Ad
Ad
  • ANALIZA
  • WIADOMOŚCI

Evolution of the cyber within NATO

nato cyber
Photo. NATO

In recent decades, the role of cyberspace within NATO has undergone a profound transformation. From a peripheral area, it has developed into a fully-fledged operational domain, treated on an equal footing with land, sea, air and space.

The development of computer technologies, the internet, communications systems, virtual reality and, more recently, artificial intelligence and quantum technologies has opened new opportunities for the Alliance to act and project power. At the same time, it has created unprecedented challenges to the security of member states.

Ad

The past several decades have therefore been a period of consistent adaptation by NATO to the growing scale and complexity of cyber threats. This process has encompassed the development of operational capabilities, organisational and doctrinal changes, and the creation of specialised cyber structures. As a result, cyber security has ceased to be merely a technical supplement to the Alliance’s activities and has become one of the foundations of its contemporary functioning.

The importance of cyber security to modern military operations first became clearly apparent to NATO at the end of the twentieth century, during the Kosovo War, which was later described as the „first internet war”. During the conflict, Serbian, Russian and Chinese hackers regularly targeted the Alliance’s information infrastructure by altering website content, distributing infected emails and carrying out distributed denial-of-service attacks (DDoS).

The experience of Operation Allied Force brought cyber security onto NATO’s political agenda. In the declaration issued after the 2002 Prague Summit, member states formally committed themselves for the first time to strengthening the Alliance’s ability to defend against cyber-attacks, thereby introducing the cyber domain into NATO’s strategic documents. One of the outcomes was the establishment of the NATO Computer Incident Response Capability (NCIRC), now known as the NATO Cyber Security Centre (NCSC), which is responsible for the round-the-clock protection of the Alliance’s network infrastructure.

The course adopted in Prague was reinforced at the 2006 NATO Summit in Riga, where Alliance leaders announced the development of network-centric capabilities for the exchange of information, data and intelligence, together with enhanced protection of key information systems against cyber-attacks. The real turning point, however, came with the large-scale cyber-attacks against Estonian websites, which began on 27 April 2007 and were attributed to Russia.

For NATO, they served as a warning signal and a direct impetus for the adoption of the Alliance’s first Cyber Defence Policy in 2008 and the establishment of the NATO Cooperative Cyber Defence Centre of Excellence (CCDCOE) in Tallinn.

Another conflict that significantly shaped NATO’s perception of cyberspace was Russia’s invasion of Georgia in 2008. It represented one of the first clear manifestations of the Russian model of hybrid warfare, in which cyber and information operations were conducted both before and alongside conventional military action. NATO’s 2010 Strategic Concept, adopted at the Lisbon Summit, reflected this change by stating that cyber attacks could reach a scale capable of threatening national and Euro-Atlantic prosperity, security and stability.

The following two years were marked by efforts to strengthen the coordination and centralisation of Allied activities. This was supported by NATO’s second Cyber Defence Policy, adopted in 2011, which established an overall framework for cooperation among member states in the face of rapidly evolving technological threats. Its most important result was the full integration of cyber defence into the NATO Defence Planning Process in 2012, enabling the joint identification, development and harmonisation of the Alliance’s cyber capabilities. In the same year, in accordance with the decisions of the NATO Summit in Chicago, the management of NATO networks and information systems was centralised through the establishment of the NATO Communications and Information Agency (NCIA).

The year 2014 brought important doctrinal and legal clarifications to NATO’s approach to cyberspace. Against the backdrop of an increasing number of cyber incidents and Russia’s annexation of Crimea, NATO explicitly linked cyber defence to the Alliance’s core task of collective defence. The new policy, announced at the Wales Summit, confirmed that a serious cyber attack against one Ally could, in principle, lead to the invocation of Article 5 of the North Atlantic Treaty.

At the same time, the Alliance recognised that international law also applies in cyberspace. In practice, this was one of the most important steps towards placing cyberspace on an equal footing with conventional operational domains and incorporating it into the logic of NATO deterrence.

At roughly the same time, the Alliance began fully to recognise the importance of cooperation with external partners for effective cyber defence. One of the most significant manifestations of this approach was the establishment of the NATO Industry Cyber Partnership (NICP), a framework designed to strengthen cooperation between the Alliance and the private sector.

A second key element was closer cooperation with the European Union, culminating in the signing of a technical arrangement on cyber defence in 2016. This cooperation was subsequently deepened in 2018 and 2023, enabling more effective information exchange and closer operational cooperation between the two key organisations of the transatlantic area.

A milestone, and at the same time the culmination of the entire process, was the NATO Summit in Warsaw in July 2016, during which cyberspace was officially recognised as the fifth operational domain, alongside land, sea, air and space. The Cyber Defence Pledge announced at the summit called on member states to make tangible improvements to the resilience of national infrastructure, networks and systems, as well as to their ability to respond rapidly to threats. It was based on the conviction that the cyber security of each Ally is inseparably linked to the security of all the others, and that the Alliance as a whole is only as strong as its weakest link.

An equally important stage was the genuine operational integration of cyberspace into the Alliance’s functioning. In February 2017, an updated Cyber Defence Action Plan and a dedicated road map were adopted in order to enable the practical implementation of the decision previously taken in Warsaw. One year later, at the Brussels Summit, the Allies decided to establish the Cyberspace Operations Centre (CyOC), whose purpose was to enhance situational awareness and response capabilities in cyberspace within NATO’s strengthened command structure. Another important decision was the agreement to allow Allies voluntarily to make national cyber capabilities available for collective Alliance operations.

In February 2019, NATO ministers agreed that the Alliance must use the full spectrum of available tools, including political, diplomatic and military measures, in order to counter cyber threats effectively. Two years later, at the 2021 Brussels Summit, the Allies broadened their existing approach by adopting NATO’s Comprehensive Cyber Defence Policy. It is based on a holistic understanding of cyber defence, encompassing the full spectrum of threats in peacetime, crisis and conflict, at the political, military and technical levels. The summit communiqué also confirmed that serious cyber attacks could be regarded by the Alliance as an armed attack.

Russia’s aggression against Ukraine on 24 February 2022 became a watershed for the further evolution of the cyber domain’s importance. In its aftermath, NATO states found themselves on the front line of Russia’s hybrid warfare, in which cyberspace plays a key role by enabling attacks against public institutions, the private sector and critical infrastructure. In practice, this means that the Alliance has now been operating for more than four years under the conditions of an undeclared cyber war with Russia.

The process of adapting NATO to the new cyber reality is still ongoing. The communiqué from the 2023 Vilnius Summit made clear that the Alliance faces a persistent threat of cyber attacks and that member states are prepared to use the full spectrum of capabilities to counter them, including through collective responses. The decisions taken in Vilnius strengthened the place of cyber defence within NATO’s overall deterrence and defence posture, deepened the Cyber Defence Pledge with a particular emphasis on the protection of critical infrastructure, and led to the establishment of NATO’s Virtual Cyber Incident Support Capability (VCISC), intended to provide rapid assistance to Allies affected by cyber attacks.

The declaration from the Washington Summit one year later envisaged the establishment of the NATO Integrated Cyber Defence Centre (NICC) at Supreme Headquarters Allied Powers Europe (SHAPE) in Belgium. The new structure is intended to integrate existing specialised cyber units and provide NATO military commanders with information on threats in cyberspace, including threats to private and civilian critical infrastructure essential to military operations. Despite the urgency of the initiative, the NICC will not become operational before 2028, primarily because of significant staffing requirements.

The year 2024 was also a breakthrough in terms of NATO’s formal entry into the field of quantum technologies, which may fundamentally change the conditions of cyber security. The adoption of the Alliance’s first quantum strategy was intended to prepare NATO for operating in the coming quantum era. In this context, particular importance was attached to the first plenary meeting of the NATO Transatlantic Quantum Community (TQC), which concluded in Copenhagen on 13 November 2024. During the meeting, the TQC industrial network was developed with the aim of connecting quantum technology developers with NATO’s military end users.

Importantly, cooperation between NATO and the European Union in the cyber domain is also continuing to deepen. On 4 October 2024, the EU and NATO held their first structured dialogue on cyber security, aimed at strengthening cooperation in the field of cyber defence. At the same time, the Alliance is also developing capabilities to increase the resilience of communications infrastructure. On 31 July 2024, NATO launched a project worth USD 2.5 million to develop the ability to reroute data transmissions through satellite links in the event of a threat to undersea fibre-optic cables.

In focusing on the Russian threat, Polish and European observers may nevertheless overlook a second and increasingly important vector of cyber risk: hostile cyber activity by the People’s Republic of China. This is even more significant because the threat is increasingly reflected in NATO’s own debate and activities. A particularly telling example was the campaign conducted by the APT31 hacking group, which is linked to the Chinese authorities, against the Czech Ministry of Foreign Affairs. The campaign, disclosed by Prague on 28 May 2025, was condemned by the Alliance. Its probable motivation was the Czech Republic’s critical policy towards Beijing, demonstrating that cyber threats to Alliance members now originate not only from Moscow but also from Beijing.

Paradoxically, one of the largest blank spots in the most recent phase of NATO’s cyber adaptation remains the brief declaration from the Alliance’s latest summit in The Hague on 25 June 2025. It is the first document published after a NATO summit of heads of state and government since 2005 not to refer directly to cyber threats. At the same time, the Hague Summit may still prove important for the further development of member states’ cyber capabilities, primarily in financial terms.

Chronology of the evolution of cyber domain in NATO
Photo. Chronology of the evolution of cyber domain in NATO

The commitment adopted there to increase annual defence expenditure to a combined total of 5 per cent of GDP includes spending on the protection of critical infrastructure, network defence, civil preparedness, resilience and innovation — all areas with a direct cyber dimension.

The Alliance is currently engaged in a strategic discussion on how further to adapt its posture in cyberspace to the growing number of cyber-attacks and the need to deter potential aggressors more effectively. One of the directions adopted is the further deepening of cooperation with leaders in the private cyber-security sector. Examples include the strategic, non-commercial partnerships with Microsoft, Palo Alto Networks and ESET, announced on 27 May 2026 during the International Conference on Cyber Conflict (CyCon) in Tallinn.

Looking ahead to 2030, one of NATO’s key priorities remains the full implementation of the Digital Transformation Implementation Strategy, which forms the basis for the Alliance’s broad digital modernisation. Its objective is to transform NATO by 2030 into a deeply digitalised, data-centric organisation capable of acting at immediate notice. At the same time, NATO will have to move beyond a narrow understanding of cyber defence and towards the broader concept of cyber resilience.

The issue is no longer solely the protection of military systems against attacks, but the ability of entire states and societies to continue functioning under constant cyber pressure. In practice, this means that the cyber-security architecture must encompass not only the armed forces and state institutions, but also the private sector, critical-infrastructure operators and society as a whole.

It may be assumed that the future trajectory of NATO’s cyber domain will depend both on the scale of the cyber threat and on its place within the broader hierarchy of security challenges. On the basis of the Alliance’s current documents, it can be concluded that cyberspace, alongside outer space, hybrid threats and terrorism, is now among the areas most frequently identified as sources of asymmetric threats to NATO.

Importantly, all three of the other categories are closely intertwined with the cyber domain, which constitutes one of their key operational dimensions. It is all the more likely that cyberspace will remain high on NATO’s strategic agenda because the development of new technologies, including artificial intelligence and quantum technologies, will largely take place within this domain. Cyber will not only remain a permanent element of NATO’s thinking about security but will increasingly permeate all other areas of Alliance deterrence, defence and resilience.

National cyber components — challenges and opportunities

It must nevertheless be understood that, despite these positive changes, NATO is neither omnipotent nor omnipresent in the cyber domain. The Alliance can set the direction, coordinate efforts and connect national capabilities within a broader architecture of deterrence and defence. It cannot, however, build those capabilities on behalf of its member states. In cyberspace, the Alliance is therefore only as strong as its individual states. Its collective potential will always be the product both of the strength, readiness and resilience of national cyber-defence structures and of their gaps, delays and weaknesses.

Among states that possess national cyber components, however, there is no single common model. Rather, there is an entire spectrum of approaches: from active-offensive models, characteristic of the United States, the United Kingdom and France, to more defensive-reactive models, found, among others, in Germany and Spain. These differences are evident at several levels: doctrinal, operational, organisational, and political and legal. In practice, they affect not only how individual states develop and employ their cyber forces, but also the scale and nature of their potential contribution to the capabilities of the Alliance as a whole.

The Alliance’s cyber fragmentation is compounded by profound differences in the maturity and funding of national capabilities. In many states, military cyber components still perform a narrow, primarily defensive function limited to protecting their own military systems, while at the same time suffering from underfunding. They also often lack full integration into a broader and coherent cyber-defence strategy, which in some cases has not yet even been clearly conceptualised.

Poorly defined roles, weak coordination mechanisms and immature frameworks for cooperation also remain problematic, particularly regarding the operational employment of cyber forces in Allied activities.

More about The evolution of cyber forces in NATO countries: here

Ad