SVG
Commentary
Atlantico

Hybrid Warfare: What Europeans Really Lack to Respond to Russian Attacks

fried
fried
Visiting Senior Fellow
Tsiporah Fried
NATO Secretary General Mark Rutte, German Chancellor Friedrich Merz, and Lieutenant General Peter Mirow, commanding general of the 1st German-Dutch Corps, during a visit to the German-Dutch Corps in North Rhine-Westphalia, Münster on October 1, 2026. (Getty Images)
Caption
NATO Secretary General Mark Rutte, German Chancellor Friedrich Merz, and Lieutenant General Peter Mirow, commanding general of the 1st German-Dutch Corps, during a visit to the German-Dutch Corps in North Rhine-Westphalia, Münster on October 1, 2026. (Getty Images)

This translation was generated using AI and edited lightly. Read the original in French here.

Faced with the growing number of cyberattacks, acts of sabotage, airspace incursions, and interference operations attributed to Russia, Europeans are still searching for the right response to a hybrid war that blurs the boundaries between domestic security and defense. The challenge is no longer simply to have new mechanisms in place, but to be able to act quickly and collectively.

Atlantico: Defense ministers meeting on Monday sought the right response to growing Russian provocations. What, in your view, are Europeans genuinely lacking today?

Tsiporah Fried: Indeed, on September 28, European defense ministers discussed options for responding to “Russia’s escalating hybrid campaign,” referring to the new emergency security protocol and coordination with NATO.

We should first welcome this growing collective awareness — the recent attack in Leipzig may well have contributed to it. Recognizing that sabotage, cyberattacks, and intimidation operations can be part of the same campaign is essential. This issue is also directly connected to the broader question of European rearmament. Rearmament is not only about replacing equipment, increasing defense budgets, or producing more ammunition. It also means being able to identify a hostile campaign, protect the infrastructure essential to our defense, and keep the country functioning when such infrastructure is targeted.

The novelty of the new arrangement seems to me to lie above all in the ambition to better coordinate the European Union’s instruments with those of NATO. Such coordination is undoubtedly necessary: a hybrid campaign can simultaneously involve civilian, economic, cyber, and military dimensions, which fall under different institutions and chains of command.

But this does not, by itself, address the fundamental issue. Above all, we should not confuse putting a mechanism in place with having the ability to act. The risk would be to reassure ourselves that, because a protocol exists, Europe has actually addressed the problem.. The risk would be to reassure ourselves simply because a protocol exists and therefore feel that Europe has solved the problem.

For the record, the EU has already had, since June 2022, a Framework for a coordinated EU response to hybrid campaigns, which is one of the central elements of the EU Hybrid Toolbox and is specifically intended to mobilize different European instruments, both civilian and military. The question is therefore less whether Europe has a new mechanism than what it intends to do with it and how it will coordinate it with NATO mechanisms and those of the member states.

A protocol can be useful: knowing whom to alert, what information to share, whom to bring together, and within what timeframe can save time. But we must still know what we want to decide once everyone is around the table.

That, in my view, is where the real challenge lies. The European question is no longer simply whether we have the capacity to react to a hostile action, but whether we are willing to act even before that action produces its effects. What interests do we want to protect? What behavior do we want to stop? What costs are we prepared to impose, and what risks are we prepared to accept in order to impose them?

Recent experience also shows that the issue does not arise only when Europe fails to respond. It also arises when its response remains essentially defensive, limited to the incident that has just occurred. A credible deterrence strategy requires the ability to move from reaction to action — including measures that make adversary operations more costly before they are repeated.

As John Walters, President of the Hudson Institute, points out, describing this as a “grey zone war” should not lead us to minimize the nature of hostile acts or indefinitely postpone any response. Russia must understand that these operations do not allow it to obtain advantages at low cost. This requires protection, intelligence, and intervention capabilities, but also credible political will. A protocol can organize a response; it cannot create the political will to use it.

Does the notion of “hybrid defense” have a concrete meaning, or does it mainly conceal the absence of a clear response?

Tsiporah Fried: I am encountering this expression for the first time, and I am wary of it if it substitutes for genuine thinking or doctrine. The term “hybrid,” which has applied to threats from the outset, describes a combination of means and methods of action — covert or overt, military or civilian, digital, economic, or informational — between conventional and irregular warfare. But it does not, by itself, tell us how to defend ourselves.

I was recently speaking with a Latvian official who explained to me that Russia was conducting destabilization campaigns in the Baltic states, notably by exploiting migration flows. Armed forces are being mobilized to help control the borders, consuming resources and time that would normally be devoted to combat training. How can this threat be prevented effectively while respecting our democratic values? That is the concrete question.

I would even question whether “hybrid defense” could be counterproductive if it were to become a sort of new Maginot Line. What needs to be countered is not merely individual attacks, but a hostile intent that we must be capable of deterring so that it is not repeated. The problem is therefore not to construct a specific response to each new form of aggression, but to connect our responses and make the adversary understand that its campaign as a whole will have consequences.

Moreover, we need to move away from the idea that hybrid warfare becomes conventional once some perfectly identifiable threshold has been crossed. These methods can coexist. A cyberattack remains a cyberattack even when its effects are considerable; that tells us neither how it should be classified nor what response it may warrant.

Our assessment should therefore focus on the effects, the context, and the links between operations, rather than simply on the means employed.

In particular, we need to examine what their accumulation produces: a succession of seemingly limited incidents may be intended to permanently disrupt an essential function or influence a political decision.

This overall assessment does not mean that every accumulation of incidents automatically triggers collective defense. It means that we must not allow our administrative categories to fragment our understanding of the adversary’s strategy. The term “hybrid” cannot serve as a guarantee that an attack will be moderate, nor as a guarantee of impunity for its perpetrator.

In the face of sabotage, we must protect, investigate, and dismantle the networks responsible. In the face of a cyberattack, we must secure systems, restore their functioning, and identify the attacker. In the face of an airspace incursion, we must detect, characterize, and, if necessary, neutralize the threat. Strategic coherence means connecting these actions and understanding the adversary’s campaign as a whole. Grouping them under a new label does not resolve any of these requirements.

Resilience also has a deterrent function: if sabotage does not paralyze our activities or alter our decisions, its strategic value diminishes. But knowing how to absorb attacks is not enough; we must also be able to act against those carrying them out.

Should Europeans publicly and systematically identify Russia when it is responsible for sabotage or a hybrid attack, and what would that change?

Tsiporah Fried: When attribution is firmly established, I support naming Russian responsibility. Ambiguity is part of the effectiveness of these operations: it allows us to fragment our perception of events and present each act of sabotage as an isolated incident. A substantiated public attribution helps make the campaign visible, inform citizens, and mobilize partners.

However, “systematically” must not mean “automatically” or “immediately.” Sometimes it is necessary to protect a source, allow an investigation to progress, or monitor a network in order to identify those directing it. The Council of the EU also points out that attribution remains a sovereign political decision, based on intelligence and made on a case-by-case basis.

We must also distinguish public attribution from the ability to act. We can protect a site, arrest suspects, or neutralize an immediate threat without waiting until we can publish the entire chain of responsibility.

Above all, naming the perpetrator is not the same as deterrence. If we regularly attribute attacks to Russia without perceptible consequences, we risk demonstrating that it can act despite our knowledge of its responsibility. Attribution should lead to a policy, not merely a communiqué.

Some European countries are tightening their own rules of engagement in response to air threats. Do these national initiatives strengthen the European response, or do they reveal the absence of a common response?

Tsiporah Fried: Both interpretations are possible, but we should not regard every national decision as a European failure. States must be able to protect their populations and territories. Faced with an air threat, a decision sometimes has to be made within seconds or minutes, without waiting for another ministerial meeting.

The problem arises when national arrangements leave exploitable gaps between neighboring countries. We therefore need to bring threat-characterization criteria closer together, share the air picture, and clarify responsibilities when an object crosses a border. The Commission itself stresses the need for tested national procedures in the face of cross-border threats, as well as coordination among civilian authorities, security forces, and the military.

Rules that are excessively restrictive, or an authorization chain that is too slow, can also render our capabilities ineffective. But tightening the rules does not mean indiscriminately firing at every unidentified object. Its trajectory, behavior, risk to the population, and the effects of interception must all be taken into account. Finally, authorization to intervene is not enough: we also need the sensors, neutralization capabilities, and trained personnel.

During Russian incursions into Polish airspace in September 2025, Poland requested consultations under Article 4, shot down the drones that posed the greatest threat, and NATO launched Eastern Sentry to strengthen its posture on the eastern flank. NATO also stated that its aircraft had intercepted Russian MiG-31s that had violated Estonian airspace.

It is true that there was no European response proportionate in strategic terms. This is not simply a matter of European “weakness” or “cowardice.” Rather, it reveals a European strategic culture that is still largely based on avoiding escalation and distinguishing between categories of aggression, as well as a European difficulty in thinking about responses to aggression outside traditional categories of warfare.

The asymmetry in perceptions between Russia and European states is precisely one of the challenges of hybrid warfare: Europe has so far sought to avoid escalation by keeping each incident below a certain threshold, while Moscow can systematically exploit the space between those thresholds.

Are we in the process of changing that framework? Beyond sanctions, what levers do Europeans actually have at their disposal, and are they prepared to use them?

Tsiporah Fried: We have several categories of leverage.

The first is to make the operation fail: protect infrastructure, strengthen counterintelligence, disrupt recruitment and financing networks, arrest operatives, and improve recovery capabilities. An attack that fails to produce its intended effect loses part of its value.

The second is to reduce the freedom of action of those responsible: criminal prosecutions when the evidence permits, expulsions of personnel involved in hostile activities, dismantling front organizations, and action against intermediaries facilitating the operations. The precise instruments depend on the responsibilities established and the applicable legal framework.

The third is strategic. If Russia’s objective is to make us reduce our support for Ukraine, one possible response is to make that support more predictable, more sustainable, and better protected against sabotage. Intimidation must be made capable of producing the opposite of the effect intended.

Are we prepared to do this? It means accepting that any policy of firmness entails costs and risks. But a lack of response also carries a risk: encouraging attacks to be repeated and escalated.

The response does not have to reproduce the attacker’s method: sabotage does not necessarily call for sabotage. Proportionality does not mean symmetry. We must choose the levers that genuinely alter its calculations, while respecting the law.

The episode involving Russian incursions into Polish airspace illustrates precisely this difficulty. The response cannot be limited to determining whether a drone, aircraft, or other action crosses the threshold of a military attack. It must also address the strategic intent underlying these actions: testing European vigilance, creating uncertainty, and, more broadly, intimidating European governments and societies.

An effective response must therefore make that strategy counterproductive. A violation of airspace or a sabotage operation should not lead Europeans to reduce their support for Ukraine out of fear of escalation; on the contrary, it should strengthen their coordination, resilience, and, where appropriate, their support for Kyiv.

The same logic applies in the information domain. Protecting European societies against Russian disinformation is necessary, but insufficient. European governments can also develop communication strategies aimed at Russian citizens, support independent Russian-language media, and highlight, factually, the human, economic, and political costs of the war.

The goal would not be to answer propaganda with European propaganda, but to ensure that the coercive instruments employed by Moscow produce the opposite of the desired effect: greater European cohesion, greater resilience, and stronger determination to support Ukraine.

There is an implicit belief that not responding too forcefully allows us to maintain control over escalation. But this can create a paradox: if every level of aggression receives a different and limited response, it is the adversary that gets to choose the level at which it acts. This is precisely why the EU’s civilian, economic, cyber, diplomatic, and military instruments must be considered together.

Is the lack of unity among European countries in the face of the Russian threat the main obstacle to an effective response?

Tsiporah Fried: The lack of unity among Europeans has long been a major obstacle, but today it would be reductive to make it the principal explanation. The speech by Commission President Ursula von der Leyen in September 2026, by contrast, marks an important evolution: she explicitly presented hybrid attacks as a threat to the Union as a whole and called for a coordinated European response, going so far as to propose an emergency security protocol inspired by Article 4 of NATO. European defense ministers have since begun to examine concrete options for responding to the Russian hybrid campaign.

The problem is now less the existence of a common perception of the threat than the ability to translate it rapidly into action. Even a very broad political agreement does not instantly create surveillance capabilities, stockpiles, counterintelligence teams, air-defense assets, or resilient infrastructure.

The challenge is therefore to transform a now much clearer political convergence into procedures, capabilities, and decision-making mechanisms that are sufficiently rapid to respond to actions that, precisely, often leave little time to decide.

Useful unity does not require everyone to do exactly the same thing. It requires states to agree on objectives and for their actions to reinforce one another: some provide intelligence, others protection, investigative capabilities, or operational support.

Some European decisions require unanimity. That does not prevent states from acting within their own areas of competence or helping one another without waiting for agreement on every detail. Above all, we must avoid allowing the legitimate pursuit of cohesion to become a permanent justification for inaction.

There are also difficulties within individual states. A hybrid campaign can simultaneously involve defense, interior affairs, intelligence, justice, transport, energy, and private-sector operators. Yet the experience of combating terrorism has already demonstrated the difficulties of interministerial coordination: when each administration analyzes and handles the incident within its own jurisdiction, there is a risk of losing sight of the campaign as a whole.

Faced with a Russian strategy that deliberately combines multiple vectors of action, the first challenge is therefore also national: being able to cross-reference signals, share intelligence rapidly, and develop a common assessment of the threat. European coordination can only be as effective as the ability of states to coordinate their own instruments.

Does the European Union have the organization and will necessary to lead this response, or must it necessarily go through NATO?

Tsiporah Fried: A campaign combining sabotage, cyberattacks, interference, and military intimidation necessarily calls for several levels of response.

States retain central responsibilities for national security, intelligence, policing, and justice. The European Union, for its part, has economic, regulatory, and coordination instruments that are particularly relevant to protecting networks, infrastructure, and supply chains. NATO provides a framework for military planning, command, and collective defense.

It would therefore be wrong to reserve everything “hybrid” for the EU and everything military for NATO. The two dimensions can be combined within the same campaign — and it is precisely their coordination that constitutes the real challenge. This is probably one of the objectives of the new protocol that has been announced.

I would assess the mechanism by asking simple questions: Does it allow a situational assessment to be shared more quickly? Does it allow concrete assistance to be mobilized? Does it clarify who decides and who executes? Is it exercised and properly coordinated with existing mechanisms?

The European Union can therefore provide genuine added value. But political will ultimately rests first and foremost with the member states. Creating a European mechanism does not relieve them of their responsibilities.

I would also stress the need to avoid confusing the articles of the EU and NATO treaties. Article 4 of NATO provides for consultations when an Ally considers its territorial integrity, political independence, or security to be threatened. Article 5, in the event of an armed attack, provides for an obligation by the Allies to assist the attacked state; it does not require an identical and automatic military response from everyone. Article 4 is neither a mandatory prerequisite nor a legal first step toward Article 5.

Article 42(7) of the Treaty on European Union is also an assistance clause in the event of armed aggression against the territory of a member state. It is not, however, a simple equivalent of Article 5: its wording and implementation framework differ, and the treaty specifies that the commitments made under it must remain consistent with those undertaken within NATO, which remains, for its members, the foundation of their collective defense.

Finally, an attack described as “hybrid” is not, by definition, an attack “below the threshold.” The “hybrid” classification does not by itself determine the level of response: the seriousness, effects, and context must be assessed on a case-by-case basis. NATO also explicitly recognizes that certain significant cyberattacks and certain hybrid attacks can constitute an “armed attack” within the meaning of Article 5.

We must therefore not give the adversary the certainty that, because an action is classified as “hybrid,” it will necessarily remain outside our collective defense.

Does Russian espionage within European institutions themselves, particularly the Council of the EU, undermine Europeans’ ability to prepare a response confidentially?

Tsiporah Fried: We have indeed seen a proliferation of cases involving Russian interference in European political networks, notably around German MEP Maximilian Krah and Bundestag member Petr Bystron, as well as broader allegations that payments were made to political figures to promote pro-Kremlin positions. In April 2024, the European Parliament referred to “credible allegations” concerning MEPs who had allegedly received payments to disseminate Russian propaganda.

The case of Vladimir Sergiyenko is also interesting. In December 2024, the Council of the EU sanctioned him, describing him as a former parliamentary assistant to a Bundestag member who had actively collaborated with Russian intelligence agents and used his political and parliamentary access to the detriment of Germany’s democratic process.

This is not proof of penetration of the Council itself, but it illustrates the risks associated with the penetration of European political and institutional networks.

Any penetration of a decision-making system can obviously undermine its effectiveness. Knowing the differences between governments, the options being considered, or the timing of a measure allows an adversary to adapt, circumvent a response, or seek to block it.

However, we must be precise: an espionage attempt, a leak, a suspected compromise, and a proven compromise are not the same thing. I would therefore not present a particular penetration of the EU Council as an established fact without verifiable evidence.

Fundamentally, protection must cover the entire chain: European institutions, national administrations, diplomatic missions, contractors, and communications systems. This requires appropriate security clearances, genuine application of the need-to-know principle, secure communications, and close cooperation with the relevant services.

We must also distinguish what should be public from what should remain confidential. Our determination and objectives should be understandable; our sources, vulnerabilities, and the operational details of a response must be protected.

But a balance must be found. Security must not lead to the paralysis of information-sharing. Intelligence that is so compartmentalized that it never reaches the person who can make a decision or take action also loses much of its value.

Ultimately, the issue is therefore not simply protecting secrecy. It is about building a sufficiently robust chain of trust so that sensitive information can move quickly among those who need to use it, without the adversary being able to exploit its weaknesses.

What does the current intensification of Russian pressure on Europe tell us about the Kremlin’s strategy and timetable?

Tsiporah Fried: My interpretation is that Moscow is seeking to influence European choices by shifting some of the pressure toward the societies and infrastructure supporting the effort on behalf of Ukraine. Several European officials have recently described this campaign as an intimidation effort intended to weaken that support and divide the allies.

These operations can serve several purposes simultaneously: causing damage, forcing Europeans to disperse their resources, feeding a sense of insecurity, and testing their reactions.

The adversary can learn from our detection times, our political hesitations, and our public disagreements.

However, this intensification alone does not allow us to infer a precise timetable for a conventional attack. Some analysts may see it as the consequence of constraints on Russian capabilities; others may see it instead as a way of preparing future options or achieving political effects without opening a direct military confrontation.

We must therefore examine capabilities, preparations, and observable decisions, without turning every incident into evidence of a scenario that has already been written.

Drone incursions illustrate this logic well. The significance of these operations does not lie solely in their immediate effect: they can also allow the adversary to test Europeans’ technical capabilities, decision-making procedures, institutional coordination, and the resilience of public opinion. This is precisely one of the questions raised by recent analyses of Russian drone incursions in Europe.

What seems essential to me is understanding that Russia’s calculations also depend, in part, on the cost we impose on its operations. An operation that is inexpensive and without consequences can encourage repetition. An operation that fails, exposes the networks involved, and generates additional costs can, by contrast, reduce its strategic value.

Russia is conducting a campaign in which its various instruments can reinforce one another, while Europeans have numerous instruments organized along different institutional chains. Our challenge is therefore less to perfectly predict the Kremlin’s intentions than to reduce the benefits it can expect to derive from our vulnerabilities and hesitations.

We do not control the Kremlin’s intentions. We can, however, influence the calculation it faces: make its operations more difficult, more costly, and less likely to produce the desired political effects. That, too, is what makes a European response credible.

Read in Atlantico.