
Field Notes
Grey-Zone Operations and the Geostrategic Threat Reaching Your Corporate Perimeter
A Willis Research Network report published in February 2026 documented that grey-zone aggression, previously assumed to affect only aviation and shipping, is now a material threat to businesses across energy, ports, logistics, defence manufacturing, and retail supply chains.1 "Every industry carries meaningful exposure," the report stated. Allianz ranked cyber incidents as the number-one business risk in its 2026 Risk Barometer, and the fastest-growing subcategory within that ranking is cyber operations linked to state-directed grey-zone campaigns with deliberate corporate targeting.2 The exposure is not new. The explicit documentation that the corporate sector has become a primary target is.

Why Geostrategic State Campaigns Now Reach Corporate Infrastructure
Grey-zone operations appeal to state actors for two structural reasons unrelated to technical sophistication: plausible deniability leaves the targeted organisation without legal or diplomatic recourse, and asymmetric impact means the attacker's execution cost is a fraction of the corporation's remediation and lost-business cost.1
- Hiring process exploitation. Google's Threat Intelligence Group documented in February 2026 that state-sponsored actors are deploying AI to profile corporate employees and identify candidates for initial compromise through fraudulent recruitment. North Korean groups have impersonated defence contractor recruiters. Iranian state-sponsored actors have created fraudulent job portals to extract credentials from drone manufacturers and defence firms. Chinese-linked group APT5 ran personalised phishing campaigns tied to employees' geographic locations and personal details.3
- Gig worker recruitment as an execution layer. The Willis report identified online-recruited gig workers as a specific execution method. Short-term employment relationships make detection by corporate security functions and law enforcement extremely difficult.1
- Attribution asymmetry as design. In supply chain tampering and cyber espionage, attribution is routinely incomplete. The attacking state pays no diplomatic cost. The targeted organisation absorbs the full operational and financial consequence. This is not a side effect of grey-zone operations. It is the architectural intent.

The Three Vectors Targeting Corporate Operations
The attack surface has diversified across three distinct vectors, each requiring a different monitoring response and a different defence posture. Treating all three as variants of the same problem produces a generic response that addresses none of them adequately.
- Supply chain tampering. The 2026 cyber-threat landscape is characterised by a shift toward software supply chain exploitation: fake GitHub profiles, malicious open-source packages, and dependencies introduced through CI/CD pipelines.4 An attacker who compromises a build environment has access to every system running code from that environment without triggering a single perimeter alert. The attack enters through a trusted supplier relationship, not through the corporate boundary.
- Cyber-enabled economic espionage. This vector targets merger and acquisition intelligence, pending patent applications, competitive pricing data, and regulatory engagement positions. The adversary is not necessarily trying to disrupt operations. It is extracting intelligence with asymmetric commercial or geopolitical value. China-linked actors targeting US AI companies escalated significantly in mid-2026 as the technology competition between the two countries intensified.5
- Disinformation and reputation targeting. State-directed disinformation campaigns are increasingly calibrated to damage the commercial credibility of specific companies rather than to advance a broad political narrative. For companies with government contracts, dual-use product lines, or significant market position in contested sectors, manufactured controversy functions simultaneously as a market disruption tool and a competitive intelligence operation.

The Watch Indicators That Precede Campaign Intensification
Grey-zone campaign intensification against corporate targets is not random but follows observable geopolitical triggers with documented lead times. A risk function monitoring these indicators operates upstream of the campaign, not downstream of the incident.
- BIS entity list additions. Each addition signals an escalation in US export control enforcement. Retaliatory grey-zone activity against corporate targets in the affected sector typically follows within 60 to 90 days. The entity list is public, updated regularly, and directly actionable as an upstream trigger.
- CISA threat actor advisories. CISA advisories on specific actor activity provide high-confidence signals of active campaigns, naming the actor, the targeted sector, and in many cases the specific techniques in use. A CISA advisory is an operationalised intelligence product with direct implications for corporate security posture.
- MOFCOM and Chinese official media commentary. Official commentary targeting specific sectors or named companies provides advance warning of pressure that may manifest through regulatory action, economic coercion, or grey-zone cyber operations. The pattern from official signal to corporate targeting is consistent and documented across multiple sector cases since 2023.
- DDTC rule changes on dual-use technology. US government enforcement priorities on dual-use export are a reliable predictor of adversarial interest in the same technology categories. A technology newly restricted in a DDTC rule change attracts elevated targeting within its development and supply chain community within 90 days.
- Insurance policy wordings. Willis recommends reviewing business interruption policy triggers and limits against grey-zone scenarios.1 Standard business interruption cover is typically limited to physical damage, and most grey-zone impacts do not qualify. Reviewing this before an incident is not a precautionary measure. It is the difference between a covered loss and an uncovered one.
Meridian Intell note: The companies least disrupted by grey-zone campaigns are not the ones with the strongest perimeter security. They are the ones treating geopolitical escalation signals as inputs to their security posture before the perimeter alert confirms the campaign has arrived. The Willis and CISA findings give those signals with specific lead times. Most corporate security functions are not structured to use them.
Methodology: Analysis draws on Willis Research Network February 2026 grey-zone aggression report, Allianz Risk Barometer 2026, Google Threat Intelligence Group February 2026 findings, Jerusalem Post cyber analysis January 2026, and CNBC reporting on China-linked actor escalation July 2026. All cited sources are publicly available.
Footnotes
1 GTR Review, Grey-Zone Attacks Pose Major Threat to Businesses and Supply Chains, citing Willis Research Network and Elisabeth Braw (Atlantic Council), March 2, 2026. Available at gtreview.com.
2 Allianz, Allianz Risk Barometer 2026: Cyber and AI as Major Business Risks, February 2, 2026. Available at allianz.com.
3 The Guardian, State-Sponsored Hackers Targeting Defence Sector Employees, Google Says, February 10, 2026. Available at theguardian.com.
4 Jerusalem Post, Why Cybersecurity in 2026 Is Fundamentally Different, January 25, 2026. Available at jpost.com.
5 CNBC, China-Linked Actors Target More Than Technology as AI Competition with US Intensifies, July 1, 2026. Available at cnbc.com.
About the author
Shekhar Attri, Co-Founder & CTO. An Indian Army Special Forces veteran with 21 years of service and a gallantry medal, Shekhar's corporate security advisory work spans Singapore, India, the Philippines, and the UAE, alongside PhD research on machine intelligence under incomplete information.