In Europe, a lot of work has been done over the years in preparation for an event that would trigger NATO’s Article 5. But the real challenge is the step beneath NATO’s Article 5. Events such as sabotage, cyberattacks, drones, and even infrastructure attacks can be costly in terms of strategy, yet intentionally ambiguous to make a military collective response difficult.
On September 16, Ursula von der Leyen, the president of the European Commission, unveiled a counter-hybrid playbook and an emergency security protocol to coordinate responses to hybrid incidents that fall below the threshold of conventional military attacks. The plan amounts to an attempt to build a response architecture for precisely this space below Article 5.
Countermeasures are thus becoming more institutionalized and operational, all to answer the question of how Europe reacts collectively to an event that is serious enough to pose a threat to national security, yet too ambiguous and limited to invoke NATO’s Article 5.
The Problem Below Article 5
NATO’s Article 5 remains the cornerstone of collective defense in Europe. But it is the very nature of gray zone operations that makes them appealing because they could be calibrated to stay under the threshold of being considered an attack demanding military response.
The toolbox for such operations is wide. The assessment of hybrid threats by the EU involves cyberattacks, information manipulation by third-party states, sabotage, explosive devices attached to planes, destruction of undersea infrastructure, airspace violations, assassination attempts, and weaponization of migration.
In July 2026, the EU officially stated that the Russian FSB’s 16th Centre was behind the several cyber threat groups and revealed that Russian malicious cyber activities have impacted at least nine EU member states – France, Germany, Poland, Cyprus, the Netherlands, Austria, Slovakia, Romania, and Finland. The listed activities include cyber infiltration of state networks and sabotage of critical infrastructure.
The appeal of such actions is not necessarily that they will be permanently untraceable, but rather that the ambiguity of who is responsible, what their intentions are, and whether there was a reasonable level of force is enough to hold up collective action.
Consultations are offered to NATO states under Article 4 should they perceive a threat to their own security, but consultations do not automatically lead to an action plan. This is precisely where the EU is trying to pick up the slack.
From Individual Incidents to Collective Security
Timing is key on von der Leyen’s proposals. Just two days after they were unveiled, on September 18, President of France Emmanuel Macron issued tougher measures to protect critical infrastructure from the threats posed by the use of drones and cyberattacks, claiming that the hostile hybrid attacks against Europe were escalating. One of the cases considered evidence of the escalation was a failed drone attack near Leipzig airport.
On September 20, intelligence heads in Europe openly claimed that Moscow could conduct its tests on NATO by means of provocations, sabotage, and other activities aimed at taking advantage of uncertainty regarding what actually constituted an armed attack. It should be noted that the intelligence officers did not fully share their opinions on the imminence of this test.
The problem is already materializing in spending plans. On September 22, Lithuania announced that the Gizai electricity substation near the Kaliningrad Russian exclave would be secured from explosive drone attacks and sabotage. Such measures include reinforced fencing, underground sensors, concrete constructions around the critical equipment, and duplication of the systems. Security demands have added €48 million to the cost of the project.
That single project also illustrates a wider funding problem. The Baltic states and Poland previously sought €382 million in EU support for protecting energy infrastructure, but received only €112 million—less than one-third of the amount requested.
Cybersecurity Exposes a Coordination Gap
Similar challenges exist in the digital space. While the EU has allocated about €1.4 billion for cybersecurity, according to a September report published by the European Court of Auditors, information sharing remains insufficient and is still undermining collective cyber defenses.
One illustrative case was mentioned in the report. In September 2025, a ransomware attack was conducted against an aviation technology company, affecting several airports in Europe; however, no affected country reported the case to the cybersecurity agency of the EU.
Most strikingly, until 2026, no “large-scale” cyberattack had been officially reported by an EU member state since 2016, even though the auditors said such incidents had occurred. In July 2026, the European Commission referred to the EU Court of Justice four member states —namely France, Ireland, the Netherlands and Spain—for failure to bring their national legislation into conformity with the EU obligations in information sharing about cybersecurity.
This illustrates one of the vulnerabilities of any future hybrid warfare framework. Europe can create consultation mechanisms, but if information-sharing processes are too slow, political coordination will still lag behind what is operationally required.
An EU emergency mechanism would not supersede NATO; its utility is precisely its ability to act under the threshold where collective military defense becomes the primary concern. An activated mechanism could facilitate rapid intelligence sharing, joint assessments of attribution, cyber assistance, critical infrastructure protection, sanctions coordination, law enforcement cooperation, and other economic and diplomatic actions.
The EU Council acknowledged the problem in March by committing to bolstering the capacity of Europe to prevent, deter, and react to hybrid campaigns “irrespective of their origin, scale and intensity.” The European Parliament has gone even further, demanding a proportional response to Russia’s hybrid activities in the ground, air, sea, and digital realms, including a possible retaliation. This means that European institutions are slowly but surely shifting from resilience to deterrence.
Toward a Layered European Deterrence Model
Institutional coordination will not resolve the most challenging aspect of hybrid warfare: attribution. Not all sightings of drones, failures of infrastructure, or cyber operations against a European target can automatically be attributed to Russia; intelligence assessments can differ, evidence can be classified, and some ostensibly suspicious operations turn out to be disconnected from state activity altogether.
There are two dangers here. A reaction that is insufficiently tough to a known hostile operation can encourage repetition. On the other hand, a collective reaction before responsibility has been sufficiently established risks politicizing intelligence and unnecessarily escalating tensions.
This is why common standards of evidence will be as important as mechanisms of common response. Current EU experience in cybersecurity reveals what happens if there are institutional mechanisms of coordination while the reporting of individual nations differs. A hybrid response system, which fails to build mutual confidence regarding attribution, might result in consultation rather than deterrence.
It seems that Europe is heading towards building its new security architecture, consisting of two layers. The first layer includes national police, intelligence, and cybersecurity agencies. The second would consist of an EU-based mechanism for collective response to hybrid operations threatening national security without being armed attacks. Article 4 of NATO would still be available for consultations on issues of security among allies.
Article 5 would still serve as the guarantee that would prevent any armed aggression towards the members of the alliance. This structure of defense considers the changes in the nature of confrontation with Russia. While the most common form of threat to Europe may not be a massive attack of armored units across the border of NATO, it may be the use of drones, sabotage, cyberattacks, and many others that would create pressure without resorting to conventional warfare.
The issue is that Europe should agree beforehand about what will happen after the threshold is crossed. Without such agreement, the counter-hybrid approach may become nothing but a consultation tool again. If an agreement is reached, Europe will start to close one of the biggest security gaps after the Cold War period. Europe has defined already what will happen in case of an armed attack; now its task is to define what will happen before that.
https://www.geopoliticalmonitor.com/eu-hybrid-threat-response-below-article-5/


