Summary
The session’s core message was that cyber operations are attractive to state actors, but they are unlikely to substitute for kinetic effects against critical infrastructure on their own. Siddharth Jethwani and Mathis Koch framed the value for infrastructure operators around understanding cyber as part of hybrid conflict: it can disrupt, shape, and amplify physical conditions, but decisive infrastructure outcomes depend heavily on the state of the underlying systems, physical dependencies, and recovery realities. They opened by grounding the audience in the practical consequences of power outages and public concern about whether major conflict effects could reach countries such as the Netherlands.
The speakers first explained why cyber operations appeal to states. They identified four criteria: scalability, outsourceability, reversibility, and deniability. Cyber operations can range from espionage and reconnaissance to disruption and denial; they can be conducted or supported by private groups; some effects can be reversed more easily than physical destruction; and attribution is harder than in kinetic warfare. However, this led to their central question: whether cyber can produce reliable and decisive infrastructure effects. Their answer was cautious, focusing on disruption, cascading effects, and whether recovery remains purely digital or requires physical repair after the cyber act.
The Venezuela case illustrated how alleged cyber intervention was less important to their analysis than the infrastructure conditions surrounding the blackout. They described the 2019 service loss, the disputed claim of U.S. cyber involvement, evidence of fire stress and physical damage, long-term undermaintenance, and Venezuela’s strong dependence on hydroelectricity. Because a large share of power generation came from a small number of turbine drops in one region and was connected to major demand centers through limited high-capacity lines, the system had clear failure potential. The Ukraine case then showed cyber in sequence with physical operations. The speakers discussed the Viasat incident shortly before Russia’s 2022 ground invasion, where AcidRain malware disabled thousands of satellite modems, reduced communications and situational awareness, and complicated early coordination, while still not collapsing Ukraine’s command structure by itself.
The conclusion for operators was practical: prepare for fused cyber, kinetic, sabotage, psychological, and supply-chain threats rather than treating cyber incidents as isolated IT events. Critical infrastructure organizations were urged to secure both digital and physical perimeters, consider dependencies in their supply chain, run simulations, practice manual recovery, and assume compromises can appear at every layer. In the Q&A, when asked about AI’s effect on development, the speaker declined to predict specific three-year outcomes and kept the focus on currently relevant preparedness fundamentals.
Key Topics
5 key topics from Mathis Koch and Siddharth Jethwani at ONE Conference. Thicker branches were mentioned more often in the talk.
Key Takeaways
- Secure both digital and physical infrastructure perimeters.
- Practice manual recovery before hybrid disruptions occur.
- Assume supply-chain compromise across critical infrastructure dependencies.
- Model cyber disruption alongside kinetic and sabotage scenarios.
- Prioritize preparedness beyond minimum compliance requirements.
“the key takeaway from this presentation is to control what you can control.”
Up Next

Next in agenda
Digital Sovereignty and Cloud Computing: technical criteria as one pillar of the European way forward
Philipp Holzmann

Also on critical infrastructure
Keynote: Hybrid Hostilities: Defending Critical Infrastructure in a Hybrid Threat Landscape


Also on critical infrastructure
