Cyber-Resilience Under Isolation

Ahura
Independent researcher · ahuraintel.com · Istanbul
Incoming MA, International Relations (Beykent University) · BSc Cybersecurity Engineering (Tallinn University of Technology)

Working Paper No. AI-WP-01 · Version 0.7 (living document) · Last updated 28 July 2026
Status: ongoing. A working paper circulated for discussion. Sections marked [OPEN] flag questions still in development. This is my secondary research strand; the primary strand is Internet Shutdowns as a Governance Instrument. Comments welcome via contact.

Suggested citation: Ahura, A. (2026). Cyber-Resilience Under Isolation. ahuraintel.com Working Paper AI-WP-01, v0.7.

Abstract

Almost all mainstream cybersecurity guidance quietly assumes a connected, cooperating country: one that can buy commercial tooling, join international information-sharing bodies, call a vendor, patch from a global update channel, and adopt an off-the-shelf governance framework. This paper is about what happens when those assumptions are removed, by sanctions, by international isolation, or by deliberate self-disconnection, and yet the infrastructure still has to be defended and the population still has to be served. I argue that isolation does not merely make standard cybersecurity harder; it changes the shape of the problem, forcing distinctive institutional, technical, and economic substitutes whose study has value well beyond the isolated cases themselves. The paper sets out the assumption-failure at the heart of the field, develops four research strands (comparative resilience models, shutdowns as infrastructure-governance failure, minimum-viable incident-response capacity, and the security supply chain under sanctions), proposes a preliminary way to characterize resilience-under-constraint, and lays out an open research agenda. Throughout, the stance is strictly policy-analytical: resilience-under-constraint is a systems-and-institutions question, and studying it is not an endorsement of the constraint.

Keywords: cyber-resilience · sanctions · digital isolation · critical information infrastructure · CSIRT · incident response · digital sovereignty · security supply chain · developing-country cybersecurity


1. The question, and why it resists the standard answers

The question I keep coming back to is simple to state and hard to answer: how do states and organizations that are cut off, by sanctions, by international isolation, by infrastructure failure, build cyber-resilience when they cannot lean on the OECD or EU frameworks, vendor ecosystems, and cooperation channels that everyone else takes for granted?

Most of the world's cybersecurity guidance assumes a connected, cooperating country. You can buy the tooling. You can join the information-sharing bodies. You can call the vendor. You can adopt the framework. Remove those assumptions and the guidance does not degrade gracefully. Much of it simply stops applying. Yet hundreds of millions of people live and work behind exactly those removed assumptions. Their hospitals, banks, power grids, and ministries still get attacked. Someone still has to defend them, with a toolkit the standard literature does not describe.

This is not a niche concern. It sits at the intersection of three large trends: the spread of sanctions as a routine instrument of statecraft, the deliberate fragmentation of the global internet into national and regional zones ("splinternet" dynamics), and the rapid digitalization of public services in precisely the low-capacity, politically-constrained states least able to secure them. The isolated case is, increasingly, not the exception but a preview of a more fragmented digital order.

1.1 Why me, why this

This agenda is not academic curiosity; it grew out of lived facts. My bachelor's thesis at Tallinn University of Technology examined VPN solutions for peer-to-peer content delivery under national network restrictions, including fieldwork interviewing people who depended on those workarounds to reach their own families. Later I experienced national-scale internet shutdowns from the inside, running a consulting practice through them. My incoming MA in International Relations adds the regional and institutional lens the technical training alone never provided. I can study this question honestly because I have lived on both sides of it: as the engineer defending systems, and as the user cut off from them. That dual vantage is the point, this is a problem that neither pure technologists nor pure policy scholars tend to see whole.


2. The assumption-failure at the center of the field

It is worth being precise about which assumptions fail under isolation, because the failures are specific and they compound. Standard cybersecurity practice, as codified in frameworks like ISO/IEC 27001, the NIST Cybersecurity Framework, and the guidance of bodies like ENISA, rests on a set of quiet preconditions:

  1. Market access. You can procure commercial security tooling, endpoint protection, SIEM platforms, threat-intelligence feeds, hardware security modules, from a global vendor market.
  2. Update and patch channels. You can reach the global software supply chain to receive patches, signatures, and certificate infrastructure.
  3. Cooperation membership. You can join international incident-response and information-sharing communities (FIRST, sector ISACs, regional CSIRT networks) and receive early warning from them.
  4. Framework adoptability. You can adopt an internationally-maintained governance framework and expect its assumptions (rule of law, independent regulators, a functioning market) to hold.
  5. Talent mobility. Your defenders can train, certify, and exchange knowledge through the global professional ecosystem.

Isolation removes these selectively and unevenly. Sanctions may cut market access and update channels while leaving talent partially mobile. Political isolation may bar cooperation membership while leaving the market technically open. Self-disconnection (a national intranet, aggressive filtering) may preserve domestic capacity while severing external early warning. The research value is in the substitutes: what emerges to replace each failed assumption, how well it works, and what it costs. A patched-together resilience built without dependence on any of the five preconditions is not only interesting in itself; it is a stress test of which parts of "best practice" are essential and which are merely conventional. [OPEN: I am building a structured matrix of assumption-to-substitute mappings, which failure forces which workaround, as the analytical spine of this strand.]


3. Research strand 1 — comparative resilience models

How do isolated states actually organize cyber-defense, institutionally, technically, economically, compared with states embedded in OECD/EU frameworks? The two sharpest contrasts are Iran and North Korea, and they are instructive precisely because they represent opposite adaptations to isolation.

  • Iran has developed a substantial domestic cyber capacity shaped defensively by direct experience of attack. The Stuxnet operation against Iranian nuclear infrastructure (widely analyzed as the first known cyber-weapon to cause physical damage) is frequently cited as a formative shock that accelerated an indigenous, retaliation-oriented doctrine and heavy investment in a state-controlled national network architecture. Iran's model substitutes domestic control and self-sufficiency for external cooperation.
  • North Korea represents a different adaptation: an extremely isolated state whose cyber capacity is oriented less toward critical-infrastructure defense than toward sanctions evasion and revenue generation, an offensive-economic model rather than a defensive-resilience one.

The comparative question is what substitutes each develops for the cooperation channels it cannot access, and at what cost. A recurring finding in the security-studies literature (for example, analyses of Iran/Russia/North Korea/China cyber strategies in outlets such as the Small Wars Journal and the work of think tanks including the Carnegie Endowment and RAND) is that isolated states often substitute peer cooperation among fellow-isolated or non-aligned states for the Western-aligned frameworks they are shut out of, an alternative governance channel that the OECD/EU-centric literature rarely models. Understanding these alternative channels matters not to endorse them but to see the full map of how resilience is actually organized outside the wealthy-country club.

3.1 A connected baseline, for contrast: what Estonia shows

Comparison needs a baseline, and I have one I know from the inside, having done my degree in Estonia. Estonia is the standard reference case for a connected, cooperating small state: heavily digitalized public services, a mature national CERT, deep integration into EU and NATO cyber structures (it hosts the NATO Cooperative Cyber Defence Centre of Excellence), and a national security posture visibly shaped by the 2007 cyberattacks it suffered. Estonia's resilience is built on the five preconditions of Section 2, market access, update channels, cooperation membership, framework adoptability, talent mobility, rather than in their absence.

Placing Estonia beside Iran and North Korea sharpens the research question. It is not that isolated states have "less" of the same thing; they build resilience of a different shape, load-bearing in different places. Estonia can lean on collective defense and shared early warning; the isolated state must internalize both. Estonia can adopt EU frameworks wholesale; the isolated state must construct governance from local materials. The comparison isolates the variable that actually matters, not resources per se, but access to cooperation, and lets me ask what a state can and cannot substitute for it. [OPEN: Estonia also fuses cyber-resilience with digital-government maturity in a way most states do not; whether that fusion is separable from its connected status is a question I want to test.]


4. Research strand 2 — shutdowns as infrastructure-governance failure

National internet shutdowns can be studied not (only) as a rights abuse but as an infrastructure-governance problem: what breaks first, what recovers slowest, what institutional capacity determines whether digital trust can be rebuilt afterward. This strand deliberately brackets the political question and treats the shutdown as a stress event applied to a socio-technical system, the unit of study is the system, not the regime.

Key questions in this strand:

  • Failure order. When connectivity is withdrawn and restored, which dependent systems fail and recover in which sequence, banking, health, logistics, identity, payments, and what does that reveal about hidden single points of dependence?
  • Recovery and trust. Rebuilding connectivity is not the same as rebuilding trust in the digital services that ran on it. What institutional capacity (incident response, communication, compensation, transparency) determines whether users and businesses return to digital channels after a shutdown, or permanently retreat to cash and paper?
  • Resilience-by-design. What does it mean to design critical services to degrade gracefully under deliberate connectivity withdrawal, rather than fail catastrophically?

This strand is the bridge to my primary research (see Internet Shutdowns as a Governance Instrument): the primary paper studies the shutdown as a governance instrument and its accountability; this strand studies the shutdown as an infrastructure stressor and the resilience and recovery it demands. The two are complementary halves of one problem, one asks who is answerable for the disruption, the other asks how the system survives it.


5. Research strand 3 — CSIRT and incident-response capacity-building

What is the minimum viable national incident-response capability, and how have states outside the wealthy-country club actually built one? The Computer Security Incident Response Team (CSIRT / CERT) is the basic institutional unit of national cyber-defense, the body that receives reports, coordinates response, and connects (where possible) to the international FIRST community. Yet a large share of the world's states either lack an operational national CSIRT or have one that exists on paper only.

The evidence base for this strand is unusually good, because development institutions have invested in it and documented it:

  • The World Bank has financed cyber-resilience and CSIRT capacity-building across dozens of developing countries, and its analysis explicitly addresses fragile and conflict-affected settings undergoing digital transformation, exactly the isolation-adjacent contexts this paper cares about.
  • The ITU's Global Cybersecurity Index provides a comparative, longitudinal measure of national cybersecurity capacity, including incident-response maturity, that makes the capacity gap visible and trackable (itu.int).
  • Ghana is a leading positive case: a sustained, decade-scale build-out of national cybersecurity institutions, including a national CSIRT and a dedicated Cyber Security Authority, produced a marked, measurable improvement in the country's international cybersecurity-capacity ranking. It is a rare, well-documented instance of a non-wealthy state deliberately constructing incident-response capacity roughly from scratch, and therefore a template worth close study.
  • The IFIP ICCIP (Critical Infrastructure Protection) conference series has, since at least 2012, published peer-reviewed work specifically on CIIP frameworks for developing countries, confirming this is an established subfield rather than a novelty.

The core research question is institutional-comparative: what governance-design factors, funding model, legal mandate, sector coordination, talent pipeline, explain why some capacity-constrained states stand up a functioning CSIRT while most do not? [OPEN: I am assembling a small-N comparison of successful vs. stalled national CSIRT build-outs, with Ghana as the anchor positive case, to isolate the design factors that travel.]

5.1 What "minimum viable" actually means

"Minimum viable incident-response capability" is easy to say and worth defining concretely, because a great deal of stalled capacity-building consists of building the wrong thing, an org chart without the operational core. Drawing on the FIRST community's service-framework thinking and the CSIRT-maturity literature, a defensible minimum has four load-bearing elements:

  1. A trusted reporting channel. A single, known, reachable point of contact that organizations and citizens can use to report incidents, and that is trusted enough to actually be used. Without this, nothing downstream functions.
  2. A coordination mandate. Legal or institutional authority to convene the relevant actors during an incident, telecoms, banks, ministries, so that response is coordinated rather than each victim fighting alone.
  3. A baseline situational-awareness function. Enough monitoring and threat-information capacity to know, roughly, what is happening across the national infrastructure, even if reconstructed from public frameworks rather than commercial feeds.
  4. A recovery and communication function. The ability to help restore services and to communicate credibly with the public during and after an incident, which, as Strand 2 argues, is what determines whether digital trust survives.

Everything else, advanced forensics, threat hunting, red-teaming, is capability above the minimum. The research value of defining the floor precisely is that it separates the states that have a functioning core from the far larger set that have a CSIRT on paper, a name and a logo without a reachable duty officer. The isolation lens matters here because each of the four elements is achievable without the five preconditions of Section 2, which is exactly why the minimum is the right unit of study for constrained states. [OPEN: can this four-element floor be turned into a lightweight assessment instrument usable in fragile settings, where the full ITU index is too heavy?]


6. Research strand 4 — sanctions and the security supply chain

What happens to patching, tooling, threat intelligence, and cloud dependence when a country's defenders are cut off from the commercial security market, and what do the workarounds teach everyone else about resilience without dependence?

This is the most technically concrete strand, and the one where my engineering background is most directly useful. Sanctions and market withdrawal produce specific, cascading security consequences:

  • Patch starvation. When access to global update channels is degraded, systems fall behind on security patches, widening the exploitable window, and defenders must improvise alternative distribution (mirrors, manual patching, backported fixes).
  • Tooling substitution. Cut off from commercial security products, defenders turn to open-source alternatives and self-built tooling. Open-source becomes not an ideological preference but a strategic necessity, which has real implications for which capabilities are reachable and which are not.
  • Threat-intelligence blindness. Isolation from commercial and community threat feeds means defenders lose early warning and must reconstruct situational awareness from public frameworks (for example, MITRE ATT&CK) and their own telemetry.
  • Certificate and trust-infrastructure fragility. Dependence on globally-operated certificate authorities and trust infrastructure becomes a chokepoint; withdrawal of these services (as documented in some recent sanctions episodes affecting developer platforms and certificate services) can break the basic machinery of secure communication.

The counter-intuitive value of this strand is that resilience-without-dependence is a general lesson, not a niche one. Every organization that studies how isolated defenders survive patch starvation and tooling withdrawal learns something transferable about reducing its own hidden dependencies, a concern that has become mainstream everywhere after a decade of high-profile software-supply-chain compromises. The isolated case is, again, a stress test that reveals which dependencies are load-bearing.

6.1 A concrete anatomy: what patch starvation actually does

To keep this strand grounded rather than abstract, it helps to trace a single dependency failure through its consequences, because the second- and third-order effects are where the real damage lives. Consider the loss of reliable access to the global software-update supply chain.

  • First order: known vulnerabilities go unpatched. The exploitable window, normally measured in the days or weeks between a patch's release and its installation, stretches open indefinitely. Attackers do not need novel capabilities; the publicly-documented, already-fixed vulnerability becomes a permanent open door.
  • Second order: defenders improvise distribution, mirrors, manual patching, backported fixes, unofficial repositories. Each workaround is itself a new trust problem: an unofficial patch mirror is an ideal supply-chain attack vector, so the substitute for the failed dependency introduces a fresh dependency on the integrity of the workaround.
  • Third order: the rational response to an untrustworthy update channel is to update less, which compounds the first-order problem. Isolation thus creates a vicious loop, the safer it feels to avoid a compromised channel, the more unpatched the estate becomes.

This anatomy generalizes. Each of the four failures in this strand, patch starvation, tooling withdrawal, intelligence blindness, trust-infrastructure fragility, follows the same pattern: the substitute for a lost external dependency introduces a new internal one, and the cost of isolation is not a single gap but a chain of compounding second-order risks. Mapping these chains precisely is the concrete engineering contribution I can make to a literature that tends to stop at the first-order statement "sanctions reduce security." [OPEN: I want to build these dependency-failure chains into reusable diagrams, both as an analytical tool and as practical guidance for defenders in constrained settings.]


7. Toward characterizing resilience-under-constraint

Pulling the strands together, I am developing a preliminary way to characterize how a state or organization achieves resilience when the standard preconditions (Section 2) are removed. The working proposition is that resilience-under-isolation rests on three substitutions, each with a cost:

  1. Cooperation → self-sufficiency and peer channels. Loss of international information-sharing is substituted by domestic capacity and by cooperation among similarly-placed states. Cost: narrower early warning, and entanglement in alternative alignments.
  2. Commercial market → open-source and indigenous tooling. Loss of vendor products is substituted by open-source and self-built capability. Cost: higher in-house skill requirement, and capability ceilings where no open substitute exists.
  3. External framework → domestic institution-building. Loss of a ready-made, externally-maintained governance framework is substituted by home-grown institutions (national CSIRT, cyber authority, sectoral coordination). Cost: slow, and dependent on scarce institutional independence and political will.

The proposition, to be tested across the cases, is that resilience-under-isolation is achievable but strictly costlier and capability-capped: isolated defenders can reach a real, functioning baseline, but the frontier capabilities that depend on market access and deep cooperation remain out of reach, and the whole edifice rests on institutional capacity that isolation itself tends to erode. [OPEN: this needs a cleaner operationalization, what exactly is the "capability ceiling," and can it be measured comparatively via the ITU index or a purpose-built instrument?]


8. Method and stance

The method is comparative case study grounded in primary sources and, where safely possible, practitioner interviews, the same method as my thesis fieldwork. Two standing rules govern the work:

  • Everything stays policy-analytical. The unit of study is the system and the institution, never personal political activity, mine or anyone else's. Resilience-under-constraint is not an endorsement of the constraint, and studying how an isolated state defends its infrastructure is not a defense of why it is isolated.
  • Every claim is verifiable or explicitly flagged as open. Contested figures are marked as provisional; [OPEN] tags mark genuinely unresolved questions rather than papering over them. This is a living document, and I would rather show the seams than pretend to a false completeness.

A safety note consistent with the rest of this site: where fieldwork touches people in constrained environments, no individual is identified, and no research artifact is created that could endanger a participant. Some questions are deliberately left less-documented for that reason, and I flag when that is the case.


9. Where this is heading

I intend to keep developing this as an open research agenda in parallel with my graduate study, with the primary thesis focused on the shutdown-accountability question and this strand as the resilience-and-recovery complement to it. The longer arc is practical, not only scholarly: advising public institutions on infrastructure resilience, helping build the incident-response capacity my region still lacks, and keeping digital literacy flowing to the people who suffer first when governance fails.

The connective thread across all four strands is a single conviction, drawn from experience rather than theory: the hardest cybersecurity problems in the world are not where the resources are, they are where the constraints are. The places with the least access, the most fragility, and the highest stakes are exactly the places the standard literature describes least well. That gap is where I want to work.


10. Related writing on this site

The blog develops these strands in public, deliberately in the open, piece by piece, starting with Why Isolated States Build Cyber-Resilience Differently, and continuing through the governance and region-focused series. My primary research strand is the companion working paper on Internet Shutdowns as a Governance Instrument. If you research adjacent questions, shutdowns, CIIP frameworks, CSIRT capacity, digital sovereignty, I would genuinely like to compare notes.


References

Selected sources. A living reference list; contested figures are treated as provisional and source-dependent.

  • World Bank. Enhancing Cyber Resilience in Developing Countries and related cybersecurity capacity-building programs. https://www.worldbank.org/
  • International Telecommunication Union (ITU). Global Cybersecurity Index. https://www.itu.int/
  • Forum of Incident Response and Security Teams (FIRST). Global CSIRT community and standards. https://www.first.org/
  • ENISA (European Union Agency for Cybersecurity). Frameworks and CSIRT guidance. https://www.enisa.europa.eu/
  • ISO/IEC 27001, Information security management systems.
  • NIST. Cybersecurity Framework. https://www.nist.gov/cyberframework
  • MITRE ATT&CK. Adversary tactics and techniques knowledge base. https://attack.mitre.org/
  • OECD. Recommendation on Digital Security of Critical Activities (2019).
  • Council of Europe. Convention on Cybercrime (Budapest Convention, 2001).
  • IFIP. Critical Infrastructure Protection (ICCIP) conference proceedings series (2012–).
  • Ghana Cyber Security Authority. National cybersecurity institutional development. https://csa.gov.gh/
  • Small Wars Journal / Irregular Warfare Initiative. Analyses of the cyber strategies of China, Russia, North Korea, and Iran (2025).
  • Carnegie Endowment for International Peace; RAND Corporation. Analyses of state cyber doctrine and critical-infrastructure protection.
  • Ahura, A. Comparative Analysis of Virtual Private Network Solutions for Peer-to-Peer Content Delivery. BSc thesis, Tallinn University of Technology (2023).

Version history

  • v0.7 (28 Jul 2026) — Expanded to full working-paper form: added the assumption-failure analysis (Sec. 2), the resilience-under-constraint characterization (Sec. 7), and full references; repositioned as the secondary strand alongside the new primary shutdown-accountability paper.
  • v0.5 (Jun 2026) — Added the four-strand structure and the Ghana/CSIRT evidence base.
  • v0.3 (Apr 2026) — Added the Iran/North Korea comparative framing and the sanctions-supply-chain strand.
  • v0.1 (Feb 2026) — Initial problem statement: cyber-resilience under isolation.

Comments and corrections welcome: contact. Policy-analytical throughout; the unit of study is the system and the institution; resilience-under-constraint is not an endorsement of the constraint.

← All research