Paul Mercer MPhil CSyP · 28 Sept 2026
In the early hours of Sunday morning, police received a report of three suspicious vehicles heading towards RAF Fairford. One local resident has described finding the road blocked by three vans and a group of hooded, masked men, who ran when they saw her. Five men were arrested, first on suspicion of explosives offences and then on suspicion of preparing a terrorist act. Around 85 households were evacuated while Army bomb disposal teams examined the vehicles.
Fairford isn’t just any airfield. It hosts US heavy bombers and has been used for operations against Iran since February. In July, Iran’s Revolutionary Guard publicly warned Britain that any base used against Iranian territory was a legitimate target. ITV News reports that one line of inquiry is whether representatives of the Iranian regime paid others to carry out the plot on their behalf. At the time of writing, no connection has been confirmed; the five men remain in custody, and it’s right that we let investigators establish the facts.
But whatever they find, the incident exposes a problem I’ve been thinking about for some time, and which clearly resonates with many of you, judging by the discussion on my recent posts.
An academic argument with practical consequences
When I argued that we are, in effect, at war with states using hybrid methods against the UK, I was rightly challenged on the word “war”. War has a legal meaning, and using it loosely carries real risk, not least the risk of escalation with nuclear-armed states.
So let me come at it from a different direction.
What is the difference between a state-sponsored terrorist act and an act of war? The objective is often identical: to coerce another country into changing its behaviour. Clausewitz described war as the continuation of policy by other means, and a proxy with a van full of explosives is simply another means.
The real difference isn’t the implement. It’s the rulebook each one triggers.
An act of war falls under the laws of armed conflict and can justify a state-level response. An act of terrorism is treated as a crime, handled by the police and the courts. The first can reach the state that ordered it. The second, in practice, reaches the people who were caught holding the tools.
That distinction can look academic, but it decides who is allowed to respond, and how.
Choosing the box you land in
Hostile states understand this better than we do. If you want to pressure the UK without paying a state-level price, you don’t send your own forces. You recruit criminals or sympathisers, often online and often for modest sums, and you make sure the act looks like arson, vandalism or terrorism. Once it lands in the criminal box, the proxy is arrested and prosecuted, and the state that directed it pays nothing.
We’ve already seen this pattern. In 2025, men recruited on behalf of Russia’s Wagner Group were convicted over an arson attack on a London warehouse storing equipment bound for Ukraine. The organisers were the first people convicted under the National Security Act 2023. MI5’s Director General has said publicly that Iran, like the Russian services, makes extensive use of criminals as proxies, and in 2025 he reported more than twenty potentially lethal Iran-backed plots in a single year. Different states, same method.
Put simply, we’ve built a system for catching the hand, not the head.
The National Security Act 2023 was a genuine step forward, creating offences for foreign-directed sabotage and interference. But it still works at the level of the individual. It punishes the proxy more effectively without changing the calculation for the state behind them.
A third category
This is where Kenneth Smart’s challenge changed my thinking. Framing these acts as war, within the current framework, does risk rapid escalation, and that’s a serious concern. But the answer can’t be to fall back on treating them as ordinary crime when they are clearly state-directed.
I think we need a third category: hostile state acts below the threshold of armed conflict, with rules of their own.
We already have the tools. Diplomatic expulsions, targeted sanctions, asset freezes, proportionate cyber operations and, under international law, lawful countermeasures against a state that has committed a wrongful act. What we lack is a framework that says when they’ll be used.
We already do this for threats we have defined. When the national terrorism threat level changes, nobody improvises. The level is published, and the protective measures that follow it are planned in advance. Hostile state acts deserve the same treatment. Whatever we choose to call them, they need to become policy, with responses agreed before the next incident rather than after it.
Salisbury in 2018 shows it can be done. The government attributed the attack to Russia on a “highly likely” intelligence assessment, rather than waiting for a conviction, and responded at state level alongside its allies. The problem is that the response was built after the fact, and ad hoc responses deter very little.
A proper framework would do three things.
First, define what a hostile state act is, so that incidents are assessed as part of a campaign rather than one at a time.
Second, set a published standard for attribution, a high-confidence assessment rather than proof beyond reasonable doubt, which runs alongside any criminal investigation instead of waiting for it.
Third, declare the kinds of proportionate, graduated response a state can expect when that threshold is met.
The honest counterargument is that publishing a threshold tells an adversary exactly where to stop. That’s a real risk. But I’d argue the current position is worse, because right now there is no threshold at all, and the fog of uncertainty is doing our adversaries’ work for them.
Why this matters beyond defence
Businesses are already on this battlefield. Critical infrastructure, defence supply chains and the companies around them are obvious targets, but anyone whose disruption creates pressure is in scope. Organisations can’t plan properly against a threat their own government hasn’t defined, and a clear national framework would give security leaders something concrete to assess risk against and to explain to their boards.
I don’t claim to have all the answers, and I’d genuinely welcome challenge. Is a third category the right approach? And if it is, where would you set the threshold?
A note of thanks
I’d like to thank everyone who took the time to respond to my recent posts on this subject. The volume and quality of the discussion made it clear this is something that matters to many of us working in security, defence and resilience.
In particular, I’d like to thank Kenneth Smart, whose thoughtful academic input on the challenges of framing these acts as war made me think harder about the problem. His challenge is a large part of why this piece explores a third category of conflict, rather than simply arguing that we are at war.
A note on how this was written
These are my own views, shaped by that discussion. I used AI to help research and draft this piece, mainly so that I could get it out while the conversation is still live and people are still engaged with it. It has also helped me organise my thinking and put it across more clearly. The arguments, and any errors, are mine.

