Home » Why Hybrid Operations Against Europe Are Becoming a New Instrument of Strategic Warfare

Why Hybrid Operations Against Europe Are Becoming a New Instrument of Strategic Warfare

The confrontation between Russia and the West is entering a phase in which the distinction between war and peace is becoming increasingly difficult to sustain. Europe is not experiencing conventional warfare on NATO territory, yet European governments are confronting a growing spectrum of activities involving sabotage, cyber operations, espionage, drones, attacks or suspected attacks on critical infrastructure, political interference and information operations. The events of recent weeks have sharpened that concern. Germany has formally attributed an attempted explosive-drone attack at Leipzig/Halle Airport to Russia, while Moscow denies responsibility; German authorities are also investigating separate sabotage incidents affecting electricity infrastructure, with attribution in those cases still unresolved. Baltic Sea states, meanwhile, are moving toward closer cooperation on drone defence amid continuing concerns about hybrid threats to infrastructure.

These developments should not be understood simply as a collection of disconnected security incidents. From a strategic perspective, they point toward the emergence of a contested zone between conventional warfare and conventional peace. Within that zone, states can attempt to impose costs on adversaries, disrupt military logistics, intimidate governments, test political cohesion and influence public opinion without crossing the threshold that would automatically produce a large-scale military response. The strategic value of hybrid warfare lies precisely in this ambiguity: it allows an adversary to generate effects traditionally associated with conflict while complicating the defender’s ability to identify, attribute and respond to the attack.

For The Global Institute for Strategic Studies (GISS), the central question is therefore larger than the protection of individual airports, power stations or undersea cables. Europe is confronting a transformation in the character of strategic competition itself. The conventional battlefield remains crucial, particularly in Ukraine, but the strategic rear supporting that battlefield has become increasingly exposed. European ports, airports, energy grids, railways, defence factories, telecommunications systems and political institutions form part of the wider architecture sustaining Western power. Consequently, pressure against these systems can influence the military balance without requiring a direct confrontation between Russia and NATO.

The strategic challenge is particularly serious because the economics of hybrid warfare often favour the attacker. Modern European societies depend on vast networks containing thousands of vulnerable nodes, while hostile actors need only identify a limited number capable of producing disproportionate disruption. Complete protection is impossible. Deterrence must therefore evolve from the promise of preventing every attack toward the ability to absorb disruption, rapidly restore functionality, attribute hostile actions and impose consequences sufficiently costly to discourage repetition.

The Battlefield Is Expanding Beyond Ukraine

The war in Ukraine has demonstrated that modern military power depends on an enormous infrastructure located far beyond the immediate battlefield. Ukraine’s ability to sustain military operations is supported by logistics, industrial production, financial assistance, intelligence, communications and transportation networks extending deep into Europe. Equipment travels through European ports and railway systems, Ukrainian aircraft and cargo operations use European infrastructure, and European defence industries increasingly contribute to the replenishment of ammunition and military equipment. The strategic rear of the Ukrainian war therefore extends far beyond Ukraine’s borders.

This produces an asymmetry with significant geopolitical consequences. Russia can strike Ukrainian infrastructure directly because Ukraine is a belligerent, but infrastructure located inside NATO countries is protected by the alliance’s collective security framework. Direct Russian military attacks against European territory would therefore involve extraordinary escalation risks. Hybrid operations potentially offer another route: pressure can be applied against the networks supporting Ukraine while actions remain sufficiently ambiguous or limited to complicate a collective military response.

The attempted drone attack at Leipzig/Halle Airport illustrates why this issue has attracted such attention. The airport is not simply a civilian aviation facility; it is also an important freight and NATO logistics hub and hosts Ukrainian Antonov cargo aircraft. Germany has publicly attributed the attempted attack to Russian state involvement, while Russia rejects the allegation. Whatever the wider implications of that attribution dispute, the strategic importance of the target demonstrates how civilian and military logistics increasingly overlap.

The underlying logic extends far beyond airports. A railway junction transporting military equipment can become strategically significant. An electricity substation supplying a defence-industrial region can acquire military relevance. A commercial port capable of receiving allied reinforcements becomes part of NATO’s logistical architecture. Telecommunications networks serving civilian customers may simultaneously carry strategically important data. Modern societies have consequently created an enormous dual-use infrastructure whose civilian and security functions cannot easily be separated.

Hybrid Warfare Is a Strategy of Controlled Ambiguity

Hybrid warfare is sometimes described as warfare below the threshold of war, but this definition understates its strategic sophistication. The objective is not necessarily to avoid war permanently. It is to manipulate uncertainty about where war begins, forcing the opponent to make difficult decisions under conditions of incomplete information.

A missile crossing an international border creates a relatively identifiable event. A suspicious fire at an energy facility does not. A military aircraft entering national airspace can usually be tracked. A commercially available drone launched locally creates a different attribution problem. A large-scale conventional attack produces an obvious political crisis, whereas sabotage can initially resemble criminal activity, technical failure or domestic extremism.

This uncertainty imposes costs on democratic governments. Security services need time to investigate. Prosecutors require evidence. Intelligence agencies may possess classified information that governments cannot immediately reveal. Allies may interpret the same evidence differently. Political leaders must determine whether retaliation is justified and whether it could produce uncontrolled escalation.

The attacker therefore gains something strategically valuable: time and ambiguity. Even when responsibility is eventually established, the political moment for retaliation may have changed. Public attention may have shifted, evidence may remain contested and allies may disagree about the appropriate response.

Hybrid warfare consequently targets decision-making systems as much as physical infrastructure. Its effectiveness depends not only on the damage caused but on the hesitation it creates.

Sabotage Can Become Strategic Without Becoming Catastrophic

A common mistake in analysing infrastructure attacks is to measure their significance according to immediate physical damage. Hybrid operations do not necessarily require spectacular destruction. Their strategic value can emerge through accumulation.

One damaged cable may be repaired. One airport closure may last only several hours. One electricity incident may not cause a major blackout. Yet dozens of incidents occurring over time can change government behaviour. Security expenditures increase, intelligence resources are diverted, businesses face higher costs, infrastructure operators introduce expensive protective measures and public anxiety grows.

The economic asymmetry is considerable. Europe cannot permanently guard every kilometre of railway, every electrical transformer, every telecommunications facility, every port and every undersea cable. An attacker does not need to target all of them. It needs to identify vulnerable nodes where relatively limited actions can impose disproportionately large defensive costs.

Recent incidents in Germany illustrate the broader vulnerability even where responsibility remains unknown. Authorities are investigating two electricity-grid sabotage cases within twenty-four hours, including an incident near Bergheim that temporarily removed several lignite generation units with a combined capacity of 4,200 megawatts from the grid, although overall grid stability was maintained. In Brandenburg, specially designed devices containing conductive material damaged high-voltage infrastructure, while officials said investigations remained at an early stage and did not exclude either foreign involvement or domestic extremism.

The analytical distinction is essential. Suspicious infrastructure incidents should not automatically be attributed to Russia or any other foreign state. Doing so without evidence would itself create strategic vulnerability by allowing accidents or domestic criminal acts to generate international escalation. Yet the absence of immediate attribution does not reduce the importance of the underlying vulnerability. A system capable of being disrupted cheaply is strategically vulnerable regardless of who ultimately conducts the attack.

Russia and NATO Are Operating Inside an Escalation Paradox

The deeper issue is an escalation paradox created by nuclear deterrence and NATO’s conventional military strength. Direct large-scale conflict between Russia and NATO would carry potentially catastrophic consequences for both sides. That creates powerful incentives to avoid overt military confrontation. Yet those same incentives can make operations below the threshold of conventional war more attractive.

The stronger deterrence becomes at the highest levels of escalation, the more competition may migrate downward.

Cyber operations, sabotage, espionage, disinformation, proxy activity, economic pressure and political interference become instruments through which adversaries can continue strategic competition without deliberately triggering direct military conflict. This does not mean escalation becomes impossible. It means escalation becomes harder to interpret.

The danger is that repeated low-level operations can gradually alter assumptions about acceptable behaviour. Actions initially considered extraordinary can become normalized. Governments adapt to one level of pressure, encouraging adversaries to test the next. The threshold between hybrid confrontation and conventional conflict can therefore erode incrementally rather than through one dramatic decision.

This is why hybrid warfare should not be viewed as a less dangerous alternative to conventional warfare. Under certain conditions, it can become an escalation pathway toward it.

The Drone Revolution Has Changed the Cost of Strategic Disruption

The proliferation of inexpensive drones is accelerating this transformation. For decades, the ability to attack strategically important infrastructure from the air required sophisticated military capabilities. Aircraft, cruise missiles and ballistic missiles were expensive, technologically demanding and generally attributable to state actors.

Small unmanned systems have changed that equation.

A relatively inexpensive drone can conduct surveillance, map security procedures, approach sensitive facilities or potentially carry an explosive payload. It may be launched from a vehicle, private property or another location inside the target country, making traditional air-defence concepts less effective.

Europe’s security institutions are beginning to respond. Baltic Sea countries are planning closer cooperation through a drone-defence task force intended to accelerate information exchange and responses to hybrid threats. The initiative follows years of concern surrounding suspicious incidents involving undersea cables, pipelines and other critical infrastructure in the Baltic region.

The military implications are substantial. Air defence can no longer focus exclusively on protecting national airspace against aircraft and missiles arriving from distant launch points. States must increasingly consider threats originating inside their own territory.

This collapses another traditional distinction: the boundary between external defence and internal security.

Police, intelligence agencies, military forces, border authorities and private infrastructure operators must now cooperate against threats that may simultaneously possess domestic and international dimensions.

The Baltic and Arctic Are Becoming Hybrid Frontiers

Geography remains important even in a conflict defined by ambiguity. The Baltic Sea and High North are particularly exposed because they combine military importance, dense infrastructure networks and proximity to Russia.

The Baltic contains electricity connections, telecommunications cables, ports and energy infrastructure essential to northern Europe. Eight NATO countries border the sea alongside Russia. Suspicious incidents affecting cables and pipelines since 2022 have consequently produced growing concern about infrastructure security, maritime surveillance and attribution.

The Arctic presents a different but related challenge. Norway’s security service warned in its 2026 threat assessment that it expects increased Russian espionage activity, particularly in northern Norway, and potential sabotage connected to Norwegian support for Ukraine. Norwegian authorities are also concerned about reconnaissance of critical infrastructure along the country’s coastline.

Norway’s importance extends beyond its NATO membership. Following the collapse of much of Europe’s previous energy relationship with Russia, Norwegian gas infrastructure acquired greater strategic significance for European energy security. Energy facilities in the North Sea and Norwegian Sea therefore sit at the intersection of economic security, alliance security and geopolitical competition.

The Baltic-Arctic corridor is consequently emerging as one of the world’s most important hybrid-security environments. It contains the infrastructure linking North America and Europe, energy systems, military facilities and maritime routes while simultaneously sitting close to major Russian military concentrations.

Critical Infrastructure Is Becoming Strategic Terrain

Traditional military geography is dominated by territory: mountain passes, rivers, ports, airfields and transportation corridors. Twenty-first-century strategic geography increasingly includes networks.

Electricity grids are networks. Telecommunications systems are networks. Financial systems are networks. Cloud infrastructure is a network. Global shipping is a network. Supply chains are networks.

The strategic characteristic of networks is that their importance does not necessarily correspond to physical size. A small component can become critical because numerous other systems depend upon it. Modern economies have therefore produced strategic chokepoints that may be almost invisible during normal conditions.

This transforms infrastructure mapping into a form of strategic intelligence. Understanding where energy, communications, logistics and defence networks intersect can reveal points at which limited disruption would generate cascading consequences.

Protecting those intersections should become a priority for NATO states. But protection cannot mean attempting to make every system invulnerable. Such an objective would be economically impossible and strategically unrealistic. The correct objective is resilience: designing networks so that the destruction or compromise of individual components does not cause systemic collapse.

Cyber and Physical Warfare Are Converging

Another major transformation is the disappearance of the boundary between cyber and physical security. Industrial infrastructure is increasingly controlled through digital systems. Energy grids, ports, factories, telecommunications networks and logistics facilities depend on interconnected software, sensors and automated control technologies.

This creates enormous efficiencies while simultaneously expanding attack surfaces.

A cyberattack can produce physical consequences without explosives. Physical access can facilitate cyber intrusion. Drones can perform reconnaissance before sabotage. Compromised employees can provide access to both digital and physical systems.

Future hybrid campaigns are therefore unlikely to remain confined to one domain. A sophisticated operation might begin with cyber reconnaissance, continue through surveillance of physical infrastructure, employ locally recruited proxies for sabotage and then use coordinated disinformation to exaggerate the resulting disruption.

The physical attack could be the smallest component of the operation. Its psychological and political amplification could produce the greater strategic effect.

Proxy Warfare Is Moving Inside Western Societies

One of the most difficult challenges for European security services is the possibility that foreign intelligence organisations can use local intermediaries rather than their own officers.

Modern digital communications make recruitment easier. Individuals can potentially be contacted, paid or manipulated remotely. Criminal networks can provide logistics. Ideologically motivated actors can be encouraged to conduct operations whose geopolitical implications they may not fully understand.

This creates another layer of plausible deniability.

A person conducting sabotage may not formally belong to a foreign intelligence service. The financial chain may contain intermediaries. Instructions may arrive through encrypted platforms. The relationship between the individual perpetrator and the state benefiting from the operation can therefore become deliberately difficult to prove.

The strategic model resembles proxy warfare but relocates it inside the adversary’s society.

For counterintelligence services, this requires moving beyond traditional espionage detection toward identifying networks connecting foreign intelligence, organised crime, online recruitment and politically motivated violence.

Hybrid Operations Can Target Political Cohesion

Physical infrastructure is only one potential target. The political cohesion supporting European policy toward Ukraine may be strategically more important.

If an adversary cannot defeat NATO militarily at acceptable cost, weakening political willingness to use NATO’s capabilities becomes an alternative strategy.

This can involve amplifying social divisions, exploiting economic grievances, supporting narratives portraying assistance to Ukraine as responsible for domestic hardship and encouraging political forces favouring disengagement.

Infrastructure disruption can interact with these campaigns. A blackout, transport interruption or cyberattack can be framed as evidence that government policies are making citizens unsafe. The operation therefore becomes politically useful even if the physical damage is limited.

This explains why elections represent particularly sensitive periods. Political systems are already experiencing intensified competition, public attention is unusually high and relatively small incidents can influence wider narratives about government competence, national security or foreign policy.

The strategic target may ultimately be not the electrical transformer or railway line that is damaged.

It may be the voter watching the consequences.

The Central Problem for NATO Is the Threshold

NATO’s greatest advantage is the clarity of Article 5 in the event of an unmistakable armed attack. Its greatest difficulty in hybrid confrontation is deciding when a sequence of ambiguous actions becomes sufficiently serious to require collective response.

One act of vandalism clearly does not trigger collective defence. A cyberattack may or may not. An explosive drone at a logistics hub creates a more serious question.

A coordinated campaign targeting electricity grids, communications networks and military logistics simultaneously would create another threshold entirely.

The alliance therefore needs to think in terms of cumulative aggression.

Hybrid warfare should not be evaluated only incident by incident. Ten individually limited operations may collectively constitute a strategic campaign even when no single event reaches the traditional threshold of armed attack.

This requires intelligence fusion across NATO members. Patterns invisible within one country’s investigation may become obvious when incidents across several states are analysed together.

Attribution Must Become a Strategic Capability

The ability to identify responsibility is therefore becoming a form of deterrence.

An attacker who expects to remain anonymous has greater freedom of action. An attacker who expects its networks, intermediaries and methods to be exposed faces higher costs.

Attribution requires combining intelligence, law enforcement, cyber forensics, financial analysis and surveillance. No single institution possesses all necessary information.

International cooperation becomes particularly important because hybrid networks can cross multiple jurisdictions. Financing may originate in one country, instructions pass through another, perpetrators operate in a third and the target lie in a fourth.

Europe and NATO therefore need attribution mechanisms capable of connecting these fragments quickly.

Public attribution should remain evidence-based. False accusations would damage credibility and potentially produce dangerous escalation.

But excessive caution carries risks as well. If governments possess convincing evidence yet remain unwilling to assign responsibility, adversaries may conclude that ambiguity provides permanent protection.

Deterrence Must Extend Below the Threshold of War

The strategic answer cannot be automatic military retaliation. Responding militarily to every suspected hybrid operation would hand adversaries enormous influence over escalation.

But absence of military retaliation must not become absence of consequences.

Hybrid deterrence requires a spectrum of responses. Diplomatic expulsions, financial sanctions, criminal prosecutions, travel restrictions, intelligence disruption, cyber responses and economic measures can impose cumulative costs while maintaining escalation control.

Germany’s response to the Leipzig/Halle case provides an example of this approach. After publicly attributing the attempted drone attack to Russia, Berlin announced measures including diplomatic restrictions, while European officials discussed additional sanctions and collective countermeasures. Moscow denied the accusation and warned against escalation.

The objective should be to create uncertainty for the attacker rather than the defender. A hostile state should not know exactly which consequence will follow a hybrid operation, but it should expect that credible attribution will generate costs.

This is deterrence by accumulated punishment rather than immediate military escalation.

Resilience May Ultimately Matter More Than Retaliation

The strongest deterrence, however, may come from denying hybrid operations their strategic effect.

If electricity is restored rapidly, alternative communications remain available, transportation is rerouted and public institutions continue functioning, sabotage becomes less valuable.

This is deterrence by denial.

Britain’s decision to conduct its largest home-defence exercise in decades in 2027 reflects this broader shift. The exercise is intended to test readiness for scenarios involving cyberattacks, disinformation and sabotage of critical infrastructure, illustrating how European governments increasingly regard domestic resilience as part of national defence.

The lesson is fundamental. A society capable of absorbing disruption is difficult to coerce. Resilience therefore has military significance even when implemented by civilian institutions.

Emergency electricity capacity, redundant telecommunications, alternative railway routes, backup data systems, strategic inventories and effective public communication can all contribute to deterrence.

The Next Strategic Competition Will Be About Systems

The broader transformation extends beyond Europe and Russia. Hybrid warfare reflects a global shift in how major powers compete in an interconnected world.

Modern states are simultaneously stronger and more vulnerable than their predecessors. They possess extraordinary technological capabilities, but their societies depend on complex networks that few governments fully control.

The global economy itself has become strategic terrain. Semiconductor supply chains can be weaponised.

Energy flows can be disrupted. Financial access can be restricted. Telecommunications infrastructure can be compromised.

Satellites can be interfered with. Data centres can become national-security assets. Undersea cables can become geopolitical chokepoints.

The strategic competition of the twenty-first century will therefore increasingly concern the ability to disrupt, protect and rapidly reconstruct systems.

Military power remains essential, but it operates inside a much larger architecture of technological, economic and societal resilience.

The most dangerous assumption Western governments could make is that the absence of conventional warfare on NATO territory means Europe remains fully at peace. The reality is more complicated. Strategic competition is increasingly occurring inside a grey zone in which hostile operations can generate meaningful political, economic and security consequences without crossing the traditional threshold of armed conflict.

Recent developments in Germany and growing concern across the Baltic and wider European security environment indicate how quickly this space can expand. German authorities have attributed the Leipzig/Halle attempted drone attack to Russia, which denies involvement, while separate sabotage investigations demonstrate the broader vulnerability of energy infrastructure even before responsibility has been determined. Europe is responding with stronger counter-drone cooperation, infrastructure protection and preparations for hybrid crises.

For The Global Institute for Strategic Studies (GISS), the strategic conclusion is that the international security system is witnessing the emergence of a new battlespace located between conventional peace and conventional war. Infrastructure, information networks, political institutions, logistics systems and civilian technologies increasingly constitute strategic terrain. The side capable of disrupting these systems can impose significant costs without necessarily deploying conventional forces, while the side capable of absorbing disruption can deny those operations much of their strategic value.

NATO therefore requires more than stronger armies. It requires societies capable of functioning under pressure, intelligence systems capable of connecting apparently isolated incidents, infrastructure capable of surviving disruption and political mechanisms capable of responding without losing escalation control. Conventional deterrence must be complemented by deterrence against ambiguity itself.

The ultimate objective of hybrid warfare is not necessarily to destroy an adversary’s infrastructure. It is to undermine confidence, create uncertainty, increase political costs and gradually weaken the adversary’s willingness to pursue its strategic objectives. That is why the most important defence will not be the ability to prevent every drone, cyberattack or act of sabotage. Such absolute protection is impossible.

The decisive capability will be ensuring that these operations fail to change strategic behaviour.

If NATO and European governments can achieve that, hybrid warfare becomes expensive harassment rather than successful coercion. If they cannot, the West may discover that an adversary does not need to defeat its armies to weaken its power. It needs only to attack the networks connecting those armies to the societies behind them.

In the emerging strategic environment, the rear is becoming the frontline, civilian infrastructure is becoming strategic terrain, and the grey zone itself is becoming a battlefield.

written by: GISS

Privacy & Cockies

We use cookies and similar technologies to enhance your browsing experience, personalize content, and analyze our traffic. By accepting, you consent to our use of cookies. If you reject, only essential cookies will be used