The case for an actor-agnostic layer in North Atlantic threat assessment
For a decade, the hybrid threat literature has developed – and continues to develop – around Russia. Hybrid campaigns in Georgia in 2008, Ukraine from 2014 onwards, and sustained pressure on the EU/NATO eastern flank have fed this trend. This is nobody's fault. Think tanks and policy analysts build their assessments on empirical evidence, rather than risky assumptions about what friendly actors might do in the future.
In the past year, alliance members have encountered something new. A NATO member imposed escalating tariffs on its allies in pursuit of a territorial claim while demanding that the alliance become an offensive rather than a defensive platform. No published assessment in Europe or North America has labelled either as a coercive campaign. Not because they do not resemble one, but because current frameworks are ill-equipped to view a security guarantor as a threat. But why is this?
How the “hybrid” category was captured
The term “hybrid warfare” entered the vocabulary as a description of Hezbollah's actions in Lebanon in 2006 (Hoffman 2007). Within eight years, it was applied to a different case entirely, largely due to a misread article by Valery Gerasimov. Galeotti, who popularised that reading, later corrected it (Galeotti 2016, 2018).
What followed was a decade of intense scholarship: Renz (2016), Charap (2015), Lanoszka (2016), Fridman (2018), Kofman and Rojansky (2015) and Wither (2016) argued about whether the concept accurately described Russian practice, whether it was analytically new, and whether it was politically useful. When you look at the overarching logic, it is entirely an argument about Russia. Almost nobody asked whether the concept could describe anyone else or whether it should be built so it could.
Then you have China, where the literature reproduced the same structure: a parallel actor-indexed body of work on economic statecraft and coercive influence (Norris 2016; Cha 2023). EU and NATO-related reporting followed a comparable logic. EEAS reporting on information manipulation is organised primarily around foreign originating actors, while the national hybrid-threat assessments produced across the Alliance tend to frame the threat through the identity of the adversary (EEAS 2023; European Commission and High Representative 2016).
When you think about it, once the concept became doctrine, it naturally entailed an exclusion. Any action by an ally is, by definition, not considered hybrid coercion.
What this blind spot costs
There are two consequences of this approach, and the second is more problematic than the first.
The indicators are actor-derived, so they detect actors rather than behaviour. Build an indicator set by generalising from observed Russian operations and you have a Russia detector. It will consistently activate on Russian-adjacent noise but remain silent when facing differently structured coercion. From an analytical perspective, this is overfitting, as indicator sets rarely transfer reliably between actor files.
Coercion by an actor nobody is watching has nowhere to go. Assessment begins by identifying which adversary sponsors or owns a set of actions. If there is no candidate, the process does not automatically determine the behaviour as harmless. Instead, it produces no conclusion at all; the actions are recorded, matched against nothing, and never compiled into a campaign. They are not labelled as benign, nor are they ever explicitly judged.
An ally is the originator guaranteed to produce that result, because the watch list contains only outsiders. It is also the worst spot for the gap to sit: cohesion keeps an alliance united, and a member is better placed than any adversary to weaken it. The literature even has a term for coercion designed to fracture a bloc – wedge strategy (Wigell 2019) – and has applied it, without exception, to actors outside the bloc.
What the current framework cannot process
Since January 2026, the United States has conditioned tariff relief on the potential transfer of Greenland, announcing escalating duties against Denmark, Norway, Sweden, France, Germany, the United Kingdom, the Netherlands and Finland, rising from ten per cent in February towards twenty-five per cent by June (Atlantic 2026; CRS 2026). At the Ankara summit in July, the President stated that further withdrawals of US forces from Europe would depend on Greenland (CNN 2026b).
A second demand runs in parallel. After launching strikes on Iran without prior notice or consultation with the alliance, Washington pressed allies to join the offensive operation. Most declined, on the stated grounds that the action was illegal and fell outside NATO's defensive mandate (CNN 2026a). The White House described the refusal as a breakdown of the alliance – testing allies and revealing their failure – while also hinting at the possibility of withdrawing from NATO (Al Jazeera 2026).
A false dilemma, two demands, and one instrument. In both cases, Washington used the security relationship itself as leverage. This creates an unusual security condition: the actor responsible for providing protection also becomes the source of coercive pressure for those who receive it. In a limited but literal sense, the security guarantor begins to function as a security threat. The novelty is that the guarantee itself is no longer merely the environment in which coercion takes place, but the mechanism by which it occurs.
When you strip out the politics and describe what is on the table, the structure is unremarkable: a demand, graduated costs for non-compliance, a publicly stated link between the two, and a sustained information effort directed at target populations. Instruments run across the economic, military and diplomatic domains, where effects compound in ways a single-domain assessment cannot capture (Jervis 1997). This is compellence in Schelling's sense (Schelling and Harvard University Center for International 1966), executed through economic chokepoints of the kind Farrell and Newman (2019) describe, and it satisfies every indicator that would open a hybrid campaign assessment if the originator carried a different flag (Drezner 2003).
An actor-indexed indicator set is unable to represent that compounding because its categories are organised around individual actors rather than their interactions. The gap is therefore structural: the existing framework provides no analytical slot in which such an assessment could be placed. The actor taxonomy, as inherited from the literature, classifies an ally primarily as a type of relationship, leaving its potential for coercive behaviour outside the classification. As a result, the existing reporting structures offer no mechanism for capturing such an assessment.
Separating two questions that were never supposed to be one
The solution is more limited than it appears. No one needs to give up attribution. Attribution determines how we respond, and response is where political authority resides. The real change lies in the sequence of the questions asked.
A behaviour-first layer analyses observed actions against a target, including their direction, intensity, timing, and coordination across domains, to determine if they form a coercive campaign. The originator field is intentionally left blank. Attribution is then linked to an existing characterisation rather than gating its production (Rid and Buchanan 2015).
The payoff is symmetry: a single procedure covers a Russian, Chinese, or even an unattributed campaign, as well as an allied one. This is the only way to make intra-alliance coercion visible, as no institution would voluntarily establish a bespoke process to accuse its own patron.
The second payoff is epistemic hygiene. When you fix the actor in advance, the confirmation becomes cheap. Ambiguous indicators resolve towards the expected culprit, and the assessment ceases to be falsifiable in any useful sense. Remove the actor, and that gradient disappears. This is a methodological argument, leaving normative considerations aside. It makes no claim about the equivalence of allies and adversaries and prejudges nothing about whether a given campaign is justified. It insists, however, that whether behaviour is coercive can be settled before who is doing it. An alliance unable to ask the first question independently is flying with a missing instrument.
Simulation scenarios reinforce the actor bias
Doctrine moves slowly and costs money. Simulation design does neither, but it is where the actor-indexed literature transforms into reflex. NATO's flagship exercises already fictionalise their adversaries, which looks like progress and is its opposite. Locked Shields, run by the CCDCOE since 2010, is built on a long-running war between the fictional states of Berylia and Crimsonia, with Berylia defending its sovereignty against Crimsonian aggression (CCDCOE n.d.). The 2026 edition adds an offensive axis led by Crimsonia and Nekelonia running a doctrine of hybrid expansionism through proxy groups (EMAD 2026).
The adversary is positioned in the scenario premise. Blue teams learn who is attacking them before the first inject. They practise responding to coercion but do not practise recognising it. The crucial analytical step – identifying campaign character from behavioural signatures under uncertain conditions – is omitted from the exercise.
The second half reinforces the actor bias even more. The 2026 scenario places Netoria and Selenoa alongside Berylia in a defensive coalition bound by military and intelligence cooperation agreements (EMAD 2026). Allies appear in these architectures exclusively as allies. No participating cell can work a set of indicators and arrive at an originator inside the alliance, not because an analyst would refuse the finding, but because the scenario space does not contain it.
Fictionalising the adversary removes the diplomatic cost of writing "Russia" on a slide. It does not remove attribution from the analytical chain. It hard-codes it and conceals that it has done so. Thirty-two nations have spent fifteen years becoming very good at a problem they will not be given.
Three things that need to change
Run one blind scenario each year. NATO and EU exercise planners should design at least one tabletop (TTX) scenario in which the coercing party is initially undefined. Teams receive indicators rather than an adversary and are evaluated on the quality of their characterisation rather than the response speed alone. CCDCOE and Hybrid CoE should be the custodians. This is a scenario-design choice and exercise architecture.
Make alignment a variable, instead of a predefined setting. A blind test whose answer is still Crimsonia falls short of being blind. Allied and internal originators should be treated as derivable outcomes, with the flexibility for an actor's alignment to change during the simulation rather than being static at the start. This is not an entirely new idea; there is a precedent for treating alignment as fluid even in open conflict. In the Croat–Bosniak war of 1993–94, two parties fighting a common enemy turned on each other and then realigned, with the ICTY later finding a joint criminal enterprise (ICTY, 2013, 2017). If alignment can reverse visibly, violently, and with cooperation structures remaining intact, then a sub-threshold version should not be exotic. It is the same phenomenon with a weaker signal. Allowing this will be politically uncomfortable, which is a fair indication of how long overdue it is.
Split the product. National cells and the EU Hybrid Fusion Cell should adopt a two-stage format separating behavioural characterisation from actor attribution, with the first releasable while the second remains open. Cyber threat intelligence solved this a decade ago: analysts cluster activity by observed tradecraft, assign the cluster a neutral identifier, and publish on it long before – or without ever – naming a sponsor, promoting it to an attributed group only when evidence supports the step (e.g. Mandiant Uncategorized Threat Groups). Strategic assessment is missing an equivalent convention. Adopting one would allow a campaign to be named and tracked at a lower classification than attribution usually permits, and would prevent a political decision from being the price of an analytical finding.
None of this requires new doctrine, new mandates or new definitions of “hybrid warfare”. It requires a single, modest concession that "what is being done" and "who is doing it" were never the same question. Separating the two does not lower NATO's guard against its potential adversaries. It raises its guard against unexpected coercion. NATO and the EU built their assessment architecture to face east, and it has served them well against the actor it was designed to counter. An actor-agnostic layer does not replace that work. It completes it so that when coercion arrives from a direction the architecture never anticipated, the alliance is not seeing it for the first time.
References
Al Jazeera. 2026. "Trump administration signals it is mulling NATO withdrawal after Iran war." Al Jazeera, April 8. https://www.aljazeera.com/news/2026/4/8/trump-administration-says-it-is-mulling-nato-withdrawal-after-iran-war.
Atlantic Council. 2026. “The US and NATO can avoid catastrophe over Greenland and emerge stronger. Here's how”. Atlantic Council, January 17. https://www.atlanticcouncil.org/dispatches/the-us-and-nato-can-avoid-catastrophe-over-greenland-and-emerge-stronger-heres-how/.
CCDCOE. n.d. “Locked Shields”. NATO Cooperative Cyber Defence Centre of Excellence. Accessed 2025. https://ccdcoe.org/exercises/locked-shields/.
Cha, Victor D. 2023. "Collective Resilience: Deterring China's Weaponization of Economic Interdependence." International Security 48 (1): 91-124. https://doi.org/10.1162/isec_a_00465.
Charap, Samuel. 2015. "The Ghost of Hybrid War." Survival 57 (6): 51-58. https://doi.org/10.1080/00396338.2015.1116147.
CNN. 2026a. "US hits more than 80 Iran targets, reimposes oil sanctions." CNN. Accessed July 28. https://www.cnn.com/2026/07/07/world/live-news/nato-summit-trump.
CNN. 2026b. "US, Iran threaten more attacks as strikes continue, Trump attends NATO summit." CNN. Accessed July 28. https://www.cnn.com/2026/07/08/world/live-news/iran-war-nato-summit-ukraine-trump.
CRS. 2026. Greenland, Denmark, and U.S. relations (IN12643). Congressional Research Service (Washington, DC). https://www.congress.gov/crs-product/IN12643.
Drezner, Daniel W. 2003. "The Hidden Hand of Economic Coercion." International Organization 57 (3): 643-659. https://doi.org/10.1017/S0020818303573052.
EEAS. 2023. 1st EEAS Report on Foreign Information Manipulation and Interference Threats. European External Action Service. https://www.eeas.europa.eu/eeas/1st-eeas-report-foreign-information-manipulation-and-interference-threats_en.
EMAD. 2026. The 'Locked Shields 2026' exercise concludes. Estado Mayor de la Defensa, April 17. https://emad.defensa.gob.es/en/prensa/noticias/2026/04/Listado/260417-ni-mcce-locked-shield.html.
European Commission and High Representative. 2016. Joint framework on countering hybrid threats: A European Union response (JOIN(2016) 18 final). European Commission (Brussels). https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:52016JC0018.
Farrell, Henry, and Abraham L. Newman. 2019. "Weaponized Interdependence: How Global Economic Networks Shape State Coercion." International Security 44 (1): 42-79. https://doi.org/10.1162/isec_a_00351.
Fridman, Ofer. 2018. Russian "Hybrid Warfare": Resurgence and Politicization: Oxford University Press. https://doi.org/10.1093/oso/9780190877378.001.0001.
Galeotti, Mark. 2016. "Hybrid, ambiguous, and non-linear? How new is Russia’s ‘new way of war’?" Small Wars & Insurgencies 27 (2): 282-301. https://doi.org/10.1080/09592318.2015.1129170.
Galeotti, Mark. 2018. "I'm sorry for creating the 'Gerasimov Doctrine'." Foreign Policy, March 5. https://foreignpolicy.com/2018/03/05/im-sorry-for-creating-the-gerasimov-doctrine/
Hoffman, Frank G. 2007. Conflict in the 21st century: The rise of hybrid wars. Potomac Institute for Policy Studies Arlington, VA. https://www.potomacinstitute.org/images/stories/publications/potomac_hybridwar_0108.pdf
ICTY. (2013, May 29). Prosecutor v. Prlić et al. (Case No. IT-04-74-T), Judgement. International Criminal Tribunal for the former Yugoslavia. https://www.icty.org/x/cases/prlic/tjug/en/130529-1.pdf
ICTY. (2017, November 29). Prosecutor v. Prlić et al. (Case No. IT-04-74-A), Appeal Judgement. International Criminal Tribunal for the former Yugoslavia. https://www.icty.org/en/case/prlic
Jervis, Robert. 1997. System Effects: Complexity in Political and Social Life. Princeton University Press.
Kofman, Michael, and Matthew Rojansky. 2015. Kennan Cable No.7: A Closer look at Russia’s “Hybrid War”. Wilson Center (Washington, DC). https://www.wilsoncenter.org/publication/kennan-cable-no7-closer-look-russias-hybrid-war.
Lanoszka, Alexander. 2016. "Russian hybrid warfare and extended deterrence in eastern Europe." International Affairs 92 (1): 175-195. https://doi.org/10.1111/1468-2346.12509.
Mandiant. (n.d.). Uncategorized (UNC) threat groups. Retrieved August 2, 2026. https://www.mandiant.com/resources/insights/uncategorized-unc-threat-groups
Norris, William J. 2016. Chinese Economic Statecraft: Commercial Actors, Grand Strategy, and State Control: Cornell University Press. https://doi.org/10.7591/cornell/9780801454493.001.0001.
Renz, Bettina. 2016. "Russia and ‘hybrid warfare’." Contemporary Politics 22 (3): 283-300. https://doi.org/10.1080/13569775.2016.1201316.
Rid, Thomas, and Ben Buchanan. 2015. "Attributing Cyber Attacks." Journal of Strategic Studies 38 (1-2): 4-37. https://doi.org/10.1080/01402390.2014.977382.
Schelling, Thomas C., and Affairs Harvard University Center for International. 1966. Arms and influence. New Haven: Yale University Press.
Wigell, Mikael. 2019. "Hybrid interference as a wedge strategy: a theory of external interference in liberal democracy." International Affairs 95 (2): 255-275. https://doi.org/10.1093/ia/iiz018. https://doi.org/10.1093/ia/iiz018.
Wither, James K. 2016. "Making Sense of Hybrid Warfare." Connections. The quarterly journal (English ed.) 15 (2): 73-87. https://doi.org/10.11610/Connections.15.2.06.
Fabio Iguavita Duarte is a Strategic Intelligence Analyst at UCEEB, Czech Technical University in Prague, and a PhD candidate at the Institute of Political Studies, Charles University. His current work focuses on the protection of strategic and critical infrastructure by developing formal methods to classify hybrid coercive behaviour, integrating geopolitical shifts, hybrid threats, and crisis dynamics into scenario design and modelling. He previously worked in Colombia's oil/energy sector, where insurgency attacks on critical infrastructure were an operational concern.


