This session provides an intelligence‐based assessment of state actor cyber operations against critical infrastructure before and during armed conflict. Using the Venezuelan energy case and lessons from Russian operations in Ukraine, it examines what cyber tools actually achieved, their limits, and why the Venezuelan case is not directly comparable to Europe. The talk offers a threat model showing cyber operations most often support coercion, kinetic action, and disinformation rather than standalone infrastructure collapse.