Europe’s response to Russian hybrid threats: What is changing for critical infrastructure?
Europe is treating threats to cables, transport links and other critical infrastructure more collectively, but it has not declared every suspected act of sabotage an attack on the whole alliance. NATO is coordinating surveillance in the Baltic Sea, while the European Union is pressing for stronger intelligence-sharing, faster responses and investment in cable protection. Those steps have gained significance after Denmark’s defence intelligence service warned on September 24, 2026, that Russia was likely to intensify its hybrid campaign against NATO and the West in the coming months.
What prompted the sharper response?
The Danish Defence Intelligence Service said it expected more frequent Russian hybrid attacks with potentially greater consequences for the countries targeted. Its assessment identified destructive cyberattacks that could disrupt essential services and sabotage carrying a high risk of casualties as possible forms of escalation. This was a forecast, not an announcement that such an attack had occurred.
The service separately assessed a low but growing risk of a limited Russian military attack on one or more NATO countries bordering Russia. It said an outright invasion remained highly unlikely and that it saw no indication one was being prepared. Keeping those judgments distinct matters: the warning about hybrid activity is stronger than its assessment of the likelihood of a conventional invasion.
European institutions have also become more explicit about what needs protecting. In a resolution adopted on September 16, the European Parliament identified energy, transport, communications, satellite and maritime infrastructure, including submarine cables, as potential targets of hybrid operations. It urged member states to share more intelligence and asked EU institutions to examine whether existing rules adequately address hostile acts that fall below the threshold of armed conflict.
What does a collective response look like?
At sea, NATO’s Baltic Sentry activity brings together allied naval and surveillance capabilities to improve the detection of threats to undersea infrastructure. Launched in January 2025 after a series of Baltic infrastructure incidents, it uses assets including frigates, maritime patrol aircraft and naval drones. NATO is also working to combine national surveillance information so allies can identify and respond to potential threats more quickly.
On the EU side, the emphasis is broader than patrols. The bloc has tools for coordinating a response to hybrid campaigns, including measures to identify responsible actors and impose sanctions where warranted. In March 2026, EU governments called for stronger use of those tools and greater protection of critical infrastructure. EU foreign policy chief Kaja Kallas told lawmakers in September that member states needed to make better use of shared intelligence and said work was under way to build international cooperation on seabed protection.
The European Commission has also set out a Cable Security Toolbox and priority projects intended to reduce vulnerabilities in submarine data and power links. It allocated €347 million for strategic submarine-cable projects over 2026 and 2027, including work on monitoring and repair capacity. A Baltic-focused pilot aims to make emergency cable repairs faster. These measures address a practical problem: a damaged link must be detected, its traffic or power supply managed where possible, and the physical infrastructure repaired, whatever investigators ultimately determine caused the damage.
Why is attribution still important?
“Hybrid” describes a range of methods that can include sabotage, cyberattacks, interference and coercion. An outage or a severed cable does not, by itself, establish who caused it or whether damage was deliberate. Investigators must distinguish a hostile act from an accident or technical failure before governments can credibly assign responsibility and choose a proportionate response.
European officials have accused Russia of conducting a wider hybrid campaign against countries supporting Ukraine. Russia’s responsibility for any particular infrastructure incident, however, cannot be inferred solely from that broader accusation. The Danish assessment concerns the risk of further attacks; the EU’s and NATO’s protective measures are intended to improve readiness across more than one possible type of threat.
Nor does a coordinated patrol or an EU sanctions decision mean NATO’s Article 5 collective-defence clause has been invoked. NATO says a serious cyber or other hybrid attack could qualify as an armed attack, but allies would assess that question case by case. For now, the visible shift is toward acting together earlier: pooling intelligence, watching vulnerable routes, preparing repairs and preserving the ability to respond once the facts of an incident are established.

