“Even if push came to shove … that for some reason support from the U.S. got degraded, you could design the system to have enough redundancy,” he said.

Hybrid warfare encompasses a range of hostile activities that fall short of conventional military conflict. Security officials have pointed to cyberattacks, online influence campaigns, sabotage, disruptions to undersea cables, interference with navigation systems, vandalism aimed at stoking political tensions, and even the coordinated movement of migrants as examples of Russia’s hybrid operations.

For years, Western governments’ response to hybrid threats rested on deterrence. The thinking was that publicly attributing cyberattacks, imposing sanctions and strengthening collective resilience would dissuade adversaries from escalating. But repeated cyberattacks, infrastructure sabotage and influence campaigns linked to Russia have challenged that thinking, with governments increasingly pivoting to active defense measures.

Unlike traditional military operations on land, at sea or in the air, hybrid attacks often unfold in the shadows, making it far harder to prove who is behind them and what they intended to achieve. NATO has previously refrained from attributing these attacks to specific countries, instead voicing support when member countries linked disruptions to Russian and Chinese state-backed actors.

The alliance’s hybrid strategy will help NATO and private partners piece together the full scope of hybrid activity across its territory instead of lurching from crisis to crisis, Appathurai said.

“If there’s one derailment of a train in the Netherlands or one arson attack at a factory, it might just be arson or derailment,” he said. “But if you see seven, all related to support to Ukraine, then you know who’s behind it.”