrastructure resilience.

DOI: https://doi.org/10.2478/raft-2026-0028 | Journal eISSN: 3100-5071 (formerly 2247-840X) | Journal ISSN: 3100-5063
Language: English
Page range: 361 - 376
Submitted on: May 27, 2026
Accepted on: Aug 21, 2026
Published on: Sep 16, 2026
Published by: Nicolae Balcescu Land Forces Academy
In partnership with: Paradigm Publishing Services

© 2026 Csaba Krasznay, published by Nicolae Balcescu Land Forces Academy
This work is licensed under the Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 License.