Europe builds new security architecture to counter Russia's sub-threshold hybrid attacks

3 min read
Source: Ukrinform
Europe builds new security architecture to counter Russia's sub-threshold hybrid attacks
Photo: Ukrinform
TL;DR

Ukrainian and European intelligence services possess specific data on Russian plans to attack EU nations, prompting Brussels to launch a counter-hybrid playbook. This move addresses the security gap below NATO Article 5, where sabotage and cyberattacks evade traditional collective defense triggers. While leaders debate the nature of these threats, Europe is shifting from resilience to deterrence through new institutional mechanisms.

Key points

  • Ukrainian Foreign Minister Andrii Sybiha stated that intelligence agencies have specific data on Russian plans to attack EU countries, emphasizing prevention as the top priority.
  • EU Commission President Ursula von der Leyen unveiled a counter-hybrid playbook and emergency security protocol on September 16 to coordinate responses to incidents below the threshold of conventional military attacks.
  • The EU identified Russian FSB’s 16th Centre as responsible for cyber threats impacting nine member states, including France, Germany, and Poland, involving sabotage of critical infrastructure.
  • Lithuania is securing the Gizai electricity substation near the Kaliningrad exclave with €48 million in additional security measures, including reinforced fencing and underground sensors.
  • Belgian Defence Minister Theo Francken criticized Europe’s decades-long focus on soft power, noting that Belgium only reached the 2% GDP defense spending threshold in 2025 after years of neglect.

Background

Recent events, including a failed drone attack near Leipzig airport in September 2026, have intensified concerns about Russian hybrid warfare. Following this incident, EU foreign ministers pledged unity and announced plans for 1,600 additional sanctions against Russia’s military-industrial complex. These developments follow earlier discussions on migration and external return hubs, highlighting the broader security challenges Europe faces.

How outlets are covering it

Ukrainian officials, such as Sybiha, argue that Russia’s actions constitute acts of sabotage and subversion, effectively a form of war. In contrast, NATO Secretary General Mark Rutte noted that responses to hybrid attacks are not always public and do not follow a 'tit-for-tat' principle. Estonian Foreign Minister Margus Tsahkna urged leaders to stop labeling these actions as 'hybrid attacks,' emphasizing their systematic nature. Meanwhile, Alexander Gabuev of the Carnegie Russia Eurasia Center suggested that Europe should focus on defensive tools and guardrails rather than direct offensive responses to avoid uncontrolled escalation.

Why it matters

The emergence of a new security architecture below Article 5 is critical for Europe to address the growing threat of hybrid warfare. By institutionalizing responses to sub-threshold attacks, the EU aims to close a significant security gap that has existed since the Cold War. This shift from resilience to deterrence could influence future defense spending and international relations, particularly in managing tensions with Russia.

What to watch

The EU is expected to implement the counter-hybrid playbook, which includes rapid intelligence sharing and joint assessments of attribution. Additionally, member states are likely to increase funding for cybersecurity and critical infrastructure protection. The success of these measures will depend on the ability to establish common standards of evidence and mutual confidence in attribution, which remains a significant challenge.

Share this article

Want the full story? Read the original reporting

Read on Ukrinform