When cyberattacks become battles over meaning
Cyberattacks don’t just disrupt systems – they shape perceptions, narratives and trust. Strategic communication is key to resilience.
When a cyberattack occurs, the key issue is not only the technical damage. It is also how the attack is interpreted, discussed, and explained in public. In some cases, these interpretations can have wider societal consequences than the immediate technical disruption itself. Distributed denial-of-service (DDoS) attacks, ransomware, cyber espionage, phishing, and data breaches are examples of cyberattack methods. In addition to financial losses, such attacks can cause social, physical, and psychological harm.
Cyberattacks can have long-lasting impacts. Even after technical recovery is completed, informational recovery can take a long time. This recovery depends on the traces an incident leaves in people’s minds and on how people interpret and perceive an organisation’s actions during and after an incident. From an organisational perspective, a cyberattack is a crisis that challenges leadership and communications and may jeopardise the organisation’s future. Similarly, attacks targeting sectors critical to society's functioning, as well as recurring and prolonged cyber disruptions, can undermine societal security and stability.
What matters is not only the cyberattack itself, but also the story that forms around it. For example, a ransomware attack against a municipality can be seen as a routine criminal act, part of a broader hybrid influence campaign, or a sign of institutional failure or incompetence. Each viewpoint points to different causes and motives. This shapes how citizens, the media, policymakers, and organisations respond. As a result, the impacts of a cyberattack are shaped not only by technical damage but also by public sensemaking and debate.
Cyberattacks can be an effective and attractive tool for malign influencers. Hacking is usually understood as the compromise of ICT systems and infrastructure. However, perceptions and interpretations surrounding an incident can also be “hacked,”. This shapes how people understand what happened, why it happened, and what it means. Let’s think about a data breach. When a system is compromised, the effects extend not only to the people directly connected to that system but also to wider audiences who learn about the incident through news media, social media, or even from a next-door neighbour they happen to meet while waiting in line at the grocery store. Their perceptions, interpretations, trust, and behaviour may also be affected.
Therefore, it is important to remember that cyberattacks can serve as instruments of information influence, either independently or as part of broader influence operations. Conversely, information operations can amplify the effects of cyberattacks, obscure the situational picture and attribution, or facilitate attacks through manipulation. Ordinary financially motivated cyberattacks can also become influence-relevant. They might generate influence effects unintentionally. When uncertainty surrounds the incident, and facts are not known, the air is filled with competing narratives and interpretations. The targeted organisation, external experts and commentators, political actors, media and social media may compete to explain what has happened before reliable evidence is available. At worst, the incident may be linked to actors and issues that have nothing to do with it. This speculative spiral may then begin to serve the objectives of a hostile external influence actor. This can happen organically, without anyone actively directing or manipulating the discussion.
Therefore, what matters is not only what actually happened, but also what people believe may have happened. Their perceptions and interpretations of the incident also matter. These can be shaped and influenced by others. Those who succeed in framing the public discussion and media coverage can influence how the incident is understood. Seizing the communications initiative can therefore provide an advantage in the struggle over meaning. The better people can contextualise events, understand their background and consequences, and place them in a broader perspective, the better they can act during disruptive situations.
From the perspective of preparedness and resilience, both organisations and society as a whole need to understand the interconnections between cyber and information environments, as well as the relationships and effects between activities taking place within them. Strategic communication is central because it supports preparation for and response to cyber influence operations.
One of the challenges in responding to cyberattacks is identifying the actors and motives behind them. The situation can be chaotic, while at the same time there is pressure to provide answers quickly. But what should you do when there are no certain answers to give?
The situational picture is often built from the observations and information of multiple actors. Up-to-date information may arrive in fragments, and the connections between events in the cyber and information environments can be difficult to grasp. What appears clear at first may turn out to be something entirely different as new information emerges. In an unclear situation, there is a risk that gaps in knowledge are filled with assumptions and that answers are sought through speculation before sufficient facts have been verified.
From an organisational perspective, it is essential to recognise when a cyberattack begins to take on meanings that extend beyond the original incident. Interpretations circulating in public may start to reinforce one another, creating a self-perpetuating cycle of influence. At that point, attention is no longer focused solely on what happened to the systems, but also on who might have carried out the attack, why they did it, and what the incident supposedly tells us about the targeted organisation or society. The risk is that unrelated issues become connected and conclusions are drawn that are not supported by facts. In such a situation, society may end up undermining itself. The cyberattack then becomes influence-relevant from the perspective of information influence as well.
Recognising this development early is important. Through communication, an organisation can help prevent unfounded interpretations from becoming established and make clear what is known, what is not yet known, and what is still being investigated. Uncertainty cannot always be eliminated quickly, but it can be managed.
If there is nothing new to report at a particular moment, it is worth saying that too. It is a better option than retreating into the potato cellar and remaining silent until all the facts are known. An information vacuum rarely stays empty: if the organisation does not explain what it knows and what it is doing, others can easily begin filling the void with their own interpretations. Communication does not therefore need to provide all the answers to be useful.
Jussi Toivanen
Head of Communications
Finnish Transport and Communications Agency Traficom/National Cyber Security Centre
Marianne Lindroth
Doctoral Researcher
Aalto University
Show other posts from this blog