Metropolitan Digital

The Conversation

  • Written by Jeremy Straub, Assistant Professor of Computer Science, North Dakota State University

People around the world may be worried about nuclear tensions rising, but I think they’re missing the fact that a major cyberattack could be just as damaging – and hackers are already laying the groundwork.

With the U.S. and Russia[1] pulling out of a key nuclear weapons pact[2] – and beginning to develop new nuclear weapons[3] – plus Iran tensions[4] and North Korea again test-launching missiles[5], the global threat to civilization[6] is high. Some fear a new nuclear arms race[7].

That threat is serious – but another could be as serious, and is less visible to the public. So far, most of the well-known hacking incidents[8], even those with foreign government backing[9], have done little more than steal data[10]. Unfortunately, there are signs that hackers have placed malicious software[11] inside U.S. power and water systems, where it’s lying in wait[12], ready to be triggered. The U.S. military has also reportedly penetrated the computers that control Russian electrical systems[13].

A cyberattack could wreak destruction comparable to a nuclear weapon Students and their teacher practice ‘duck and cover’ during the Cold War. AP Photo/Dan Grossi[14]

Many intrusions already

As someone who studies cybersecurity[15] and information warfare[16], I’m concerned that a cyberattack with widespread impact, an intrusion in one area that spreads to others[17] or a combination[18] of lots of smaller attacks, could cause significant damage, including mass injury and death rivaling the death toll of a nuclear weapon.

Unlike a nuclear weapon, which would vaporize people within 100 feet and kill almost everyone within a half-mile[19], the death toll from most cyberattacks would be slower. People might die from a lack of food, power or gas for heat[20] or from car crashes resulting from a corrupted traffic light system[21]. This could happen over a wide area, resulting in mass injury and even deaths.

This might sound alarmist, but look at what has been happening in recent years, in the U.S. and around the world.

In early 2016, hackers took control of a U.S. treatment plant[22] for drinking water, and changed the chemical mixture[23] used to purify the water. If changes had been made – and gone unnoticed – this could have led to poisonings, an unusable water supply and a lack of water.

In 2016 and 2017, hackers shut down major sections[24] of the power grid in Ukraine[25]. This attack was milder than it could have been, as no equipment was destroyed during it[26], despite the ability to do so. Officials think it was designed to send a message[27]. In 2018, unknown cybercriminals gained access throughout the United Kingdom’s electricity system[28]; in 2019 a similar incursion may have penetrated the U.S. grid[29].

In August 2017, a Saudi Arabian petrochemical plant was hit by hackers who tried to blow up equipment[30] by taking control of the same types of electronics used in industrial facilities of all kinds throughout the world. Just a few months later, hackers shut down monitoring systems for oil and gas pipelines[31] across the U.S. This primarily caused logistical problems – but it showed how an insecure contractor’s systems could potentially cause problems for primary ones.

The FBI has even warned that hackers are targeting nuclear facilities[32]. A compromised nuclear facility could result in the discharge of radioactive material[33], chemicals or even possibly a reactor meltdown. A cyberattack could cause an event similar to the incident in Chernobyl[34]. That explosion, caused by inadvertent error, resulted in[35] 50 deaths and evacuation of 120,000 and has left parts of the region uninhabitable for thousands of years into the future.

A cyberattack could wreak destruction comparable to a nuclear weapon A test of a North Korean missile. KRT via AP Video[36]

Mutual assured destruction

My concern is not intended to downplay the devastating and immediate effects of a nuclear attack. Rather, it’s to point out that some of the international protections against nuclear conflicts don’t exist for cyberattacks. For instance, the idea of “mutual assured destruction[37]” suggests that no country should launch a nuclear weapon at another nuclear-armed nation: The launch would likely be detected, and the target nation would launch its own weapons in response, destroying both nations.

Cyberattackers have fewer inhibitions[38]. For one thing, it’s much easier to disguise the source of a digital incursion than it is to hide where a missile blasted off from. Further, cyberwarfare can start small, targeting even a single phone or laptop[39]. Larger attacks might target businesses[40], such as banks[41] or hotels[42], or a government agency[43]. But those aren’t enough to escalate a conflict to the nuclear scale.

Nuclear grade cyberattacks

There are three basic scenarios for how a nuclear grade cyberattack might develop. It could start modestly, with one country’s intelligence service stealing, deleting or compromising another nation’s military data. Successive rounds of retaliation could expand the scope of the attacks and the severity of the damage to civilian life.

In another situation, a nation or a terrorist organization could unleash a massively destructive cyberattack – targeting several electricity utilities, water treatment facilities or industrial plants at once, or in combination with each other to compound the damage.

Perhaps the most concerning possibility, though, is that it might happen by mistake. On several occasions, human and mechanical errors very nearly destroyed the world[44] during the Cold War; something analogous could happen in the software and hardware of the digital realm.

A cyberattack could wreak destruction comparable to a nuclear weapon A cyberattack wouldn’t be launched from a nuclear operator’s console, like the one shown here from the decommissioned Oscar Zero site, but rather through cyberspace. A human might not even be required. Jeremy Straub

Defending against disaster

Just as there is no way to completely protect against a nuclear attack, there are only ways to make devastating cyberattacks less likely.

The first is that governments, businesses and regular people need to secure their systems to prevent outside intruders from finding their way in, and then exploiting their connections and access to dive deeper.

Critical systems, like those at public utilities, transportation companies and firms that use hazardous chemicals, need to be much more secure. One analysis found that only about one-fifth of companies that use computers to control industrial machinery[45] in the U.S. even monitor their equipment to detect potential attacks – and that in 40% of the attacks they did catch, the intruder had been accessing the system for more than a year[46]. Another survey found that nearly three-quarters of energy companies[47] had experienced some sort of network intrusion in the previous year.

A cyberattack could wreak destruction comparable to a nuclear weapon Industrial control rooms like this often contain vulnerable computer systems. nostal6ie/[48]

But all those systems can’t be protected without skilled cybersecurity staffs to handle the work. At present, nearly a quarter[49] of all cybersecurity jobs in the U.S. are vacant, with more positions opening up[50] than there are people to fill them. One recruiter has expressed concern that even some of the jobs that are filled are held by people who aren’t qualified[51] to do them. The solution is more training and education, to teach people the skills they need to do cybersecurity work, and to keep existing workers up to date on the latest threats and defense strategies.

If the world is to hold off major cyberattacks[52] – including some with the potential to be as damaging as a nuclear strike – it will be up to each person, each company, each government agency to work on its own and together to secure the vital systems on which people’s lives depend.


  1. ^ U.S. and Russia (
  2. ^ key nuclear weapons pact (
  3. ^ beginning to develop new nuclear weapons (
  4. ^ Iran tensions (
  5. ^ again test-launching missiles (
  6. ^ global threat to civilization (
  7. ^ new nuclear arms race (
  8. ^ most of the well-known hacking incidents (
  9. ^ foreign government backing (
  10. ^ steal data (
  11. ^ hackers have placed malicious software (
  12. ^ lying in wait (
  13. ^ computers that control Russian electrical systems (
  14. ^ AP Photo/Dan Grossi (
  15. ^ cybersecurity (
  16. ^ information warfare (
  17. ^ that spreads to others (
  18. ^ combination (
  19. ^ which would vaporize people within 100 feet and kill almost everyone within a half-mile (
  20. ^ lack of food, power or gas for heat (
  21. ^ corrupted traffic light system (
  22. ^ took control of a U.S. treatment plant (
  23. ^ changed the chemical mixture (
  24. ^ major sections (
  25. ^ power grid in Ukraine (
  26. ^ equipment was destroyed during it (
  27. ^ designed to send a message (
  28. ^ throughout the United Kingdom’s electricity system (
  29. ^ penetrated the U.S. grid (
  30. ^ hackers who tried to blow up equipment (
  31. ^ monitoring systems for oil and gas pipelines (
  32. ^ hackers are targeting nuclear facilities (
  33. ^ discharge of radioactive material (
  34. ^ incident in Chernobyl (
  35. ^ resulted in (
  36. ^ KRT via AP Video (
  37. ^ mutual assured destruction (
  38. ^ fewer inhibitions (
  39. ^ phone or laptop (
  40. ^ businesses (
  41. ^ banks (
  42. ^ hotels (
  43. ^ government agency (
  44. ^ nearly destroyed the world (
  45. ^ only about one-fifth of companies that use computers to control industrial machinery (
  46. ^ accessing the system for more than a year (
  47. ^ nearly three-quarters of energy companies (
  48. ^ nostal6ie/ (
  49. ^ nearly a quarter (
  50. ^ more positions opening up (
  51. ^ held by people who aren’t qualified (
  52. ^ hold off major cyberattacks (

Authors: Jeremy Straub, Assistant Professor of Computer Science, North Dakota State University

Read more

Metropolitan republishes selected articles from The Conversation USA with permission

Visit The Conversation to see more

Entertainment News

Phish’s 2018 Fall Tour to Conclude with Four Performances at MGM Grand Garden Arena

LAS VEGAS (May 15, 2018) – Phish, the American rock band known worldwide for its dedicated fan base, recently announced a 14-date Fall tour which will conclude in Las Vegas with four performances at...

Blane Ferguson - avatar Blane Ferguson

Dave Damiani and The No Vacancy Orchestra are “Bending The Standard”

Tina Sinatra, Dave Damiani & Landau Murphy Jr. celebrate 100 years of Frank Sinatra in Los Angeles There have been stories about independent filmmakers, but how about the independent big band...

Tom Estey - avatar Tom Estey

Billboard Chart-Topping Saxophonist VANDELL ANDREW Returns With New Single

From the vantage point of 30, his age and the name of his infectious, sensually grooving new full length album, Vandell continues to be fueled by the impressive roar of accolades and achievements th...

Metropolitan Digital - avatar Metropolitan Digital

Metropolitan Business News

Office Cleaner Takes Ownership of the Neglected Dishwasher

In an office that a dishwasher is being used communally, it is pretty difficult to set rules on how a certain appliance needs to be taken cared of. A dishwasher is a responsibility of no one until you...

News Company - avatar News Company

Amazing tips to become a successful trader

Everyone is working very hard to secure their financial freedom. Most of the people find it hard to support their family even after having a 9-5 day job. For this very reason, people often look for ...

News Company - avatar News Company

Best Practice For Young Professionals Working Through HR Internships

The industry of human relations is vitally important to the health and prosperity of a business.   Whether they are operating in textile manufacturing, accounting, sports, IT development or hospit...

News Company - avatar News Company

4 Easy Steps To Gaining SEO Momentum For Your Business

SEO (search engine optimisation) does not have to be a tiresome and overbearing exercise that diverts attention away from the core functions of a business.   SEO Shark affirms this as a smart and ...

News Company - avatar News Company

How to Manage An SEO Project On Limited Funds

SEO operators don’t need thousands upon thousands of dollars to become successful.   What SEO practitioners needs more than ever is the skills and diligence to identify problems that are acting a...

News Company - avatar News Company

An Introduction To Coworking For Australian Business Owners

Advancing technology is bringing with it great advantages in communications and networking, and to survive in business you need to keep up. With the rate at which everything changes these days, that...

News Company - avatar News Company


New Baggage Regulations to Help Aussie Parents Travel with Infants

Travelling around the globe has never been easy, especially when infants tag along for the trip. One of the main issues that parents often have to deal with is the need to bring extra item...

News Company - avatar News Company

Maya Beach Opens to Tourists

Despite recent reports that Southern Thailand's famous Maya Beach will close for three months this year, in fact no decision to this effect has been made by Thai authorities. Phi Phi Nati...

Maevadi Rosenfeldt - avatar Maevadi Rosenfeldt


SKYN®, Australia’s best-selling condom*, today launches its very first SKYN® Places of Intimacy Guide.   Curated in partnership with GQ Magazine and Conde Nast, the Guide features 30 lux...

SKYN - avatar SKYN