Treaty and Talks

Cyber And Hybrid Operations

Instrument typeNon-kinetic and kinetic actions below the threshold of war
Primary domainCyberspace and information environment
Typified byDeniability and ambiguity
Common objectivesCoercion, espionage, disruption, influence
Legal statusGoverned by international law and national sovereignty norms
Common targetsCritical infrastructure, political processes, public opinion
Attribution difficultyHigh to very high
Response mechanismsDiplomatic, economic, cyber countermeasures

Origin and history

The concepts of cyber and hybrid operations evolved from the convergence of information technology and traditional statecraft in the late 20th and early 21st centuries. Their intellectual and doctrinal origins are primarily attributed to strategic thinkers within the United States, Russia, and China, who recognized the potential of non-kinetic tools for achieving political and military objectives. The term "hybrid warfare" gained widespread prominence in Western strategic discourse following the 2014 Russian annexation of Crimea, which demonstrated the integrated use of cyber tools, information campaigns, and conventional proxies. The foundational ideas, however, draw from earlier Russian concepts like "reflexive control" and "information warfare" developed in the late Soviet period. The formalization of cyber operations as a distinct military domain occurred in the early 2000s, with nations establishing dedicated cyber commands. This historical development reflects a broader shift in conflict, where the boundaries between war and peace, and between state and non-state actors, have become deliberately blurred.

What it is for

Cyber and hybrid operations are instruments of state power designed to achieve strategic goals below the threshold of open, conventional warfare. They are employed to undermine an adversary's political cohesion, economic stability, and social trust without triggering a full-scale military response. Cyber operations specifically target data, networks, and information systems to conduct espionage, sabotage, or influence campaigns. Hybrid operations integrate cyber tools with a broader suite of means, including disinformation, economic pressure, diplomatic coercion, and the use of proxy forces. The primary purpose is to create ambiguity and plausible deniability, allowing a state to exert pressure while avoiding attribution and retaliation. These instruments are used for persistent competition, to shape the operational environment in peacetime, and to gain advantages that could be decisive in a potential future conflict.

Overview

Cyber and hybrid operations represent a paradigm of conflict focused on the exploitation of information and connectivity. A cyber operation is a state-sponsored or state-affiliated action using computer networks to disrupt, deny, degrade, or destroy information or the systems themselves. A hybrid operation is a coordinated campaign that synchronizes cyber actions with kinetic, informational, and political tools to achieve synergistic effects. The relationship between the two is integral; cyber capabilities are a core, often enabling, component of modern hybrid warfare. This form of state interaction exists in the "gray zone" between peace and war, exploiting legal and normative gaps in international law and security frameworks. The overarching objective is to weaken an adversary's resolve, capabilities, and alliances through persistent, low-cost attrition rather than through a single, decisive confrontation.

What to know

States engaging in these operations prioritize stealth and attribution challenges, often routing activities through non-state proxies or compromised infrastructure in third countries. The target set is vast, encompassing critical national infrastructure like power grids, financial systems, electoral processes, and media ecosystems. Defensive preparedness requires a whole-of-society approach, as vulnerabilities often exist in private sector networks and public trust. International law, particularly the UN Charter's provisions on the use of force and sovereignty, applies but is contested and difficult to enforce in this domain. A key strategic concept is "deterrence by denial," which focuses on making systems resilient and attacks costly to execute, rather than solely threatening retaliation. Understanding that these are instruments of persistent competition, not episodic events, is critical for formulating effective long-term national security policy.

Common questions

A common question is whether a major cyber attack constitutes an act of war, a determination that depends on the attack's scale, effects, and intent, and remains a political decision by the affected state. People often ask how attribution is definitively proven, which involves technical forensics, intelligence gathering, and pattern analysis, but state actors often leave false flags. Many inquire about the most likely targets, which consistently include government networks, defense industrial bases, energy sectors, and democratic institutions like elections. A frequent concern is how individuals can protect themselves, focusing on basic cyber hygiene like strong passwords and software updates, though systemic defense is a government responsibility. Questions arise about the role of treaties, but binding international agreements are scarce due to verification difficulties and fears of limiting offensive options. There is also debate over whether declaring a "red line" for cyber actions is effective or instead reveals a state's tolerance threshold to adversaries.

Pros and cons

A significant pro for the employing state is the asymmetric cost-imposition, where relatively inexpensive operations can inflict massive economic or political damage on a far more advanced adversary. The ambiguity and deniability inherent in these operations provide a shield against direct retaliation, allowing for persistent pressure. However, a major con is the risk of escalation miscalculation, where an operation causes unintended physical destruction or crosses an unspoken red line, potentially sparking a conventional conflict. The employing state also faces the "blowback" con, where developed techniques or malware can be reverse-engineered and used against them, or where actions galvanize adversary alliances. A common mistake is overestimating the precision of cyber effects and underestimating the resilience and adaptive capacity of targeted societies. States often regret heavy reliance on these tools when they provoke a unified and robust defensive response that strengthens the adversary's cyber defenses and international cooperation.

Who it suits

This instrument suits revisionist or authoritarian states seeking to alter the international status quo without possessing overwhelming conventional military superiority. It suits states with advanced technical capabilities and a tightly controlled information environment domestically, which allows them to conduct external information operations while limiting internal exposure. It suits strategic cultures that emphasize patience, indirect approaches, and the accumulation of incremental advantages over time. Conversely, it is less suited for transparent democracies that value open networks and struggle with attribution debates in public, potentially hampering swift response. It is also poorly suited for achieving definitive, lasting political outcomes on its own, as it often creates friction without delivering a decisive capitulation. Ultimately, it is a tool for the strategically patient operating in the gaps of the international system.

Latest Cyber And Hybrid Operations news

Latest reporting