When the Siege Becomes the Weather
When governments treat AI-driven cyberattacks as weather, they buy operational calm and spend attribution pressure — and the smallest institutions pay the difference.
On 14 May 2021, staff across Ireland's public hospitals went back to paper. The Conti ransomware crew had locked the Health Service Executive's systems overnight; radiology and diagnostics went dark, records became illegible to the people who needed them, and the post-incident review commissioned from PwC and published that December described a national health service that had been running without a chief information security officer. Five years on, Western officials told Nextgov/FCW in August 2026 that gains in AI capability have pushed attacks of that character from exceptional events toward routine background operations. Reframing an attack as a condition is a policy choice with a bill attached, and the people who pay it are rarely the people who make it.
I want to be honest about the sourcing, because the sourcing is part of the story. The claim arrives from unnamed Western officials, in the passive collective voice that governments use when they want a proposition in the air without anyone standing behind it. There is no directive to read, no agency to write to, no line item. A doctrine that reaches the public anonymously is a doctrine nobody has to defend in a hearing.
What does it mean to call a cyberattack "weather"?
Weather is the category we reserve for harm without an author. You dress for it, you build for it, you insure against it, and you never ask it to explain itself. Routinization is genuine engineering: it is how institutions survive recurring damage without burning out the humans inside them. We test the tornado siren at noon on the first Wednesday of the month, and nobody treats the test as an emergency.
The trouble is that a state-directed intrusion has a person at the other end of it, sitting in a building, drawing a salary from a budget approved by someone. Calling that person's work "the new baseline" performs a small act of forgetting. The forgetting is operationally useful — it lowers the political temperature, keeps the incident-response teams from treating every alert as a crisis — and it is the cheapest line in any budget, because it costs nothing to declare and requires no new appropriation.
Who pays when attribution stops being automatic?
Attribution is not a press release. It is machinery, and the machinery has a record you can check. In October 2018 the U.S. Justice Department indicted seven GRU officers by name. In July 2020 the European Union imposed its first-ever cyber sanctions under its horizontal regime, hitting GRU Unit 74455 over NotPetya and individuals linked to APT10. On 19 July 2021 the United States, the EU, the UK and NATO jointly attributed the Microsoft Exchange compromises to actors affiliated with China's Ministry of State Security, with four indictments unsealed the same day. In February 2024, CISA, the NSA and the FBI told American utilities in plain language that Volt Typhoon had pre-positioned inside water, power, transportation and communications networks — not to steal, but to be there when it mattered. That is one of two negations I will allow myself, because the distinction is the whole point of the advisory.
Every one of those acts was slow, expensive, contested inside government, and irritating to somebody's diplomatic calendar. Each also did the one thing an incident-response playbook cannot: converted an attack into a consequence for the attacker. Weather never gets indicted. If the working assumption inside Western governments is that AI has made intrusions ambient, the political demand for that machinery falls, and the machinery is the kind that atrophies quietly. Here is the tradeoff, named plainly: treating attacks as weather buys operational calm and spends attribution pressure. Calm is felt immediately by the officials who chose it. The attribution deficit is felt years later by whoever is standing under the next thing.
What did the last round of routinization already cost?
There is a precedent nobody quotes enough. When NotPetya tore through Merck in June 2017, the pharmaceutical company filed a claim of roughly $1.4 billion, and its insurers invoked the "hostile or warlike action" exclusion — arguing, in effect, that a Russian military operation was an act of war and therefore uncovered. A New Jersey court sided with Merck in January 2022; the case settled in January 2024 before the state's highest court could rule. Meanwhile, in August 2022, Lloyd's of London instructed its market that standalone cyber policies written from 31 March 2023 must exclude state-backed attacks.
Read those two developments together and you get the quiet consequence of routinization. Once attacks are ambient, the question "who did this, and does it count?" migrates out of foreign ministries and into underwriting departments. An insurance exclusion is a form of attribution: it names a perpetrator category, assigns a harm, and allocates the cost. It arrives with no evidentiary standard the public can inspect, no appeal, and no hearing. Governments that decline to attribute do not abolish attribution. They privatize it.
What does this actually look like at the bottom?
In November 2023, the Municipal Water Authority of Aliquippa, Pennsylvania, found a screen on one of its booster stations displaying a message from CyberAv3ngers, an Iranian-linked group that had gone hunting for internet-exposed Unitronics controllers. The authority serves a few thousand customers. Its people switched the station to manual operation and kept the water moving — which is to say a small municipal utility in Beaver County absorbed a geopolitical event with hand-operated valves and the good sense of the person on shift.
That is the distributional truth underneath the weather metaphor. A hyperscaler has a threat intelligence team, a legal department and a lobbying budget; it can treat constant intrusion as an operating cost and price it in. A county water authority has neither the staff nor the vocabulary, and when the harm is reclassified as background noise, no one arrives to help, because nobody sends help for the climate. The gap between those two experiences is not a gap in technology. It is a gap in who gets to have an emergency.
And there is a slower cost, harder to put in a budget line. Citizens learn what to expect from the pattern of official response. When a school district loses a year of records and the answer is a credit-monitoring letter, when a hospital cancels a month of surgeries and the answer is a resilience framework, people are not lied to — they are simply never told who did it. Over enough repetitions, the absence of an answer becomes the expected shape of the world. That is how a democracy stops asking.
The officials describing this shift are, I think, describing something real. AI has compressed the cost of reconnaissance, phishing and exploit development, and the tempo genuinely has changed. But tempo is a fact and weather is a metaphor, and the metaphor smuggles in a conclusion the fact does not support: that nobody is responsible. Storms have no defendants. Somebody chose to call this a storm.
FAQ
Does treating cyberattacks as routine actually make anyone safer?
It makes response teams more sustainable and it makes attribution less likely, and those two effects do not land on the same people. Hardened institutions gain steadiness. Under-resourced ones — the rural water authority, the county hospital — lose the political urgency that used to bring outside help, because nobody dispatches a task force to deal with the climate.
If governments stop attributing attacks, who decides who is responsible?
Insurers, mostly. Lloyd's of London required state-backed attack exclusions in standalone cyber policies from March 2023, and Merck's insurers spent years arguing that NotPetya was an act of war. When a state declines to name a perpetrator, the naming still happens — it just happens in a claims department, with no evidentiary standard the public can inspect.