Understanding hybrid threats for analysts
Turn a contested concept into disciplined analysis.

About
Hybrid threats have become a buzzword in security debates, but familiarity does not guarantee analytical precision. When diverse activities are grouped together without definitions or evidence of coordination, the resulting assessment can obscure the threat and weaken policy. This course equips analysts to investigate suspected hybrid campaigns systematically.
The programme begins with the conceptual questions behind hybrid warfare: what makes it hybrid, what falls outside the concept, whether it constitutes warfare, what is historically new and why the term remains contested. A sixth, applied question connects this debate to practice: how can evidence about a suspected campaign support a proportionate policy response?
Participants work with seven characteristics proposed in research on hybrid operations: adaptability, ambiguity, asymmetry, deniability, irregularity, multimodality and synchronicity. These provide prompts for investigation. Analysts examine what evidence supports each characteristic, where alternative explanations remain plausible and how the choice of research boundaries changes their conclusions.
Case work centres on the published analysis of the Russian Orthodox Church and Russian activity in the Sahel, alongside comparisons with cases discussed in the conceptual article. Participants connect information, religious, diplomatic, financial, legal and irregular activities while assessing sources, causal claims and uncertainty. They distinguish an incident from a campaign and examine effects at different levels.
The final exercise turns analysis into a policy brief and a research plan. Participants identify knowledge gaps, specify further evidence requirements and compare response options. The goal is a repeatable approach that helps research organisations and government teams understand the threat and justify their recommendations.
Modules and timing
Day 1 / Build the analytical framework
| Module | Time |
|---|---|
| Conceptual foundations and the course questions | 90 min |
| Research design and the unit of analysis | 90 min |
| The seven characteristics of a hybrid signature | 90 min |
| Evidence sources and competing explanations | 90 min |
Day 2 / Move from cases to policy
| Module | Time |
|---|---|
| Case laboratory on Russian and Chinese activities | 90 min |
| Comparative cases and campaign mapping | 90 min |
| Assessing effects and developing policy options | 90 min |
| Policy brief and research design workshop | 90 min |
What you will get out of it
Leave with a case assessment, an evidence and confidence log, a map of actors and activities, and a concise policy brief. A research design template helps define the next investigation, its evidence requirements and the decisions it should inform.
Who is it for
Analysts in universities, think tanks and research organisations, as well as intelligence services, ministries of foreign affairs and ministries of defence. Also relevant to diplomatic and security policy teams, risk consultants and corporate geopolitical analysts. Familiarity with research or policy analysis is helpful; specialist hybrid-threat expertise is not required.