Back to overview
Press release

[New short course] Countering hybrid attacks: when an attack doesn't look like one

05 Oct 2026

Hybrid threats are becoming harder to identify and respond to, as cyberattacks; information manipulation, military threats and other tactics increasingly overlap. A new short course on countering hybrid threats (2–3 December 2026, The Hague) brings together legal, policy and security perspectives on how to respond. Registration is now open.

A course built for a whole-of-society response 

In recent years, the Netherlands has increasingly framed hybrid threats as a ‘whole-of-society' challenge. Since 2024, the country’s approach has emphasised cross-sector cooperation among defence, critical infrastructure, energy regulators, public health infrastructure and communications authorities to strengthen resilience and preparedness. 

That approach creates a practical challenge: the people responsible for identifying technical vulnerabilities may not always be involved in developing the legal and policy responses to them. Understanding how these different perspectives fit together is therefore becoming increasingly important. 

The ICCT and the Asser Institute are collaborating on a new short course, Countering hybrid threats: Enhancing (inter)national security and resilience (2–3 December 2026, The Hague), brings these perspectives together in a practice-oriented programme. 

The incidents are already here 

On 15 September 2026 - the day the Dutch government presented its annual budget, tubes and pipes were placed along railroad tracks at around thirty locations across the Dutch rail network, bringing train traffic in central and northern regions to a standstill. Investigators are still working to establish who was responsible. The incident was not isolated. In June 2025, a cable fire near Schiphol airport severely disrupted rail traffic during the NATO Summit in The Hague, prompting Dutch security officials to raise the possibility of deliberate interference. 

The pattern is visible across Europe. In Germany, a series of arson attacks on railway cable infrastructure in 2025 shut down major corridors for over 36 hours, affecting hundreds of thousands of passengers. Undersea data and energy cables in the Baltic Sea were damaged on multiple occasions between 2023 and 2025, disrupting connections between several northern European countries. Some cases led to vessel seizures and charges, while others remain under investigation. Together, these incidents illustrate why hybrid threats can be difficult to identify, attribute and respond to. 

The legal challenge of hybrid threats 

Hybrid methods of warfare can deliberately exploit ambiguity, making legal attribution difficult even when responsibility appears clear. For instance, a cyberattack may be criminal, state-sponsored, or both, while election interference and infrastructure disruption often remain difficult to attribute. 

To respond, the EU has introduced a hybrid toolbox, including Hybrid Rapid Response Teams, and has strengthened cooperation with NATO. But practitioners across sectors still have to navigate an evolving set of legal and policy tools while responding to threats that cross organisational and national boundaries. 

Bridging the gap 

The course focuses on the practical questions that arise when hybrid threats cross the boundaries between law, security, technology and policy. You will learn how to identify and assess different types of hybrid threats, evaluate possible responses, and strengthen resilience and preparedness within your organisation. 

No legal background is required. The course, co-organised with ICCT The Hague, is aimed at security officials, policymakers, academics, tech experts, police officers and other professionals working at the intersection of law, security, technology, human rights and international affairs. 

Seats are limited. Save your spot today.