This talk analyzes four years of Russian cyber operations in the Ukraine conflict (2022–2026) by combining MITRE ATT&CK mapping with an in-depth review of destructive malware and ICS/OT attacks to extract practical defensive lessons for modern cybersecurity teams.