Operation Epic Fury. Volt Typhoon. BRICS Settlement Rails. Your Portfolio's Cyber Risk Just Became a Geopolitical Position.
On February 28, 2026, the United States and Israel struck Iran. Within hours, Iran's cyber proxies activated pre-planted backdoors inside American financial institutions, airports, and defense contractors. The kinetic war is contained to the Middle East. The cyber war has no such borders.
The History You Need Before the Threat Briefing
Ray Dalio has spent decades mapping the same pattern across five centuries of rising and falling empires. The Dutch. The British. The Americans. Each followed a predictable arc: technological and financial innovation built the reserve currency; the reserve currency funded military expansion; military expansion outpaced economic output; debt accumulated; internal wealth gaps widened; external challengers emerged; conflict — trade, financial, or kinetic — followed. He calls Stage 6 the Restructuring. By his framework, the United States entered Stage 6 before 2026.
The symptoms are textbook. US debt now exceeds $37 trillion, with interest payments approaching $1 trillion annually — exceeding the entire defense budget. The top 1% hold 32% of assets. Political polarization is at levels that historically precede institutional breakdown. Foreign inflows into US assets have fallen sharply as confidence in US fiscal management erodes. And in February 2026, the United States launched a major military strike against a sovereign nation's capital. Not a proxy war. Not a sanctions regime. Strikes.
Paul Kennedy wrote about this dynamic in 1987, though few were reading it as a forecast. In The Rise and Fall of the Great Powers, he described the condition he called "imperial overstretch" — the gap between a declining power's global commitments and its ability to fund them. Every empire reaches this point. The mechanism of decline is not defeat. It is the cost of maintaining an order the economy can no longer sustain.
Jared Diamond would add the resource layer. In Collapse, he traced how civilizations unravel not from a single cause but from compounding pressures: environmental stress, economic strain, institutional rigidity, external enemies who arrive precisely when internal resilience is lowest. You don't have to believe the US is collapsing to recognize that compounding pressures produce nonlinear outcomes. When Iran's Hormuz toll disrupted oil flows and BRICS members began settling energy trades in yuan and dirhams, the world Diamond described arrived on the front pages.
Thomas Friedman spent two decades arguing the world was flat — that economic integration would produce peace through mutual dependence. That thesis is over. The world in 2026 is not flat. It is fractured along three fault lines: US-China competition for technological and financial dominance, a Middle East conflict with no clear endpoint, and a global financial architecture under active challenge from BRICS settlement infrastructure. None of these fault lines produce clean attribution. All of them produce cyber spillover.
This matters to PE. Not because portfolio companies are geopolitical targets. Because they are incidental ones — and incidental targeting, at scale, is now the operating model.
February 28, 2026: The Day the Cyber Threat Model Changed
On February 28, 2026, the United States and Israel launched Operation Epic Fury — coordinated air, missile, naval, and cyber strikes against Iran's military command, missile infrastructure, nuclear facilities, and senior leadership. Khamenei was reported killed within hours. The IRGC commander and army chief of staff followed.
Iran retaliated with ballistic missiles and drones against US bases across the region — Bahrain's 5th Fleet headquarters, Kuwait's airport, Al Udeid Air Base in Qatar. Gulf states caught in the crossfire saw strikes on Dubai's Fairmont Hotel and Abu Dhabi's airport. Iran attempted a Hormuz blockade that sent oil markets into volatility unseen since 2008.
And within hours of the first strikes, Iran's cyber proxies activated.
The groups you need to understand are not new. MuddyWater, also tracked as Seedworm, had already planted Python backdoors inside US financial institutions, airports, and defense contractors before the first bomb landed. CISA and Unit 42 confirmed this. APT42 was running spearphishing campaigns against NGOs, media organizations, and academic institutions using macro-laced documents. Pioneer Kitten — the same group that attacked water treatment facility PLCs in 2023 — was running ransomware partnerships with Western criminal affiliates. And Handala, nominally a hacktivist group, was running wiper campaigns that left data permanently destroyed, not ransomed.
The distinction between state-sponsored actors and criminal ransomware groups dissolved years ago. Iran learned this from Russia. Criminal ransomware groups that accept state tasking in exchange for operational freedom are functionally state weapons with financial incentives. They don't limit their targeting to strategic infrastructure. They hit whoever is accessible and profitable. Healthcare. Manufacturing. Financial services. Industrial controls. The same sectors that comprise middle-market PE portfolios.
One data point that deserves more attention than it got: on March 11, 2026, Iran-linked hackers forced Stryker Corporation offline, affecting tens of thousands of employees globally. US officials called it the most significant wartime cyberattack on an American corporate target. Stryker is a medical device manufacturer. Its connection to Operation Epic Fury is zero. Its connection to the sectors Iran has historically targeted — healthcare and manufacturing — is everything. Stryker's portco equivalent across the PE landscape just watched that happen and asked their CISO if they were at risk. Most CISOs said they weren't sure.
The most dangerous word in your portfolio's cyber program right now is "unrelated." Iran's retaliatory campaign doesn't care that your portco makes industrial fasteners. Volt Typhoon doesn't care that your healthcare platform has no China operations. Pre-positioned access doesn't announce itself until a trigger event that your board will not see coming.
The China Problem Is Different — And Older
If Iran's cyber campaign is a retaliatory wildfire, China's is a controlled burn that has been running for years.
Volt Typhoon has been inside US critical infrastructure since at least 2021. Communications networks. Energy grids. Transportation hubs. Water systems. Maritime ports. The FBI Director's characterization was precise: "China's hackers are targeting American civilian critical infrastructure, pre-positioning to cause real-world harm to American citizens and communities in the event of conflict."
The phrase "pre-positioning" is doing significant analytical work in that sentence. This is not espionage in the traditional sense — exfiltrate intelligence, brief the principals, close the operation. Pre-positioning for disruption means the access exists for a future trigger event. The backdoors are planted. The footholds are maintained. The kill switch, when China chooses to activate it, is already inside the wall.
The scenario US defense planners describe: China initiates military action against Taiwan. Simultaneously, Volt Typhoon activates pre-positioned access to create blackouts, communications outages, and water disruptions inside the continental United States. Not to win a military battle. To distract the American public and erode political support for intervention. Russia demonstrated this playbook in Ukraine — Sandworm pre-positioned in Ukrainian infrastructure before the 2022 invasion and used that access to take down power grids in the opening days of conflict.
The 2026 ODNI Annual Threat Assessment confirmed that Volt Typhoon and Salt Typhoon exhibit tactics and target selection that extend beyond traditional cyber espionage. The IISS noted that Volt Typhoon has redrawn the boundary for acceptable state behavior in cyberspace, extending states' freedom of action in peacetime.
For PE, the translation is this: your portcos in energy, manufacturing, healthcare, and communications are already operating inside a compromised environment. Not compromised by their own security failures. Compromised by the infrastructure they depend on — utility providers, telecom carriers, cloud services — that Volt Typhoon has already accessed. When China decides the trigger event has arrived, the impact does not require your portco to be targeted directly. It requires the infrastructure your portco depends on to fail.
The Financial Architecture Shift: Why BRICS Matters to Ransomware Economics
The BRICS dimension is the least discussed and the most consequential for the ransomware threat model.
Here is the chain of causation. The US weaponization of the dollar — sanctions regimes against Russia, Iran, Venezuela, North Korea — created the political demand for alternative settlement rails. India now settles 60 million barrels of oil per month in yuan and dirhams. The New Development Bank has set a target of 30% local currency lending. The Hormuz situation accelerated what was already in motion. The dollar's share of global reserves has been declining since the 2022 Russia sanctions made clear that dollar-denominated assets were a geopolitical liability for any country that might someday be on the wrong side of US foreign policy.
This matters to cybersecurity for a reason that rarely appears in threat intelligence reports: ransomware groups need financial rails to operate. Cryptocurrency was the supposed permanent solution — decentralized, pseudonymous, difficult to trace. It turned out to be traceable. The US government seized Bitcoin from Colonial Pipeline's ransom payment within weeks. Chainalysis built a business following the money. OFAC sanctioned crypto wallets. The on-ramp and off-ramp problem — converting ransomware proceeds to spendable currency — remained a vulnerability for criminal groups.
Alternative settlement infrastructure built for BRICS energy trade is, secondarily, infrastructure for sanctions evasion. Not by design. By consequence. As yuan-denominated settlement rails mature and as more countries build payment systems outside the SWIFT architecture, the ability to trace and seize criminal proceeds decreases. The ransomware groups operating at the intersection of state sponsorship and financial crime will benefit from this shift. Pioneer Kitten, Tarnished Scorpius, and the RaaS ecosystem are watching the same financial architecture changes that PE fund CFOs are watching — and drawing different conclusions.
Wealth concentration adds a second vector. Dalio's Stage 6 framework identifies widening wealth gaps as a driver of internal fracture. In cybersecurity terms, economic dislocation is a recruitment pipeline for criminal cybercrime. The Eastern European ransomware ecosystem that produced LockBit and Conti was built in no small part on technically skilled individuals who had limited legal economic alternatives. Economic conditions that produce more of those individuals produce more of those groups.
What Your Portcos Are Not Accounting For
The standard PE cyber due diligence framework asks the right questions about the wrong threat model.
Current DD frameworks look for: unpatched vulnerabilities, EDR coverage gaps, SOC 2 compliance status, incident history, third-party vendor risk, backup and recovery capability. These are legitimate questions. They catch the bottom 60% of risk. They are almost entirely irrelevant to geopolitically-induced cyber exposure.
The geopolitical threat model looks different. Five things your portcos are not accounting for:
1. Critical infrastructure dependency. Does your portco rely on utility providers, telecom carriers, or industrial control systems vendors with confirmed Volt Typhoon or Salt Typhoon exposure? The company's own security controls are irrelevant if the infrastructure it depends on fails.
2. Sector targeting history. Has Iran, Russia, or a state-affiliated criminal group demonstrably targeted this sector in the last 36 months? Healthcare, manufacturing, financial services, energy, and water-adjacent operations are all on confirmed target lists. This is not speculation — it is CISA's documented guidance.
3. Supply chain exposure. Does your portco use vendors with China-manufactured network equipment, Iranian-exposed cloud services, or offshore development teams in jurisdictions that create access risk? Volt Typhoon specifically uses living-off-the-land techniques through legitimate network infrastructure. The Taiwan-manufactured routers in your portco's server room are not hypothetical attack vectors.
4. Financial operations resilience. If your portco's primary payment processor, payroll system, or ERP vendor went offline for 72 hours during a geopolitically-triggered disruption, what is the financial impact? Stryker didn't lose data. It lost operations. The cost was not a ransom. It was business continuity.
5. Incident response assumptions. Does your portco's IR plan assume a motivated criminal group seeking ransom? Or does it account for a state actor seeking disruption with no negotiating interest? Wiper malware — Handala, BibiWiper, Hatef — destroys data permanently. Paying the ransom doesn't restore operations because there is no ransom. There is only destruction.
The Questions Your Board Hasn't Asked
Paul Kennedy's framework for imperial decline separates the question of whether decline occurs from the question of how fast. The US is not collapsing. The dollar is not being replaced this year. China is not invading Taiwan on a known schedule. Iran's cyber capability, absent state infrastructure, is bounded.
But the strategic environment has shifted in ways that are not reversible in the near term, and the secondary effects on your portfolio's cyber threat model are already active.
The questions boards should be asking now:
Does our portco's threat model reflect the 2026 environment or the 2022 environment? Most mid-market security programs were designed for financially motivated criminal actors. The threat landscape now includes state-affiliated actors with destructive intent, hacktivist groups operating as state proxies, and criminal groups with state relationships. These actors do not behave like ransomware groups. They do not negotiate. They are not deterred by strong EDR.
What is our portco's critical infrastructure dependency map? Most portfolio operators cannot answer this question with specificity. They know who their vendors are. They do not know which of those vendors have confirmed exposure to Volt Typhoon, Salt Typhoon, or Iranian pre-positioned access. That map needs to exist.
Does our portco have a geopolitical trigger scenario in its incident response plan? Most IR plans are built around the assumption of a discrete, attributable event. Geopolitically-triggered disruption often looks like a cascading infrastructure failure with no single point of attribution. The response posture is different. The escalation chain is different. The communication to customers, regulators, and limited partners is different.
What is our aggregate portfolio exposure? PE firms manage diverse portfolios. The question is not whether any individual portco is at risk — most are. The question is whether the fund-level view accounts for correlated risk. If a Volt Typhoon activation takes down power or telecom infrastructure in a metro area, it doesn't hit one portco. It hits the region. If the fund has five portcos in the same geography, the exposure is concentrated in ways that individual portco security assessments will not surface.
The Dalio Reframe
Ray Dalio's Stage 6 framework is, at its core, a risk management argument. His point is not that empires inevitably collapse. His point is that Stage 6 dynamics create non-linear risks that linear models do not price correctly. The institutions and frameworks that managed risk in Stage 4 and Stage 5 — international law, multilateral trade agreements, stable reserve currencies, predictable deterrence — function differently in Stage 6. The rules are being rewritten in real time.
In cyber terms: the threat models, frameworks, and compliance regimes that defined "adequate security" in 2019 were built for a different world order. SOC 2 Type II was designed for a world where your primary adversary was a ransomware group that wanted money. NIST CSF was designed for a world where attribution was possible and deterrence was functional. The 2026 threat environment breaks both assumptions.
Boards that govern by compliance checklist are managing to the old world. The cyber programs that will actually protect portfolio value in the 2026 environment are built on threat intelligence that accounts for geopolitical context, not just vulnerability counts.
Cloudskope advises PE firms and their portfolio companies on exactly this — threat models that reflect the actual operating environment, not the 2019 one. If your current cyber program was built before the world changed, it needs to be rebuilt.
Operation Epic Fury will end. The Hormuz situation will resolve. Iran will reconstitute. What will not change is the structural dynamic that produced it: a declining hegemon under fiscal stress, a rising challenger using pre-positioned cyber access as a coercive instrument, criminal groups with state relationships operating across alternative financial rails, and a BRICS bloc actively building the infrastructure to reduce dollar dependency. Your portcos didn't choose to be inside that risk environment. But they are. The question is whether your cyber program knows it.
.png)
