Thanks! The Kyivstar dwell time was the detail that stuck with me most. 7 months of access, and they waited for maximum impact. Same pattern with Mikord — sitting and waiting. The patience is what makes state-level actors different from typical ransomware crews.
The IT/OT convergence point is underexplored — most security frameworks still treat them as separate domains. Ukraine learned the hard way they're not.
Thanks! The Kyivstar dwell time was the detail that stuck with me most. 7 months of access, and they waited for maximum impact. Same pattern with Mikord — sitting and waiting. The patience is what makes state-level actors different from typical ransomware crews.
The IT/OT convergence point is underexplored — most security frameworks still treat them as separate domains. Ukraine learned the hard way they're not.