top of page

Harder to Divide

13 hours ago
10 min read


Why protection against cognitive warfare depends on training, cultural change and building sensemaking into everyone, including children


The perimeter has moved. For a generation, organisational and national security was organised around things that could be counted and walled off: a border, a building, a network. The defining threat of the present decade respects none of those boundaries, because it does not target infrastructure at all. It targets the human capacity to interpret events. Cognitive warfare, the deliberate and systematic degradation of the epistemic processes through which individuals and communities construct a shared understanding of reality, is now treated as a distinct mode of conflict in its own right. NATO’s Allied Command Transformation puts it without hedging: cognitive warfare “is not the means by which we fight; it is the fight itself” (NATO ACT). The World Economic Forum’s Global Risks Report 2025 ranked mis- and disinformation the most severe short-term global risk for the second-year running. Nothing in the trajectory suggests it is settling.


The distinction that matters is easy to state and costly to miss. Propaganda tries to change what people believe; it pushes a message and attempts to win an argument. Cognitive warfare is more ambitious. It degrades how people think: the shared sense of what is even true (Rid, 2020). A population that has been persuaded of a specific falsehood can, in principle, be corrected with accurate information. A population whose trust in institutions has been hollowed out, whose shared epistemic norms have fractured along identity lines and whose attention has been exhausted by a high-volume, contradictory information stream cannot be. Paul and Matthews (2016) named the mechanism in their account of Russian output: a “firehose of falsehood” that does not seek to convince anyone of any particular account but to overwhelm the evaluative capacity through which accounts are weighed at all. The remediation of a false belief is a communications problem. The restoration of a damaged epistemic process is an institutional and social one and it cannot be bought after the fact.


This is why the instinct to reach for a technological solution consistently disappoints. Detection systems, content moderation and rapid rebuttal all operate on the content of information after it has entered the environment. They do not touch the variable the adversary is working on: the condition of the minds receiving it. Organisations and societies withstand cognitive attack when they are structurally harder to divide. Detection technology does not make them so. No product confers that property. It has to be grown, through two levers working together: training that builds individual judgement and cultural change that makes clear thinking a shared, protected behaviour instead of an individual act of courage.


Sensemaking as the capacity under attack

The most useful lens for understanding both the attack and the defence is sensemaking, the account developed by Weick (1995) of how people construct workable interpretations of ambiguous, equivocal, fast-moving situations. For Weick, meaning is not extracted from the world so much as enacted, through the interaction of prior frameworks, unfolding experience and social conversation. Sensemaking is grounded in identity, embedded in social interaction and driven by plausibility rather than accuracy. Each of those properties is a seam an adversary can work. When group identity is threatened, interpretation bends towards defending the identity rather than representing the situation. When trusted institutions and social networks are discredited, the collective machinery through which people ordinarily orient themselves is disabled.


People are left to make sense of frightening events alone, or in whatever alternative community will have them. Cognitive operations work on the process by which any belief is formed and tested, which is why inserting a false belief is the least of what they do.

If sensemaking is the capacity under attack, then sensemaking capacity is the resource that resilience must build. The practical discipline follows: notice, interpret, act, review. A team trained to run that loop deliberately, treating a startling event as something to be examined before it is reacted to, is running a live defence against manipulation. This is not the same as scepticism, which curdles into paralysis, nor the same as compliance training, which teaches people to recognise the cases they have already been shown. Judgement is built by working through novel, ambiguous situations that have no single correct answer and then debriefing them honestly. The distinction between a completion rate and a resilience measure is exactly this: a team can pass every module and still freeze when a convincing voice claiming to be the chief financial officer asks it to move money in ten minutes.


Where the damage lands

Degraded sensemaking is the common cause behind three quite different failures. Following it into each is what makes the abstraction urgent.


  • Insider threat is where it bites first. The dominant frameworks for insider risk assume that harmful behaviour is a departure from an established baseline: that a person joins with legitimate intent and later turns. Applied to insiders, Wortley’s (2001) account of situational precipitators cuts against that assumption. Organisational conditions such as procedural unfairness, perceived disrespect and unaddressed grievance do more than create opportunity. They generate motive. The National Protective Security Authority, found that insider acts were commonly committed by people who held no malicious intent when they were hired, their circumstances and motivational states having changed afterwards (CPNI, 2013). A workforce primed by months of polarising content to distrust its own leadership is softer ground for social engineering, recruitment and radicalisation from within.


    Two developments sharpen the point. The first is the manufactured insider: an operative who acquires access under a fabricated identity, with intent already formed. The North Korean IT-worker schemes reported by the FBI (2025) show adversaries engineering the access itself. The second is that the human detection layer such an operative must evade depends entirely on culture. Colleagues notice anomalies that no analytics package registers, but only report them if it is safe to do so. Edmondson’s (1999) psychological safety, the shared belief that raising a concern will not be punished, therefore functions as a security control. What stops people reporting is social risk, not ignorance of what to report. The evidence on retaliation against whistle-blowers shows why (Miceli and Near, 2013).


  • Social unrest shows the same failure at population scale. The disorder that spread across British towns and cities in the summer of 2024, following the Southport killings, is the clearest recent illustration of cognitive warfare’s domestic effect. False claims about the identity and motive of the perpetrator were seeded and amplified. Violence followed within hours. The speed is the tell. Established models of radicalisation assume a gradual process unfolding over months or years; what happened here was a compression of that timeline under acute informational pressure. The underlying grievances were real. Cognitive warfare does not manufacture the fractures it exploits; it selects and weaponises them. What turned latent discontent into organised disorder, though, carried the signature of deliberate amplification. False information travels faster and further than the truth online. It does so mainly through ordinary human sharing, not automation (Vosoughi et al., 2018). His Majesty’s Inspectorate of Constabulary and Fire & Rescue Services concluded afterwards that the police service had not kept pace with online communications and that the speed and volume of online content fuelled the spread (HMICFRS, 2025). When the institutions that might have supplied an authoritative, timely account are already discredited, the interpretive field is ceded to whoever framed the event first (Boin et al., 2005).


  • The sharpest case is the individual drawn to violence. Within any population susceptible to radicalisation sits a smaller group whose attraction to violence is less ideological than existential, for whom violence offers significance, identity and agency. Meloy et al. (2015) describe the process of identification, in which a person aligns psychologically with a violent actor or cause through fixation and mimicry, as a critical precursor to lone-actor violence. Such individuals may hold incoherent political commitments while showing intense investment in violence as an object of fascination. Lone actors differ from group actors in documented ways: higher rates of mental-health difficulty (Corner and Gill, 2015) and observable leakage and preparation before the act (Gill et al., 2014). They also lack an organisation to restrain their timing. Kruglanski et al.’s (2014) significance-quest theory explains the pull: a person sensitised to humiliation and loss finds in extremist narratives a compelling account of how violence restores significance where peaceful alternatives do not.

    The danger of the cognitive-warfare environment is that it collapses the observation window on which conventional intervention depends. A person already predisposed, encountering a sudden crisis-framed information surge that validates their predisposition and delegitimises restraint, may move from vulnerability to action faster than any watch-list process can engage.


Building resilience into everyone, including children

If the damage lands everywhere, the defence cannot be confined to specialists. This is the case for cultural change rather than training alone. Training produces capable individuals; culture determines whether their capability is used. The most rigorous individual-level evidence points towards inoculation. Roozenbeek and van der Linden (2019) showed that exposing people to weakened forms of manipulative technique, together with explicit awareness of how the manipulation works, reduces susceptibility to misinformation they have not previously seen. Later longitudinal work found that the effect persists for weeks but decays without reinforcement (Maertens et al., 2021). Epistemic immunity, then, needs boosters. Complementary work indicates that susceptibility to false content owes more to a failure to stop and reason than to fixed bias, which means the protective habit is teachable (Pennycook and Rand, 2019). An immunity conferred in adulthood, in a workplace module, is a late and partial intervention. The capacities that resist manipulation are developmental: reflexive awareness of one’s own interpretation, the discipline to pause before reacting, comfort with ambiguity. They are most durable when they are grown early and treated as ordinary, which is the argument for building sensemaking into education itself, so that children acquire epistemic self-defence as a basic literacy long before anyone hands them a corporate e-learning package.


That is what a whole-of-society posture means in practice. It is also the premise of the Friþian framework developed at Emerging Risks Global: when the front line runs through workplaces, utilities and individual minds, resilience becomes everyone’s task, which is why it also needs specialists in the form of Crisis Resilience Professionals. Community-level resilience matters here as much as the individual and the institutional. Norris et al. (2008) identify social capital as the foundation of a community’s ability to absorb acute disruption and the same reserves of trust that carry a neighbourhood through a disaster carry it through an information shock. Such reserves are not generated spontaneously under crisis pressure; they are built in advance, through sustained investment in relationships and deliberative norms, or they are not available when needed.


Measuring what holds

Culture and capability are only manageable if they can be seen. The reasonable objection from any board is that resilience sounds unfalsifiable: a claim to have improved judgement, unverifiable until the day it fails. The answer is to treat human judgement as one would treat any other critical control: instrument it, test it under adversarial conditions and review it on a cycle. No competent organisation accepts a firewall installed once and never tested; the primary target of cognitive attack deserves the same seriousness. This is the logic of ERG’s Cognitive Resilience Index℠, which resolves a system of indicators into a single board-level measure built from four visible sub-scores: a psychological-safety baseline measured by team rather than averaged across the organisation; the coverage of ambiguous, scenario-based sensemaking exercises; a resistance rate against bespoke red-teams designed to fall just outside the training pattern; and a reporting-culture index. The composite matters less than the conversation it forces at the right altitude: an evidence-based discussion of whether the organisation’s judgement is improving or quietly eroding.


The most revealing indicators are the counter-intuitive ones. A falling rate of near-miss reports, absent any external reason, rarely means the threats have stopped; it usually means people have stopped bothering to report and a quiet reporting line is a blind one. Decision times that get faster when urgency and authority signals stack together are a warning, not a win; the pause-and-verify habit is decaying under exactly the pressure an attacker engineers.


None of this displaces conventional security. Access controls, vetting and monitoring remain essential and a caring culture is no substitute for structural counterintelligence in sectors that handle sensitive material. What changes is the priority. Organisations and societies hold under cognitive attack because of what they invested in before the crisis: credibility, a reporting culture and collective judgement that make a false message land softly. Detection spending does not buy any of it. The threat is epistemic. The response has to be epistemic in kind: built into training, embedded in culture, extended to children and measured with the seriousness we already grant every other control we would not dream of leaving untested.


Dr Paul Wood


References

Boin, A., ’t Hart, P., Stern, E. and Sundelius, B. (2005) The Politics of Crisis Management: Public Leadership under Pressure. Cambridge: Cambridge University Press.


Centre for the Protection of National Infrastructure (CPNI) (2013) Insider Data Collection Study: Report of Main Findings. London: CPNI.


Corner, E. and Gill, P. (2015) ‘A false dichotomy? Mental illness and lone-actor terrorism’, Law and Human Behavior, 39(1), pp. 23–34. https://doi.org/10.1037/lhb0000102


Edmondson, A. (1999) ‘Psychological safety and learning behavior in work teams’, Administrative Science Quarterly, 44(2), pp. 350–383. https://doi.org/10.2307/2666999


Federal Bureau of Investigation (2025) North Korean IT Workers Conducting Data Extortion. Internet Crime Complaint Center, Public Service Announcement I-012325-PSA. https://www.ic3.gov/PSA/2025/PSA250123


Gill, P., Horgan, J. and Deckert, P. (2014) ‘Bombing alone: Tracing the motivations and antecedent behaviors of lone-actor terrorists’, Journal of Forensic Sciences, 59(2), pp. 425–435. https://doi.org/10.1111/1556-4029.12312


His Majesty’s Inspectorate of Constabulary and Fire & Rescue Services (HMICFRS) (2025) An Inspection of the Police Response to the Public Disorder in July and August 2024: Tranche 2. London: HMICFRS.


Kruglanski, A.W., Gelfand, M.J., Bélanger, J.J., Sheveland, A., Hetiarachchi, M. and Gunaratna, R. (2014) ‘The psychology of radicalization and deradicalization: How significance quest impacts violent extremism’, Political Psychology, 35(S1), pp. 69–93. https://doi.org/10.1111/pops.12163


Maertens, R., Roozenbeek, J., Basol, M. and van der Linden, S. (2021) ‘Long-term effectiveness of inoculation against misinformation: Three longitudinal experiments’, Journal of Experimental Psychology: Applied, 27(1), pp. 1–16. https://doi.org/10.1037/xap0000315


Meloy, J.R., Mohandie, K., Knoll, J.L. and Hoffmann, J. (2015) ‘The concept of identification in threat assessment’, Behavioral Sciences & the Law, 33(2–3), pp. 213–237. https://doi.org/10.1002/bsl.2166


Miceli, M.P. and Near, J.P. (2013) ‘An international comparison of the incidence of public sector whistle-blowing and the prediction of retaliation: Australia, Norway, and the US’, Australian Journal of Public Administration, 72(4), pp. 433–446. https://doi.org/10.1111/1467-8500.12040


NATO Allied Command Transformation (no date) Cognitive Warfare. Norfolk, VA: NATO ACT. https://www.act.nato.int/activities/cognitive-warfare/ (Accessed: 27 September 2026).


Norris, F.H., Stevens, S.P., Pfefferbaum, B., Wyche, K.F. and Pfefferbaum, R.L. (2008) ‘Community resilience as a metaphor, theory, set of capacities, and strategy for disaster readiness’, American Journal of Community Psychology, 41(1–2), pp. 127–150. https://doi.org/10.1007/s10464-007-9156-6


Paul, C. and Matthews, M. (2016) The Russian ‘Firehose of Falsehood’ Propaganda Model: Why It Might Work and Options to Counter It. Santa Monica: RAND Corporation.

Pennycook, G. and Rand, D.G. (2019) ‘Lazy, not biased: Susceptibility to partisan fake news is better explained by lack of reasoning than by motivated reasoning’, Cognition, 188, pp. 39–50. https://doi.org/10.1016/j.cognition.2018.06.011


Rid, T. (2020) Active Measures: The Secret History of Disinformation and Political Warfare. London: Profile Books.


Roozenbeek, J. and van der Linden, S. (2019) ‘The fake news game: Actively inoculating against the risk of misinformation’, Journal of Risk Research, 22(5), pp. 570–580. https://doi.org/10.1080/13669877.2018.1443491


Vosoughi, S., Roy, D. and Aral, S. (2018) ‘The spread of true and false news online’, Science, 359(6380), pp. 1146–1151. https://doi.org/10.1126/science.aap9559


Weick, K.E. (1995) Sensemaking in Organizations. Thousand Oaks: Sage.


Wortley, R. (2001) ‘A classification of techniques for controlling situational precipitators of crime’, Security Journal, 14(4), pp. 63–82. https://doi.org/10.1057/palgrave.sj.8340098


World Economic Forum (2025) The Global Risks Report 2025. Geneva: World Economic Forum.

 
 
 

Comments


business-people-working-data-project.jpg

REQUEST ERG'S SECURITY CONVERGENCE EXPERTISE

Receive tailored, intelligence-led and risk-based
security advice, designed 
to meet your requirements

 

Get in touch with us and we will assist you further.

Security Education, Risk, Resilience Awareness and Culture

Address

Southgate Chambers, 37-39 Southgate Street, Winchester, England, SO23 9EH

EMERGING RISKS GLOBAL ®

Emerging Risks Global ® (ERG) is a trading name of Woodlands International Ltd ©

Registered in England and Wales: 11256211.

VAT GB 507 077 204

Connect With Us

  • Instagram

© 2026 Woodlands International Ltd. All rights reserved.

bottom of page