How does hybrid warfare (cyberattacks, sabotage, drone incursions) blur the line between war and peace in contemporary international relations?
In this answer
Hybrid warfare combines cyberattacks, sabotage, disinformation and drone incursions to inflict strategic damage while staying deliberately below the threshold of armed attack. By making hostility continuous but deniable, it dissolves the binary of declared war and formal peace on which the post-1945 order rests.
How the threshold is blurred
- Deniability: unmanned and cyber tools allow harm without attributable state signature; NATO jets shot down a drone entering Romanian airspace in July 2026, yet such incidents are treated as violations rather than acts of war [1].
- Calibrated intensity: attacks are pitched high enough to coerce, low enough to avoid a military response — the North Atlantic Council in August 2026 called Russia's airspace violations "dangerous and unacceptable" but responded with solidarity and air-defence reinforcement, not war [2].
- Continuity: unlike conventional war, hybrid pressure has no start or end date, making "peacetime" itself contested.
Legal ambiguity
- The UN Charter permits self-defence only against an "armed attack" (Article 51), while Article 2(4) bars the use of force — leaving sub-threshold coercion under-regulated [3].
- The Tallinn Manual 2.0 devoted itself precisely to cyber incidents "below the thresholds of the use of force or armed conflict", confirming that law applies but its triggers remain contested [4].
Strain on collective security
- NATO's Article 5 has been invoked only once, after 9/11, 2001; hybrid probing tests whether a drone or cyber intrusion ever qualifies, risking either paralysis or over-reaction [5].
Relevance for India
- CERT-In handled over 29 lakh cyber incidents in 2025, showing that critical infrastructure is a permanent contested space even absent war [6].
Hybrid warfare therefore relocates conflict into a persistent grey zone where deterrence must be built on resilience rather than retaliation alone. States need clearer attribution capacity, agreed thresholds, and hardened critical infrastructure, supported by norms consistent with the UN Charter's commitment to peaceful settlement — turning ambiguity from an aggressor's asset into a manageable, rule-governed space.
Sources
- 1NATO fighter jets scramble, shoot down drone after it enters Romania airspace — NATO Allied Air Command (July 2026)drone incursion into NATO airspace and non-war response
- 2NATO Allies condemn recent airspace violations and incidents — NATO News (12 August 2026)Allied characterisation of violations; eastern-flank air-defence reinforcement
- 3Charter of the United Nations, full text — United NationsArticle 2(4) prohibition of force; Article 51 armed-attack threshold
- 4Tallinn Manual 2.0 on the International Law Applicable to Cyber Operations — NATO CCDCOElegal treatment of operations below the use-of-force threshold
- 5Collective defence and Article 5 — NATOArticle 5 invoked only once, after 9/11 (2001)
- 6CERT-In: India's Frontline Defender against Cyber Threats — PIBvolume of cyber incidents handled in India