Matthew Heiman kicks off this episode of the podcast with a breakdown of Russia's attack on Ukraine's largest mobile operator. The attack was strikingly effective in destroying much of Kyivstar's infrastructure, and strikingly ineffective in achieving any meaningful Russian objectives, since service was quickly restored. Perhaps to even up the score, Ukraine supporters launched an even less effective cyberattack on an Iranian medical software company, presumably as retribution for Iran's supplying drones to Russia.
Hacking as an act of war may turn out to be more important in court than on the battlefield, at least when the victims file insurance claims, Jim Dempsey tells us. Merck's effort to get insurance coverage for its NotPetya losses despite an act of war exclusion has been settled. Which means that, if you want to know what cyberwar means for your insurance coverage, you need to review your current policy, which has almost certainly changed since the Merck case began.
Moving to the world of cybersecurity regulation, Cristin Flynn Goodwin recommends digging into the output of the reigning American champion for prescriptive cybersecurity rules, New York's Department of Financial Services, which recently sanctioned a cryptocurrency firm for a host of violations, including insufficient cybersecurity.