Dear {{ first_name | reader }},
You've probably seen the phrase "gray zone" somewhere this year — next to Russia, a severed undersea cable, or a drone hovering over an airport nobody quite wanted to explain. It sounds like a term for people in uniforms, several floors above where crisis communication usually sits.
It isn't.
It started with a LinkedIn post. Consultant Aaron Marks has been writing about the gray zone regularly and reading his updates was enough to make me realise I couldn't have defined it properly myself. That's usually my cue to go and do the reading before I use a word like that in front of a client and hope nobody asks me to define it.
This week's edition works from a new Council on Foreign Relations playbook, Gray Zone Attacks Against U.S. Allies and Partners by F. David Diaz, read alongside the US intelligence community's own lexicon on the subject.
Both are written for a US policy audience, but the ambiguity they describe — deniability, delayed attribution, private-sector targets — doesn't stop at any one country's border.
The intelligence community's own assessment names China, Iran, North Korea and Russia as the states currently running these campaigns, and the case studies span the Baltic, East Asia and Latin America.
That ambiguity isn't a side effect. It's the entire design.
Enjoy!
WAG THE DOG NEWSLETTER | ISSUE WEEK 14, 2026
KEY TAKEAWAYS
Gray zone attacks are deliberate, deniable acts of coercion built to hit critical infrastructure, contractors and private citizens hard enough to matter, without crossing the line into open war.
Attribution isn't a formality — it's the single biggest delay in any response, and the Council on Foreign Relations notes that campaigns are often recognised, let alone attributed to a state, only months after they began.
Four attack types dominate the current wave: infrastructure destruction, industrial sabotage, targeted violence carried out through criminal proxies, and drone harassment, the fastest-growing of the four.
Most targets aren't government bodies at all. They're the commercial infrastructure, defence contractors, logistics networks and private citizens connected to whichever state or region is currently in an adversary's sights — which may well include yours, wherever you're based.
Speed signals resolve independent of certainty. The 2018 Salisbury poisoning drew a 25-nation coordinated response within nine days, proof that credible action doesn't require waiting for proof beyond doubt.
Table of Contents
What "gray zone" actually means
Strip away the jargon and the definition is fairly plain. The intelligence community describes the gray zone as the space between ordinary diplomacy and outright armed conflict — a realm where states use coercive or subversive means, violent or not, to get what they want while staying just short of triggering a formal military response.
The Council on Foreign Relations puts it more bluntly: gray zone attacks are deliberate but deniable acts of violence, engineered to impose real costs while giving the attacking state room to deny involvement, at least at first.
The deniability is the point. A conventional attack forces a response, because everyone can see who did it. A gray zone attack is built so that the "who" stays unclear for as long as possible — long enough for the attacker to bank the advantage before anyone can act on it.
The current wave breaks down into four recognisable patterns.
Infrastructure destruction covers undersea cable cuts and pipeline sabotage — Russia's shadow-fleet campaign in the Baltic Sea has damaged the Nord Stream pipelines, the Estlink 2 power cable, and at least eleven telecom cables since 2022.
Industrial sabotage covers arson and explosives aimed at defence and logistics facilities; researchers at the International Centre for Counter-Terrorism and GLOBSEC have documented 151 confirmed Russian-directed incidents across Europe in four years.
Targeted violence runs through criminal proxies recruited on encrypted platforms, often for a few thousand euros a job.
And drone harassment — flights over airports, military sites and city centres — is growing faster than any of the other three, and is judged the modality most likely to tip into outright conventional conflict.
Different methods, same shared flaw for the attacker to exploit: each one can plausibly pass as crime, accident, or coincidence, for as long as nobody looks too closely.
You won't know it's happening until it's too late
The CFR playbook calls this the campaign recognition problem, and it should worry a communicator more than the physical damage itself. It unfolds in two stages, one after the other, each one slow.
First, someone has to notice that a pattern exists at all. Gray zone incidents are spaced out and varied by design, so no single event looks like a campaign — a fire here, a cut cable there, a drone sighting somewhere else entirely.
Only in hindsight does the shape become visible. Second, once a pattern is finally recognised, someone still has to work out which state is behind it, which is its own separate, slower problem, because the whole point of routing an attack through a criminal proxy or an unregistered vessel is to make that step as hard as possible.
The 2023 Balticconnector incident is the case CFR keeps coming back to. A Chinese-flagged vessel dragged its anchor across a gas pipeline connecting Estonia and Finland, then slipped into Russian waters before anyone could act — not because nobody had a ship nearby, but because nobody had agreed in advance what to do.
That's a communications lesson as much as an operational one. Nobody lacked ships. What was missing was an agreed protocol for what to do next.
Why this lands on your desk, not just a government one
CFR is explicit that the primary targets of gray zone attacks abroad are frequently not government assets at all — they're commercial infrastructure, defence contractors, energy companies, logistics networks and private citizens connected to whichever state a campaign is aimed at, wherever in the world that happens to be.
That means the first phone call after an incident may land with a corporate comms director, not a foreign ministry spokesperson.
If your organisation touches energy, telecoms, ports, defence supply chains or any critical infrastructure with an international footprint, you're inside that target set, whether or not anyone has told you so.
The blind spot most crisis plans have
I've long held that risk, crisis and emergency communication are three distinct disciplines, not three names for the same job.
Gray zone attacks are a good demonstration of why that distinction matters, because a single incident forces all three at once, and most crisis plans aren't built to move between them on the same afternoon.
The physical event demands emergency-style communication within the hour. The unresolved cause holds the situation in risk territory for weeks or months afterwards — probabilistic, hedged, genuinely uncertain.
And if attribution eventually lands, it can convert overnight into a full reputational and geopolitical crisis, one that retroactively reframes everything said in the two phases before it.
A plan built for one of those three moments will fail you in the other two.
What to build before the next cable gets cut
Build these before the next incident, not during it. Separate your communications into two explicit tracks from the outset: what happened, and who is responsible.
The first track — facts, safety, operational status — can and should move fast.
The second should be held back and released only through coordinated, official channels, because premature attribution carries its own escalation risk. Draft holding language now for "cause under investigation" that doesn't quietly imply accident on one side or attack on the other; writing that sentence under pressure, for the first time, in front of a journalist, is a bad place to compose it.
Work out in advance who in your organisation actually talks to a host government, an embassy, or your national critical-infrastructure security authority — CISA in the US, and there's a comparable body in most jurisdictions — and build that relationship before you need it, not during the call.
CFR's own point about private-sector engagement applies directly here: treating that coordination as optional forfeits resilience you can't rebuild in the moment.
And don't let the absence of attribution become an excuse for silence on the facts your stakeholders are owed on day one — the two tracks move on different clocks, and only one of them can afford to wait.
The honest limitation
There's no clean fix for the core tension here. CFR's own timeline gives attribution a window of 72 hours to 30 days, sometimes longer, and you will be under pressure — from journalists, from leadership, from your own instinct — to say more than you actually know well before that window closes.
Saying too much too soon has real cost. So does saying too little. This isn't a problem you solve with better wording. It's a discipline: keep the two tracks separate, be explicit about what remains unconfirmed, and update as the picture changes rather than trying to get it right in one statement.
The actual crisis communication work happens before the incident
Gray zone attacks aren't designed to be recognised as attacks — that's the whole mechanism. Which means the useful work for a communicator happens in the anticipate phase, long before the first fact needs stating: the protocols, the two-track language, the relationships with the people you'll need on day one.
By the time attribution is confirmed, the deniability has usually already done its work. Build for that now, and you're doing crisis communication.
Wait, and you're doing clean-up.
FOOTNOTES/REFERENCES
Updated IC Gray Zone Lexicon: Key Terms and Definitions - https://archive.dni.gov/files/ODNI/documents/assessments/NIC-Unclassified-Updated-IC-Gray-Zone-Lexicon-July2024.pdf
Gray Zone Attacks Against U.S. Allies and Partners - https://www.cfr.org/reports/gray-zone-attacks-against-u-s-allies-and-partners
By Aaron Marks - The Choice You've Been Making - https://www.linkedin.com/pulse/choice-youve-been-making-aaron-marks-srmcp-aruye
Worth Attending + A Gift For You
I have a gift for you.
Free tickets to the Natural Disasters Expo USA
October 14–15, George R. Brown Convention Center, Houston – exclusively for Wag the Dog readers.
This isn't a generic trade show. It's where the people responsible for keeping communities safe come to work through the hardest problems: climate change, ageing infrastructure, extreme weather events, and population growth. Government, emergency leaders, and private-sector innovators are in one room, focused on building resilience before the next disaster hits.
THE RADAR: WHAT I’M TRACKING
[LAUNCH WEBINAR]
Pre launch preview of ‘Crisis Communications for Boards’ - CIPR[TOOL]
Best AI Agent for Non Techies[TOOL]
New AI Driven Content Curation Platform[RESEARCH]
How a legacy of mistrust in DRC has led to 17 Ebola outbreaks in 50 years
SPONSOR
4x your communication output. Same quality. No burnout.
The bottleneck isn't what you want to say — it's how long it takes to type it. Wispr Flow removes the bottleneck.
Speak naturally and get polished, send-ready text for executive summaries, client updates, board recaps, investor notes, or just the 30 Slack messages you're behind on. Flow strips filler, formats numbers and lists, and preserves your tone.
Used by teams at OpenAI, Vercel, and Clay. 89% of messages sent with zero edits. Works in every app on Mac, Windows, and iPhone.
LET’S MEET
🇪🇸 OCT 8-9 | BARCELONA
🇦🇪 MAY 10-14 | ABU DHABI
How valuable was the strategic insight in this edition?
Transparency & Disclosures
AI Transparency: In alignment with EU AI Act requirements, please note that AI technology was used in the research, drafting, and/or image generation for this edition. All strategic analysis, professional opinions, and final editorial oversight are conducted exclusively by the author. Affiliate Disclosure: Some links in this briefing may be affiliate links. I only recommend tools and services I use personally or have vetted for professional efficacy. Professional Advice: This newsletter is for educational and informational purposes only and does not constitute legal or professional crisis management advice. © 2026 RiskComms FZCO. All rights reserved.


