CPX’s Andrea Multari on the rise of cyber operations in modern warfare, national security
The VP of Cyber Defense at CPX, shares the evolution of warfare in the digital age, the growing complexity of hybrid conflict, and its implications for governments, businesses, and critical infrastructure
29 April, 2026
TT
16
Warfare is no longer confined to borders, battlefields, or even visible weapons. It is increasingly shaped in the invisible space where networks, data, and critical infrastructure intersect, a space where disruption can be as powerful as destruction. As cyber capabilities become embedded into military strategy, the distinction between civilian and defence domains is eroding, giving rise to a new era of hybrid conflict.
In this conversation, Andrea Multari, VP of Cyber Defence at CPX, traces how conflict has evolved from clearly defined physical domains into a multi-layered battlespace that includes cyber and space. He explains why cyber operations have become a decisive instrument of modern power projection, how recent conflicts have demonstrated the spillover between military operations and civilian systems, and why governments and businesses can no longer treat cyber resilience as separate from national security.
From the changing role of private sector operators on the front lines of conflict to the need for deeper public-private coordination, Multari lays out what it now takes to defend in an environment where escalation is often silent, continuous, and global in reach.
You began your career in the Italian Navy over three decades ago. How has the nature of warfare changed since then?
Thinking back to my early years as a naval officer, the operational world felt clear and well-defined. Military doctrine revolved around three physical domains: land, sea, and air. Technology supported these domains but did not shape them.
Today, that certainty has disappeared. Multi-domain operations (MDO) have expanded the battlespace to include space and, most disruptively, cyber.
Why has cyber emerged as such a disruptive force in modern conflict?
Cyber is unique because it permeates all domains. In modern hybrid conflicts, cyber operations blur the lines between military defence, national security, and the protection of civilian infrastructure.
Cyber is not “IT security in uniform”. It is an operational domain where states manoeuvre, project power, deny access, influence decisions, and create strategic effects, often without triggering open conflict.
Cyber operations today support kinetic military actions by degrading command and control, disrupting intelligence, and manipulating the information environment.
To what extent are the lines between military defence and civilian infrastructure now blurred?
What makes cyber fundamentally different from land, sea, air, and space is that its terrain is largely civilian-owned. Military systems depend on commercial telecommunications, cloud platforms, satellite services, and energy grids. This makes defending military cyber capability inseparable from defending the broader digital ecosystem, forcing us to rethink where national defence begins and ends.
In a hybrid conflict, there is no clean technical line. The boundary is defined by authority, intent, impact, and escalation—and it shifts constantly. Hybrid threat actors exploit this ambiguity, operating below the threshold of war and targeting civilian systems that are strategically vital but politically difficult to defend with military force.
Cyber is the ideal tool for this grey zone strategy. The recent US–Israeli operation against Iran and the subsequent cyber spillover into the Gulf region illustrate this dynamic clearly.
How was cyber integrated into recent military operations, and how did the resulting “cyber spillover” impact civilian infrastructure?
From the outset, cyber activity was integrated into a broader military campaign. Cyber effects disrupted coordination, isolated decision makers, and constrained Iran’s ability to respond. In this context, cyber functioned as a military domain, synchronised with kinetic planning and strategic signalling.
Iran’s response also blended kinetic and cyber operations, but the effects quickly extended beyond military networks, revealing the true complexity of hybrid conflict. Many affected systems, communications backbones, cloud services, aviation platforms, and digital government systems were civilian in ownership but military in relevance. This created heightened cyber pressure on public and private sectors across the region.
This reflects a core truth: in hybrid conflict, strategic effects are often achieved by targeting civilian infrastructure because it is so deeply intertwined with military capability. This grey-zone activity forced national authorities and private operators to respond long before any formal military escalation.
This seems to imply that private companies are now on the front lines. Is that accurate?
Absolutely. Perhaps the most revealing aspect of this conflict is the role of private organisations. Cloud providers, logistics firms, and technology vendors found themselves targeted not because they were combatants, but because they are deeply embedded in national and regional operations.
This underscores a hard reality: in hybrid conflict, private organisations become part of the operational terrain. Their networks and services are now integral to national security.
Given these realities, how should governments and businesses rethink their approach to cyber defence?
One thing is clear: cyber defence can no longer be divided into “military cyber defence” and “civilian critical infrastructure protection.” These are now interdependent components of national and collective security. Military cyber forces cannot operate effectively without resilient civilian infrastructure, and civilian operators cannot withstand sustained hybrid pressure without intelligence, coordination, and support traditionally associated with national defence.
Hybrid conflict demands deep, institutionalised collaboration between governments and the private sector. This requires joint preparation and planning, shared situational awareness, coordinated response mechanisms, and clear escalation pathways.
Resilience must be designed collaboratively, not improvised during crises.
What is your message for regional leaders navigating this evolving threat landscape?
Protecting critical infrastructure is a pillar of deterrence. Hybrid threats ignore borders, which means defences must be interconnected through alliances that share intelligence and coordinate responses.
Leaders must recognise that cyber conflict is a continuous societal condition, making cyber defence a permanent necessity, not just a wartime measure. The Crystal Ball initiative is a strong example of this necessary shift, acting as a collective intelligence-sharing platform to build global resilience against borderless threats.
How does your organisation, CPX, contribute to this effort?
CPX plays a key role in reinforcing the infrastructure of platforms like Crystal Ball and helping organisations turn that shared intelligence into actionable resilience. Our Threat Intelligence Center (TIC), operating under FalconWatch, is the largest of its kind in the UAE and consolidates insights from CPX, the National Security Operations Center, and the newly established Sectoral OT SOC. This integrated approach enables early detection of significant shifts in the threat landscape.






















