
Cyber expert, Jamie Moles from ExtraHop tallies key moments in in Channel 4’s cyber warfare drama
The UK’s Channel 4 has started airing its highly anticipated cyber warfare drama The Undeclared War. The drama was informed by experts, but how close to the truth did it remain?
The hacking community is often disappointed by the inaccurate depiction of its daily toils. However, they may well now be pleasantly surprised to finally see the media take hacking seriously. It’s one of the first times TV has accurately depicted the daily life experience of coding and cyber security, instead of the usual Hollywood cliches and glitz.
Sure, some aspects are still a little far from the truth, but others hit the nail on the head. Below are three things the show’s creators got right, and three that were more Hollywood than reality.
Unlike most Hollywood films, which purport to show screens of code which is in fact just a computer rebooting, Channel 4 made sure it used the right tools and coding language. Nmap, Gobuster, and IDA pro are all real tools cyber experts use to identify, isolate, and reverse engineer malware.
The only caveat here is that for some reason they did not show the use of any NSA tools.

Saara debugging the malware with IDA Pro
Saara attacking the CTF challenge with metasploit, wordpress scanner, and Gobuster
GCHQ’s team of experts missed a potentially fatal second virus hiding in a Library file, which was discovered by a work experience student on her first day. The UK Government COBRA team, which traditionally convenes in Cabinet Office Briefing Room A (hence the acronym) seemed embarrassed that the missed malware was discovered by a rookie intern. However, in reality this is realistic and exactly what could happen.
Years of experience reverse engineering malware code told those experts that the student, Saara, didn’t need to investigate the code she questioned because “it’s just a library.” But, if you’re going to hide malware in code you would look for somewhere no one will look. Making it look like a standard library was spot on.
Cyber security is a race against the bad guys who continuously develop new tools and tactics. To get ahead of the game, organisations need fresh talent with fresh eyes that can see things differently.
The idea a European Prime Minister would immediately opt for an offensive response is good for suspense but farcical. Imagine firing a cruise missile at a nation state only to find out that the attack in fact came from a different country.
No Prime Minister would move to attack a country for a cyber security attack without being able to attribute the attack’s origin. Attribution is even more essential in cyber warfare because of how easy it is to leave false flags, such as cyrillic code fragments, to disguise where the malware originated.
Drilling down into the level of detection and understanding how the malware moves across the network is a much more solid way to find an indicator for attribution. However, assuming and reacting without attribution is political suicide—at best.
One of the ways the Prime Minister suggested retaliating against Russia was to hack into Putin’s office to turn the lights off in his office. There is no way they would be able to do this. These systems, and many others, are deliberately air-gapped to run independently even from other Critical National Infrastructure.
While great for the narrative, this sort of plot point is very much the show’s directors taking artistic licence.
The use of bots by organised groups to spread misinformation is an established reality. Social media platforms are actively manipulated not just by nation states, and especially through gangs-for-hire, which has the advantage of plausible deniability.
Geographically dispersed teams regularly set up bots, which aim to hook in useful idiots; who will then communicate between themselves and bots to allow manipulative hashtags to go viral and create trends. Posting to other bots, already set up, moves malicious posts up and, as they trend, gullible people get sucked in.
It’s evidence of a flaw in the way Facebook and Twitter work, as Elon Musk and others have pointed out.
In the first episode, an NSA operative demands access to the full malware code from GCHQ developers. Their response? You need authorisation from the boss—who duly gives it. In reality, would approval from above come so quickly?
It’s hard to know for sure, but it seems somewhat unbelievable that a simple question to a more senior person in GCHQ would result in almost immediate access to the malware code. However, for those in the industry, the cagey nature in which the operative asked for access was spot on.
Despite several Hollywood-isms, the show does an excellent job of depicting cyber security in a way that coders relate to and that non-coders can understand. For example, when Saara searches for code in a phone box by looking through phone directories looking for a sequential number, or when she bounces a ball looking for any deviation - which happened when the ball went somewhere else.
This is a really striking way of visualising how cyber security experts hunt for and patch entry points from attacks. Whether they can continue to lean more toward fact than fiction as the show goes on is yet to be seen.
Jamie Moles is a Senior Technical Marketing Manager and cyber expert at ExtraHop
Main image courtesy of iStockPhoto.com
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543