Skip to main content

Course 02

Understanding hybrid threats for analysts

Turn a contested concept into disciplined analysis.

Illustration for the course on understanding hybrid threats for analysts

About

Hybrid threats have become a buzzword in security debates, but familiarity does not guarantee analytical precision. When diverse activities are grouped together without definitions or evidence of coordination, the resulting assessment can obscure the threat and weaken policy. This course equips analysts to investigate suspected hybrid campaigns systematically.

The programme begins with the conceptual questions behind hybrid warfare: what makes it hybrid, what falls outside the concept, whether it constitutes warfare, what is historically new and why the term remains contested. A sixth, applied question connects this debate to practice: how can evidence about a suspected campaign support a proportionate policy response?

Participants work with seven characteristics proposed in research on hybrid operations: adaptability, ambiguity, asymmetry, deniability, irregularity, multimodality and synchronicity. These provide prompts for investigation. Analysts examine what evidence supports each characteristic, where alternative explanations remain plausible and how the choice of research boundaries changes their conclusions.

Case work centres on the published analysis of the Russian Orthodox Church and Russian activity in the Sahel, alongside comparisons with cases discussed in the conceptual article. Participants connect information, religious, diplomatic, financial, legal and irregular activities while assessing sources, causal claims and uncertainty. They distinguish an incident from a campaign and examine effects at different levels.

The final exercise turns analysis into a policy brief and a research plan. Participants identify knowledge gaps, specify further evidence requirements and compare response options. The goal is a repeatable approach that helps research organisations and government teams understand the threat and justify their recommendations.

Modules and timing

Day 1 / Build the analytical framework

Day 1: Build the analytical framework
ModuleTime
Conceptual foundations and the course questions90 min
Research design and the unit of analysis90 min
The seven characteristics of a hybrid signature90 min
Evidence sources and competing explanations90 min

Day 2 / Move from cases to policy

Day 2: Move from cases to policy
ModuleTime
Case laboratory on Russian and Chinese activities90 min
Comparative cases and campaign mapping90 min
Assessing effects and developing policy options90 min
Policy brief and research design workshop90 min

What you will get out of it

Leave with a case assessment, an evidence and confidence log, a map of actors and activities, and a concise policy brief. A research design template helps define the next investigation, its evidence requirements and the decisions it should inform.

Who is it for

Analysts in universities, think tanks and research organisations, as well as intelligence services, ministries of foreign affairs and ministries of defence. Also relevant to diplomatic and security policy teams, risk consultants and corporate geopolitical analysts. Familiarity with research or policy analysis is helpful; specialist hybrid-threat expertise is not required.