No organisation can control whether it will face a cyberattack, they can only control their ability to survive one.
A recent cyberattack on US medical technology company Stryker with bases in Ireland, highlights a dangerous trend in modern cyber conflict: the rise of ‘wiper attacks’ on organisations and commercial corporations as a political weapon.
Unlike ransomware, aims extort money from victims, wiper attacks aim to destroy data, cripple systems and materially disrupt operations.
For businesses, the implications are stark. Awareness and preparation are vital – Craig Kennedy, Partner & Head of Cyber Consultancy provides a specialist cyber resilience service to organisations nationally and internationally and here examines the risks and growing imperative for mitigation.
From Extortion to Destruction
For the past decade, ransomware has dominated the cyber threat landscape. Attackers encrypt systems and demand payment in exchange for restoring access.
While deeply damaging, there is scope for recovery. Data may still exist. Systems may still be restored. Backups may save the day.
Wiper attacks change that position completely.
Their purpose is to permanently destroy systems, files and, in some cases, entire networks.
These attacks are often associated with state-linked actors or geopolitical conflict – the Stryker attack has been claimed by pro-Iran hackers.
Often the aim extends beyond the company itself to targeting the wider economic or infrastructure system that company supports.
It’s easy to see how devastating a wiper attack could be in the finance, insurance, energy, marine or aviation sectors
Operational Resilience – it’s not just an IT issue
The Stryker attack illustrates an easily underestimated issue – cyber incidents are no longer simply IT problems. They are events requiring operational resilience.
When systems are wiped, critical operational data can disappear in an instant.
Production lines stop, supply chains stall and communications fail. They are an existential threat to businesses.
In extreme cases, organisations can be forced into manual operations overnight.
The UK and Ireland experienced this during a 2021 ransomware attack on the NHS, which reportedly cost hundreds of millions of Pounds to recover from and forced many hospitals to revert to paper-based processes for months.
A wiper attack causing similar disruption could be infinitely worse by removing the potential to restore encrypted systems.
Warning to Businesses to Expect More of These Attacks
Three trends suggest businesses should take the risk of wiper attacks increasingly seriously.
- Warfare is moving into the private sector through Cyber Businesses are increasingly becoming targets in geopolitical cyber conflict. Multinational firms, critical infrastructure operators and supply chain hubs are particularly attractive targets given the potential scale of disruption and publicity.
- Cyber operations are low-cost compared to military action Traditional military operations are expensive, resource-intensive and highly visible. Cyberattacks can deliver significant disruption at a fraction of the cost, offering states and supporters an attractive alternative to conventional force.
- Plausible Deniability – tactical advantage Cyber operations can be routed through compromised systems, proxy groups and global infrastructure. That makes it difficult to determine who is responsible, giving attackers plausible deniability. A powerful tactical advantage enabling disruption without triggering the immediate political or military consequences of conventional acts of aggression.
What can Businesses Do Now
No organisation can control whether it will face a cyberattack, they can only control their ability to survive one.
Operational resilience planning should assume that systems may be unavailable, data may be destroyed and recovery may take months rather than days.
Professional advice and insight are vital alongside some obvious practical steps that are too often underdeveloped.
- Assume data destruction. Business continuity planning must include the possibility that systems are wiped entirely, not merely encrypted.
- Build recovery around offline resilience. Backups should include offline capability – cloud backups alone may not be enough.
- Prioritise (manual) operational continuity. Identify the processes that must continue. Manual workarounds should be documented, tested and capable of being deployed at speed.
- Understand supply chain dependency. Many destructive attacks affect organisations indirectly through suppliers and service providers. It’s vital to identify critical suppliers, the dependency on them, and how communication would be maintained during a crisis.
- Practise crisis response. Tabletop exercises that simulate catastrophic system loss help leadership teams understand just how quickly operational paralysis can take hold.
The Real Question
Resilience is essential when protection fails.
It’s no longer safe to assume that cyber disruption will be temporary, and businesses must understand how to manage cyber risk in all its forms. Failure to do so brings the risk of the impact being irrecoverable. For clear, professional insight and advice contact Craig Kennedy, Partner and Head of Cyber Consultancy.
Related Insights
The Wrong Cyber Story Is Making Headlines
A recent striking headline reported that AI belonging to a major technology company had hacked into another company's systems during...
Ten Things Every Board Needs to Know About Cyber Risk
Recent developments in artificial intelligence have underlined how quickly the cyber risk landscape is evolving. The recent controlled release of...
How the Escalating Iran Crisis Is Impacting Marine, Aviation and Cyber Risk for Clients
The Middle East has entered a period of severe instability, with the Strait of Hormuz experiencing a rapid escalation in...
Free Webinar: Autonomous Vehicles – The Cyber Risk
With autonomous vehicles poised to redefine mobility, the conversation is shifting from infrastructure and insurance to one of the most...




