Whose job is it to defend a private company?

Photo: Matthew Zheng/Unsplash

25 August 2026

We do not ask supermarkets to repel air strikes or hand factories the job of intercepting missiles. Yet when it comes to cyber, companies are left to fend off nation-state threats on their own. 

Earlier this year, for example, a group claiming to be the ‘Chaos ransomware group’, known for targeting high-profile, US-based construction, manufacturing, and business services companies, gained access to an unnamed company’s internal systems, stole data, and initiated ransom discussions, according to a report from cybersecurity firm Rapid7. Further investigation showed the intruders left a digital signature consistent with the hacking group known as ‘MuddyWater’, affiliated with the Iranian Ministry of Intelligence and Security (MOIS). They appear to have been using ransomware to complicate attribution and cover for espionage, and there is evidence to suggest they’ve been doing this for years.

From the Soviets stealing intellectual property during the Cold War to the Chinese doing the same in the 2010s, nation-state threats to private business aren’t anything new. What has changed, however, is the nature of this activity. The days of espionage being the biggest problem are gone. Our increasingly digital world has allowed for a wider range of hostile actions taken through communications infrastructure, from Russian cyberattacks on a satellite internet provider that served Ukraine, to North Korean targeting of Sony Pictures and the Iranian wiper attack on US medical-device company Stryker.

In an increasingly computerised world, beset by hybrid warfare, private enterprise has often been left alone on the frontlines of geopolitical conflict, directly in the crosshairs of nation-state adversaries.  

Private firms, state targets 

Many utilities, such as power, water, and gas are privately owned. Much of the sensitive technology providing states a military edge is developed by private aerospace and defence firms. The line between private industry and critical national infrastructure has become increasingly blurry, and disruption that used to require a physical presence can now be done from thousands of miles away, giving attackers effective legal immunity and potentially useful ambiguity of intention.

We can see this in action with events such as the Stryker hack, where the Iranian group Handala claimed responsibility for disrupting the operations of the medical firm, including the wiping of devices with no indication of a ransom demand. Handala claimed this was in retaliation for a strike on a school in southern Iran during the war with the US and Israel, and ‘ongoing cyber assaults’. This directly links a cyberattack on a private organisation to kinetic action in an ongoing war, putting private industry in the thick of the action. The US Justice Department has identified Handala as a front for the MOIS. 

Some of the most concerning activity, though, never announces itself. Rather than disrupt or steal, states are increasingly working to establish quiet, durable access – to already be inside an organisation when a crisis arrives. The US Office of the Director of National Intelligence’s 2026 Annual Threat Assessment finds that actors linked to China, Russia, Iran, and North Korea are embedding themselves in critical systems precisely to enable disruption in a future conflict.

Volt Typhoon is the clearest public case: the China-attributed group sat inside telecoms, energy, water, and transport companies for years, using living-off-the-land techniques to stay hidden. Having worked in threat intelligence, I would be astonished if the cases we know about were anything but a fraction.

We privatised national defence and didn’t tell anyone

Police forces protect citizens from threats within, and militaries from threats without. Most societies expect this as a bare minimum from the state. When a bank gets robbed, the state doesn’t come in and fine them for bad security – it comes in to enforce the law. When a foreign army invades, we don’t expect each individual to protect their own plot of land, or to pay the bill for mercenaries.

Cyber defence, meanwhile, is overwhelmingly procured from private companies. And much of their work amounts to national defence. Governments, rather than deal with a threat, fine organisations for not having handled it well themselves. 

Organisations do obviously need to maintain good cyber hygiene – staying within regulations and maintaining common-sense measures to stop breaches. State involvement in tackling this problem, however, feels incredibly insignificant.

There is some work taking place in the public sector to tackle this problem – for example, the UK National Cyber Security Centre’s Active Cyber Defence programme has taken down or removed 1.2 million mass-market criminal campaigns – phishing pages, fake shops, and malware hosting – from the internet in a year.

This is only the first step, however – while tackling phishing, scams, and fraud is good, the task of defending the country’s digital frontlines is nowhere near complete. 

As geopolitics moves further into private industry, and vice versa, organisations will be outmatched against state adversaries. States will increasingly have to take some of that cyber defence burden into their own hands. 

Winning a war you weren’t built to fight

Organisations are being asked to win conflicts they were never structured or resourced for – and many critical national security functions are in their hands.

The private sector is of course home to significant cyber expertise, financial resources, and defensive ability, and has weathered this situation so far. However, this dynamic isn’t something we chose, it’s something we sleepwalked into, and it’s time to address that. The question isn’t whether companies should defend themselves – they must – but whether it’s reasonable to expect an organisation to repel state adversaries while standing alone. 

Defenders are good and getting better, and it still won’t be enough. No amount of private excellence closes a gap that is fundamentally structural. Defence should be returned to the remit of the state, where it belongs.