Saturday, July 11, 2026

Episode 2 -What Is Cyber Warfare? The Fifth Domain of Conflict




In Episode 1, we drew the line between cyber crime, cyber terrorism and cyber warfare. Of the three, cyber warfare is the one that carries the most strategic weight — and the most confusion.

Governments call things "cyber war" that scholars would call espionage. Headlines warn of a "cyber Pearl Harbor" that has never actually happened. Meanwhile, quieter operations — the ones that never make headlines — are reshaping the balance of power between nations in real time.

So what is cyber warfare, really? And why does the answer matter more for India than for almost anyone else?


A Working Definition

Strip away the jargon, and cyber warfare is this: politically motivated digital operations conducted by a state, or a group acting on a state's behalf, against another state's networks, infrastructure or information systems.

It is an extension of policy — Clausewitz's old idea that war is "policy by other means" — carried out in a new domain. The tools are different. The logic is not.

Cyber warfare can disable official websites, cripple financial systems, steal classified data, or quietly map a rival's power grid for future use. Some of it looks like sabotage. Much of it looks like nothing at all — until years later, when the pre-positioning becomes clear.

Security researcher Jeffrey Carr described it, memorably, as "the art and science of fighting without fighting." That phrase borrows directly from Sun Tzu — and that borrowing is not an accident. To understand cyber warfare, it helps to look at three much older ways of thinking about conflict.


Three Lenses on War

Every strategist who has tried to make sense of cyber conflict has reached, consciously or not, for one of three classical frameworks.



Figure 1. Three strategic traditions, each offering a different way to read cyber conflict.

Clausewitz insisted that war requires organised violence — force used to compel an enemy to submit. By this standard, most cyber operations fall short: no blood, no wreckage, no formal declaration.

Sun Tzu took the opposite view centuries earlier. The highest form of warfare, he argued, is to "subdue the enemy without fighting" — through deception, foreknowledge and espionage. He devoted an entire chapter of The Art of War to spies. In digital form, that foreknowledge now comes from network intrusion rather than human informants.

Kautilya, writing the Arthashastra in India around 300 BCE, went further still. He described three forms of warfare: open war (prakasha yuddha), concealed war (kutayuddha), and silent war (tushnim yuddha) — the last involving secret agents, misinformation and covert action against a rival state, conducted so quietly that the target may not even know it is under attack.

Cyber warfare, as practised today, looks far less like Clausewitz's battlefield and far more like Kautilya's silent war. It is a technological continuation of a very old idea, not an unprecedented invention.


The Rid–Kello Debate: Is It Really "War"?

Two contemporary scholars capture the modern version of this same disagreement.

Thomas Rid, in Cyber War Will Not Take Place, argues that no cyber operation to date meets the classical definition of war. Without lethal force and physical destruction, he contends, what we call "cyber war" is really espionage, sabotage or subversion wearing a dramatic label.

Lucas Kello disagrees. In The Virtual Weapon and International Order, he argues that judging cyber conflict purely by physical violence misses the point entirely. He coins the term "unpeace" — a persistent state of strategic rivalry, conducted through cyberspace, that is neither full war nor genuine peace. Repeated intrusions into power grids, defence networks and government databases, Kello argues, can shift the balance of power between nations without a single shot fired.



Figure 2. Two scholars, two thresholds — and two very different pictures of the same activity.

 

Digital Arthashastra Insight
"Rid is right that cyber war rarely produces immediate destruction. Kello is right that its cumulative effects can quietly rewrite the balance of power. India lives inside that gap."


Why This Matters More for India

Along both its western and northern borders, India does not experience declared war. It experiences something closer to Kello's "unpeace" — a sustained condition of pressure, probing and calibrated disruption that rarely crosses into open conflict.

State-linked activity attributed to actors such as RedEcho has been associated with reconnaissance of Indian power infrastructure. Groups such as APT36 (Transparent Tribe), linked to Pakistan-based operations, have focused on sustained espionage, credential harvesting and profiling of Indian defence personnel. Neither pattern looks like war in the Clausewitzian sense. Both look exactly like Kautilya's silent war, and both are consistent with Kello's unpeace.

This is not a coincidence. Kautilya's own strategic worldview — the mandala theory, which treats neighbouring states as natural rivals — maps closely onto India's position between two nuclear-armed neighbours with unresolved territorial disputes. Ancient strategic geography did not disappear in the digital age. It simply found a new domain to operate in.


The Takeaway

Cyber warfare is not a futuristic abstraction, and it is not science fiction. It is the modern expression of a form of conflict that Sun Tzu and Kautilya were already describing more than two thousand years ago: advantage sought through information, deception and patience rather than open battle.

Key Takeaway: Whether or not a given cyber operation meets Rid's strict definition of "war," it can still meet Kello's threshold of strategically consequential "unpeace" — and for India, that distinction is not academic. It shapes how threats should be detected, attributed and deterred.

In the next episode, we turn to a related but distinct threat: Cyber Terrorism — what happens when the objective shifts from strategic advantage to psychological fear, and why treating it identically to cyber warfare leads to the wrong response.


Digital Arthashastra is a research-driven platform on cyber warfare, cyber terrorism, national security and the future of conflict. Follow along on YouTube, LinkedIn, X and Instagram.


Tuesday, July 7, 2026

Digital Arthashastra™ — Episode 1














There was a time when wars were fought with swords, then with guns, tanks and missiles.

Today, a nation can be attacked without a single soldier crossing its borders.

A power grid can be shut down. A bank can be crippled. Military secrets can be stolen. Elections can be influenced. Public opinion can be manipulated. All without firing a single bullet.

Welcome to the age of cyber conflict.


This is the first article on Digital Arthashastra— a platform dedicated to understanding cyber warfare, cyber terrorism, cyber crime, crypto-terrorism, digital forensics, national security, emerging technologies, artificial intelligence and the future of conflict.

The name Digital Arthashastrais inspired by Kautilya's Arthashastra — one of the world's oldest treatises on statecraft, intelligence and strategy. More than two thousand years ago, Kautilya recognised that power was not exercised only through armies. Intelligence, deception, economics and information were equally important instruments of national security.

The digital age has not changed this principle. It has simply given it a new battlefield.


Why Should You Care?

Cyber security is no longer just an IT problem. It affects every citizen.

Every online payment, every Aadhaar-linked service, every mobile banking transaction, every hospital database, every railway network and every defence communication system depends on secure digital infrastructure.

As India rapidly transforms into a digital economy, our opportunities have multiplied — but so have our vulnerabilities.

The numbers tell the story. India's reported cyber incidents rose from roughly 10,800 in 2011 to over 2 million in 2024 — one of the steepest escalation curves seen in any major democracy. This is not a wave of isolated hacking incidents. It reflects a sustained, structural shift in how conflict is being waged against India.

Understanding cyber threats is therefore no longer optional. It is essential.

Before we go further, we need to understand three terms that are constantly used interchangeably but mean very different things:

  • Cyber Crime
  • Cyber Terrorism
  • Cyber Warfare

Understanding the difference between them is the first step toward understanding the modern battlefield.


Cyber Crime: Crime for Profit

Cyber crime is the most common digital threat. The motivation is usually financial gain.

Cyber criminals want money — not political change. They steal banking credentials, hack email accounts, conduct ransomware attacks, run fake investment schemes, spread malware and commit identity theft.

Every day, millions of people around the world become victims of cyber crime. The targets are usually individuals, companies and financial institutions.

Simply put: cyber crime is digital crime committed for personal or financial benefit.


Cyber Terrorism: Fear Through Cyberspace

Cyber terrorism is fundamentally different. Here, the objective is not money — it is fear.

Cyber terrorists use digital tools to intimidate governments, disrupt essential services, spread extremist propaganda or support acts of terrorism.

Imagine a terrorist organisation attempting to disable a city's power supply, disrupt emergency services, or spread coordinated panic through digital platforms. The intended outcome is psychological impact, not financial gain.

Cyber terrorism therefore combines the objectives of terrorism with the methods of cyberspace — and increasingly, it overlaps with crypto-terrorism, where digital currencies are used to fund, launder or move money for extremist activity outside the reach of traditional financial oversight.


Cyber Warfare: When Nations Fight in Cyberspace

Cyber warfare operates at an entirely different level. Here, the actors are usually nation-states or groups acting on behalf of states. Their objective is strategic advantage.

Cyber warfare includes espionage, intelligence gathering, disruption of military networks, attacks on critical infrastructure, influence operations, and long-term preparation for future conflict.

Unlike conventional war, cyber warfare often exists in what strategists call the grey zone — the space between peace and war. Many operations are deliberately designed to stay below the threshold that would trigger a military response. This makes attribution difficult, retaliation complicated, and deterrence uncertain.

Increasingly, cyber operations have become an extension of national strategy rather than isolated acts of hacking. Research into state-linked activity against India shows a pattern of sustained, persistent campaigns rather than random or opportunistic intrusions — evidence of long-term strategic intent, not chance.


Why the Difference Matters


Not every hacker is a terrorist. Not every cyber attack is an act of war.

Confusing these concepts leads to poor policy, weak laws and ineffective responses. A ransomware gang stealing money should not be treated the same as a foreign intelligence agency infiltrating a defence network. Similarly, an act of cyber terrorism demands a different legal, intelligence and security response than ordinary cyber crime.

Digital Arthashastra Insight "Not every cyber attack is an act of war. Understanding the difference is the foundation of good cyber policy."

Understanding these distinctions allows governments, businesses and citizens to respond appropriately — with the right law, the right agency, and the right level of urgency.


India's Digital Challenge

India is one of the world's fastest-growing digital societies. Digital payments, online governance, cloud infrastructure, artificial intelligence and connected critical infrastructure have transformed how we live.

But increased connectivity also expands the attack surface available to hostile actors. India today faces threats from cyber criminals, state-sponsored espionage, information warfare, ransomware groups, and persistent grey-zone cyber campaigns across banking, defence, government, healthcare and telecom networks.

The challenge is no longer whether cyber attacks will occur. The real question is how prepared we are to detect, attribute and respond to them.


Why Digital Arthashastra Exists

Most discussions about cyber security focus only on technology. But cyber conflict is much more than technology.

It is about strategy. It is about geopolitics. It is about intelligence. It is about law. It is about national power.

Digital Arthashastra exists to explain these issues in a way that is accurate, evidence-based and accessible — for students, professionals, policymakers and security enthusiasts alike.

Key Takeaway: Cyber conflict cannot be understood through technology alone. It must be understood through strategy, law, and national power — the same lens Kautilya applied to statecraft over two thousand years ago.

Future episodes of Digital Arthashastra will explore:




The Battlefield Has Changed

The wars of the future may not begin with missiles. They may begin with malicious code.

The strongest nation may not always be the one with the biggest army, but the one with the most resilient digital infrastructure, the best intelligence, and the clearest strategy.

The battlefield has expanded. Understanding it is the first step toward securing it.

Welcome to Digital Arthashastra. The journey begins here.


 Follow Digital Arthashastra on YouTube, LinkedIn, X and Instagram for the full multi-platform series.