Daniele Garofalo Monitoring

Daniele Garofalo Monitoring

Global Jihadist, Insurgent & Hybrid Warfare Threat Assessment

Executive Intelligence Briefing | Rolling Forecast (30–90 Days): Semptember – November 2026

Daniele Garofalo's avatar
Daniele Garofalo
Sep 09, 2026
∙ Paid

Cover & Classification Note

Document Type: Executive Intelligence Briefing
Scope: Global Jihadist, Insurgent & Hybrid Warfare Threat Assessment
Time Horizon: Rolling Forecast (30–90 Days)
Reference Period: September- November 2026.

This document is an independent analytical product intended for professional use by analysts, policy planners, security practitioners, and decision-makers.


Intended Audience & Use

This Executive Intelligence Briefing is intended for use by intelligence analysts, policy planners, military and security decision-makers, international organisations, and applied academic researchers concerned with the threat dynamics of jihadist, insurgent, and hybrid warfare.

The document supports strategic awareness, forward-looking risk assessment, and prioritising monitoring over a rolling 30–90-day horizon. It is not intended to provide tactical-level tasking, real-time operational guidance, or event-specific prediction. Use the briefing as a decision-support and situational-awareness tool to inform planning, posture adjustment, and analytical focus, not immediate response.


📌 Inside this Executive Intelligence Briefing

This briefing includes:

  • Executive Overview – Strategic Context

  • Key Judgments

  • Global Threat Posture

  • Global Structural Assessment

    Africa, Middle East & Asia, Transnational Networks & Secondary Threat Environment.

  • Operational Actor Assessment

    • Africa: ISWAP, IS-Sahel, IS-Somalia, ISM, ISCAP, JNIM, al-Shabaab, Boko Haram, Lakurawa.

    • Middle East & South Asia: IS Syria/Iraq, AQAP, AQIS, ISKP, ISPP, ISEAP, TTP, Ittehad-ul-Mujahidin Pakistan.

  • Cognitive & Hybrid Battlespace
    Narrative Competition and Strategic Legitimacy, Al-Qaeda’s Wider Narrative Adaptation, Palestine as a Cross-Ecosystem Mobilisation Narrative, Capability Dissemination and Operational Enablement, Digital Ecosystem Evolution, Iranian-Aligned Cognitive and Digital Architecture, Ansar Allah and the Weaponisation of Strategic Geography, Hamas and Post-Conflict Cognitive Survival.

  • Forward Assessment (30–90 Days)
    Forecast Framework, Europe and the Western Threat Environment, Hybrid Actors and European Strategic Exposure, Strategic Risk Assessment, Escalatory Scenario, Strategic Shock Scenario, Early Warning Indicators.

  • Strategic Risk Assessment

    Strategic Risk Hierarchy, Escalation Triggers, Cross-Theatre Risk Interaction, Executive “So What?”

  • Intelligence Monitoring
    Priority Indicators, Key Intelligence Questions.


Confidence, Assessment & Intelligence Gaps

This assessment is produced with moderate to high confidence regarding structural trends, theatre-level operational logic, tempo modulation patterns, and the most likely 30 to 90-day trajectories, based on systematic analysis of incident data, propaganda monitoring, and pattern continuity across regions to ensure methodological transparency.

Confidence is highest in assessing Africa as the primary kinetic centre of gravity, Pakistan as a high-endurance attrition theatre, and the broader ecosystem’s reliance on below-threshold operational logic, while acknowledging that intelligence gaps in remote or contested areas introduce moderate confidence levels.

Key limitations remain:

  • In some theatres, especially remote or contested areas, incident visibility is structurally uneven.

  • Quiet months or reduced media output may reflect risk management and force preservation rather than degradation. Conversely, concentrated claim density may serve reputational objectives without a proportional increase in kinetic expansion.

  • Assessments of intent are based on pattern analysis, target-selection logic, propaganda framing, and behavioural shifts rather than confirmed insider access.

  • The dissemination of training material, UAV manuals, and cumulative infographics signals capability socialisation, but the conversion rate from dissemination to operational activation is difficult to measure in advance.

  • Attribution ambiguity in decentralised ecosystems complicates the accurate linking of online enablement, local facilitation networks, and offline incidents, particularly in transnational secondary environments.

These gaps do not alter the central assessment of continuity, resilience, and distributed attritional logic. They reinforce the need to prioritise qualitative shifts over quantitative fluctuations, including changes in target class, geographic clustering, claim behaviour, technical enablement signals, and evidence of HUMINT degradation.

Ongoing monitoring should therefore focus less on monthly totals and more on behavioural anomalies, corridor reactivation, escalation in target salience, and the intersection between cognitive signalling and operational execution.


Methodological Note

This briefing is based on:

  • systematic monitoring of primary jihadist propaganda (statements, videos, magazines, claims);

  • analysis of reports from field sources, local media, and military publications/statements

  • analysis of OSINT, IMINT, Digital HUMINT, and SOCMINT

  • comparative temporal analysis to distinguish short-term variation from structural trends;

  • explicit separation between observation, assessment, and judgment.

Forecasting judgments are probabilistic, not predictive, and are designed to inform preparedness and decision-making rather than to anticipate specific events.


Scope Exclusions

This briefing operates within clearly defined analytical boundaries.

  • It does not include classified, law-enforcement–sensitive, or restricted government information, and is based exclusively on open-source intelligence and structured analytical assessment.

  • It does not assess domestic extremism in Western states except where relevant to transnational jihadist cognitive and influence dynamics.

  • It does not attempt to predict specific attacks, timelines, or targets; instead, it focuses on probabilistic trends, threat configurations, and early warning indicators.

  • It does not provide policy prescriptions or normative recommendations, limiting its scope to assessment, implications, and monitoring priorities.


Executive Overview – Strategic Context

The global jihadist, insurgent and hybrid threat environment entering September–November 2026 is characterised by operational resilience, selective acceleration and increasing threat density rather than a single systemic escalation.

Africa remains the principal centre of gravity. JNIM has demonstrated exceptional surge capacity across the central Sahel and is increasingly positioned to convert military persistence into economic and political pressure. Al-Shabaab has recorded the strongest recent operational acceleration, expanding from 48 attacks in June to 152 in August while simultaneously increasing activity in Kenya. Islamic State’s African provinces have declined in aggregate activity but retain substantial geographic resilience across Nigeria, eastern DRC, Mozambique, Somalia, Niger and Cameroon.

Pakistan represents the most intense counter-state insurgency environment. TTP’s 406 attacks in August confirm that exceptionally high operational tempo has become structural, while IMP adds a secondary layer of pressure against many of the same security institutions. The principal escalation mechanism remains the Afghanistan–Pakistan border, where a major militant attack and subsequent cross-border retaliation could rapidly expand a domestic insurgency into a wider political and security crisis.

Syria remains strategically important despite limited Islamic State attack volume. The principal concern is clandestine regeneration during political and security transition rather than renewed territorial control. Urban facilitation, detention instability and selective attacks against politically consequential targets would provide more meaningful indicators of Islamic State recovery than aggregate attack statistics.

Europe has become the priority external threat environment. Recent counterterrorism cases indicate continued movement by a limited number of subjects from ideological exposure toward technical research, external training intent, reconnaissance and attack preparation. There is insufficient evidence of a restored centrally directed jihadist campaign against Europe. The more immediate threat comes from self-initiated actors, micro-networks and partially facilitated individuals whose operational development may occur largely within digital environments.

Europe simultaneously faces persistent hybrid pressure. Russia-linked sabotage and hostile intelligence activity increasingly rely on deniable methods, low-cost technologies and disposable intermediaries. Iranian-aligned networks retain a separate latent external capability whose activation will depend heavily on escalation in the Middle East. These threat systems remain organisationally distinct, but their simultaneous presence creates growing pressure on European intelligence and protective-security resources.

The information environment increasingly operates as a capability layer across these theatres. JNIM integrates communications with insurgent legitimacy and governance. Al-Qaeda-aligned networks exploit Gaza, Iran, Yemen and other conflicts to maintain ideological coherence. Islamic State supporters continue distributing attack-enabling material. Hezbollah, Ansar Allah and Iranian-linked structures combine information activity with deterrence, proxy warfare and strategic coercion.

This post is for subscribers in the Founding Member plan

Already in the Founding Member plan? Sign in
© 2026 Daniele Garofalo Monitoring · Privacy ∙ Terms ∙ Collection notice
Start your SubstackGet the app
Substack is the home for great culture