Insights

Secure Front: Read the Strategy, Not the Reporting

Written by k54 Cyber Intel Analyst | Sep 17, 2026, 2:45:00 PM

What China’s Five-Year Plan Reveals About Future Cyber Targets

China's Five-Year Plans offer defenders a window into the industry most likely to attract Chinese cyber espionage by publicly identifying the technologies and capabilities Beijing considers strategically important.

Looking in the Wrong Place

When analysts and researchers are looking for threat intelligence, they focus on things like malware analysis, IOCs, CVEs, and other threat reports. But I want to challenge this mindset. What if one of the biggest predictors of tomorrow's cyber targets wasn't hidden in the malware or buried under an alphabet soup of classification headers? What if the adversary published their priorities out in the open?  

Pattern Recognition > Crystal Ball 

Good intelligence analysts don't predict the future. They reduce uncertainty. We identify priorities, incentives, capability gaps, and historical behavior. Using this information, we can assess and estimate what happens next.

Russian forces building up on the Ukraine border. Budget allocations. What leaders are saying out loud. Industrial policy. Military procurement. These things often happen right out in the open. It's nearly impossible for states to hide what they find valuable. More often than not, they publish it. 

The Plan Itself 

China's National People's Congress formally adopted the 15th Five-Year Plan on March 12, 2026, covering 2026-2030. This marks a sharper, more security-driven technology agenda than its predecessor, treating AI as the organizing logic for a broad industrial transformation rather than just one priority sector among many.

AI is mentioned 52 times, versus just six in the 2021 plan. Beyond AI, priority sectors include semiconductors, robotics, biotech, quantum computing, and 6G, all framed around achieving technological self-reliance amid U.S. export controls.

On cyber specifically, the plan calls for integrating cybersecurity into every layer of digital development to "ensure national economic security" while accelerating China's effort to build a "cyber superpower," with emphasis on protecting critical information infrastructure, cloud service assessments, and building disaster-recovery/backup systems. This is the first time technical resilience has appeared in a Five-Year Plan.

Taken together, these priorities describe the capabilities China believes will determine economic competitiveness, military strength, and geopolitical influence over the coming decade.

That raises an important question: if these capabilities matter to Beijing, what information would accelerate those goals? Who already possesses it? 

Gaps Create Requirements 

Nation-states don't only collect against their strengths. They collect against weaknesses. We can use the Five-Year Plan to assess where Beijing views itself and where it stands.

Semiconductor manufacturing, cloud technologies, and advanced chips point to AI and China's technological self-reliance, especially in the era of trade wars and tariffs. A focus on aerospace tells us they want to advance their military capability.

These capability gaps almost certainly shape China's broader national collection requirements. While the Five-Year Plan is not an intelligence tasking document, it publicly identifies the technologies Beijing considers strategically important, making it a useful indicator of where intelligence collection is likely to focus.

Espionage has long served as a force multiplier for national development. If a foreign intelligence service can collect research, engineering data, or operational insight more quickly than domestic development can produce it, the return on investment can be significant. Cyber operations make that collection faster, cheaper, and often harder to attribute than traditional espionage.

Does Reality Match the Theory? 

Historically, China has leveraged its military, intelligence services, and freelance hackers to achieve its strategic goals. Let's look at the last two decades. PRC threat actors have targeted global aerospace, defense, universities, telecommunications, and manufacturing sectors.

In the last three years alone we have seen a major uptick in activity, and the U.S. government and its allies have run the gamut on its PR campaign to let the world know just how bad it's getting.

But does the theory actually hold up? Look at the timeline. China's 14th Five-Year Plan was published in March 2021. It called for stronger protection of critical information infrastructure while China doubled down on building out its telecom and 5G networks. Within months, private-sector analysts were reading the tea leaves. A SecAlliance threat report published in October 2021, based on the plan's language, predicted that Chinese cyber operations would target critical national infrastructure and telecommunications specifically to monitor individuals and communications.

That prediction preceded the public reveal of both Volt Typhoon and Salt Typhoon, sometimes by years. That does not prove the Five-Year Plan caused those campaigns. Rather, it demonstrates how strategic documents can provide useful indicators when combined with observed threat activity. 

Volt Typhoon

The name we've all heard since around 2023, with Microsoft's infamous report on critical infrastructure targeting by Volt Typhoon. Why would they go after critical infrastructure? Former FBI Director Christopher Wray said it was to "sow chaos" in the event of a Taiwan crisis.

Chinese state-sponsored actors are pre-positioning access in the event of a conflict between the U.S. and China to turn off the lights and stop the water flow in an effort to use the American people to convince the American government that a conflict with China isn't worth it.

Microsoft first revealed the Volt Typhoon campaign in May 2023, but the group had reportedly been quietly active since mid-2021. Their targets read like a checklist of what keeps a country running: communications, energy, water, transportation, and infrastructure tied to Guam, a strategically critical location for any U.S. response to a conflict over Taiwan. CISA, NSA, and the Five Eyes alliance later confirmed the assessment in a joint advisory, and the FBI has disrupted the group's botnet infrastructure more than once since, only to see it rebuilt. 

Salt Typhoon

The other main threat from China focuses on telecommunications. Telecommunications networks are not simply infrastructure; they are intelligent infrastructure.

With access here, intelligence services are able to gain key insights into U.S. government communications and geolocation data, and could potentially give Beijing a heads-up on future military operations. This also ties into the Five-Year Plan's stated interest in 6G.

Salt Typhoon's telecom-focused campaign came to light in 2024, breaching major U.S. carriers and reportedly reaching systems tied to court-authorized wiretap requests. It wasn't an isolated case, either. Bloomberg later reported that investigators believed Volt Typhoon had compromised Singapore's Singtel in what may have been a test run for subsequent operations against telecommunications providers. Singtel confirmed detecting and removing malware, but did not publicly confirm the Volt Typhoon attribution. 

Read Strategy Like Threat Intelligence 

Threat intelligence should begin long before the first IOC appears. Strategic documents, like the Five-Year Plan, deserve a place in every intelligence team's workflow. Not because they predict an attack. But because they reveal incentives, priorities, investments, and long-term objectives.

If your organization is listed in a foreign adversary's list of top priorities, do you think you might see espionage activity against your organization? Probably.

And security teams, rethink the question. Instead of are we likely to be targeted? Ask: Are we part of someone else's strategic roadmap? If you're a supplier, research lab, university, manufacturer, software vendor, or infrastructure operator, you should probably start paying attention. Our adversaries are providing the answer key. It's up to us to ensure that we are paying attention to the right pieces.

The most important part isn't that China may start looking at specific sectors in the U.S. This methodology applies everywhere, across the globe. Russia, Iran, and DPRK. Even the U.S. and its allies project through their strategic documents. Industrial policy often predicts intelligence priorities, and public strategy precedes cyber activity.

Conclusion

Threat intelligence isn't only technical. It is strategic. Before the targets, the malware, or the phishing email, there is someone making decisions on what's worth stealing. National strategy documents often reveal those priorities years in advance. For defenders willing to read them and look for the patterns, they offer something increasingly valuable: Time. Malware changes. Infrastructure changes. Even threat actor names change. National priorities rarely do. If we want to understand where cyber espionage is going next, we should spend less time asking what an adversary attacked yesterday and more time paying attention to what they publicly say they need next. 

Sources