Hybrid warfare and the origins of the Bunker Brief

Hybrid warfare and the origins of the Bunker Brief

Hybrid warfare and the origins of the Bunker Brief
ProtectUK currently lists the UK national terrorism threat level as SEVERE, meaning an attack is assessed as highly likely.

In 60 seconds

Validate your crisis management, business continuity and cyber arrangements together, including how you will operate when normal systems are unavailable. Hybrid threats can disrupt everyday services, and the consequences can spread quickly. That practical focus on maintaining control runs through our work at Controlled Events and the story behind our Bunker Brief.
đŸ‘€

Who this is for

This article is for Event Directors, Event professionals, Operations Directors, Security Directors and Chief Executives.

What the guidance and good practice says

Hybrid warfare reaches everyday operations

Gibridnaya voyna is the Russian term for hybrid warfare. NATO describes hybrid threats as combining military and non-military methods, including cyber attacks, disinformation, economic pressure and covert activity, to destabilise societies and blur the boundary between war and peace. NATO explains hybrid threats.

The UK is exposed to this activity. In its October 2025 threat update, MI5 described Russian sabotage and the use of proxies, including the case of an East London warehouse containing supplies for Ukraine being deliberately set alight. Read the MI5 threat update.

For organisations, the practical concern extends beyond being directly targeted. A disruption affecting a power network, telecoms provider or supplier can interrupt your own services. Power loss may affect communications, building access and the IT needed to coordinate recovery. Several dependencies can fail together.

The cause may initially be unclear. Your team still needs to protect people, prioritise essential activities and communicate what is known. Planning around those consequences also strengthens your response to accidental failures and other emergencies.

The story behind Controlled Events and the Bunker Brief

Controlled Events was established in 2011. Our name grew from work across diverse sectors: nuclear site emergency planning, where we planned for uncontrolled events as risk scenarios, and event command and control projects. Both required people to make sound decisions and coordinate an effective response when circumstances changed.

That connection continues through our five pillars: Learn, Plan, Validate, Control and Communicate. It also explains why a resilient base for our own work matters to us.

Our bunker in the Chiltern chalk hills took shape as a working base in the summer of 2025. The timing coincided with international events; our purpose was practical: to create a resilient place from which we could continue delivering projects for clients.

The site dates from the 1940s, when a school required a hardened shelter close to a requisitioned manor house. Today, it has been refitted with modern IT, a generator and backup IT. Many clients will recognise it as the background to our calls and webinars.

It also gives the Bunker Brief its name: a place from which to share practical observations on readiness, disruption and maintaining control. The setting has a history of protection; our work today focuses on how organisations prepare to keep functioning.

What good looks like

Validation must test how your plans work together

Imagine your main IT platform becomes unavailable. A key supplier reports disruption, mobile communications are unreliable and an inaccurate account of the incident starts circulating online. Who takes charge, what continues and how do you reach the people who need instructions?

That is an illustrative exercise scenario. It brings crisis leadership, operational continuity and cyber response into the same conversation, with the uncertainty and competing demands that separate plan reviews can miss.

 

Common mistakes we see

Resilience planning must cover the full chain of organisations and infrastructure that keeps your service running. The UK Government’s National Risk Register includes scenarios involving simultaneous infrastructure failures and prolonged recovery. Organisations often focus on the individual risks and not the compound risk from multiple scenarios occuring. All organisations should therefore develop realistic assumptions about losing power, communications, premises, staff and access to reliable information, with durations matched to their critical activities and the risks they face. A generator needs fuel, maintenance and someone able to operate it; remote working needs domestic electricity and connectivity; restored IT needs functioning suppliers and people who can use it. Those dependencies extend beyond your direct contracts. Your supplier may rely on a subcontractor, cloud platform, distribution centre or transport route that also supports your alternative provider. Two supplier names do not necessarily provide two independent options. Government supply-chain guidance emphasises visibility, alternative sources and access to reserves or additional capacity. Common mistakes include accepting a continuity plan as proof of capability, assuming replacement resources will be available during widespread disruption, and setting recovery targets that suppliers cannot support. Downstream dependencies deserve equal attention: customers and partners may be unable to receive your outputs, while interruption to your service may stop theirs. A low-cost supplier can also be operationally critical, making contract value a poor substitute for understanding impact. At Controlled Events, we encourage organisations to turn these assumptions into practical tests: identify what must continue, establish how long disruption is tolerable, and exercise fallback arrangements with the people and partners involved. The Cabinet Office’s business continuity toolkit supports this approach through business impact analysis and exercising. Validate your crisis management, business continuity and cyber arrangements together, record what actually works, and assign ownership to the gaps before an incident exposes them.

Practical checklist

A useful starting point is to test three things:

  1. Crisis management: can the team assemble through an alternative route, establish authority, assess incomplete information and maintain a decision log?
  2. Business continuity: can essential activities continue without the usual premises, systems or suppliers, and for how long? Test access to fallback resources, including power, fuel and communications.
  3. Cyber arrangements: can leaders and technical responders coordinate containment and recovery, use trusted communications and demonstrate that critical information can be restored?

A backup should be checked for dependencies shared with the primary system. A second communications service may still rely on the same power supply, network or login. Equipment also needs people who know how to use it.

Start with a focused tabletop exercise, then use controlled drills to demonstrate the capabilities that matter. Record what worked, assign owners and deadlines to improvements, and retest the gaps. Validation should produce evidence of what your organisation can sustain.

Validate your arrangements with Controlled Events

We help organisations turn planning assumptions into realistic exercises, from crisis team tabletops and cyber scenarios to practical continuity drills. We bring the relevant people together, test how arrangements work and identify improvements that can be acted upon.When did your team last practise operating without its normal systems? Contact Controlled Events or email support@controlledevents.com to discuss validating your crisis management, business continuity and cyber arrangements.

FAQs

What does ‘operational readiness’ actually mean?

Operational readiness is the ability of a team or organisation to respond effectively to incidents or deliver events safely. It includes:

  • Trained people
  • Clear procedures
  • Tested systems
  • Strong communication protocols

How can organisations improve their readiness?

Key ways include:

  • Scenario-based training
  • Regular exercises and simulations
  • Clear roles and responsibilities
  • Reviewing and refining processes after events

Training plays a key role in building confidence and coordination under pressure.

Why do teams struggle during live incidents even if they are experienced?
Control rooms often bring together people who don’t usually work together, meaning:

  • There may be no shared processes
  • Communication styles may differ
  • Decision-making structures may be unclear

This can impact performance unless teams have trained together beforehand.

Controlled Events supports readiness reviews, training and live drills. Get in touch to arrange a conversation about your next steps.

Contact us

Related Topics

Contact Us

Interested in the products and services we have to offer? Please get in touch with our team, and we’ll get back to you as quickly as possible.