Webinar Description
Key Takeaways
- Live webinar examining coordinated hybrid campaigns targeting Denmark, Norway, and Sweden
- Analysis of recent incidents including drone incursions, suspected cable sabotage, and GPS jamming
- Focus on threats designed to operate below the threshold of armed conflict
- Discussion of national detection, attribution, and resilience strategies
- Intended for security analysts, intelligence professionals, policymakers, and critical infrastructure operators
Introduction
Hybrid Threats in Scandinavia is a live webinar scheduled for 19 August 2026, addressing the convergence of cyber operations, maritime interference, and information campaigns into coordinated hostile activities across the Nordic region. The session is designed for security analysts, policymakers, intelligence officers, and professionals responsible for protecting critical infrastructure and national security interests. As Scandinavian nations face an evolving threat environment characterised by activities that deliberately avoid triggering conventional military responses, understanding how these campaigns are structured and countered has become operationally urgent.
About This Event
This virtual session takes an analytical, discussion-based approach to examining hybrid threats currently affecting Denmark, Norway, and Sweden. Rather than theoretical frameworks, the webinar draws on real monitoring data and field-tested methodologies to explore how hostile actors coordinate physical operations with information campaigns. The format emphasises data-driven analysis over speculation, providing attendees with practical insights into threat detection and response.
Coordinated Campaigns Across Multiple Domains
The webinar examines how hybrid threats manifest through the deliberate combination of different operational domains. Physical incidents such as undersea cable damage and airspace incursions do not occur in isolation but are frequently linked to broader information campaigns designed to amplify their psychological and political impact. This coordination presents particular challenges for defenders, who must track activity across cyber, maritime, and information environments simultaneously.
Recent incidents in the region illustrate this pattern. Drone incursions over sensitive sites, suspected sabotage of submarine communications cables, and GPS jamming affecting civilian and military navigation have all occurred alongside heightened information operations. The timing of increased Russian activity ahead of Swedish elections demonstrates how hybrid campaigns can be calibrated to exploit specific political moments while maintaining plausible deniability.
Operating Below the Threshold of Armed Conflict
A defining characteristic of hybrid threats is their deliberate positioning below the threshold that would trigger collective defence mechanisms or justify military responses. This grey zone exploitation creates significant challenges for targeted nations, which must respond to hostile activities without the legal and political frameworks typically available during declared conflicts. The webinar addresses the tactics and dynamics that enable adversaries to maintain this ambiguity while still achieving strategic objectives.
For Scandinavian nations, this has required developing new approaches to detection and attribution that can function effectively despite the deliberate obscuring of responsibility. Building resilience against such campaigns demands coordination across government agencies, critical infrastructure operators, and international partners.
National Strategies for Detection and Response
The session explores how Denmark, Norway, and Sweden are developing and implementing strategies to counter hybrid threats. This includes methods for detecting coordinated campaigns across different domains, attributing responsibility despite deliberate obfuscation, and building institutional capacity to respond effectively. The discussion draws on real-world examples to illustrate both the challenges these nations face and the approaches they have adopted.
Who Should Attend
This webinar is relevant for professionals working in national security, defence, intelligence, and critical infrastructure protection. Security analysts seeking to understand the structure of hybrid campaigns, policy advisors developing response frameworks, and senior security executives responsible for organisational resilience will find the analytical approach particularly valuable. The session is also appropriate for those working in information security who need to understand how cyber operations fit within broader hybrid threat contexts.

