Are Russian grey ops the new War on Terror?


Russia is menacing Europe: It is testing reactions and resolve, spreading instability, and chipping away at the principles of collective defence. The only appropriate response is to acknowledge the seriousness of the threat and ramp up preparedness and defence spending — and to show Russia that the West will not shy away from confrontation.

This, at least, is the narrative that dominates the media and security landscape. There is strong justification for it: There is ample evidence of Russia pushing the boundaries and engaging in nefarious activities, and Russia has long held a low — and, until the war in Ukraine, entirely justifiable — opinion of the West’s resolve. But to what degree does the nature of the threat align with the perception. In this week's newsletter, I ruminate on the parallels between the current threat and the Global War on Terror (GWOT) — and argue that this ultimately serves the interests of Russia more than those of the Western security community.

Here’s what you can expect this week:

  • The Russian threat menacing Europe
  • The GWOT and the securitisation of everything
  • Parallels, lessons, and pathways

To read this newsletter in your browser, click here.

The Russian threat menacing Europe

Browse through any serious newspaper and it likely won’t be long before you encountera headline warning of the threat that Russia poses to Western security. Over the last week, the Estonian foreign minister has cautioned that Russia is escalating a campaign of sabotage and arson; the German chancellor has spoken about preparing for Russian hybrid attacks,and the Danish intelligence services have claimed that Russia could be readying a limited military operation against a NATO country. Pick a different week and the details will change, but the underlying message will likely remain the same.

This rhetoric has a long history. For some commentators, there has always been a threat from the East and the transition from the Soviet Union to the Russian Federation meant little more than a change of clothes. Russia’s invasion of Ukraine was, therefore, little more than a vindication of long-held beliefs. Historian Mark Smith penned an entire book on what he termed “The Russia Anxiety”, which he characterised as “an historic syndrome that alternates between three sets of symptoms: fear of Russia, disregard of Russia and contempt for Russia”.

Over the years, Russia has provided ample material to fuel these concerns: from a UK perspective, the poisonings of Aleksandr Litvinenko in 2006 and Sergey and Yuriy Skripal in 2018 stand out as two of the most egregious examples. Since the start of Russia’s invasion of Ukraine, the number of nefarious incidents linked to Russia have proliferated, from an arson attack on a London warehouse involving the Wagner private military company to damage to undersea cables allegedly inflicted by the “shadow fleet”.

Much of this activity is bracketed under the label “grey zone” or “hybrid” operations (the different terms and the problems with how they are defined is a topic I’ll tackle later). These refer to hostile acts that seek to cause damage and spread instability but fall short of the threshold that would necessitate a military response. Since this threshold is by design not clearly demarcated, such activities test where they are and how far back they can be pushed. Hybrid operations are also marked by challenges of attribution, which can further complicate responses. Although there are reasonable doubts about whether it holds in the age of Trump, NATO’s Article 5 is the bedrock of Western collective security. Hybrid operations seek to remain below the threshold at which it can be invoked while at the same time further undermining confidence that it ever will be.

The GWOT and the securitisation of everything

NATO’s Article 5 has been invoked precisely once in the history of the organisation: After the terrorist attacks on the United States on 11 September 2001. The response to those events is relevant in other ways too. The West transformed its security architecture in the wake of those attacks. It launched ruinous wars in Afghanistan and Iraq. It increased security at airports and most other places where people gather. It forced schools and universities to identify and report potential extremists. It policed thought as well as behaviour. It created entire new security institutions.

However, questions were asked about whether this corresponded to the scale of the actual threat. Between 2001 and 2011, US expenditure on domestic security alone increased by approximately $1 trillion, and similar hikes were seen elsewhere. The total number of people killed globally by Muslim extremists operating outside war zones, by contrast, averaged 200-300 per year over that same period. The definitional parameters can be tweaked to produce different figures, but it is indisputable that in statistical terms terrorism was never a primary threat to Western lives. Certainly no jihadist groups ever seriously threatened to bring down a Western state or defeat its military. Yet the impact of terrorism on Western security postures was transformative.

The process of exaggeration, inflation, and securitisation gave rise to a cottage industry of “critical terrorism” scholars who devoted entire journals, books, and conferences to challenging the shortcomings of Western counterterrorism approaches. Occasionally, parts of this community would smear other academics or lambast the sources of research funding while hypocritically submitting funding bids to the very same sources. But they also raised valid concerns about whether the response to terrorism corresponded to the actual threat it posed. A single person with a knife and a grudge could be transformed into a global menace by invoking the spectre of jihadism. A small group could become a “threat to our way of life” without being able to secure control over territory as small as their own apartment.

Parallels, lessons, and pathways

There are lessons that we can draw from both the GWOT and the responses to it. One of the flaws of the critical terrorism crowd was that it had very little to say about terrorism itself. Scan its core journals and articles dealing with actual political violence are a relative rarity; its focus instead was on challenging the discourses around terrorism and the way that this was used to justify policy responses. The group also demonstrated only limited understanding of the state apparatuses that were tasked with challenging it. One of its doyens, Richard Jackson, once charged that “Policymakers are, for the most part, uninterested in evidence-based policy, or in the rigorous evaluation of counterterrorism policy, or in listening to reasonable, evidence-based suggestions about how to more effectively, and more ethically, respond to acts of terrorism”. This was always untrue and, ironically enough, an entirely unsubstantiated claim. Critical assessments of the West’s current security posture should not fall into the same trap of simply dismissing concerns about the threat posed by Russia and the motives of those who draw attention to it.

At the same time, we can recognise that two things can be true simultaneously: We can acknowledge that Russia is engaging in activities that give rise to genuine security concerns while also recognising that the nature of the threat that it poses is being exaggerated and/or misunderstood. The first part of this is uncontroversial: Russia has invaded its neighbour, so the threat that it poses is not purely abstract or theoretical; its potential to inflict harm far exceeds that of terrorists; and there are numerous deleterious activities that can plausibly be linked to it. The second part, however, is defensible even in the face of this: By bundling together very different types of activity together and treating everything from a bin fire to an explosive-laden drone attack on an aircraft as the same thing, we lose sight of which activities pose a genuine security threat and which are merely a nuisance. In the next newsletter, I’ll unpack how this bundling manifests itself in how we talk about hybrid threats.

The cynical among you will rightly point out that this heightened rhetoric serves the interests of a security community that desires ever-more resources. Both state apparatuses and the think tank community that supports them benefit from heightened perceptions of threat, just as they did in the case of terrorism. But it is equally true that, among the same community, there are people who genuinely want to understand the nature of the threat and design responses to it. They are poorly served by discussions that cast Russia as a ubiquitous, all-powerful bogeyman — a narrative that benefits the Russian security apparatus more than it does its Western counterparts.


Think someone else would find this useful? Why not forward it to them?

About me

I'm Dr Mark Youngman, an open-source investigator specialising in Russian security, and I run Threatologist. You can explore the free research and resources available in the Russian Security Research Lab (RSRL). If you need bespoke analysis or data — a dataset, literature review, or tailored report scoped to your question — check out my services.

600 1st Ave, Ste 330 PMB 92768, Seattle, WA 98104-2246
​Unsubscribe · Preferences​

Tracing Patterns

Each issue unpacks a major news story from the world of Russian security — tracing the relationships, trends, and deeper meaning behind it — so you can move beyond surface-level news and better understand the threats coming from Russia today.

Read more from Tracing Patterns
Tracing Patterns logo

In a result that surprised absolutely no one, Ramzan Kadyrov secured a comprehensive victory in this week's elections, ensuring that he will remain as Chechen head for the foreseeable future. The size of his “victory” was preposterous, but what many observers miss is that the preposterousness is the point. In this week’s newsletter, I’ll explain why the Chechen regime does not even pretend that it’s elections are competitive. Here’s what you’ll find this week: Ramzan’s inevitable victory...

Tracing Patterns logo

In the modern world, we have no shortage of “content” to consume (a ghastly noun combined with an equally ghastly verb, yet somehow quite appropriate). Much of it is like fast food: nutritionally dubious. How many things do you read and instantly forget? How many sound identical to something you’ve already read? How many do you not even read because time is short and the demands on it many? We do not need more words on the page. What we need are more words that are carefully crafted and stem...

Tracing Patterns logo

We need to know where the Chechen security services have operated if we want to make reliable assessments of the scale and significance of their activities. Yet the question of where is much harder to answer than it often appears. In this week’s newsletter, I want to reflect on some of the challenges that hinder efforts to track security service operations on the ground. Mitigating these challenges is, after all, important if I want to add a robust database of their Chechen activity in...