The Threshold Problem Takes Center Stage
A convergence of new policy analysis and real-world incidents is forcing Western governments and legal scholars to confront a fundamental challenge: how should states respond, legally and institutionally, when hostile cyber operations against civilian critical infrastructure are deliberate enough to cause societal disruption yet calibrated precisely to remain below the thresholds that would trigger treaty obligations or justify a military response?
The question is no longer theoretical. In April 2026, Swedish Civil Defense Minister Carl-Oskar Bohlin stated publicly that Russian methods had shifted, and announced that the Swedish government had concluded that a 2025 cyberattack on a heating plant in western Sweden was carried out by a pro-Russian group with links to Russian security and intelligence services. Bohlin drew a direct comparison to a December 2025 attack on Poland's power grid. Writing in the Atlantic Council, analysts Anna Wieslander, Aaron Korewa, and Justin Sherman observed that Sweden's announcement marked an important shift in how the country publicly frames the threat from Russia — specifically, for the first time, Swedish authorities openly attributed such activity to actors linked to Russian security and intelligence services, connecting it to an attempted intrusion into critical infrastructure on Swedish territory.
The Swedish case did not produce major physical disruption — protective systems held — but it nevertheless represents an attempt to affect civilian infrastructure in a NATO member state. That distinction matters enormously under international law: an operation that fails to cause significant effects may not constitute an "attack" within the meaning of international humanitarian law, leaving the victim state with limited recognized legal options for response.
A Deliberate Strategy of Sub-Threshold Pressure
The incidents point to a shift in Russian tactics, with operations increasingly directed at operational technology controlling physical functions, raising the potential for real-world disruption, particularly in the energy sector, where even limited interference can generate disproportionate societal effects. The Atlantic Council analysis situates these episodes within a broader pattern: against the backdrop of more than 150 incidents of sabotage, cyberattacks, and influence operations linked to Russia across Europe since 2022, this reflects a more risk-acceptant approach within a sustained campaign to pressure European states supporting Ukraine, testing resilience, creating uncertainty, and demonstrating reach without triggering direct military confrontation.
This design — deliberately staying below thresholds while accumulating strategic effect — is precisely what a July 2026 Council on Foreign Relations Crisis Response Playbook addresses in broader hybrid-warfare terms. Gray zone attacks, the playbook argues, are part of a deliberate strategy by states to weaken adversaries — in this case U.S. allies and partners — without crossing the threshold that would legally or politically compel a military response. The legal consequence is significant: responding quickly and effectively to hybrid warfare attacks against U.S. allies and partners is a growing challenge for policymakers, because when an aggressor designs an attack to deliberately obscure its identity and avoid triggering a full-scale military response, choosing an approach, as well as securing domestic and international support, becomes uniquely difficult.
Institutional and Legal Gaps
The CFR playbook identifies structural gaps that compound the legal ambiguity. Two institutional gaps complicate every policy decision: no single U.S. government agency is responsible for integrating each of the warning indicators before a crisis, and no standing mechanism exists to orchestrate a rapid government-wide response during one. The playbook further recommends that which agency should lead the U.S. government's response — State, Defense, or Treasury — is best determined by attack type, and that determination should be made as a matter of policy before a crisis, not improvised under pressure.
The absence of such pre-agreed frameworks has legal as well as operational significance. Attribution — already contested in Swedish and Polish cases — conditions almost every available legal response, from countermeasures under the law of state responsibility to sanctions and treaty consultations under Article 4 or Article 5 of the North Atlantic Treaty. Russia is consistently testing the boundaries of what it can do against the Baltic states and their allies without provoking a decisive response, and the pattern of actions linked to Russia ranges from drone incursions and sabotage of critical infrastructure to arson, assassination plots, cyber operations, and GPS jamming and spoofing.
The European response has been primarily defensive and coordinative. The incidents have accelerated a policy shift, with Sweden and its regional partners placing greater emphasis on civil preparedness, infrastructure protection, and public-private coordination, while deepening cooperation through NATO and the European Union. However, CFR analysts have cautioned that transatlantic friction complicates collective action. The loss of trust in the transatlantic relationship raises the risk that Russia could step out of the so-called gray zone and cross the line to low-level conventional attacks against European countries, with the hope that a lackluster response would fatally wound the NATO alliance.
The U.S. Strategy's Silence on Allies
Against this backdrop, the Trump administration's national cyber strategy — released in early 2026 — has drawn pointed criticism for omitting a coherent allied coordination framework. CFR fellow Matthew Ferren argued in March 2026 that for the Trump administration, cyberspace is a hostile, militarized domain in which U.S. power is unmatched, and the strategy privileges offense over defense, prizes visible displays of capability over sustained institutional reform, and treats the private sector primarily as a source of energy to be unleashed rather than a source of systemic risk to be managed. Critically, as the United States ramps up offensive operations and integrates cyber effects into military campaigns, it will also need allied cooperation for access, coordination, and deconfliction — yet the strategy offers no framework for any of these activities, and the administration's broader approach to alliances has not created the reservoir of goodwill such cooperation requires.
Ferren further noted that the administration paused planned sanctions against China over Salt Typhoon to avoid disrupting trade negotiations, undermining confidence that it will impose costs when they conflict with other priorities. That same reluctance to bear cross-domain costs when strategically inconvenient may blunt the deterrent effect against Russian sub-threshold operations in Europe as well.
Legal Outlook
The accumulated record suggests that existing legal categories — use of force, armed attack, countermeasures — remain ill-fitted to operations that are persistent, cumulative, and aimed at operational technology rather than immediately destructive outcomes. The CFR and Atlantic Council analyses together imply that the next phase of policy debate will turn on whether states can articulate and agree upon an aggregation doctrine: the legal theory under which a series of individually sub-threshold operations, linked to a single state actor, triggers collective rights of response. Until that doctrine is settled — either through state practice, UN processes, or updated alliance guidance — the legal gap will remain a standing invitation to the very calibrated coercion that these incidents exemplify.