Hybrid Threats
Hybrid threats are campaigns that combine legal, economic, informational, migratory and cyber instruments to obtain a political effect without crossing the threshold of armed conflict. Their defining feature is ambiguity: taken in isolation, each action looks explainable and is hard to attribute.
This area analyses precisely that accumulation. The goal is not to label an incident as hybrid, but to determine whether a set of scattered facts corresponds to a sustained pattern, and what consequences it has for the organisation affected.
What the discipline covers
- Non-military coercion: administrative, customs, judicial or regulatory pressure applied selectively.
- Instrumentalisation of flows: migration, energy, food, licences or supply chains used as leverage.
- Information operations: narrative construction, coordinated amplification and exploitation of existing social fractures.
- Cyber activity below the threshold: low-noise intrusions, well-timed leaks, denial of service with a reputational effect.
- Use of proxies and non-state actors that allow plausible deniability to be maintained.
Scope
The analysis covers the grey zone as it reaches a private organisation: the point where a state-level campaign becomes a customs delay, a licence that does not arrive, a smear campaign or an incident in a subsidiary.
- Observed effect on the organisation, its subsidiaries, its local staff and its distribution chain.
- Correlation between incidents across different domains within a defined time window.
- Assessment of exposure to coercive leverage: single-source dependencies, sensitive markets, concentrated routes.
- Explicit exclusions: no state attribution presented as proven, no offensive activity, no counter-messaging campaigns.
Main risks and threats
- Administrative and customs pressure that raises operating costs without any formal restriction being announced.
- Reputational campaigns aimed at the organisation, its executives or its regulator, timed to a negotiation.
- Interruption of a supply on which production depends, presented as a technical or bureaucratic issue.
- Pressure on local staff, subsidiaries or distributors as an indirect route against the parent company.
- Leaks of genuine internal information released at the moment of maximum damage.
- Premature attribution by the organisation itself, which turns an analytical error into a second-order effect.
Relevant indicators and warning signs
In the grey zone the most useful indicator is not the intensity of an event, but its coincidence with a political decision and its repetition across separate domains.
- Coincidence between administrative friction and moments of diplomatic or contractual negotiation.
- Series of minor incidents in different domains — customs, cyber, press, social platforms — pointing at the same target.
- Synchronised appearance of identical messages from accounts with no coherent history.
- Change in the behaviour of a partner or supplier after a political shift in their country of origin.
- Sudden reactivation of a dormant dispute, complaint or inspection file.
- Public statements that pre-justify a restriction not yet formally adopted.
Application of OSINT
- Construction of a baseline of normal friction, so that a genuine anomaly can be distinguished from operational noise.
- Temporal correlation between incidents in different domains and documented political decisions.
- Analysis of diffusion patterns: account age, text coincidence, publishing cadence, cross-platform reposting.
- Strict separation between observed effect, probable authorship and evidenced authorship.
- Mandatory competing hypotheses, always including the hypothesis of unintended coincidence.
Zero101OSINT methodology
- Baseline first: without a reference period, any incident looks exceptional.
- Event log with date, domain, source and reliability, kept separate from interpretation.
- Pattern assessment across at least two independent domains before any campaign hypothesis is raised.
- Attribution expressed as a confidence level, never as a conclusion, and always with the alternative explanation stated.
- Deliverables written so that a non-specialist decision-maker can act without accepting an unproven attribution.
- Monitoring indicators handed over so the organisation can keep tracking the pattern on its own.
Open sources used
- Official gazettes, administrative resolutions, and customs and transport statistics.
- Statements by national and European bodies on incidents and on the measures adopted.
- Public advisories from national cyber-incident response teams and from manufacturers.
- Public social platform data: account metadata, publication timing and text repetition.
- Specialised and regional press, always traced and rated, never used as the only support for a claim.
Applications for companies, organisations and security decision-makers
- Distinguish a coordinated pattern from a run of unrelated bad luck before escalating internally.
- Support crisis-committee decisions with a documented chronology instead of impressions.
- Review dependencies that can be used as leverage and prepare realistic alternatives.
- Prepare a communications position that does not rest on an attribution that cannot be sustained.
- Give a board or risk committee an auditable basis for a defensive investment.
Products or analytical outputs Zero101OSINT can provide
- Pattern report: incident log, cross-domain correlation, competing hypotheses and confidence levels.
- Coercive exposure assessment: which dependencies could be used as pressure and with what effect.
- Verified chronology of an incident or campaign, with evidence and reliability rating per entry.
- Indicator dashboard for the security or operations team, with thresholds and owners.
Legal, ethical and reliability limitations
No intrusive techniques, no access to third-party systems and no covert interaction with online communities are used. Analysis relies on lawfully accessible published information.
Attribution in the grey zone is inherently uncertain: coincidence in time does not prove causation, and a single actor rarely leaves conclusive public evidence. Every finding is issued with its confidence level, and the possibility of unintended coincidence is kept on the table. This work does not constitute a criminal accusation and does not replace legal advice or a formal technical audit.
Related reports
Spain cyberwar Morocco: defence analysis southern flank
Critical analysis of the Spanish defensive position facing Morocco: real MCCE capabilities, NIS2 delay, critical infrastructure, grey zone and plausible scenarios over 12-36 months.
Read →Why Spain doesn't respond to Morocco: anatomy of a managed asymmetry
Diagnosis of the six structural and six political factors that explain Spanish inaction against espionage and sustained southern-flank pressure after Pegasus and the Western Sahara pivot.
Read →Related articles
Geopolitical context and OSINT: how it affects corporate risk
The geopolitical context transforms the meaning of public information. Analysis of how international dynamics alter the corporate risk profile.
Read →Weak signals: how to detect risks before they become problems
Corporate incidents rarely appear without warning. Analysis of how weak signals in open sources enable anticipating risks conventional systems don't capture.
Read →How a digital narrative about a company is built
Every organization has a digital narrative that is built with or without its participation. Analysis of how public information shapes corporate perception.
Read →Information dynamics on the internet: how public perception of a company evolves
A company's public perception on the internet is not static. Analysis of the mechanisms that transform corporate image in the digital environment.
Read →Cumulative risk: how small data builds large vulnerabilities
Each piece of public data, however insignificant it may seem, contributes to a larger exposure profile. Analysis of how information accumulation generates risks that exceed the sum of their parts.
Read →Related areas
Geopolitical Intelligence
Strategic reading of state scenarios, alliances and power balances with operational impact.
Cyber Intelligence
Digital exposure, attack surface and anticipation of information risks.
Critical Infrastructure
Operational resilience, CER/NIS2 framework and protection of essential facilities.
Need analysis in this area?
Describe the scope, the deadline and the decision the analysis has to support. You will receive the proposed approach, the limits of the assessment and the deliverable that can realistically be produced.
Get in touch