The Battle to Know Before the Battle Begins: Intelligence in an Age of Irregular Threats

As discussed in the author’s previous RSDI article, irregular warfare has re-emerged as an important feature of contemporary strategic competition. Building on that discussion, this article focuses more specifically on the nature and implications of irregular threats operating between routine peacetime competition and open armed conflict, state and non-state actors can exploit political and legal uncertainty, proxy networks, emerging technologies, economic relationships, and vulnerabilities in critical infrastructure to advance strategic objectives while reducing the risks associated with direct military confrontation. The significance of these threats lies not only in the impact of individual incidents, but also in their cumulative ability to exert sustained pressure on governments, institutions, economies, and societies.

This changing security environment presents significant challenges for intelligence organisations, particularly those whose structures and practices were developed primarily to address conventional state-based threats. Against this backdrop, this article examines the key intelligence challenges created by irregular threats and identifies the lessons intelligence organisations can draw from recent cases to improve their ability to anticipate, understand, and respond to an evolving threat environment.

How do Irregular Threats Challenge the Conventional Strategic Intelligence Systems?

Traditional strategic intelligence systems were largely designed to monitor states, assess military capabilities, identify troop movements, and provide warning of conventional attack. Irregular threats challenge this model because they are often less visible, cross traditional institutional boundaries, and do not always produce the clear warning indicators associated with conventional military threats.

Determining who is responsible for an irregular activity, and whether it was deliberate, can be difficult. A surveillance balloon entering another state’s airspace may be presented as a civilian research platform that drifted off course, while damage to undersea cables caused by a commercial vessel may initially appear to be an accident. Intelligence agencies may therefore have indications of hostile activity without sufficient evidence to establish state responsibility or intent. This creates a difficult policy problem. The governments may need to respond quickly while still facing uncertainty about who was responsible, what they intended to achieve, and whether the incident forms part of a wider campaign.

Irregular threats frequently cross the boundaries between national security, law enforcement, economic regulation, cyber security, and foreign policy. Activities such as corruption, foreign interference, sabotage, cyber operations, or politically motivated violence may therefore be investigated separately by different government agencies. While each institution may understand one part of the problem, policymakers may not receive a complete picture of how apparently unrelated activities could contribute to a broader strategy of coercion or influence. The intelligence challenge is therefore to connect individual incidents and identify patterns that may reveal a coordinated campaign.

Geography and environmental conditions can create significant gaps in surveillance and situational awareness. The High North provides an important example. Its vast distances, difficult weather conditions, limited infrastructure, and growing presence of dual-use civilian and military activities make sustained monitoring difficult. Research facilities, commercial vessels, communications infrastructure, and other civilian activities can potentially serve both legitimate and strategic purposes. Intelligence organisations must therefore distinguish routine civilian activity from behaviour that may have wider security implications.

Converting intelligence into timely action is one of the predominant challenges intelligence organizations face countering/preventing irregular threats. This is particularly important in counterinsurgency environments such as the Sahel and Lake Chad Basin. Security forces may possess information about insurgent movements or possible attacks, but that information is valuable only if it reaches the relevant commanders and units in sufficient time to act. Weak communications, institutional barriers, limited coordination, and delays between intelligence collection and operational decision-making can allow small and dispersed armed groups to retain the initiative even when warning information exists. The problem, therefore, is not always an absence of intelligence. It can also be a failure to distribute, interpret, and act upon available intelligence effectively.

Taken together, these challenges suggest that intelligence systems designed primarily around identifiable state adversaries and conventional military warning are not always well suited to irregular threats. Contemporary intelligence organisations increasingly need to identify relationships between activities occurring across different sectors, assess threats under conditions of incomplete attribution, and ensure that intelligence reaches decision-makers quickly enough to support effective action.

What are the Lessons for the Intelligence Community?

Responding effectively to irregular threats requires intelligence organisations to adapt how they collect information, assess threats, share intelligence, and support decision-making. Within this context, five priorities are particularly important for intelligence organizations to function effectively and efficiently.

Intelligence organisations need to develop a more integrated understanding of threats. Irregular campaigns rarely occur within a single area of national security. Activities at sea, in cyberspace, within financial systems, across information environments, and around critical infrastructure may be connected to the same strategic objective. Intelligence organisations therefore need mechanisms that bring together information from different government agencies and intelligence disciplines.

The objective is not simply to collect more information, but to identify relationships between activities that might appear insignificant when assessed separately.

Technology should be complemented by strong local networks. Satellites, sensors, drones, and other surveillance technologies can significantly improve situational awareness, but they cannot provide a complete understanding of every operating environment. This is particularly evident in remote and geographically challenging regions. Community-based arrangements, including models such as the Canadian Rangers, Greenland’s Sirius Patrol, and Norway’s Home Guard, demonstrate the potential value of combining national security capabilities with local knowledge and sustained human presence. Such partnerships can help governments identify unusual activities, understand changes in the local environment, and maintain awareness in areas where a permanent state presence may be difficult or expensive.

Greater attention needs to be given to counterintelligence and the protection of critical sectors. Irregular threats can exploit individuals, commercial relationships, financial networks, and legitimate businesses to gain access to strategically important infrastructure and institutions. Governments therefore need stronger mechanisms for identifying foreign influence, conflicts of interest, insider risks, and suspicious financial relationships in sensitive sectors such as transportation, ports, telecommunications, energy, and logistics. These measures should be proportionate to the level of risk and operate within clear legal, privacy, and oversight frameworks.

Intelligence needs to reach operational units quickly enough to be useful. This is particularly important in counterinsurgency and other rapidly changing security environments. Smaller units can benefit from direct access to drones, surveillance systems, and relevant intelligence, supported by command structures capable of analysing and distributing information rapidly. Shortening the time between identifying a threat and informing those responsible for responding to it can reduce opportunities for dispersed and mobile adversaries to exploit delays in decision-making.

Governments need to assess individual incidents within their wider strategic context. Sabotage, foreign interference, corruption, cyber activity, disinformation, or suspicious commercial behaviour may initially appear to be separate criminal or regulatory issues. Intelligence organisations should be capable of determining whether such activities form part of a broader pattern of foreign coercion or interference. Where sufficient evidence exists, policymakers should communicate this wider context clearly through appropriate intelligence assessments, public statements, prosecutions, and policy responses. At the same time, public attribution should remain evidence-based and proportionate, since overstating uncertain connections can undermine rather than strengthen public confidence.

Ultimately, adapting intelligence to irregular threats is not primarily about creating more powerful intelligence agencies or acquiring more sophisticated technology. It requires governments to become better at connecting information across institutional boundaries, combining technological capabilities with human knowledge, protecting strategically important sectors, and translating intelligence into timely decisions. The central objective of intelligence should be to recognise coordinated patterns of hostile activity early enough to provide policymakers with meaningful options before individual incidents develop into a wider national security challenge.

Conclusion

In conclusion, intelligence systems designed primarily to monitor conventional military threats need to become better at identifying connections between activities occurring across different areas of national security. This requires closer cooperation across government, stronger partnerships with local communities and the private sector, better integration of human and technological sources, and faster movement of relevant intelligence from collection to decision-making. It also requires intelligence organisations to distinguish isolated incidents from coordinated campaigns without overstating connections where the evidence remains uncertain.

The central policy challenge is therefore not simply to collect more intelligence, but to recognise emerging patterns early enough to support effective decisions. Irregular threats gain much of their advantage from ambiguity, fragmentation, and delayed responses. Intelligence can reduce that advantage by connecting information that would otherwise remain separated, clarifying the strategic significance of seemingly unrelated activities, and providing policymakers with options before those activities develop into a wider security challenge. Adapting intelligence institutions to this environment will be essential to strengthening national resilience and protecting states and societies against the evolving irregular threats of the twenty-first century.

Submit Your Publication

Submit Your Publication

Submit Your Publication

Submit Your Publication

Submit Your Publication

Submit Your Publication

Submit Your Publication

Submit Your Publication

Submit Your Publication

Submit Your Publication

An error has occurred. This application may no longer respond until reloaded. Reload 🗙