Working area · A.02

    Hybrid Threats

    Hybrid threats are campaigns that combine legal, economic, informational, migratory and cyber instruments to obtain a political effect without crossing the threshold of armed conflict. Their defining feature is ambiguity: taken in isolation, each action looks explainable and is hard to attribute.

    This area analyses precisely that accumulation. The goal is not to label an incident as hybrid, but to determine whether a set of scattered facts corresponds to a sustained pattern, and what consequences it has for the organisation affected.

    What the discipline covers

    • Non-military coercion: administrative, customs, judicial or regulatory pressure applied selectively.
    • Instrumentalisation of flows: migration, energy, food, licences or supply chains used as leverage.
    • Information operations: narrative construction, coordinated amplification and exploitation of existing social fractures.
    • Cyber activity below the threshold: low-noise intrusions, well-timed leaks, denial of service with a reputational effect.
    • Use of proxies and non-state actors that allow plausible deniability to be maintained.

    Scope

    The analysis covers the grey zone as it reaches a private organisation: the point where a state-level campaign becomes a customs delay, a licence that does not arrive, a smear campaign or an incident in a subsidiary.

    • Observed effect on the organisation, its subsidiaries, its local staff and its distribution chain.
    • Correlation between incidents across different domains within a defined time window.
    • Assessment of exposure to coercive leverage: single-source dependencies, sensitive markets, concentrated routes.
    • Explicit exclusions: no state attribution presented as proven, no offensive activity, no counter-messaging campaigns.

    Main risks and threats

    • Administrative and customs pressure that raises operating costs without any formal restriction being announced.
    • Reputational campaigns aimed at the organisation, its executives or its regulator, timed to a negotiation.
    • Interruption of a supply on which production depends, presented as a technical or bureaucratic issue.
    • Pressure on local staff, subsidiaries or distributors as an indirect route against the parent company.
    • Leaks of genuine internal information released at the moment of maximum damage.
    • Premature attribution by the organisation itself, which turns an analytical error into a second-order effect.

    Relevant indicators and warning signs

    In the grey zone the most useful indicator is not the intensity of an event, but its coincidence with a political decision and its repetition across separate domains.

    • Coincidence between administrative friction and moments of diplomatic or contractual negotiation.
    • Series of minor incidents in different domains — customs, cyber, press, social platforms — pointing at the same target.
    • Synchronised appearance of identical messages from accounts with no coherent history.
    • Change in the behaviour of a partner or supplier after a political shift in their country of origin.
    • Sudden reactivation of a dormant dispute, complaint or inspection file.
    • Public statements that pre-justify a restriction not yet formally adopted.

    Application of OSINT

    • Construction of a baseline of normal friction, so that a genuine anomaly can be distinguished from operational noise.
    • Temporal correlation between incidents in different domains and documented political decisions.
    • Analysis of diffusion patterns: account age, text coincidence, publishing cadence, cross-platform reposting.
    • Strict separation between observed effect, probable authorship and evidenced authorship.
    • Mandatory competing hypotheses, always including the hypothesis of unintended coincidence.

    Zero101OSINT methodology

    • Baseline first: without a reference period, any incident looks exceptional.
    • Event log with date, domain, source and reliability, kept separate from interpretation.
    • Pattern assessment across at least two independent domains before any campaign hypothesis is raised.
    • Attribution expressed as a confidence level, never as a conclusion, and always with the alternative explanation stated.
    • Deliverables written so that a non-specialist decision-maker can act without accepting an unproven attribution.
    • Monitoring indicators handed over so the organisation can keep tracking the pattern on its own.

    Open sources used

    • Official gazettes, administrative resolutions, and customs and transport statistics.
    • Statements by national and European bodies on incidents and on the measures adopted.
    • Public advisories from national cyber-incident response teams and from manufacturers.
    • Public social platform data: account metadata, publication timing and text repetition.
    • Specialised and regional press, always traced and rated, never used as the only support for a claim.

    Applications for companies, organisations and security decision-makers

    • Distinguish a coordinated pattern from a run of unrelated bad luck before escalating internally.
    • Support crisis-committee decisions with a documented chronology instead of impressions.
    • Review dependencies that can be used as leverage and prepare realistic alternatives.
    • Prepare a communications position that does not rest on an attribution that cannot be sustained.
    • Give a board or risk committee an auditable basis for a defensive investment.

    Products or analytical outputs Zero101OSINT can provide

    • Pattern report: incident log, cross-domain correlation, competing hypotheses and confidence levels.
    • Coercive exposure assessment: which dependencies could be used as pressure and with what effect.
    • Verified chronology of an incident or campaign, with evidence and reliability rating per entry.
    • Indicator dashboard for the security or operations team, with thresholds and owners.

    Legal, ethical and reliability limitations

    No intrusive techniques, no access to third-party systems and no covert interaction with online communities are used. Analysis relies on lawfully accessible published information.

    Attribution in the grey zone is inherently uncertain: coincidence in time does not prove causation, and a single actor rarely leaves conclusive public evidence. Every finding is issued with its confidence level, and the possibility of unintended coincidence is kept on the table. This work does not constitute a criminal accusation and does not replace legal advice or a formal technical audit.

    Need analysis in this area?

    Describe the scope, the deadline and the decision the analysis has to support. You will receive the proposed approach, the limits of the assessment and the deliverable that can realistically be produced.

    Get in touch